PetMeUp
Version 6 · In force from September 30, 2026

Privacy notice

Draft pending legal review: this text describes how the demonstration works today and may change.

What personal data PetMeUp keeps, why, and your rights. This is a draft awaiting legal review.

Controller

The PetMeUp operator is the controller of your personal data. Its legal identity and contact details will be published here before any public launch.

What we keep

Your email address, a hash of your password (never the password itself), your sign-in sessions and the time each expires, and whether your email is confirmed. We also keep short-lived records of failed sign-in attempts (keyed by a hash of the email) and queued account emails, encrypted until sent.

Profile drafts you save: display name, handle, biography, city and activities.

Verification results from an identity provider (adult, identity and phone checks, their expiry). PetMeUp does not store identity documents, selfies or dates of birth.

Reports you send or that concern your profiles, staff decisions with their reasons, and appeals. Staff actions are recorded in an audit log.

If you report illegal content without an account, the name and email address you give, kept with the case to confirm your report and tell you the outcome; the person reported never sees them. If an account is banned, the ban, its reasons, dates and any appeal. The language of your last sign-in, so that notices reach you in it.

If you are a creator: the photos, videos and caption files you upload, kept on our own server, with their review status and our reasons; and your posts (caption, files, whether explicit, and when published). Location data is removed from photos in your browser before upload, and files that still carry it are refused.

If you appear in a creator’s post and answer their invitation: whether you accepted or declined, when, the wording you agreed to and the files it covers, linked to your account. If you decline or withdraw, we keep that record so the files are never used again; when your account is erased, your releases are withdrawn and no longer linked to you.

If you send or receive messages: their text, who each conversation is between, when messages were sent, what you have read, and anyone you have blocked. Messages are kept until an account is deleted; that person’s messages then lose their text, and the conversation stays for the other person.

Why we use it

To run your account and keep it secure, to review and publish profiles, to handle reports and appeals, and to meet legal duties. We do not sell personal data and do not use advertising or analytics trackers.

Who sees it

Staff see what they need to review profiles, reports and appeals. The person you report never sees who reported them or what you wrote. Our hosting provider stores the data on our behalf.

On a first visit to the bare address, when your browser does not ask for a language we support, your browser asks country.is for your country so we can suggest a language; that service receives your IP address. Nothing else is sent to it.

Uploads stay private until our team reviews them. Published non-explicit posts of an approved, verified creator are visible to anyone who has confirmed being 18 or older; explicit posts are seen only by their creator and our team until paid access exists. Files are delivered only through links that expire after 10 minutes.

For a post with other people in it, the creator sees whether each release is waiting, accepted, declined or withdrawn, but not your account details; our team can see who gave a release when reviewing a case. You can withdraw a release at any time from your dashboard: the post is hidden at once.

Only the two people in a conversation see its messages. Creators see members as an anonymous tag, never their email. Our team sees a private message only when someone in the conversation reports it, and each such view is logged.

How long we keep it

Sessions end after 7 days or when you sign out. Email and password links expire soon after they are sent and are stored only as hashes. Other data is kept while your account exists; a full retention schedule will be published before launch.

To limit abuse, reports are counted per network address and per email address for one hour under a one-way hash; network addresses themselves are not stored. Notices are kept encrypted until sent and dropped if they cannot be sent within 10 business days. A banned person’s link to the decision and to their data works for 6 months.

Your rights

You may ask for access to, correction or deletion of your data, restriction of or objection to its use, and a copy to take elsewhere. You may complain to the Hellenic Data Protection Authority (www.dpa.gr).

You can download your data or delete your account yourself on the Privacy page of your account. Deletion signs you out and hides your profiles at once, and erases the account after 30 days unless you sign in again first. While a report, dispute or appeal involving you is open, or a lawful request from a competent authority applies, we keep the data needed to resolve it safely for everyone involved and to meet our legal obligations (GDPR Art. 17(3)), tell you why, and erase it once that ends. Moderation records are kept without your identity. We share data with police, courts or other competent authorities only when the law requires it.