Privacy Policy
HFM (app.hudsonfleiss.vip) · Operated by Hudson Fleiss Media US LLC · Last updated August 14, 2026
Hudson Fleiss Media US LLC ("HFM," "we," "us," or "our") operates HFM (the "Platform"), a single application serving several distinct communities. This policy governs the Platform as a whole; your community determines which features are available to you, not which privacy rules apply. This Privacy Policy explains how we collect, use, share, and protect your personal information. It applies to all users worldwide. By using the Platform, you agree to the practices described in this policy.
1. Information We Collect
We collect the following categories of personal information:
- Account information: username, email address, date of birth, phone number, city/region
- Profile content: photos, profile text, sexuality, body attributes, relationship preferences
- Payment information: handled entirely by the payment processors listed in section 3. Card details are entered on the processor's own page, and purchases made inside the phone apps are billed by Apple or Google. HFM never receives or stores full card numbers or CVVs.
- Age and identity verification: verification status, provider reference, method, and completion time. Where a government ID is legally required, the verification provider processes it; HFM does not store the ID image.
- Communications: messages you send through the platform, support requests, reports you submit
- Usage data: features used, pages visited, login times, interactions
- Technical data: IP address, browser type, device type, operating system
- Precise location (GPS): if you grant your device's location permission, we collect your device's precise latitude and longitude. See section 5A for exactly what it is used for, how long it is kept, and how to turn it off.
- Approximate location: country and region derived from your IP address. This is collected for every visit and does not require a permission prompt.
2. How We Use Your Information
- To create and manage your account and provide platform services
- To verify your age and identity before granting platform access
- To process payments and subscriptions through the payment processors listed in section 3
- To send SMS verification codes and account notifications via Twilio Inc.
- To provide AI-powered features (Ace AI assistant, Haven wellness companion) via the Anthropic API
- To translate chat text on your phone when supported, with a capped server translation fallback when on-device translation is unavailable
- To scan all uploaded images for child sexual abuse material (CSAM) using Microsoft PhotoDNA
- To enforce our Terms of Service and protect platform safety
- To respond to legal requests and comply with applicable law
- To send service communications and — with your consent — promotional messages
3. Service Providers & Third Parties
We share your personal information with the following third-party service providers only as necessary to operate the Platform. We do not sell your personal information. We do not allow advertisers to pay for placement in your experience.
| Provider | Purpose | Data Shared |
|---|---|---|
| Apple Inc. | Subscription purchase and billing inside the iPhone app | Purchase receipt and an opaque account token that is not your user id or email |
| Apple Inc. (Translation framework) | On-device chat translation in the iPhone app | Message text stays on the device. Apple may receive language-pair, app identifier, usage, and performance metrics, but not the original or translated text. |
| Google LLC (Play Billing) | Subscription purchase and billing inside the Android app | Purchase token and an opaque account token that is not your user id or email |
| Google LLC (ML Kit) | On-device chat translation and language identification in the Android app | Message text and translation results stay on the device. Google may receive API performance and utilization metrics. |
| Didit | Age and identity verification | A selfie, and where a jurisdiction requires full identity verification, a government-issued ID document |
| iDenfy (UAB iDenfy) | Age and identity verification, used as the fallback when Didit is unavailable | A selfie, and where a jurisdiction requires full identity verification, a government-issued ID document |
| Twilio Inc. | SMS verification, voice services | Phone number |
| Cloudflare Inc. (R2) | Media storage, CDN, DDoS protection | Uploaded photos, videos, IP address |
| Anthropic PBC | AI-powered features (Ace, Haven) and capped translation fallback when on-device translation is unavailable | Messages sent to those AI features or submitted for cloud translation |
| Microsoft (PhotoDNA) | Automated CSAM detection on all uploads | Image hash fingerprints only (no raw images) |
| Google LLC (Workspace) | Email delivery | Email address, message content |
| Railway Inc. | Application hosting & infrastructure | All platform data passing through the servers |
| Supabase Inc. | Managed database hosting | All platform data held in the database |
4. International Data Transfers
Hudson Fleiss Media US LLC is a Wyoming company. Your data may be processed in the United States, Canada, and other countries where our service providers operate servers. When personal data is transferred internationally, we rely on appropriate safeguards — such as standard contractual clauses or equivalent protections — to ensure your data receives adequate protection consistent with this policy.
5. Cookies & Tracking Technologies
We use essential cookies and similar technologies to keep you signed in and to remember your preferences. We do not currently use advertising cookies or third-party tracking pixels.
We automatically collect the following when you use the Platform:
- Session identifiers (authentication cookies)
- Device and browser information
- IP address and approximate geolocation (country and region)
- Precise GPS coordinates, only where you have granted location permission — see section 5A
- Usage patterns (pages visited, features used, time on platform)
You may control cookie behavior through your browser settings. Disabling essential cookies will impair platform functionality.
5A. Precise Location
Earlier versions of this policy said we collected only approximate, IP-derived location. That was not accurate, and this section replaces it.
What we collect
If you grant your device's location permission, we collect your device's precise latitude and longitude. Location permission is optional and the Platform is usable without it, though discovery and distance features will not work.
What we use it for
- Discovery and distance. Your coordinates are stored on your profile and used to determine which members appear in your grid and to calculate the approximate distance shown between you and another member. Your exact coordinates are never shown to another member; distance is presented as a rounded figure.
- City assignment. To place you in the correct city feed and city chat rooms.
- SafeCheck safety timers. While — and only while — you have a SafeCheck session running, the app sends periodic location updates so that, if you do not check in, the alert to the emergency contact you nominated can include your last known position and a map link. These periodic updates stop when the session ends or is cancelled.
- Travel mode. If you set a travel destination, that location is used in place of your device location until you turn it off.
What we do not use it for
We do not sell location data, use it for advertising, share it with data brokers, or use it to build a movement history. Private Match proximity detection uses Bluetooth signal strength between two devices that have both opted into the same session; it does not use or transmit GPS coordinates.
Who it is shared with
- Other members see only a rounded distance, never coordinates.
- During an active SafeCheck alert, your last known position and a map link are sent to the emergency contact you nominated, and delivered through our SMS and voice provider (Twilio Inc.).
- Our hosting and database providers process it as part of operating the Platform.
How long we keep it
- Your profile stores only your most recent coordinates; each update overwrites the previous one. No history is retained.
- SafeCheck session location readings are kept with that session record and are deleted when you delete your account.
- Deleting your account clears the coordinates on your profile and deletes your SafeCheck session records. See section 6A.
How to turn it off
Revoke location permission in your device settings (iOS: Settings → Privacy & Security → Location Services; Android: Settings → Location → App permissions). You can also stop a SafeCheck session at any time from inside the app, which ends periodic updates immediately.
6. Your Rights (All Users)
Regardless of where you live, you may contact us at privacy@dondemand.vip to:
- Request a copy of the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your account and associated personal data
- Object to or request restriction of certain processing
- Withdraw consent where processing is based on consent
- Request portability of your data in a structured, machine-readable format
We will respond to verified requests within 30 days (45 days for complex requests, with notice). We may need to verify your identity before processing a request.
6A. Account Deletion — What Happens and When
You can delete your account yourself, from inside the app, at Profile → Leave. No email or support request is required.
Deleted immediately
When you confirm deletion, the following are removed or irreversibly anonymised in a single operation, and you are signed out on every device you are signed in on:
- Your email address, username, password, phone number and date of birth
- Your profile: display name, bio, orientation, pronouns, personality, body and height details, scene preferences, health status, and precise coordinates
- Your direct messages, group and city chat messages, city posts, reactions and compliments
- SafeCheck sessions, Haven companion conversations, and AI assistant sessions, intents and consent grants
- Private Match sessions, preferences, match records and explicit-media consent grants
- Push notification subscriptions, known-device records, and any outstanding password reset links
- Identity and age verification session references, referral records and waitlist position
- Your signup IP region, pledge IP and geolocation record, device identifier, and all payment-provider tokens
Deleted within minutes
Your stored images — profile photos, their cached thumbnails, and photos you sent in chat — are queued for removal from our object storage as part of the same operation and are deleted by a background job, normally within a few minutes. This is a background step because our storage provider is a separate system; the deletion is recorded and retried until it is confirmed.
What we keep, and why
We keep only what we are required to, and none of it is used to contact you or to build a profile of you:
- Billing records — amounts and dates of payments, for tax and chargeback obligations. Payment credentials and processor tokens are deleted.
- Safety reports and blocks involving other members — a report about you is a record of a harm to somebody else, and blocks placed against you prevent an account returning by deleting and re-registering.
- Moderation audit records — so moderation decisions can be reviewed after the fact.
- Anti-fraud signals — hashed card fingerprints and trial dates that prevent chargeback fraud and repeat-trial abuse. These contain no card numbers.
- Legal and child-safety holds — where an account is subject to a preservation obligation, deletion is refused and you are directed to support. Any such material is stored separately, with restricted access, and every access is logged.
Verification providers
Where a third-party age or identity verification provider processed your check, that provider holds its own record under its own retention policy. Deleting your HFM account removes our reference to it; contact the provider directly to exercise rights against their copy.
7. Regional Privacy Rights
California (CCPA / CPRA)
California residents have the right to: know what personal information we collect and how it is used; delete personal information; correct inaccurate personal information; opt out of the "sale" or "sharing" of personal information (we do not sell or share personal information for advertising); and be free from discrimination for exercising these rights. To exercise your California privacy rights, contact privacy@dondemand.vip. We will respond within 45 days.
Canada (PIPEDA & Provincial Laws)
Canadian residents have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws, including the right to access, correct, and challenge how we handle your personal information. Quebec residents have additional rights under Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25), including data portability rights. Contact our Privacy Officer at privacy@dondemand.vip.
European Union & United Kingdom (GDPR / UK GDPR)
EU and UK residents have rights under the General Data Protection Regulation (GDPR) and UK GDPR, including rights of access, rectification, erasure, restriction, portability, and objection. Our legal bases for processing are: contractual necessity (providing the service), legitimate interests (operating and improving the platform), legal obligation (compliance with law), and consent (where specifically obtained). You have the right to lodge a complaint with your local supervisory authority. Contact us at privacy@dondemand.vip.
Special category (sensitive) data. Information you choose to share about your sexual orientation, and any health-related information you choose to disclose, is "special category" personal data under Article 9 of the GDPR and UK GDPR. We process this data only on the basis of your explicit consent, which you provide through a clear affirmative action when voluntarily submitting such information to your profile or account. Providing this information is voluntary; however, because this platform is a social service for the LGBTQ+ community, some core features may not function without it. You may withdraw your consent at any time by editing or removing the information or by closing your account, which will end the related processing going forward (without affecting processing that already took place).
Mexico (LFPDPPP)
Los usuarios en México tienen derechos ARCO (Acceso, Rectificación, Cancelación y Oposición) conforme a la Ley Federal de Protección de Datos Personales en Posesión de los Particulares. Contacte a privacy@dondemand.vip.
8. Age-Restricted Content & Verification
HFM is an 18+ platform. Access requires an age check, and which check you are asked for depends on where you are. In jurisdictions whose law requires verified identification — including the UK, France, Germany, Italy, Spain, Australia and the US states with age-verification statutes — the check is a full identity verification against a government-issued document, performed by Didit or, as a fallback, iDenfy. Everywhere else it is an age estimate from a selfie, and no identity document is requested. The provider performs the check and returns a result; HFM stores the outcome, the provider's reference, the method and the time, and retains a SHA-256 hash rather than the document itself.
Accounts created before 18 June 2026 were verified under the age controls that operated at the time, before the current provider-based checks were introduced, and their verified status was carried across when those checks launched. Their records therefore show a verified outcome without a Didit or iDenfy reference. We describe this accurately rather than claiming a provider check that did not happen; the 18+ requirement applied to those accounts then and applies to them now.
A small number of controlled review accounts — used by Apple, Google and our payment processors to test the platform — are marked verified without a provider check, because a reviewer cannot and should not submit identity documents. These accounts are created by us, are not member accounts, and are not visible to members.
All uploaded images are automatically scanned using Microsoft PhotoDNA to detect child sexual abuse material (CSAM). Any detected material is automatically blocked and reported to the National Center for Missing & Exploited Children (NCMEC) as required by 18 U.S.C. § 2258A.
9. Automated Decision-Making
Chat-photo safety records: when a member shares a private chat photo, we record the sender, intended recipient or accepted group audience, conversation context, delivery time, automated explicit-content classification, and an opaque watermark serial when watermarking is enabled. The visible serial does not contain a name, email address, or other direct identifier. We use these records to investigate non-consensual sharing, respond to member safety requests, enforce our rules, and respond to valid legal process. Turning watermarking off prevents the serial from being embedded but does not disable required safety and delivery logging.
We use automated systems in the following ways:
- PhotoDNA image scanning: all uploaded images are automatically scanned. A match results in the upload being rejected and the content reported to NCMEC. You may contact support@dondemand.vip to request human review of any automated decision.
- Geographic access controls: your country of access is determined automatically by IP address. Access from jurisdictions where the Platform cannot legally operate is denied at the network level.
- Account safety systems: accounts exhibiting patterns consistent with fraud or abuse may be flagged or restricted automatically.
You have the right to request human review of any automated decision that significantly affects you. Contact support@dondemand.vip.
10. Children's Privacy
HFM is intended exclusively for adults aged 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account on our platform, contact us immediately at support@dondemand.vip. Upon verified report, we will promptly delete the account and all associated data.
11. Data Retention
We retain your personal information for as long as your account is active. Upon account deletion, we delete or anonymize personal data within 30 days, except where retention is required by law. Payment records may be retained for up to 7 years for tax and compliance purposes. Identity and age verification records are retained for as long as required by applicable law. Chat message history is deleted within 90 days of account deletion. Backup copies may persist for up to an additional 60 days before permanent deletion.
12. Security
We implement industry-standard security measures including TLS encryption in transit, hashed and salted passwords, signed media URLs with expiry, and access controls. We use Cloudflare for DDoS protection and CDN security. No system is 100% secure; we encourage you to use a strong unique password and to notify us immediately at support@dondemand.vip if you suspect unauthorized access to your account.
13. Breach Notification
In the event of a data breach affecting your personal information, we will notify you and applicable regulatory authorities within the timeframes required by law — within 72 hours under GDPR, as soon as reasonably practicable under PIPEDA, and without unreasonable delay under applicable US state laws. Notification will be provided by email to the address associated with your account.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or by a notice on the platform at least 7 days before they take effect. Continued use of the platform after the effective date constitutes your acceptance of the updated policy.
15. Contact
Privacy Officer. For privacy-related requests, questions, complaints, or data-rights inquiries, please contact our Privacy Officer at the address below.
- Email: privacy@dondemand.vip
- Hudson Fleiss Media US LLC
- 30 N Gould St, Ste N
- Sheridan, WY 82801, USA