Privacy Policy
Last updated: July 28, 2026 · Effective: July 28, 2026
1. Introduction & Scope
Pretty Things Online Inc (“IslaFans,” “we,” “our,” or “us”), a Delaware C corporation, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website, platform, applications, and related services (collectively, the “Services”).
This Policy applies to all users of the Services, including visitors, registered fans, and verified creators. By using the Services, you agree to the collection and use of information in accordance with this Policy. If you do not agree with the terms of this Policy, please discontinue use of the Services immediately.
This Privacy Policy is incorporated into and forms part of our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.
2. Information We Collect
2.1 Information You Provide Directly
- Account information: name, email address, date of birth, username, and password (stored as a cryptographic hash — we never store your plaintext password).
- Profile information: display name, profile photo (avatar), biography, location, and other optional profile details you choose to share.
- Payment information: billing address, and the last four digits and type of your payment card. Full card numbers and CVVs are transmitted directly to and stored by our payment processors — CCBill and Segpay for card payments, and NOWPayments for cryptocurrency payments — and are never held on IslaFans servers.
- Identity & age verification data: for creators, managers, recruiters, and affiliates who verify their own account, and separately for every performer depicted in explicit content on the platform (not only the uploading creator, as required by 18 U.S.C. § 2257): your legal name and date of birth, front-and-back images of a government-issued photo ID, a real-time selfie, a five-second liveness-detection video (an arrow-guided head-turn recording), and, for performers, a digitally signed consent release identifying the content you authorized. See § 2.4 below for exactly how each of these is used, protected, shared, retained, and eventually destroyed, and our § 2257 Compliance Statement for the full record-keeping program.
- Content you upload: photographs, videos, audio, written posts, and other materials submitted to the platform.
- Communications: direct messages between creators and fans, support tickets, and other correspondence with IslaFans.
- Tax information: for creators, W-9 or W-8 forms and related tax identification data required for payment reporting.
2.2 Information Collected Automatically
- Usage data: pages visited, content viewed, features used, session duration, clicks, and other interaction data.
- Device and technical data: IP address, browser type and version, operating system, device identifiers, screen resolution, and referring URL.
- Log data: server logs including timestamps, access requests, and error information.
- Cookies and similar technologies: we use cookies, local storage, and similar technologies as described in our Cookie Policy.
2.3 Information from Third Parties
- Payment processors: CCBill, Segpay, and NOWPayments may each provide us with transaction identifiers, payment status, and fraud signals.
- Identity verification vendor: Didit (didit.me), the vendor we use for account-level identity and age verification, provides us with the decision (approved/declined), and the legal name, date of birth, and document data extracted from your ID, from the verification session you complete on their platform.
2.4 Identity & Age Verification Records
This section explains, for the identity and age verification data described in § 2.1 above (ID images, legal name, date of birth, selfie, liveness video, and signed consent release), exactly how we use, protect, share, retain, and eventually destroy it. This data is collected in two distinct ways, and it is important to understand which applies:
- Account verification (creators, managers, recruiters, affiliates): handled through a hosted verification session with our vendor, Didit. Didit collects your ID images, selfie, and liveness check directly on its platform and returns a decision plus the extracted legal name and date of birth to us; this decision is generally automated by Didit, though our records also support a manual override by an IslaFans reviewer.
- Performer records (18 U.S.C. § 2257): every person depicted in explicit content — not only the account holder — must have a verified performer record and signed consent release before that content can publish. This verification is not outsourced to a KYC vendor — the performer (or, for a one-off collaborator without their own account, the producing creator on their behalf) submits legal name, date of birth, ID images, a selfie, and, where completed through our own verification flow, a five-second liveness video and a typed e-signature, and a member of our Trust & Safety team manually reviews and approves the record before any content depicting that person can go live. See our § 2257 Compliance Statement for the full program, including the publication hold and cross-record duplicate/match review.
Purpose
Date of birth confirms you are 18 or older; ID images and legal name establish your legal identity for our records; the selfie and liveness video confirm the person completing verification is a real, present person who matches the ID; and the signed consent release documents that the performer authorized the specific content in question, its distribution rights, and the date of consent. We use this data solely for age/identity verification, § 2257 record-keeping, fraud prevention, and responding to law enforcement or NCMEC obligations — never for advertising or profiling.
Access restrictions
Access is restricted to IslaFans staff who need it to review, moderate, or respond to a legal request — not company-wide. Every admin view, search, or export of a performer or production record is logged (who, when, what) in a permanent access log, and ordinary account deletion cannot remove these records; only a designated senior administrator can approve a purge, and only after the retention period below has passed.
Encryption
ID document numbers, images, selfies, liveness videos, and other sensitive fields are encrypted with AES-256 at the application layer before storage, in addition to encryption in transit (TLS) and at rest. Document and video files are stored in a private cloud storage bucket that is never publicly accessible — not the same bucket used to serve public profile photos or content.
Sharing
Didit processes account-level verification data as our vendor, under contract, solely to perform the verification we request. We do not sell this data or share it for advertising. We disclose it only where legally required — for example, to NCMEC and law enforcement if content is found to depict a minor (18 U.S.C. § 2258A), or in response to valid legal process, or to the extent 28 C.F.R. § 75.5 requires making § 2257 records available for inspection by the Attorney General.
Retention
Account-level identity/age verification records (the Didit-based check) are retained for five years. Performer records, consent releases, and production records under § 2257 are retained for the greater of seven years from the date the content was last offered for sale or distribution, or two years after the last production date, in accordance with 28 C.F.R. § 75.2. Records subject to a pending legal or NCMEC matter are retained until that matter is resolved, regardless of these timeframes (see § 5).
Destruction
These records cannot be deleted through ordinary account-deletion requests. Once the applicable retention period above has passed and no legal hold applies, a designated senior administrator must separately review and approve a purge before the underlying files and database records are deleted.
2.5 Biometric Information Notice (Illinois BIPA / Texas CUBI / Washington biometric privacy law)
Your selfie image, liveness-detection video, and the facial-geometry comparison we run between identity photos (see § 4, Amazon Web Services (Rekognition)) are “biometric identifiers” or “biometric information” under these and similar state laws. This notice explains how we handle that specific data, in addition to everything already described above:
- Purpose: we collect and use this data solely for identity and age verification, fraud prevention, and § 2257 duplicate-record checks, as described in § 2.4. We do not use it for advertising, profiling, or any purpose unrelated to verification and compliance.
- Written consent: we obtain your written consent before any biometric identifier or biometric information is captured — either through the verification session hosted by our vendor Didit (account-level verification), which presents its own consent disclosures before capturing your selfie or liveness video, or through the typed attestation and e-signature step in our own verification flow used for § 2257 performer records.
- No sale or profit: we do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information, and we do not disclose them to any party beyond the processors named in § 4 or as required by law.
- Amazon Rekognition specifically: our face-comparison checks call Rekognition's stateless
CompareFacesAPI — we do not use Rekognition's face-collection/indexing features, so AWS does not persistently store your image or a facial vector after returning the comparison result to us. - Retention schedule and destruction: we do not collect or retain biometric identifiers or biometric information for any purpose beyond identity/age verification and § 2257 record-keeping. It is retained only for as long as, and destroyed by the same process as, the records described in § 2.4 above — five years for account-level verification, or the greater of seven years / two years past last production for § 2257 performer records. Those periods are themselves required by 28 C.F.R. § 75.2 and our own age-verification program, which is the statutory exception these biometric privacy laws provide for data retained pursuant to a legal obligation.
If you are a resident of Illinois, Texas, Washington, or another state with a biometric privacy law, and have questions about our biometric data practices or wish to exercise any right available to you under that law, contact privacy@islafans.com.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing and operating the Services: creating and managing your account, enabling content sharing, processing payments, and delivering core platform features.
- Processing transactions: completing subscriptions, tips, pay-per-view purchases, and creator payouts.
- Communication: sending transactional emails (receipts, security alerts, account notices) and, with your consent, marketing communications and product updates. You may opt out of marketing emails at any time.
- Safety and fraud prevention: detecting, investigating, and preventing fraudulent transactions, abuse, and violations of our Terms of Service.
- Legal compliance: complying with applicable laws and regulations, including 18 U.S.C. § 2257 record-keeping, tax reporting, and responding to valid legal process.
- Analytics and improvement: understanding how users interact with the Services to improve performance, features, and user experience.
- Customer support: responding to your inquiries and resolving disputes.
- Personalization: tailoring your experience, including content recommendations and platform customizations.
We process your personal data on the following legal bases: (a) performance of a contract with you; (b) your consent, where applicable; (c) compliance with a legal obligation; and (d) our legitimate interests, where not overridden by your rights.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Services. When you close your account, we will delete or anonymize your personal information within 90 days, subject to the following exceptions:
- Legal holds and NCMEC/CyberTipline reports: information subject to a pending legal proceeding, government investigation, or regulatory requirement, and any report we make (or evidence underlying it) to the National Center for Missing & Exploited Children under 18 U.S.C. § 2258A, is retained indefinitely while that matter is open, and is never deleted through an ordinary account-deletion request regardless of how much time has passed.
- 18 U.S.C. § 2257 performer records: identity records, consent releases, and production records for performers depicted in explicit content are retained for the greater of seven years from the date the content was last offered for sale or distribution, or two years after the last production date, in accordance with 28 C.F.R. § 75.2. See § 2.4 for how these records are protected and eventually destroyed.
- Account/age verification records: the identity verification data collected when you verify your own creator, manager, recruiter, or affiliate account (see § 2.4) is retained for five years.
- Financial records: payment and transaction records are retained for at least 7 years to comply with tax and financial regulations, and to investigate and prevent fraud and chargebacks.
- Safety records: records of account violations, bans, and related safety actions may be retained indefinitely to prevent circumvention of safety measures.
6. Security
We implement reasonable and appropriate technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption of data in transit using TLS (Transport Layer Security);
- Encryption of sensitive data at rest;
- Access controls limiting employee access to personal data on a need-to-know basis;
- Regular security assessments and vulnerability scanning;
- PCI-DSS compliant payment processing through our processors, CCBill and Segpay.
No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security. In the event of a data breach that is likely to result in harm to you, we will notify affected users in accordance with applicable law.
7. Children's Privacy
The Services are strictly for users 18 years of age or older. IslaFans does not knowingly collect, solicit, or use personal information from individuals under the age of 18. Our platform is designed with an age verification gate and requires date-of-birth confirmation at registration.
In compliance with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, we do not knowingly collect personal information from children under 13 years of age. If we discover that we have inadvertently collected personal information from a person under 18, we will immediately delete that information and terminate the associated account.
If you believe we may have collected information from a minor, please contact us immediately at privacy@islafans.com.
8. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
Right to Know / Access
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of collection, the purposes for collection, and the categories of third parties with whom we share your information.
Right to Delete
You have the right to request deletion of personal information we have collected about you, subject to certain exceptions (e.g., information needed to complete a transaction, detect security incidents, or comply with legal obligations).
Right to Correct
You have the right to request correction of inaccurate personal information we maintain about you.
Right to Opt Out of Sale or Sharing
IslaFans does not sell or share your personal information with third parties for cross-context behavioral advertising. We will update this Policy if our practices change.
Right to Limit Use of Sensitive Personal Information
You have the right to direct us to limit the use and disclosure of sensitive personal information — including government ID numbers, financial account information, and biometric information processed to uniquely identify you (the selfie images, liveness-detection videos, and facial-geometry comparisons described in § 2.5) — to what is necessary to perform the Services or as otherwise permitted by law. Because this biometric data is collected solely for identity/age verification and § 2257 record-keeping, which are themselves necessary to perform the Services and comply with legal obligations, we already limit its use to those purposes by default; see § 2.5 for the specific consent, retention, and no-sale commitments that apply to it under Illinois BIPA, Texas CUBI, and Washington's biometric privacy law.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights.
How to Submit a Request
If you are logged in, the fastest way to submit a request is through your Privacy & Data Requests page. You can also submit a verifiable consumer request by emailing us at privacy@islafans.com with the subject line “California Privacy Request.” We will respond within 45 days of receiving a verifiable request. We may extend this period by an additional 45 days where reasonably necessary, with prior notice to you.
We may ask you to verify your identity before processing your request. You may designate an authorized agent to submit requests on your behalf by providing written authorization.
9. Your Choices & Rights
- Data export, correction, and account deletion: submit any of these requests directly from your Privacy & Data Requests page (or by emailing privacy@islafans.com if you cannot log in). Each request is tracked with a target response deadline: we aim to complete export and correction requests within 45 days, and account deletion requests within 90 days, subject to the retention exceptions described in Section 5.
- Profile corrections: you can update most of your information (display name, bio, profile photo, and similar) directly and immediately through your account settings. For information you cannot edit yourself — such as the legal name or date of birth on file from identity verification — submit a correction request as described above.
- Appeals: if enforcement action was taken against your account or content in error, you may appeal within 30 days of the notice as described in our Community Guidelines. We aim to respond to appeals within 5 business days.
- Email opt-out: you may unsubscribe from marketing emails by clicking the “Unsubscribe” link in any marketing email or by contacting us at privacy@islafans.com. Note that transactional emails (e.g., receipts, security alerts) cannot be opted out of while your account is active.
- Cookie preferences: you may manage your cookie preferences through our Cookie Consent banner, the “Cookie Settings” link in the footer of any page, or your browser settings. See our Cookie Policy for details.
10. International Transfers
IslaFans is based in the United States and our servers are located in the United States. If you access the Services from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your country or jurisdiction.
By using the Services, you consent to the transfer of your information to the United States and acknowledge that your information may be subject to disclosure under US law, including lawful requests by US government authorities.
11. Do Not Track
Some browsers offer a “Do Not Track” (DNT) signal that transmits a preference not to be tracked across websites. IslaFans does not currently respond to DNT signals from browsers, as there is no uniform industry standard for how such signals should be interpreted.
We do not use cross-site tracking for advertising purposes. For more information on managing tracking technologies, please see our Cookie Policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' advance notice via email to your registered address or through a prominent notice on the platform. Non-material changes may be made without prior notice, though we will update the “Last updated” date at the top of this Policy.
Your continued use of the Services after the effective date of any changes constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy team:
Pretty Things Online Inc — Privacy Team
A Delaware Corporation
8 The Green #STE A, Dover, DE 19901
Email: privacy@islafans.com
General Support: support@islafans.com
This Privacy Policy was last updated on July 28, 2026. Prior versions are available upon request.