Privacy Policy
Version 2026-07-22.2 · Prelaunch review dated July 22, 2026
Masque minimizes identity data while requiring an independent adult and identity check. You are pseudonymous to other members, not anonymous to Masque's service providers or valid legal process.
Information Masque processes
- Account and security: email address, account identifiers, session and device records, authentication level, network addresses, approximate city, region, and country derived from those addresses, user-agent records kept for security, abuse prevention, and lawful requests, and abuse-prevention events.
- Profile and social activity: handle, mask or avatar, verified gender marker and age band when available, optional self-described pronouns or profile wording, interests, connections, blocks, requests, groups, salons, rooms, messages, and media.
- Limited verification attestation: provider, status, adult result, document-derived marker, age band, workflow and session references, timestamps, consent version, and provider risk or account state.
- Creator and transaction data: offerings, orders, entitlements, subscriptions, charges, refunds, disputes, balances, payout details, and tax records when paid features are active.
- Safety and support: reports, takedown requests, selected content and context, content hashes, moderator decisions, appeals, legal holds, access logs, support correspondence, and external-report references.
- Product telemetry: limited events needed to understand reliability, verification completion, abuse, and feature performance.
Identity and document-gender verification
The configured verification provider processes identity documents, selfie and liveness signals, face comparison, and related verification data on its systems. Masque does not intentionally copy the raw document, verification selfie, biometric template, legal name, or exact birth date into its own application database. Provider retention and deletion are also governed by the provider's terms, configured workflow, and applicable law.
Masque retains a limited private attestation. The document-derived gender marker associated with an approved verification is also used for the member's gender-based verified badge and discovery inside Masque. It is not editable by the member. Optional pronouns and other profile wording may be self-described, but cannot change that badge.
Missing, unsupported, or conflicting markers enter a correction, review, appeal, or reverification path. Masque does not infer a verified marker from appearance, conversation, profile text, or user metadata.
How information is used
- Provide authentication, verification, messaging, discovery, groups, salons, media access, purchases, subscriptions, support, and payouts.
- Enforce the verified-only door, account integrity, one-person operation, member choices, and policy rules.
- Quarantine, scan, classify, restrict, deliver, remove, preserve, and audit media and safety evidence.
- Process transactions, refunds, disputes, taxes, creator earnings, fraud controls, and financial reconciliation.
- Comply with legal obligations, valid legal process, emergency requests, recordkeeping, and required reports.
- Maintain, debug, measure, and improve service reliability and safety.
Messages, media, and safety evidence
Messages and media are stored to deliver the service. When uploads are enabled, new media is private and quarantined until server-side safety checks and required evidence preservation complete. Browser-side image re-encoding may remove common metadata, but it is not a promise that every identifying detail or metadata field is removed. Members should inspect what is visible before sharing.
A report may preserve the exact selected item, a limited context snapshot, content hashes, and relevant audit data in a restricted case. Ordinary closed-case evidence is not eligible for automated purge before its retention deadline, which begins no sooner than 14 days after closure. Higher-risk material may begin with a longer period. Appeals, suspected child sexual abuse material, intimate-image removal, fraud, payment disputes, external reporting, legal holds, or other legal obligations may extend retention.
Authorized safety administrators must use an MFA-authenticated session to open retained media, and each view creates an audit record. A legal hold does not expire automatically. Independent approval is required to release a hold before ordinary purge can resume.
Payments and creators
When paid features are enabled, approved processors and payout providers receive the details needed to authorize, settle, refund, dispute, screen, and report a transaction. Masque should store processor references and limited display details, not raw card numbers. Creator onboarding may require legal identity, address, taxpayer, banking, sanctions, and age-record information that is not public to members.
Who receives information
Masque uses providers for authentication, hosting, database and storage, identity verification, email, analytics, content safety, support, payments, payouts, fraud controls, and legal operations. Each receives information needed for its role. Masque may also disclose information when reasonably necessary to protect a person, investigate abuse, comply with valid legal process or a reporting duty, enforce agreements, or complete a corporate transaction subject to appropriate safeguards.
Public and member-visible information
Accounts begin private and excluded from Discovery and member search. If you turn on Find and be found, other verified members who also opted in may see your handle, avatar, permitted profile fields, and verified badge in Discovery or handle search and may request a chat. Turning it off does not delete likes, requests, friends, chats, or memberships. Discovery is not required to use invitations or chats, act on an existing request, or join groups, salons, or rooms. Participating in a shared space intentionally makes your profile and the content you share visible to that audience. No access control makes screenshots or external recording impossible.
Account and security settings show you the device, approximate location, network address, and time associated with your own recent sign-ins so you can recognize and revoke access. Other members cannot see that sign-in information. Approximate network location may be wrong or reflect a VPN, mobile carrier, relay, or other network intermediary.
Retention and deletion
- Active account, profile, message, and media data remains while needed to provide the service or until deletion, subject to other retention categories.
- Current operations retain the limited verification attestation during the account and for up to 10 years after closure or the latest related enforcement need, subject to final counsel review and any shorter or longer legal requirement.
- Sign-in and verification network-address records and their approximate city, region, and country are retained for up to 12 months, unless an open safety case or legal hold requires longer.
- Transaction, policy-acceptance, tax, payout, fraud, and dispute records remain for the applicable accounting, processor, tax, and legal periods.
- Closed public support intake contact and free-text fields are scheduled for redaction after 30 days unless another obligation or safety case requires preservation.
- Backups age out on their own protected schedule and are not restored except for disaster recovery.
Settings → Delete account immediately makes the account inactive, excludes it from Discovery and search, hides the public Masque profile, and starts a 28-day recovery window. During that window, signing in with the same account can restore it; Discovery remains off after restoration. After the window, ordinary profile, message, media, and account data is permanently deleted through the deletion worker. Limited records described above may remain. Deletion does not erase another person's independent message copy or a record Masque must retain.
Analytics and cookies
Masque uses essential cookies or local storage for authentication, security, preferences, and service operation. Current product analytics are configured without session replay or automatic interaction capture. If optional analytics or advertising technologies are introduced, this policy and any required consent controls must be updated first.
Security and international processing
Masque uses access controls, row-level authorization, private storage, encryption in transit, privileged-session checks, audit logs, and retention limits. No system is perfectly secure. Providers may process data in countries other than yours, subject to their contractual and legal transfer mechanisms.
Your choices and requests
You can change permitted profile fields, manage messages and memberships, block people, keep your account excluded from Discovery and handle search, cancel subscriptions, download information where offered, and request account deletion. Depending on where you live, you may also have rights to access, correct, delete, restrict, object, or receive a portable copy of certain data, and to appeal a privacy decision. Submit a request through support. Masque may verify the requester and retain evidence of the request and response.
Children
Masque is strictly for adults and is not directed to anyone under 18. Suspected underage access or sexual content involving a minor should be reported immediately without downloading, copying, or forwarding the material.
Changes and contact
Material changes receive a new version and effective date. Masque may require renewed acceptance before continued use of verification, creator, purchase, or subscription features. Contact support for privacy questions or requests.