Privacy policy
Last updated 2 October 2026
the operator of Subz is the controller of your personal data under UK GDPR. This policy explains what we collect, why, and your rights.
What we collect
- Account data: name, username, email, password (stored as a one-way hash), date of birth and country.
- Identity verification (creators and co-performers): legal name, date of birth, photo ID and a selfie. This is special category data used only to confirm age and identity.
- Content and activity: posts, messages, comments, likes, subscriptions and purchases.
- Payment data: transaction records. Card details are handled by our payment processor; we never see or store full card numbers.
- Payout data (creators): bank details, stored encrypted.
- Technical data: IP address, device and browser information, and security logs.
Why we use it (lawful bases)
- To provide the service and take payments — contract.
- To verify ages and identities, keep records required by law, and prevent fraud and abuse — legal obligation and legitimate interests; for ID documents, the substantial public interest in preventing unlawful acts and safeguarding.
- To send service messages (e.g. payment receipts, security alerts) — contract.
We do not sell your data and do not use advertising trackers.
Who we share it with
Payment processors, our hosting and video-streaming providers, identity-verification providers (when used), professional advisers, and law enforcement where the law requires it. Creators see your username, display name and what you choose to share with them — never your email, date of birth or payment details.
How long we keep it
Account data for as long as your account is open. Payment records for 6 years (tax law). Identity and age-verification records for creators and co-performers for at least 7 years after the content is removed, as required by record-keeping laws. Security logs for up to 12 months.
Your rights
You can ask to access, correct, delete or export your data, or object to or restrict how we use it. Email [email protected] — we reply within one month. You can also complain to the Information Commissioner’s Office (ico.org.uk).
Security
Passwords are hashed, ID documents and media are stored privately and served only through expiring links, bank details are encrypted, and staff access to verification documents is logged.