Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how GERSOG DIGITAL MEDIA LTD collects, uses, and shares your information when you use Kisscat Studio. By using the website, you agree to this policy.
Information We Collect
- Account data: email, username, password hash. An email address is not required for an X-only account.
- Third-party sign-in data: when you use Sign in with X, the X user ID, current @handle, display name, avatar URL, sign-in time, and the fact that you authorized the sign-in flow. We do not retain the temporary X access token used to complete sign-in.
- Performer-link data: the private association between a Studio account, an immutable X user ID, and an existing model record, including link, verification, revocation, and reset timestamps.
- Payment data: handled by payment processors (we do not store full card details).
- Purchase and balance records: invoice identifiers, Studio Credit balances and transaction ledgers, purchased-video entitlements, carts and saved-video choices, automatic-purchase instructions, checkout consent records, and download audit events. The dedicated photo-download audit record contains limited authorization and operational metadata and does not store the private album token. The full requested URL may still be processed temporarily by browsers, hosting, content-delivery, security, or other network infrastructure under their applicable operational logging and retention controls.
- Usage data: IP address, browser type, device identifiers, and viewing activity.
- Cookies and similar tracking technologies.
- Casting application data: contact details, age and identity-related information, professional experience, availability, stated performance boundaries, and application photographs submitted voluntarily by adult applicants.
How We Use Information
- Provide and secure access to the service.
- Authenticate users through X, display the connected X identity, and prevent duplicate or fraudulent performer claims.
- Match an approved model's first claim by the configured X handle and bind later sign-ins to the immutable X user ID.
- Authorize and audit a verified performer's downloads of published original photographs associated with that performer's own model record.
- Authorize owner-issued private album links without writing the bearer token to the dedicated photo-download audit record.
- Process subscriptions, Studio Credit top-ups, balance purchases, payment reversals, and refunds.
- Provide personal purchased-video galleries, authorize downloads, prevent unauthorized access, and resolve payment disputes.
- Restore carts and saved videos across signed-in devices and complete authorized purchases after a balance top-up.
- Measure marketplace performance, including card impressions, cart activity, checkout completion and failed purchase steps, and improve the service.
- Review performer applications, assess suitability, plan potential shoots, and contact applicants.
- Comply with legal obligations.
X Sign-In and Performer Linking
When you choose Sign in with X, X processes the authentication request under its own terms and privacy policy and returns the limited profile information described above. Kisscat Studio uses that information to create or access your Studio account. We request only the sign-in permissions needed to identify the X account.
An approved model's first claim compares the current X handle with the exact handle configured by the owner. If it matches, the link is stored against the immutable X user ID so a later handle change does not transfer model access. We do not use X sign-in to infer that an unrelated account is a performer, and existing accounts are not merged automatically.
Cookies
We use cookies for authentication and site functionality. The signed studio_age_decision cookie
remembers adult self-attestation, not verified age, for a configurable period (30 days by default).
Where age assurance is required, studio_yoti_browser binds the browser for up to 24 hours and
studio_age_assurance carries a signed age-check proof for the configured period (currently one hour).
These cookies are HttpOnly and SameSite=Lax; Secure is set on secure requests. You can adjust cookie settings
in your browser, but blocking required cookies may prevent access.
First-party Studio analytics requires kisscat_cookie_consent=analytics and no Global Privacy
Control signal. If configured, Google Tag Manager loads before any site-wide consent banner; its external
container's actual tags are not established by this code. We do not claim that GTM waits for consent.
Age Assurance Data
If age assurance is required and available, Yoti handles the check. A temporary Yoti pending record in Redis contains session and browser-binding information, profile and policy details, the hosted-check URL and poll state. Its TTL is 15 minutes. The signed proof cookie contains the profile and policy versions, territory, method, age threshold and result age, verification and expiry times, a hashed provider-session identifier and a browser binding. These details support access decisions and fraud prevention.
For age-verification analytics, Firestore stores event time, territory, method, result state and technical status, plus SHA-256 hashes of provider session, reference, browser and, when present, evidence identifiers. These hashes are pseudonymous, not anonymous. They support verification operations and reporting and can remain after account deletion; this code does not set a retention period for these analytics records. Yoti also processes verification information under its own controls.
GDPR Rights (EU Users)
- Right to access, correct, or delete your personal data.
- Right to restrict or object to processing.
- Right to data portability.
CCPA/CPRA Rights (California Users)
- Right to know what personal information we collect.
- Right to request deletion of personal information.
- Right to opt out of sale or sharing of personal information.
- Right to limit use of sensitive personal information.
Email us at privacy@kisscat.xyz to opt out of the sale or sharing of personal information.
Data Retention
We retain personal data only as long as necessary for the purposes described above or as required by law. Payment, balance-ledger, tax, fraud-prevention, dispute, and consent records may be retained after account closure where reasonably necessary or legally required, with access restricted and identifiers minimized where appropriate.
Active X identity and performer-link records are retained while the Studio account or verified link remains active. If a linked Studio account is deleted, the live X association and download authorization are removed. We may retain minimal non-identifying security, revocation, accounting, dispute, or compliance records where reasonably necessary or legally required. Public model cards and legally required performer compliance records are managed separately and are not automatically deleted merely because a Studio login is removed.
On successful account deletion, we remove the account's location history and selected account-linked records. Financial records, including invoices, purchases and balance transactions, are pseudonymised rather than deleted. An account with a positive Studio Credits balance cannot be deleted until the balance is used or support resolves it. Pseudonymous age-verification analytics can remain under a separate, unspecified retention period. Backups may persist under infrastructure retention controls; this code does not establish their retention period or guarantee immediate physical erasure from backups.
When location history is enabled, signing in records a limited server-side location observation (the time in UTC, the country, and a valid US state when the country is the United States) so we can apply age-assurance rules, prevent fraud and account misuse, and respond to legal and support requests. We keep at most the 20 most recent observations. Entries older than 365 days are excluded on update and marked with a 365-day expiry; physical expiry depends on the Firestore TTL configuration.
Casting Applications
Casting applications may contain sensitive information and photographs. They are used only for private casting review, applicant communication, safety planning, and any later contracting process. Application materials are not published merely because an application was submitted. Applicants should not upload identity documents through the casting form; age and identity verification is requested separately if an application proceeds.
Applicants are solely responsible for the legality, accuracy, ownership, consent, and authorization of every file and statement they submit. To the fullest extent permitted by applicable law, GERSOG DIGITAL MEDIA LTD is not responsible for unauthorized, unlawful, false, or third-party material uploaded by an applicant.
Applicants may withdraw an application or request deletion of application materials by contacting privacy@kisscat.xyz. Legal or compliance records may be retained where required by law.
Contact
For privacy-related inquiries, contact privacy@kisscat.xyz.
Postal correspondence: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.