Privacy Policy
Effective date: 2026-04-23 · Version 2.1 · Updated: 2026-04-23
Bootekol is an image browsing platform. We believe in anonymity by default and collect only the data we need to keep the site running. This policy explains who we are, what personal data we process, on what legal basis, and what rights you have. It applies to users in the European Economic Area (EEA) and all other jurisdictions.
0. Data controller and contact
Who is responsible for your data?
The data controller for personal data processed through bootekol.com is:
Bootekol
Operating name (pre-incorporation; Netherlands B.V. registration planned — registered address will be published in this policy upon incorporation)
Email: [email protected]
Data Protection Officer
No Data Protection Officer (DPO) is currently designated. A formal assessment of whether a DPO is required under GDPR Art. 37 (large-scale processing of special category data) is underway. The outcome of that assessment will be published in this policy. For all data protection enquiries in the meantime, please contact [email protected].
1. What data we collect and why
The tables below list every category of personal data we process, the legal basis under GDPR Art. 6 (and GDPR Art. 9(2) where applicable), and how long we keep it.
All visitors (no account required)
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| IP address (geoblocking) | Enforcing active-market access restrictions | Art. 6(1)(c) — legal obligation | Not retained |
| IP address (abuse prevention) | Detecting and preventing abuse, spam, credential stuffing | Art. 6(1)(f) — legitimate interest (see §2) | 30 days |
| Server / edge request logs (IP + metadata; path stripped on adult-content pages) | Security monitoring, error diagnosis | Art. 6(1)(f) — legitimate interest (see §2) | 30 days |
| Age verification age_ok cookie | Remembering that you confirmed you are 18 or older | Art. 6(1)(c) — legal obligation | 1 year |
| Aggregate analytics (Cloudflare Web Analytics, cookieless) | Aggregate traffic measurement; no individual tracking | Art. 6(1)(f) — legitimate interest (see §2) | No individual retention |
Registered users (account required)
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Email address, username | Account creation and identification | Art. 6(1)(b) — performance of contract | Account duration + 30 days post-deletion |
| Password (hashed; never stored in plaintext) | Authentication | Art. 6(1)(b) — performance of contract | Account duration + 30 days post-deletion |
| Session token session cookie | Keeping you logged in between requests | Art. 6(1)(b) — performance of contract | 7 days (auto-expires) |
| Transactional email (via Resend) | Account confirmation, password reset, account notifications | Art. 6(1)(b) — performance of contract | Sending log: 30 days |
| Uploaded content (Cloudflare R2) | Storing content you choose to publish on the platform | Art. 6(1)(b) — contract; where sexually explicit: additionally Art. 9(2)(a) — explicit consent (obtained at upload) | Content duration + 30 days post-deletion |
| EXIF metadata (from uploaded images) | Transient read for format compliance; stripped immediately | Art. 6(1)(b) — performance of contract | Not retained (stripped immediately) |
| PDQ perceptual hash (CSAM detection — triggered by upload) | Detecting and reporting child sexual abuse material (mandatory legal obligation) | Art. 6(1)(c) — legal obligation | 90 days (hash only; source deleted on detection) |
| Content moderation records (content hash, flags, decision) | CSAM detection and mandatory reporting; content policy enforcement | Art. 6(1)(c) — legal obligation (CSAM); Art. 6(1)(f) — legitimate interest (other moderation) | 90 days (CSAM); 30 days (other) |
| IP address (upload audit log) | Compliance with legal obligations for CSAM reporting and law enforcement cooperation (Criminal Code s.163.1; OP-007 §7) | Art. 6(1)(c) — legal obligation | 90 days (D1); 7 years (in compliance record if CSAM detected) |
| User agent string (upload audit log) | Compliance with legal obligations for CSAM reporting and law enforcement cooperation (Criminal Code s.163.1; OP-007 §7) | Art. 6(1)(c) — legal obligation | 90 days (D1); 7 years (in compliance record if CSAM detected) |
| User behaviour — votes, favourites, browse history Special category data (GDPR Art. 9) — reveals sexual interests | Personalising your experience | Art. 6(1)(a) — consent + Art. 9(2)(a) — explicit consent (sought separately; withdrawable at any time) | Account duration + 30 days; deleted within 30 days of consent withdrawal |
Special category data (GDPR Art. 9). Your votes, favourites, and browse history on an adult content platform reveal information about your sexual interests. GDPR classifies this as special category data requiring a higher standard of protection. We process this data only with your explicit, separate consent. You can withdraw that consent at any time (see §7 — Your rights) without losing access to the rest of the platform.
2. Our legitimate interests
Where we rely on GDPR Art. 6(1)(f) (legitimate interest) as the legal basis, Art. 13(1)(d) requires us to explain what that interest is. The three legitimate-interest activities are:
Platform security — IP address abuse prevention
We log IP addresses for 30 days to detect and prevent credential stuffing attacks, spam registrations, and denial-of-service attempts. This protects other users' accounts and the integrity of the platform. We retain only IP address and request timestamp — no browsing history or content data is included for this purpose. You can object to this processing at any time under Art. 21 GDPR (see §7).
Security and error monitoring — server / edge logs
Server and edge request logs (IP address and request metadata) help us detect security incidents and diagnose infrastructure failures. These logs are retained for 30 days. Safeguard: the URL path of your request is stripped from log records for any page displaying adult content, so that the log does not reveal what content you accessed. You can object to this processing at any time under Art. 21 GDPR (see §7).
Aggregate traffic analytics — Cloudflare Web Analytics
We use Cloudflare Web Analytics to understand platform usage at an aggregate level (page views, traffic trends). This uses a cookieless JavaScript beacon that does not set cookies, does not track individual visitors, and does not retain IP addresses after aggregation. The analytics beacon is not loaded on pages where you are browsing adult content as an authenticated user. You can object at any time under Art. 21 GDPR (see §7).
3. Cookies
This site uses only strictly necessary cookies. No analytics, advertising, or tracking cookies are set. Because all cookies are strictly necessary for functionality you explicitly request, no consent mechanism is required under the ePrivacy Directive.
| Cookie | Purpose | Category | Duration |
|---|---|---|---|
| age_ok | Remembers that you confirmed you are 18 or older | Strictly necessary | 1 year |
| session | Keeps you logged in after registration or login | Strictly necessary | 7 days |
We do not use third-party cookies, advertising cookies, or tracking pixels. Cloudflare Web Analytics uses a cookieless JavaScript beacon (loaded from static.cloudflareinsights.com) for anonymous, aggregated page-view measurement. This beacon does not set cookies, does not fingerprint or track individual visitors, and does not collect personal information. No advertising or behavioural tracking technologies are used.
4. Processors and international transfers
Third-party processors
We use the following third-party processors, each acting under a Data Processing Agreement and processing your data only on our documented instructions:
| Processor | Services | Data processed | Location |
|---|---|---|---|
| Cloudflare, Inc. Privacy policy | CDN and DDoS protection; Cloudflare KV (session storage); Cloudflare R2 (content storage); Cloudflare D1 (database); Cloudflare Web Analytics | IP addresses, request metadata, session tokens, uploaded content, account data | Global edge network; primary region: Netherlands |
| Amazon Web Services, Inc. (AWS EC2) Privacy policy | EC2 image processing — EXIF stripping, CSAM detection (PDQ hashing), NSFW classificationPhase 3 (when active): additionally biometric inference (face embeddings, body vectors, demographic attributes) and persistent biometric storage — see §7 | Uploaded images (processed transiently; EXIF stripped; PDQ hash retained 90 days)Phase 3 (when active): additionally face embeddings, body re-identification vectors, demographic attributes — processed and stored persistently — see §7.4–7.5 | United States (us-east-1) |
| Resend, Inc. Privacy policy | Transactional email delivery (account confirmation, password reset, account notifications) | Email address, email sending metadata | United States |
International transfers
AWS EC2 (image processing) and Resend (transactional email) are located in the United States, outside the European Economic Area (EEA). Transfers of your personal data to these processors are made subject to appropriate safeguards to ensure your data receives a level of protection equivalent to that required under GDPR Art. 46.
The specific transfer mechanism — Standard Contractual Clauses adopted by the European Commission under Decision 2021/914 (Module 2: Controller-to-Processor) — is being finalised. This notice will be updated once Data Processing Agreements are executed. If you would like information about the safeguards in place for your personal data, please contact [email protected].
We do not sell, rent, or share your personal data with any other third parties for their own purposes.
5. How long we keep your data
| Data category | Retention period |
|---|---|
| Email address, username | Account duration + 30 days after account deletion |
| Password hash | Account duration + 30 days after account deletion |
| Session token | 7 days (auto-expires; renewed on active sessions) |
| User behaviour (votes, favourites, browse history) | Account duration + 30 days; deleted within 30 days of consent withdrawal |
| IP address — geoblocking check | Not retained (transient per-request evaluation only) |
| IP address — abuse prevention logs | 30 days |
| Server / edge request logs | 30 days (URL path stripped on adult-content pages) |
| Uploaded content | Content duration + 30 days after deletion |
| Age verification cookie (age_ok) | 1 year |
| CSAM detection hash (PDQ) | 90 days (source image deleted immediately on positive detection) |
| EXIF metadata | Not retained (stripped immediately during image processing) |
| Web analytics data | No individual retention; aggregated statistics only |
| Email sending log (Resend) | 30 days |
| Content moderation records — CSAM | 90 days after resolution |
| Content moderation records — other | 30 days after resolution |
| Upload audit log — IP address, user agent | 90 days (D1 hot storage); 7 years (in R2 compliance record if CSAM detected — Art. 17(3)(b) legal obligation exemption) |
If you delete your account, we will remove your personal data within 30 days. Some anonymised, aggregated data that cannot be attributed to you may be retained beyond this period.
Phase 3 biometric data (not yet active): retention periods for face embeddings, body re-identification vectors, demographic attribute estimates, and person cluster assignments are set out in §7.5 below, pending Phase 3 activation.
6. What happens if you don't provide data
Providing your email address, username, and a password is required to create a registered account. This data is a contractual requirement — without it, we cannot enter into or perform the contract enabling you to use registered features (uploading content, voting, saving favourites). The consequence of not providing this data is that you cannot create an account.
You may browse the platform anonymously without providing any personal data. Anonymous browsing does not require registration.
7. Your rights
Under GDPR (and equivalent laws in your jurisdiction), you have the following rights:
- Access (Art. 15) — request a copy of the personal data we hold about you.
- Rectification (Art. 16) — correct inaccurate data.
- Erasure (Art. 17) — request deletion of your data ("right to be forgotten").
- Restriction (Art. 18) — ask us to restrict processing in certain circumstances.
- Portability (Art. 20) — receive your data in a machine-readable format and transfer it to another controller.
- Object (Art. 21) — object to processing based on legitimate interests (including the three activities in §2). We will stop unless we can demonstrate compelling legitimate grounds that override your interests.
- Withdraw consent (Art. 7(3)) — where processing is based on consent (including the explicit consent for user behaviour / special category data), you can withdraw at any time without detriment to your use of the rest of the platform.
For biometric data processing (Phase 3, when active), additional rights — including the right to withdraw biometric processing consent — are described in §7 above.
To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month (GDPR Art. 12(3)).
Right to lodge a complaint (GDPR Art. 13(2)(d) / Art. 77). You have the right to lodge a complaint with a supervisory authority at any time — you do not need to contact us first:
- Netherlands: Autoriteit Persoonsgegevens (AP) — autoriteitpersoonsgegevens.nl, telephone +31 70 888 8500
- Czech Republic: Úřad pro ochranu osobních údajů (UOOU) — uoou.cz, telephone +420 234 665 111, Pplk. Sochora 27, 170 00 Praha 7
- Other EEA jurisdictions: Contact the supervisory authority of the EU member state where you reside or work, or where the alleged infringement occurred.
8. Automated decision-making
We use one automated decision-making process that produces a significant effect on data subjects (GDPR Art. 22 / Art. 13(2)(f)):
CSAM detection — automatic content rejection
All uploaded images are compared against a database of known child sexual abuse material (CSAM) perceptual hashes (PDQ hashes). A hash match results in automatic rejection of the upload without prior human review, and triggers a mandatory report to the relevant authority (cybertip.ca in Canada; NBIP in the Netherlands).
How it works: A perceptual hash of each uploaded image is computed and compared against a blocklist of known CSAM hashes. A match results in immediate, automatic rejection of the upload and deletion of the source image. No parameters are adjustable by the data subject.
Your right to human review: If your content was rejected by this automated system and you believe this is an error (i.e., your content does not constitute CSAM), you may request human review by contacting [email protected]. Note: this right does not apply where the automated decision is required by law and has been confirmed by a law enforcement authority.
Other processing (content ranking, search results, feed curation) relies on aggregate signals and does not produce decisions with significant legal or similarly significant effects on individual data subjects within the scope of Art. 22 GDPR.
9. Children's privacy
Bootekol contains adult content and is not intended for anyone under 18 years of age (or the age of majority in your jurisdiction). We do not knowingly collect data from minors. If we discover that a minor has provided personal data, we will delete it promptly.
10. Changes to this policy
We may update this policy from time to time. When we do, we will revise the effective date at the top. If changes are significant (including any change to the lawful basis or the introduction of new processing activities), we will make reasonable efforts to notify registered users (e.g. via email or a site banner). Where processing requires consent, we will seek fresh consent. Your continued use of Bootekol after changes take effect constitutes acknowledgement of the updated policy.
11. Contact
If you have questions about this policy, want to exercise your data rights, or want a copy of the Standard Contractual Clauses applicable to international transfers, reach us at:
See also our Terms of Service, Content Removal Policy, and Transparency Report.