Privacy Policy
Contents
- Article 1 - Introduction
- Article 2 - Identity of the Data Controller
- Article 2 bis - Data Protection Contact Point
- Article 3 - Collected Personal Data
- Article 4 - Processing of Sensitive Data
- Article 5 - Purposes and Legal Bases of Processing
- Article 6 - Data Recipients
- Article 7 - Data Processors
- Article 8 - Data Transfers Outside the European Union
- Article 9 - Data Retention Period
- Article 10 - Fate of Data Upon Cancellation
- Article 11 - Cookies and Trackers
- Article 12 - Data Processed by Artificial Intelligence
- Article 13 - Desirely Chrome Extension
- Article 14 - User Rights
- Article 15 - Data Security
- Article 16 - Modifications
- Article 17 - Contact
Last updated: September 2026
Article 1 - Introduction
This Privacy Policy aims to inform users of the Desirely platform (hereinafter the "Platform") about how their personal data is collected, processed, stored, and protected, in accordance with Regulation (EU) 2016/679 of April 27, 2016 on the protection of natural persons with regard to the processing of personal data ("GDPR"), Act No. 78-17 of January 6, 1978 on Information Technology, Data Files and Civil Liberties ("French Data Protection Act"), and Regulation (EU) 2024/1689 of June 13, 2024 laying down harmonised rules on artificial intelligence ("AI Act").
By using the Platform, the User acknowledges having read this Privacy Policy and accepts its terms.
Article 2 - Identity of the Data Controller
Data Controller: Desirely
Legal form: Simplified joint-stock company (SAS)
Share capital: €1,000.00
RCS: 102 631 108 R.C.S. Paris
Registered office: 59 rue de Ponthieu, Bureau 326, 75008 Paris
Represented by: Mr. Romuald Pouget, President
Email: [email protected]
Phone: +33 6 32 92 10 88
Article 2 bis - Data Protection Contact Point
Desirely has not appointed a Data Protection Officer (DPO) within the meaning of Article 37 of the GDPR. Given the nature of the processing operations carried out, the volume of data processed as of the date of drafting this Policy, and the company's staff size, Desirely considers that appointing a DPO is not required under Article 37.1 of the GDPR.
Desirely regularly reassesses this position based on the development of its activities, processing volumes, and CNIL recommendations. If necessary, a DPO will be designated and their appointment will be published in this Policy.
In the meantime, all requests regarding personal data protection should be sent to: [email protected]
All requests are processed under the direct supervision of the President, in his capacity as the legal representative of the data controller.
Article 3 - Collected Personal Data
As part of the use of the Platform and the provision of services, Desirely collects the following categories of personal data:
3.1 - Account and Identification Data
Collected data: agency or creator name, email address, password (encrypted), login credentials for third-party platforms (authentication tokens). Collection time: account creation and connection to third-party platforms.
3.2 - Technical Data
Collected data: IP address, browser type and version, session and connection data. Collection time: connection to the Platform.
3.3 - Usage Data
Collected data: connected models and AI configuration parameters, history of conversations processed by the AI, Platform usage statistics, configured alerts, and notifications. Collection time: use of services.
3.4 - Billing Data
Collected data: billing and commission-related information, transaction history. Collection time: subscription and use of paid services.
Article 4 - Processing of Sensitive Data
4.1 - Nature of Data Processed by the AI
As part of providing the services, Desirely's artificial intelligence system processes conversations exchanged between Models (content creators) and their subscribers (fans) on adult content platforms.
These conversations may contain data relating to sex life or sexual orientation, falling under Article 9 of the GDPR (special categories of personal data).
4.2 - Legal Basis for Processing
Desirely acts as a data processor on behalf of the User (data controller), as specified in Article 4.3.
The processing carried out by Desirely is based on the performance of the contract between Desirely and the User (Article 6.1.b of the GDPR), as processing the conversations is strictly necessary to provide the conversational automation services ordered by the User.
Regarding data falling under Article 9 of the GDPR (special categories), it is the User's responsibility, as the data controller, to ensure they have a valid legal basis under Article 9.2 of the GDPR regarding the data subjects (fans), in accordance with the obligations specified in Article 4.3 below and Appendix 1 of the T&C (DPA).
4.3 - Allocation of Responsibilities
Desirely acts as a processor within the meaning of Article 28 of the GDPR for the processing of fan data and conversations. The User (agency or creator) remains the data controller for the personal data of the fans they collect and process through the Platform.
As such, the User is solely responsible for compliance with the GDPR and fan rights in connection with the processing of their data, obtaining fans' consent for data processing where applicable, and informing fans about the use of an artificial intelligence system in interactions, in accordance with Article 50 of Regulation (EU) 2024/1689 (AI Act).
Article 5 - Purposes and Legal Bases of Processing
Service provision: account management, AI operation, message processing, response personalization. Legal basis: contract performance (Art. 6.1.b GDPR).
Billing and commissions: subscription management, calculation and collection of commissions, billing. Legal basis: contract performance (Art. 6.1.b GDPR).
Minor detection: automated analysis of conversations to detect the potential presence of minors and disable the AI. Legal basis: legitimate interest (Art. 6.1.f GDPR) - protection of minors.
Moderation and security: content filtering, detection of risky behavior, fraud prevention. Legal basis: legitimate interest (Art. 6.1.f GDPR).
Product communication: sending product updates, service notifications. Legal basis: contract performance (Art. 6.1.b GDPR).
Service improvement: analysis of the pages viewed and the features used inside the Platform, linked to the User's account. Legal basis: legitimate interest (Art. 6.1.f GDPR).
Legal obligations: compliance with tax, accounting, and regulatory obligations. Legal basis: legal obligation (Art. 6.1.c GDPR).
Judicial cooperation: disclosure of data to authorities in the event of a judicial subpoena. Legal basis: legal obligation (Art. 6.1.c GDPR).
Important note: Desirely never uses User or fan conversation data to train, improve, or develop its own or third-party artificial intelligence models.
Article 6 - Data Recipients
The personal data collected is accessible to Desirely, as data controller, represented by its President Mr. Romuald Pouget and its Managing Director Mr. Célestin Cordos, as well as to the technical processors listed in Article 7 below, within the limits of what is strictly necessary to perform their duties.
Desirely undertakes not to sell, rent, or transfer the personal data of its Users or fans to third parties for commercial, advertising, or profiling purposes.
In the event of a legal request, Desirely reserves the right to transfer any data to the competent authorities (police, courts, CNIL) within the framework of a judicial investigation, legal request, or legal obligation, in accordance with applicable legislation.
Article 7 - Data Processors
Desirely uses the following processors to provide its services:
OpenAI, L.L.C. - AI model provider (generating responses) - United States - Guarantees: EU-US Data Privacy Framework (DPF).
Stripe Payments Europe Limited - Payment processing and subscription management - Ireland (EU) - GDPR directly applicable. Data may be transferred to Stripe Inc. (United States) as part of intra-group transfers, with the guarantees of the EU-US Data Privacy Framework (DPF).
Google LLC (Gemini) - AI model provider (generating responses) - United States - Guarantees: EU-US Data Privacy Framework (DPF).
Vercel Inc. - Web application hosting - United States - Guarantees: EU-US Data Privacy Framework (DPF).
Clerk Inc. - User authentication service - United States - Guarantees: EU-US Data Privacy Framework (DPF).
Cloudflare, Inc. - Landing page hosting - United States - Guarantees: EU-US Data Privacy Framework (DPF).
Google LLC (Analytics) - Landing page audience measurement - United States - Guarantees: EU-US Data Privacy Framework (DPF).
PostHog, Inc. - Navigation analysis: session recording on the marketing site, usage measurement inside the Platform without session recording - European Union (eu.i.posthog.com instance), publisher established in the United States - Guarantees: European Commission standard contractual clauses.
Tolt - Referral tracking for the partner program, through a thirty (30) day attribution cookie - United States - Guarantees: European Commission standard contractual clauses.
OpenAI, L.L.C. (ChatGPT Ads) - Measurement of advertising campaigns served inside ChatGPT, through attribution cookies - United States - Guarantees: EU-US Data Privacy Framework (DPF).
Desirely ensures that each processor provides sufficient guarantees regarding personal data protection and is contractually committed to complying with GDPR obligations.
Article 8 - Data Transfers Outside the European Union
In connection with providing the services, personal data is transferred to the United States, in particular via the processors listed in Article 7.
These transfers are governed by the following safeguards, in accordance with Chapter V of the GDPR: the EU-US Data Privacy Framework (DPF) for certified entities, standard contractual clauses (SCCs) approved by the European Commission where applicable, and additional technical measures (encryption, pseudonymization) in accordance with the recommendations of the European Data Protection Board (EDPB).
The User can obtain more information about the safeguards in place by contacting Desirely at [email protected].
Article 9 - Data Retention Period
Account data (email, name, credentials): duration of subscription + 3 years after account deletion.
Billing and commission data: 10 years (accounting and tax obligation - Art. L.123-22 of the French Commercial Code).
Technical data (IP address): 1 year from collection.
Conversation data processed by AI: duration of subscription - deleted within 30 days after cancellation or account deletion.
Third-party platform authentication tokens: duration of subscription - deleted immediately upon cancellation.
AI configuration and model settings: duration of subscription - deleted within 30 days after cancellation.
Analytical cookies data: maximum of 13 months (CNIL recommendation).
At the end of these periods, the data is irreversibly deleted or anonymized.
Article 10 - Fate of Data Upon Cancellation
10.1 - Transition Period
In the event of subscription cancellation or account deletion, the User has a period of thirty (30) calendar days from the effective date of cancellation to request the export of their data (AI configuration, model settings, usage statistics).
10.2 - Data Deletion
Upon expiration of this 30-day period, conversation data, AI configurations, model settings, and authentication tokens are permanently deleted. Billing data is retained in accordance with accounting obligations (10 years). Account data (email, name) is kept for 3 years to manage potential disputes.
10.3 - Export Request
The User can send their export request by email to [email protected]. Desirely undertakes to provide the data in a structured, commonly used, and machine-readable format within fifteen (15) business days.
Article 11 - Cookies and Trackers
11.1 - Technical Cookies
The Site uses technical session and navigation cookies strictly necessary for the Platform to function correctly. These cookies do not require the prior consent of the User.
11.2 - Analytical and Advertising Measurement Cookies (Subject to Consent)
Subject to User consent, the site uses the following cookies:
Google Analytics 4 (Google LLC): audience measurement. Anonymized data transmitted to Google servers. Learn more: https://policies.google.com/privacy
PostHog (PostHog, Inc.): navigation analysis via session recordings, automatic click capture and surveys. Learn more: https://posthog.com/privacy
OpenAI (OpenAI, L.L.C.): measurement of advertising campaigns served inside ChatGPT. Two cookies are placed on behalf of the Site. __oppref stores the ad click identifier for thirty (30) days, so that any resulting sign-up can be linked to the campaign that brought it; __obref holds a randomly generated browser identifier, kept for twelve (12) months. When a form is submitted, the email address entered is transmitted as a SHA-256 digest computed in the browser, never in plain text. Learn more: https://openai.com/policies/privacy-policy
11.3 - Consent Management
On their first visit, the User is invited to express their choices through a consent banner. It is not entrusted to a provider: it relies on an open-source library (CookieConsent, MIT licence) hosted on the Site, and the User's choice is stored in a cookie set by the Site itself (cc_cookie, six months). No data is passed to a third party in the process.
The User can change their mind at any time via the “Cookie preferences” link in the footer, as easily as the choice was given.
The banner collects and stores the User's choice, but the measurement tools load as soon as the page opens: non-essential cookies may therefore be placed before that choice is made. The User can delete them, and block them from being placed, from their browser settings.
11.4 - Cookie Retention Period
Analytical cookies are kept for a maximum of 13 months. The User's consent is kept for 6 months.
11.5 - Usage Measurement Inside the Platform
Sections 11.2 and 11.3 above concern the marketing site. Inside the Platform, measurement only starts once the User is signed in: nothing is stored in the browser or transmitted on the sign-in screens.
From that point, the pages viewed and the elements clicked are recorded, linked to the internal account identifier, the email address and the name of the User. No session is recorded, the text displayed on screen is not captured, and the parameters contained in page addresses, which hold the searches and filters typed by the User, are removed before anything is sent. Conversation content and fan data are never passed to this tool.
The data is hosted in the European Union and travels through the Platform's own domain. On sign-out, the identifier is erased from the browser and measurement stops. Legal basis: legitimate interest (Art. 6.1.f GDPR) - service improvement.
Article 12 - Data Processed by Artificial Intelligence
12.1 - Nature of the Processing
Desirely's artificial intelligence system processes conversation data from Models and their fans for the exclusive purpose of generating automated responses in accordance with the settings defined by the User.
12.2 - Safeguards
Conversation data is processed solely for the purpose of providing the services. Desirely does not use conversation data to train, fine-tune, or improve its AI models or those of third parties. Conversation data is not shared with AI providers (OpenAI, Google) beyond what is strictly necessary to process each request in real time. Desirely implements automatic detection mechanisms to identify risky situations, particularly the potential presence of minors in conversations. The User retains the ability to monitor, correct, or disable the AI's operation at any time.
12.3 - Transparency Obligation (AI Act)
Pursuant to Article 50 of Regulation (EU) 2024/1689 (AI Act), people interacting with an AI system must be informed. The User is solely responsible for informing fans about the use of an AI system in exchanges, in accordance with applicable regulations.
Desirely provides the User with the necessary information to comply with this obligation but cannot be held responsible for the User's failure to comply.
Article 13 - Desirely Chrome Extension
13.1 - Purpose of the Extension
The sole purpose of the Desirely Chrome extension is to facilitate the secure link between the User's creator profile on third-party platforms (currently OnlyFans, MYM, Uncove, and Reveal) and their Desirely account.
13.2 - Data Collected by the Extension
The extension only collects and processes the following data: the authentication tokens required to connect with the Clerk service (clerk.desirely.co), stored locally in the browser via chrome.storage and cookies, as well as the creator model IDs present on the pages of third-party platforms visited by the User, transmitted to the Desirely server when the User explicitly requests it.
The extension does not collect any browsing data, history, or personal data other than the elements mentioned above.
13.3 - Token Security
Authentication tokens retrieved by the extension are transmitted securely (HTTPS/TLS protocol) and are only used as part of providing Desirely services. Desirely undertakes not to exploit these tokens to access data or features beyond what is strictly necessary to provide its automated messaging services.
13.4 - Accessible Domains
The extension communicates exclusively with clerk.desirely.co (authentication) and Desirely backend servers (transmission of identifiers). The content script runs only on the pages of compatible third-party platforms.
13.5 - Data Sharing
No data collected by the extension is sold, rented, or shared with third parties.
13.6 - Data Deletion
Uninstalling the extension results in the deletion of all locally stored data. Data transmitted to the Desirely server is subject to the retention periods set out in Article 9.
Article 14 - User Rights
In accordance with the GDPR and the French Data Protection Act, the User has the following rights:
Right of access: obtain confirmation of the processing of their data and receive a copy of it.
Right to rectification: request the correction of inaccurate or incomplete data.
Right to erasure: request the deletion of their data (Art. 17 GDPR).
Right to restriction: request the restriction of processing (Art. 18 GDPR).
Right to portability: receive their data in a structured, commonly used, and machine-readable format.
Right to object: object to the processing of their data for legitimate reasons.
Right to withdraw consent: when processing is based on consent (in particular for analytical cookies), the User can withdraw consent at any time, without affecting the lawfulness of the processing carried out prior to withdrawal.
Post-mortem instructions: define guidelines regarding the fate of their data after death.
To exercise these rights: [email protected]
Desirely undertakes to respond within one (1) month. This period may be extended by two (2) months in cases of complexity.
Complaint to the CNIL: Website: https://www.cnil.fr - Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
Article 15 - Data Security
Desirely implements appropriate technical and organizational measures to protect personal data, in accordance with Article 32 of the GDPR:
Encryption of data in transit (HTTPS/TLS protocol). Encryption of authentication tokens at rest. Restricted data access only to authorized personnel. Regular backup procedures. Regular monitoring and updates of security systems. Logging of access to sensitive data.
In the event of a data breach likely to result in a high risk to the rights and freedoms of data subjects, Desirely will notify the CNIL within 72 hours and inform the affected Users as soon as possible, in accordance with Articles 33 and 34 of the GDPR.
Article 16 - Modifications
Desirely reserves the right to modify this Privacy Policy at any time. Any material changes will be communicated to Users by email or notification on the Platform.
The date of the last update is indicated at the top of the document. Continued use of the Platform after publication of changes constitutes acknowledgment of the modified Privacy Policy.
Article 17 - Contact
Email: [email protected]
Phone: +33 6 32 92 10 88
Form: https://www.desirely.co/en/contact