Your data on Lewdden

This guide is the plain-English summary of what data Lewdden holds about you, how long we keep it, who we share it with, and the requests you can make under EU GDPR. It complements (and never overrides) the formal Privacy Policy — when in doubt, the policy text is the binding document.

1) The data you give us, and where it lives

Different parts of your account live in different places. The two big buckets are Lewdden itself (this platform, run from Berlin) and third-party providers we use for specific jobs (payment processing, identity verification). The split matters because the request paths are different.

On the Lewdden side, we hold:

  • Your account basics — username, email address, password (hashed, never stored as readable text), display name, account-creation date, last sign-in.
  • Your purchase / order history — what you bought, when, from which creator, the price, the payment method (card / wallet), the order status. For physical items, the shipping address you provided at checkout.
  • Your subscription history — which creators, which tiers, when each renewal happened, when (and why) any subscription was cancelled.
  • Your wallet history — every top-up and every spend, with timestamps. The wallet itself is a balance number stored against your account.
  • Your message threads with creators — the message bodies you sent and received, their timestamps, and any media (clips/photos/voice notes) you attached or unlocked.
  • Your follow / followers list — which creators you follow.
  • Your content (creator side only) — clips you uploaded, feed posts, storefront avatar / banner / bio, live-stream VODs, custom-order replies, anything you’ve published to your storefront.
  • Your verification record (creator side) — the verification status (Approved / Declined / etc.), the first and last name you submitted, the latest decision timestamp. The actual ID document images and biometric data live at the verification provider, not on Lewdden.
  • Operational logs — sign-in timestamps, IP addresses for security audits, browser user-agents (used to detect compromised sessions). Kept for a rolling window (typically 30–90 days), then aged out.

At third-party providers, we cause to be held:

  • Netfield Media S.L — the merchant of record. Holds the card details for any card you’ve used (we don’t see your full card number), the receipts for every charge, and the data needed to issue VAT-compliant invoices. The line on your bank statement is theirs.
  • The identity-verification provider (creator side only) — holds the document images, the selfie video, and the audit trail of the verification session. They keep these per their own retention policy and applicable EU/AML rules (typically several years).
  • Email delivery providers — handle the actual sending of the receipt / digest / support emails. Hold a transient copy of each email and delivery / open / click data per their retention windows.
  • Cloud storage (for media files) — your uploaded clips, profile images, and live-stream recordings are physically stored in EU data-centres and served via a content-delivery network. The data is encrypted at rest.

2) How long we keep it

  • Account basics — for as long as your account is open.
  • Purchase / order / subscription / payout records — 7+ years after the transaction, per EU tax / accounting / AML law. We can’t delete these even on request — we’re legally required to keep them.
  • Verification status (the platform-side fields) — kept on the application record permanently, even after a creator account is closed, for audit purposes.
  • Verification document images / selfie — held by the verification provider per their retention window (typically several years for AML compliance).
  • Operational logs — 30–90 days then aged out.
  • Message threads — for the lifetime of the account on each side. When one side closes their account, their view is removed; the other side’s view persists for a normal communication-record period.
  • Marketing / communication preferences — for the lifetime of the account; reset only when you change them.
  • Closed-account residuals — anonymised reviews / ratings stay in place to preserve thread context (display name replaced with “Former user”).

3) Who we share data with — and what we don’t share

What we share, and why:

  • Netfield Media S.L — your name + email + the order details on every paid action (so they can charge you and email the receipt).
  • The identity-verification provider — your first / last name + the documents you upload during the session (creator side only).
  • Email delivery providers — your email + the message body of any system email.
  • Hosting / cloud storage / CDN providers — the actual files (clips, images) and database queries (encrypted).
  • Tax / accounting / AML authorities — purchase records and creator-side payout records, where legally compelled (e.g. responding to a court order or a tax-authority audit).

What we don’t share, ever:

  • Your purchase history with anyone outside the parties above. We don’t sell or rent customer data. There’s no advertising network in our stack.
  • Your message threads with anyone outside the two participants (and our internal moderation team if a thread is reported for safety reasons).
  • Your IP address with creators, buyers, or third parties — operational logs only, retained for security audit, not exposed.
  • Your identity-verification documents with anyone other than the verification provider (and our internal compliance team if specifically reviewing a flagged account).
  • Your viewing history. We don’t track which clips you watch or pages you scroll for ad-targeting purposes — there’s no ad-targeting product to feed.

4) Your GDPR rights — what to ask for

If you’re in the EU/EEA (and in many other jurisdictions with similar laws), you have a set of formal rights over your personal data. We honour them; here’s the short version of how to exercise each one.

  • Right of access (a copy of what we hold). Open a ticket under Account & login at Contacting support with the subject “GDPR access request”. We compile a structured export of the data on the Lewdden side and email it to you, typically within 30 days.
  • Right to rectification (fix wrong data). Most fields you can edit yourself from My Account → Account details. For fields you can’t edit (verification name, order historical data), open a ticket and we’ll correct them.
  • Right to erasure (be forgotten). Open a ticket asking for account closure + erasure. We close the account, remove the data we’re allowed to remove, and explain which records have to be retained for legal compliance (mostly: financial records, retained for 7+ years; verification status on the audit record). For the data the verification provider holds, we’ll route the request to them. See Closing your account or Pausing or closing your storefront for the practical process.
  • Right to restrict / object to processing. Open a ticket explaining what processing you object to. We can stop most marketing-style processing immediately; some operational processing (e.g. for fulfilling an open order) we have to continue until the order is complete.
  • Right to data portability. The “Right of access” export is in a structured machine-readable format — you can use it to migrate your data elsewhere if you like. For your uploaded media specifically, see §6.
  • Right to withdraw consent. For things you’ve explicitly consented to (e.g. marketing emails), withdraw it from Account details notification settings or via support.
  • Right to complain to a supervisory authority. If you’re unhappy with how we’ve handled your request, you can complain to your local data-protection authority. In Germany that’s the BfDI; in other EU countries it’s the equivalent national DPA.

5) Cookies and tracking

  • Strictly-necessary cookies — sign-in session, age-gate confirmation, cart contents. Set automatically; can’t be opted out of without breaking the site.
  • Functional cookies — remember your language and display preferences. Opt-in via the cookie banner on first visit.
  • Analytics — first-party, aggregate, no cross-site tracking. Opt-in via the cookie banner.
  • Advertising cookies — none. We don’t run ads on Lewdden and don’t share data with ad networks.

The cookie banner you saw on first visit is where to manage preferences. You can re-open it at any time by clicking the Manage consent button in the page footer (it appears via our Complianz GDPR cookie-consent plugin once you’ve made an initial choice).

6) Downloading your media before a close

If you’re considering closing your account and want to keep copies of media you’ve uploaded or bought:

  • Buyers: downloadable clips you bought are downloadable from your My Library page. Save them locally. Streaming-only access (subscriber-included clips, sub-bound VODs) ends with the close.
  • Creators: your uploaded clips are downloadable from your storefront management. Custom orders you delivered are in the order record. Live-stream VODs are downloadable from the VOD library before the close runs.
  • Both: message threads are not exported as media — open a GDPR access request if you want a structured copy.

7) FAQ

Q: How do I make a “right of access” request?
Open a ticket from Contacting support under Account & login with subject “GDPR access request”. We respond within 30 days. The export includes everything on the Lewdden side; for verification documents (held at the third-party provider) and payment receipts (held at Netfield Media S.L), we’ll point you at the right contact for those.

Q: Can I delete just my message threads, not my whole account?
Per-thread deletion isn’t a self-serve feature. Open a ticket explaining which threads (or which time period) you want removed and why; we evaluate per the GDPR right-to-erasure framework — most genuine requests are honoured, with the caveat that the other party’s view of the conversation is also affected.

Q: I’m under 18 — can I be on Lewdden at all?
No. Both creators and buyers must be 18+. The age-gate at the front of the site enforces this, and creators go through a hard ID-based age check. Anyone we discover on the platform under 18 has their account closed immediately. See Age verification — why we ask, what we keep.

Q: Does Lewdden use my data to train AI models?
No. Your content, messages, and viewing data are not used to train any AI model — ours, anyone else’s, or fed to external services for that purpose.

Q: Where are my data physically stored?
EU data centres. The content-delivery edge nodes that serve media to your browser may be closer to your location for performance, but the system of record is in the EU.

Q: Has Lewdden ever had a data breach?
We’re required to disclose any incident affecting personal data publicly and to notify affected users directly within 72 hours of detection. Check the security page for the most up-to-date status; the absence of an entry there means no incident has been reported.

Q: Who is the data controller?
The legal entity behind Lewdden. The exact details are in the formal Privacy Policy and the Imprint page (/imprint/).

Need more help

For any GDPR request, anything you noticed about your data on the platform that doesn’t match this article, or to ask for a specific data export, open a ticket under Account & login at Contacting support. For complaints about how we’ve handled a request, your local EU/EEA data-protection authority is your escalation route.

Was this helpful?

Still need help?

Our team usually replies within a few hours. Pre-filling the right category for you.

Open a ticket

Related articles

Discover