Privacy Policy
1. Data collected
The service database stores email addresses, generated display names (or names received from a chosen sign-in provider), account creation and last sign-in times, email verification times, roles and account status, session and verification hashes, independent provider identifiers, consent versions and times, orders and payment confirmations, diamond rewards, daily check-in dates, top-ups and episode unlock debits, membership records, favorites, viewing progress, temporary playback sessions, per-episode base and actual play counts, manual playback compensations, payment exceptions and administration audit records. The live account schema contains no password field; old password hashes have been removed from it. Historical backups may retain previous records until their retention period ends. We do not ask for a date of birth or identity document in the entry confirmation.
2. Purpose
These records support account verification, sign-in, access control, purchases, account management and security. Verification codes expire after ten minutes and can be used once. The website does not collect card details. When payments are enabled, the payment provider will process the required payment information.
3. Cookies
Necessary cookies remember your entry confirmation for up to 90 days, your session for up to seven days, and the browser binding for verification and social sign-in for one day. They are not advertising consent. Entry confirmation is required again after expiry.
4. Services and sharing
When enabled, Resend receives the destination email address and verification message. Google, X or Telegram processes your chosen sign-in and shares the authorized identity information. Bunny Stream receives video delivery requests. When cryptocurrency payments are enabled, OxaPay processes checkout and returns transaction status; the service stores order identifiers, payment tracking identifiers, checkout links and payment confirmations. Delivery and payment services receive the network information needed to handle those requests. We request basic sign-in information, not permission to post or message on your behalf. Server tokens and merchant secrets are not published in the browser.
5. Storage and rights
Account records are stored on the configured application server. Bunny Stream delivers video through its configured locations. Contact the site administrator to request access, correction or deletion of your records and provider identities. Expired verification challenges and authorization states are removed when new verification or authorization requests are made, after an additional one-day window. Order and consent records may need retention for account and transaction checks.
6. Minors and policy changes
The service is restricted to eligible adults. If an ineligible account is identified, contact the administrator to restrict access and handle its data. Policy changes receive a new version. Account and transaction records are retained for service and transaction checks.