Eros
Legal

Privacy Policy

What Eros collects, what it deliberately does not collect, and who is responsible for what. Written to describe the system as it is actually built rather than to cover every possibility.

Effective 20 August 2026

Draft — not yet reviewed by a lawyer. This document was written against how Eros actually works, but it is not legal advice and must be reviewed by a qualified lawyer before Eros accepts real users. Highlighted passages mark decisions still to be made.

1. Who this covers

This policy covers two different groups, and the answers are different for each: account holders — creators and agency staff who sign in to Eros — and visitors who open a creator's page without an account.

The data controller for account data is Needs legal input: registered legal entity name, Needs legal input: registered address. Needs legal input: If a data protection officer or EU/UK representative is required, name them here.

2. Who is responsible for what

This distinction matters and is easy to get wrong.

  • For your account — your email, your pages, your settings — Eros is the controller.
  • For email addresses collected through a creator's page, the creator or their agency is the controller and decides what the list is used for. Eros processes those addresses on their behalf and does not market to them.
  • For content a creator publishes, the creator is responsible for having the right to publish it.

If you gave your email to a creator's page and want it removed, ask that creator. If you cannot reach them, contact us and we will help.

3. What we collect from account holders

  • Sign-in details — your email address, and either a hashed password or the fact that you signed in with Google. We never see or store your Google password.
  • Profile — display name and avatar, if you set them.
  • Page content — handle, title, display name, bio, avatar and cover images, theme, links and blocks, and any media you upload.
  • Agency data — agency name, logo, members and their roles.
  • Custom domains — the hostname, its verification token and status.
  • Claim links — the page, the invited email, and when the link was issued, used or revoked.
  • Subscription state — plan and status mirrored from our payment provider. We never receive or store your card details.

We use this to run your account, publish your pages, provide support, keep the service secure, and contact you about the service. Our lawful bases are performing our contract with you, our legitimate interest in keeping Eros secure and working, and where required, your consent.

4. What creator pages record about visitors

Eros does not currently record anything about visits to creator pages. When page analytics are switched on, each record will be deliberately coarse and will contain only:

  • which page and which element was involved
  • the kind of interaction — for example a view or a click
  • the time it happened
  • the domain a visitor arrived from, such as a social network — not the full address
  • a country, derived at the network layer
  • a broad device category, such as mobile or desktop
  • a visit hash that changes every day

These limits are fixed in the database schema rather than left to configuration, which is why the next section can state flatly what is never collected.

5. What we deliberately do not collect

These are design decisions built into the database, not promises we could quietly drop:

  • We do not store visitors' IP addresses. There is no column for one.
  • We do not fingerprint devices — no canvas, WebGL, font or hardware profiling.
  • We do not record mouse movement, typing rhythm or similar behavioural biometrics.
  • We do not set a persistent visitor identifier. The visit hash rotates daily, so the same person cannot be linked from one day to the next.
  • We do not sell personal data, and we do not share it with advertising networks.
  • We do not use third-party advertising or cross-site tracking pixels.

Be aware of one honest limitation: our hosting and security providers necessarily see IP addresses in transit in order to deliver the page and block attacks. We do not receive that data in a form we can attach to a visit, and we do not retain it.

6. Email sign-up on a creator's page

Where a creator's page invites you to leave your email, we store the address, which page and which block it came from, the exact wording of the consent you were shown, and when you agreed. Storing the wording verbatim means it is always possible to check what you were actually told.

You can unsubscribe at any time; we record when you did. Your address is not added to any Eros mailing list.

7. Tips

If you tip a creator we record the amount, the currency, the payment provider and its reference, and — if you provide them — your email address and message, so the creator can thank you. Card details are handled by the payment provider and never reach us.

8. Cookies

We use as few as we can:

  • Session cookies that keep you signed in. Without them the dashboard cannot work.
  • Cloudflare Turnstile, on sign-up and sign-in only, to tell people from bots.

We set no advertising or analytics cookies, which is why you are not asked to dismiss a consent banner.

9. Companies that process data for us

Each is bound to process data only on our instructions:

  • Supabase — database, authentication and file storage.
  • Vercel — application hosting and delivery.
  • Cloudflare — bot protection on sign-up and sign-in.
  • Resend — sending service email such as sign-in links.
  • ImprovMX — forwarding email sent to our addresses.
  • Google — only if you choose to sign in with Google.
  • Needs legal input: Payment provider — name once billing is live.
  • Needs legal input: Identity verification provider — name once verification is live.

10. Where data is held

Our providers operate internationally, so data may be processed outside your country, including in the United States. Where the law requires a transfer safeguard we rely on the relevant standard contractual clauses or equivalent mechanism. Needs legal input: Confirm the specific transfer mechanism and each provider's processing region.

11. How long we keep things

  • Account and page data: while your account is open, then deleted within Needs legal input: retention period of closure.
  • Interaction records: Needs legal input: retention period, after which they are aggregated or deleted.
  • Email sign-ups: until the creator deletes them or you unsubscribe.
  • Records we need for security, tax, or evidence in a safety investigation: as long as is necessary, and no longer.
  • Backups: overwritten on their normal cycle.

12. Your rights

Depending on where you live you may have the right to see a copy of your data, correct it, delete it, receive it in a portable form, object to or restrict processing, and withdraw consent. Where processing is based on consent, withdrawing it does not undo what was done beforehand.

Email hello@erostest.online to exercise any of these. We reply within one month. If you are unhappy with our response you may complain to your local data protection authority.

13. Under-18s

Eros is for adults. We do not knowingly collect data from anyone under 18. If you believe a minor holds an account or appears in content on Eros, contact us immediately and we will act.

14. Changes and contact

If we change this policy materially we will tell you before it takes effect. Questions: hello@erostest.online.