Last updated 25 September 2026
Privacy Policy
kink.io is an adult service, so we think hard about privacy. This policy explains what we collect, why, who helps us process it, how long we keep it, and the rights you have under the UK GDPR and the Data Protection Act 2018. kink.io is the data controller. Contact us at hello@kink.io.
1. What we collect
Account data. Your email address, a hashed password (we never see the plain text), the sign-in provider you used (for example Google), your display name and avatar if you set them, and account settings.
Age-verification result. When verification is live, our partner Yoti confirms whether you are over 18. We store only the outcome (pass), the method used, the date and a hashed reference. We never receive or store your ID document, selfie, photo or date of birth. Those stay with Yoti under Yoti’s privacy policy.
Chats and creations.Messages you exchange with characters, characters you create, prompts, favourites, and images, voice and video generated for you. These are intimate by nature. Please treat them that way: do not include real names, addresses, or other people’s personal information.
Usage and device data. IP address, browser and device type, pages viewed, approximate country, error logs and security events (for example failed logins or rate-limit hits). We use privacy-preserving analytics and do not run advertising trackers.
Payments. Credits are not currently sold. If that changes, payments will be handled by a payment processor and we will never store full card numbers.
2. Why we use it (our legal bases)
- To run the Service you signed up for (contract): creating your account, generating characters and chats, remembering your favourites.
- To keep adults-only content away from children (legal obligation under the Online Safety Act 2023 and related UK rules): the age-verification result and related security logs.
- To keep the Service safe and lawful (legitimate interests and legal obligation): detecting abuse, enforcing our Content Policy, responding to reports and legal requests, and preventing fraud.
- To improve the Service (legitimate interests): aggregated, de-identified usage statistics and error reports. We do not use your private chats to train AI models.
- To contact you (contract and legitimate interests): transactional email such as confirmation links, password resets, and a note when early access opens. We only send marketing with your consent, and you can opt out at any time.
3. Who helps us process your data
We use a small number of specialist providers. Each acts on our instructions under a data-processing agreement and only receives what it needs for its job.
- Supabase (EU region): our database, authentication and account storage.
- Vercel: hosting and serving the website; may see IP addresses and request logs at the edge.
- Cloudflare R2: storage for generated images, audio and video.
- ElevenLabs: turning character replies into voice. Receives the text to be spoken, not your account identity.
- AI model providers: the large language and image/video models that generate character replies and media. They receive the content of the conversation or prompt needed to produce a response, pseudonymised where possible, and are contractually prohibited from using it to train their models.
- Yoti: age assurance, as described above.
- Email delivery: a transactional email provider for confirmation and reset links.
Some providers process data outside the UK (mainly in the EU and United States). Where that happens we rely on the UK adequacy decisions, the UK International Data Transfer Agreement or Addendum, and appropriate safeguards.
We do not sell your personal data, and we do not share it with advertisers.
4. How long we keep it
- Account data: for as long as your account exists, then deleted within 30 days of closure.
- Chats and generated media: until you delete them or close your account, after which they are deleted within 30 days (backups roll off within a further 30 days).
- Age-verification result: for the life of your account plus a short period, so we can show regulators that a check was passed. Verification expires and must be repeated periodically.
- Security and abuse logs: up to 12 months, or longer where needed for an active investigation or legal claim.
- Content-policy reports and records of accounts closed for serious breaches: retained as needed to prevent re-registration and to meet legal duties.
5. Your rights
Under UK GDPR you can ask us to:
- Access the personal data we hold about you and receive a copy.
- Correct data that is inaccurate.
- Delete your data (the right to erasure), subject to legal retention duties.
- Restrict or object to certain processing, including any marketing.
- Receive your data in a portable format.
- Withdraw consent where we rely on it, without affecting earlier processing.
Email hello@kink.iofrom the address on your account. We respond within one month. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk, though we would appreciate the chance to fix things first.
6. Security
Data is encrypted in transit and at rest. Access to production systems is restricted, logged and limited to staff who need it. Passwords are hashed, and sensitive identifiers (like the age-verification reference) are stored as one-way hashes. No system is perfectly secure, so please use a strong, unique password. If we ever suffer a breach that affects you we will tell you and the ICO as the law requires.
8. Children
9. Changes to this policy
We will update this policy as the Service changes and show the date at the top. If a change significantly affects how we use your data we will email you or show a notice in the app before it takes effect. See also our Terms of Service and Content Policy.