Legal

Privacy Policy

Effective 14 July 2026GDPR · ePrivacy

Privacy is the point. We collect the minimum we need to run the service, we never train AI on your content, and we never sell your data. With your consent, we use product analytics to understand what works and where the product breaks. This policy explains exactly what we process, why, and the rights you have under the GDPR.

Data controller

Feral Signal Limited, 20 Harcourt Street, Dublin 2, D02 H364, Ireland (company no. 814597) is the controller of your personal data. Contact our privacy team at privacy@generateporn.ai.

1.What we collect

Your private gallery does not become public automatically. Only a generation you explicitly submit and staff approve appears in the Prompt Library. A published entry shows the approved output, prompt snapshot, selected settings, model details, tags, aggregate activity counts, and your chosen attribution. It never displays your account email or internal user ID. Individual saves, votes, reports, internal moderation notes, and support tickets are not published.

2.What we never do

3.Why we process data & legal bases

PurposeLegal basis (GDPR Art. 6)
Create your account & provide the servicePerformance of a contract (Art. 6(1)(b))
Process generations & manage CreditsPerformance of a contract (Art. 6(1)(b))
Run community profiles, submissions, saves, votes, reports & remix attributionContract, your explicit publication request & legitimate interests (Art. 6(1)(b),(f))
Operate Wiki sign-in, drafts, review & revision historyContract & legitimate interests (Art. 6(1)(b),(f))
Answer and manage support requestsContract & legitimate interests (Art. 6(1)(b),(f))
Process payments & keep financial recordsContract & legal obligation (Art. 6(1)(b),(c))
Security, fraud & abuse preventionLegitimate interests (Art. 6(1)(f))
Enforce safety policies & report illegal contentLegal obligation & legitimate interests (Art. 6(1)(c),(f))
Optional product analytics and conversion attributionConsent (Art. 6(1)(a))
Service & policy notificationsContract / legitimate interests

4.Who processes data for us

We use internal systems and a small set of external services to run the product. Each system is configured to receive only the data needed for its function:

ServicePurposeData
Better AuthAuthentication, account management & first-party OAuth/OIDC for the Community WikiEmail, auth identifiers, and the minimum account claims needed for sign-in and attribution
Hosting and storage servicesHosting, edge delivery, database & media storageAll service data, at rest & in transit
PikaPodsManaged hosting for the Community Wiki (Wiki.js) and Support Centre (FreeScout)Wiki identity claims and contributions; support email, ticket content, supplied account or job references, and support attachments
Support mailbox serviceReceiving and replying to support tickets handled in FreeScoutEmail address, message headers, ticket content, and email attachments
AI generation systemRunning your generationsPrompt & generated media for the job
Payment processorsCard payments for Credit packs and memberships; cryptocurrency payments for Credit packs and membershipsBilling contact and address data, transaction metadata, membership-term metadata for card and crypto memberships, full card details handled by the processor, and cryptocurrency wallet addresses and transaction data needed to complete a Credit-pack payment
PostHogConsent-gated app product analytics, page views, feature usage and reliability signalsDevice/browser data, app page and event data, approximate location, in-memory pseudonymous identifiers

Wiki.js and FreeScout do not receive direct access to the generation database or private generation storage. If you give support a generation ID, authorised staff use internal tools to retrieve the relevant account and job context.

External services operate under their own terms and applicable data-processing agreements. We do not grant any service access beyond what its function requires.

5.How long we keep data

6.International transfers

Some of our service partners operate outside the European Economic Area. Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision. You can ask us for details using the contact below.

7.Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, or object to processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. To exercise any right, email privacy@generateporn.ai or delete your account from your dashboard. We respond within one month.

You also have the right to lodge a complaint with your local supervisory authority. Our lead authority is the Irish Data Protection Commission (dataprotection.ie).

8.Security

We use encryption in transit (HTTPS/TLS) and at rest, salted hashing of IP addresses, and role-based access controls on production systems. No system is perfectly secure: protect access to your email account, never share or forward a GeneratePorn.ai one-time code, and sign out on shared devices. Report any suspected vulnerability to support@generateporn.ai.

9.Cookies

We use strictly-necessary cookies or local storage for authentication, Better Auth OAuth/OIDC sign-in to the Community Wiki, age confirmation, consent preferences and session security. If you choose Accept, the app uses in-memory PostHog product analytics to measure app page views, feature usage and reliability, while landing pages may use first-party cookies for affiliate or referral conversion attribution. Landing pages do not load PostHog. Optional measurement stays off if you reject or close the banner. We do not use advertising cookies or cross-site ad tracking. See our Cookie Notice for the full list and controls.

10.Children

The service is strictly for adults. We do not knowingly collect data from anyone under 18. If you believe a minor has used the service, contact removals@generateporn.ai immediately and we will act.

Contact

We may update this policy; material changes are posted here with a new effective date.