Privacy Policy
Last updated: 28.07.2026
1. Data Controller
The data controller for data processing on this website is the operator of AdultHouseFinder.com. Full details about the data controller can be found in the Legal Notice.
2. Registration and Account Data
During registration, we collect the following data: email address and password (stored encrypted using bcrypt). An internal username is automatically generated and is not part of the registration input.
Registration requires email confirmation. For this purpose, a temporary verification token is stored, which is automatically deleted after successful confirmation.
For security reasons, we additionally store: the number of failed login attempts, any account lockout timestamp, and the time of the last successful login.
Additionally, we store your preferred language setting in order to display the website in your chosen language on future visits. This setting is automatically determined from the language in use at the time of registration and is stored in your user account.
For the "Forgot Password" function, a temporary reset token is generated and sent by email. The token is valid for 1 hour and is automatically deleted after use or expiry. To protect against brute-force attacks, the IP address is temporarily used for rate limiting during login (account lockout after 5 failed attempts for 15 minutes); the IP address is not stored permanently.
2a. User Registration
In addition to provider registration, Adulthousefinder.com offers a free user registration. During user registration, we collect the following data: nickname (3–20 characters, publicly visible in future reviews), email address and password (stored encrypted using bcrypt).
The nickname is chosen by the user and must be unique. It will be publicly displayed in the context of reviews. Users are explicitly informed of this during registration.
Registration requires email confirmation via a temporary verification token, which is automatically deleted after successful confirmation. For security reasons, we additionally store the number of failed login attempts and any account lockout timestamp.
To prevent abuse, the IP address is used for rate limiting during registration (max. 5 registrations per IP per hour). The IP address is not stored permanently.
Users can delete their account at any time independently and irrevocably (in the user dashboard under "Delete account"). All personal data (email address, nickname, password) will be pseudonymised in accordance with GDPR Art. 17.
3. Profile Data
Providers who create a public profile can provide the following data: profile name, short and long description, city, street, postal code, and geographic coordinates (latitude/longitude), which are automatically determined from the entered address via OpenStreetMap/Nominatim (see Section 12). Additionally, opening hours, website URL, and links to social media profiles (e.g., WhatsApp, OnlyFans, Telegram, Twitter/X) can be provided.
Providers in the Escort, Model and Trans categories may additionally provide the following personal details on a voluntary basis: age, height, measurements (bust/waist/hips), hair colour, eye colour, languages spoken, origin/nationality, and travel availability. These details are entirely optional. When the profile is active, they are publicly displayed and may be indexed by search engines. They can be changed or deleted at any time in the dashboard.
This profile data is publicly viewable when the profile is active. Internally, we also store a completeness score for the profile and a timestamp of the last profile activity for sorting and quality purposes.
4. Image Upload
Providers can upload profile images that are stored on our servers. One image can be designated as the profile's cover image. Images are publicly viewable when the profile is active and are also removed upon deletion of the profile or account.
4a. Automatic Face Detection During Image Upload
When uploading profile photos, an optional feature is available that automatically anonymises faces in the photo (mosaic/pixelation effect). This feature is activated via a checkbox ("Privacy: Automatically blur faces") and is enabled by default.
Face detection and image processing take place entirely in the user's browser (client-side processing). The unedited original photo never leaves the user's device. Only the already processed image is transmitted to our servers. No biometric data is collected or stored.
The AI model used for detection (TinyFaceDetector, part of the open-source library face-api.js) is loaded from our own servers – no data is transmitted to third parties. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in providing a privacy-friendly upload feature).
5. Statistics and Click Data
We collect anonymized usage statistics for profiles: the number of profile views and aggregated click events by channel (e.g., website click, contact click). This data is exclusively viewable by the respective provider in the dashboard and is not shared with third parties.
6. Inactivity Reminders
If a registered provider has not logged in for 6 months or longer, a reminder email may be sent. The time of the last reminder is stored to avoid multiple mailings. These notifications can be permanently stopped by deleting the account.
6a. Profile Notifications (Follow Feature)
Registered users can optionally activate email notifications for individual favourited profiles (bell icon in the dashboard; disabled by default). When enabled, users receive an email when the provider updates their profile (e.g. name or description).
Data processed: The notification setting is stored as a flag
(notify) in the favourites relationship. After a notification is
sent, a log entry is created to prevent more than one email being sent for the
same profile within 24 hours (debounce). This entry contains only the user ID,
profile ID, and sending timestamp, and is not linked to any other data.
Unsubscribe: Every notification email contains a personal
one-click unsubscribe link that can be used without logging in. The link is
cryptographically signed (HMAC-SHA256) and valid for 7 days. Notifications
can also be disabled at any time in the dashboard.
Legal basis: Art. 6(1)(a) GDPR
(active consent by explicitly enabling the feature).
Email delivery is handled by Brevo (see Section 14).
6b. Private Messaging (DM, from May 2026)
Verified users can have 1:1 private conversations with providers who have explicitly enabled this feature. The feature is disabled by default and must be activated per profile by the provider ("Inbox Settings" in the provider dashboard).
Processed data: Message content (text, max. 4,000 characters), sender and recipient IDs, timestamps and a technical idempotency key (client UUID). At opt-in and at revocation, the audit log additionally records IP address, user agent, language setting as well as version number and cryptographic hash (SHA-256) of the consent text. This hash serves as evidence under Art. 7(1) GDPR of the exact wording consented to.
Special categories of data: Since contents may concern sexual life, we obtain prior explicit consent pursuant to Art. 9(2)(a) GDPR. Consent is given via a separate checkbox in the opt-in form.
Legal bases:
For message contents: Art. 9(2)(a) GDPR (explicit consent).
For connection data, audit log and block list: Art. 6(1)(f) GDPR (legitimate interest in functioning platform communication, abuse prevention and compliance with legal duties of care).
Storage period and separation:
– Message contents: automatic deletion 90 days after sending (data minimisation, Art. 5(1)(c) GDPR).
– Conversations with pending abuse reports ("legal hold"): kept until the reported matter is resolved.
– Block list (dm_blocks): kept for three years on the basis of Art. 6(1)(f) GDPR (abuse prevention). The period is oriented on the general limitation period in §§ 195, 199 BGB (German Civil Code).
– Consent audit log: kept under the accountability principle Art. 5(2) GDPR for the duration of the feature plus limitation; on revocation, the original consent log is preserved as proof.
Recipients: Message contents are transmitted only to the respective conversation partner. Administrative access is only granted upon active abuse reports and is itself logged.
Third-country transfers: The platform is delivered via the Cloudflare CDN (cf. section 13); connection data may therefore briefly be processed in the United States. Basis are Standard Contractual Clauses (SCC) and Cloudflare's self-certification under the EU-US Data Privacy Framework. Message contents themselves are stored only on EU servers (Amsterdam hosting) and are not transferred outside the EEA.
Your rights:
– Access (Art. 15 GDPR): includes contents and metadata of your active conversations.
– Early erasure (Art. 17 GDPR): you can delete individual messages within five minutes of sending, or hide/close an entire conversation. You may also request early erasure of your full DM history via support.
– Data portability (Art. 20 GDPR): your messages are provided in JSON format on request via data export.
– Objection (Art. 21 GDPR): against processing based on legitimate interests at any time.
– Right to lodge a complaint (Art. 77 GDPR): with your competent supervisory authority.
Withdrawal of consent: Providers may deactivate the DM feature per profile at any time. Existing conversations are then muted (history remains visible, no new messages). Withdrawal applies for the future; the lawfulness of processing prior thereto remains unaffected.
Automated decisions (Art. 22 GDPR): For abuse prevention, technical sending rates are limited (e.g. max. three new conversations per 24 hours); exceeding the limit blocks further sends. This throttling is purely technical and not final. Re-enabling or clarification is handled informally via support.
Technical delivery: Messages are delivered over an encrypted real-time connection (WebSocket over TLS), authenticated by a short-lived signed session token. E-mail notifications on new messages are sent via Brevo (see section 14).
Internal complaint mechanism (Art. 20 DSA). Whenever
a person receives a notification about a moderation decision in the DM area,
that notification includes a personal, cryptographically signed objection
link of the form /dm/widerspruch/<token>. Through this
form the decision can be contested informally and without re-login within
six months of receipt. Appeal proceedings are recorded
in the internal table dm_appeals; the token itself is stored
only as a SHA-256 hash.
Digest emails and 1-click unsubscribe. For new messages
the platform may send – earliest 15 minutes after receipt and with a
4-hour per-recipient cooldown – a bundled notification email via Brevo.
Each such email contains a cryptographically signed 1-click
unsubscribe link (HMAC-SHA256, valid 7 days) and the
RFC 8058 List-Unsubscribe header. One click permanently
disables the digest emails without any login (Art. 21(3) GDPR).
DM data export (Art. 20 GDPR). Logged-in users can
obtain a JSON export of their DM data (conversations, messages, consent
history) via the self-service endpoint
/user/account/export. For abuse-prevention reasons, this
export is rate-limited to one request per 7 days;
every call is recorded in the audit log with timestamp and IP.
Outbox pattern for DSA emails. Acknowledgements of
reported messages and the subsequent statement of reasons regarding the
moderation decision are delivered asynchronously via an internal queue
(dm_dsa_outbox). This guarantees, at the technical level,
the 24-hour acknowledgement deadline set out in Art. 16(5) DSA.
8. Cookies and Sessions
We use session cookies for the operation of the platform. These cookies are
technically necessary and are not used for tracking purposes. Optionally,
a "Remember me" cookie can be set (30-day duration). To store your cookie consent, the cookie ahf_cookie_consent
(365 days) is set.
To store your age verification, the cookie ahf_age_ok
(30-day lifetime) is set; this cookie is technically necessary to avoid
repeating the legally required age verification on every page visit.
When you change your password, for security reasons your session identifier is regenerated and your "Remember me" token is reset. Existing parallel sessions and automatic sign-ins on other devices or browsers are terminated; you will need to sign in again with the new password.
In addition to cookies, the platform uses local browser storage
(localStorage and sessionStorage) for technical
auxiliary data: e.g., the most recently viewed map
position (center and zoom level) of the overview map on the home page.
This data remains exclusively in the
browser and is not transmitted to our servers.
9. Server Logs
When accessing our website, information is automatically stored in server log files (IP address, time, page accessed). This data is not combined with other data.
9a. Content Security Policy Reports
For security reasons our website uses a Content Security Policy (CSP) that tells browsers which resources (scripts, stylesheets, images, fonts) are permitted on our pages. If an unexpected resource is encountered, the browser automatically sends a technical report to our server.
These reports only contain: the URL that was accessed, the blocked resource, the violated directive and a truncated hash of the browser type. No personal data (name, email, session cookies, IP address) is stored.
Purpose: detection of technical errors and improvement of our website's
security.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure
website).
Retention period: at most 30 days, after which the data is automatically
deleted via log rotation.
10. Reporting Function
Users can report profiles via the report form. The reporter's IP address is stored as a non-reversible HMAC-SHA256 hash to prevent abuse (spam reports). Tracing back to the original IP address is technically impossible. Report data is deleted after processing.
10a. Ratings and Review System
Registered users can rate provider profiles with a star rating (1–5 stars) and an optional free-text comment. The following data is processed: number of stars, comment text (optional), language of the comment, and a SHA-256 hash of the IP address for abuse prevention (no plain text, technically impossible to trace back to the original IP address).
Reviews are linked to the user account. The reviewer's self-chosen nickname is publicly visible on the profile page. Every review goes through a manual moderation process before publication; rejected reviews are not published.
Providers have the option to publicly reply to reviews. These replies are also visible on the profile page.
A user account can only rate a profile once. If a user account is deleted, the link to the review is removed (the user reference is anonymised); the review text is retained in anonymised form to preserve the integrity of the profile's overall rating.
The legal basis for this processing is Art. 6(1)(f) GDPR (legitimate interest in providing transparent, user-based reviews).
11. Your Rights (GDPR)
You have the right to access, rectification, deletion, restriction of processing, and data portability. To exercise your rights, please use our contact form.
12. Third Party: OpenStreetMap / Nominatim
We use the Nominatim service from OpenStreetMap for geo-search and for automatic coordinate determination from addresses. Queries are transmitted to OpenStreetMap Foundation servers. To minimize the number of requests, query results are cached on our servers for up to 30 days. Please refer to the OpenStreetMap Foundation's privacy policy: wiki.osmfoundation.org/wiki/Privacy_Policy.
Optional geolocation (location button): The search bar on the homepage contains an optional location button (crosshair icon). If you click it, your browser requests permission to access your device's location via the browser's native Geolocation API. This permission dialog is a browser security feature — we have no influence over it and do not receive your location if you deny. If you grant permission, your coordinates (latitude/longitude) are transmitted directly from your browser to the Nominatim service of the OpenStreetMap Foundation for reverse geocoding (converting coordinates into a city name). Your coordinates are not transmitted to our servers and are not stored by us. Only the resulting city name is filled into the search field in your browser. The legal basis is Art. 6(1)(a) GDPR (your explicit consent via the browser permission dialog). You can revoke location permission at any time in your browser settings.
In addition, we embed interactive map views on the homepage and search results page. Map tiles are loaded directly from the tile servers of the OpenStreetMap Foundation. When loading these tiles, your device's IP address is transmitted to OpenStreetMap Foundation servers. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in providing a user-friendly map view). Please refer to the OpenStreetMap Foundation's privacy policy linked above for further details.
Address geocoding during provider registration: When providers enter their address (street, postal code, city) during profile setup or when editing their profile, their browser sends the entered address data directly to the Nominatim service of the OpenStreetMap Foundation to determine the geographic coordinates (latitude/longitude) for the map pin. This transmission occurs directly from the provider's browser and is not relayed through our servers. The provider's IP address and the entered address are transmitted to OpenStreetMap Foundation servers. The legal basis is Art. 6(1)(b) GDPR (performance of the contract for creating a provider listing).
13. Third Party: Cloudflare CDN
To deliver stylesheets, JavaScript libraries, and icon fonts (Bootstrap, Font Awesome, etc.), we use the Content Delivery Network (CDN) of Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). When loading these resources, the visitor's IP address is transmitted to Cloudflare servers. Cloudflare is certified under the EU-US Data Privacy Framework. Please refer to Cloudflare's privacy policy: cloudflare.com/privacypolicy.
13a. Hosting: Cloudzy (Amsterdam, EU)
The application is hosted on a virtual server provided by Cloudzy in Amsterdam (Netherlands). Cloudzy acts as a processor under Art. 28 GDPR. No transfer to third countries takes place within the hosting layer; only the upstream Cloudflare CDN (section 13) may technically touch US infrastructure briefly.
14. Third Party: Brevo (Email Delivery)
For sending transactional emails (e.g., registration confirmation, password reset, profile notifications), we use the email service of Sendinblue SAS (trading as Brevo, 7 rue de Madrid, 75008 Paris, France). The recipient's email address and the respective email content are transmitted via Brevo's servers. Brevo acts as a data processor in accordance with Art. 28 GDPR. Please refer to Brevo's privacy policy: brevo.com/legal/privacypolicy.
15. Profile Claims (Taking Over Imported Profiles)
Providers can initiate a claim process to take ownership of an imported profile. In doing so, the profile ID, provider ID, and an optional justification message are stored. Claims are manually reviewed by an administrator and either approved (the profile is transferred to the provider) or rejected. The claim data remains in the database after the process is concluded for documentation purposes. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in correct profile assignment).
16. Our Social Media Presences (X / Telegram)
We operate presences on the following social media platforms:
- X (formerly Twitter), operated by X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA
- Telegram, operated by Telegram Messenger Inc. / Telegram FZ-LLC, Dubai, UAE
When you visit our presences on these platforms, the respective platform operators collect data (e.g. IP address, device information, usage behaviour). We ourselves only receive aggregated, non-personal statistics (e.g. reach, interactions). We have no influence over the data processing carried out by the platform operators.
For our X presence, we may act as joint controllers together with X Corp. within the meaning of Art. 26 GDPR, insofar as X provides us with insights data about visitors to our profile. The legal basis for maintaining our social media presences is Art. 6(1)(f) GDPR (legitimate interest in public relations and communication with prospective users).
Please refer to the privacy policies of the respective platforms:
- X: x.com/privacy
- Telegram: telegram.org/privacy
You can object to data processing by these platforms by using the respective privacy settings within the platforms or by not visiting our presences.
16a. Contact Form
When you use our contact form, we process the following data: name, email address, subject and the content of your message. For abuse protection we also store your browser (user agent) and a hashed version of your IP address (HMAC-SHA256, not reversible). The hash is used solely for rate-limiting and spam prevention.
Purpose: handling your request and ensuring security
and abuse prevention on the form.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest
in responding to enquiries and operating the service securely). Where
your request concerns the initiation or performance of a contract,
additionally Art. 6(1)(b) GDPR.
Retention: data submitted via the form is deleted
90 days after receipt, unless a longer statutory retention period
applies or processing is still ongoing.
Recipients: operator only. No data is transferred
to third parties.
17. AHF Games (House of Pairs)
The page /games/house-of-pairs and the tab switcher on the start page offer
the memory game House of Pairs. We do not process any
personal data in connection with this game. The following values are stored
only locally in your browser via localStorage and are
never transmitted to our server:
hop_easy_best_v1,hop_medium_best_v1,hop_hard_best_v1– best time per difficulty (seconds)hop_sound_on– sound preference (on/off)hop_difficulty– last selected difficulty
This data serves convenience only (showing best time, remembering sound preference). You can delete it at any time by clearing your browser's site data for www.adulthousefinder.com.
18. Web Analytics (Umami)
This website uses Umami, a privacy-friendly open-source analytics tool that we host on our own server. Umami sets no cookies and stores no personal data. IP addresses are not retained.
We collect only anonymised usage statistics such as pages visited, time on site,
country of origin, device type, and referrer. Individual visitors cannot be
identified. All data remains exclusively on our own servers and is not shared
with third parties.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in
optimising our online offering).
19. ahf.to – Link Hub & Short Links
We operate a Link Hub service at the domain ahf.to. It serves
two purposes: (a) short links of the form
ahf.to/profilename redirect visitors directly to provider profiles
on adulthousefinder.com; (b) Link Hub pages allow registered
providers to publish a public micro-profile at ahf.to/{slug} listing
their social media accounts, booking links and other relevant URLs.
Data stored for a Link Hub page: display name (up to 120 characters),
short bio (up to 300 characters), an optional avatar image uploaded by the provider,
the selected visual theme, and up to several external links (platform type, title, URL).
A Link Hub page may be linked to the provider's AdultHouseFinder profile or account.
All content of an active Link Hub page is publicly accessible without
login via ahf.to/{slug}.
Click analytics: Each click on a link inside a Link Hub page increments an anonymised click counter stored in our database. No personal data of visitors is stored beyond the regular server logs (see Section 9).
Short link redirects: When a short link pointing to a club profile is accessed, the request is processed via our servers and forwarded to the corresponding profile page. Technical data (IP address, timestamp, browser type) may be recorded as part of the regular server logs (see Section 9) and no further storage takes place.
Providers can deactivate their Link Hub page at any time via the dashboard; the page will then no longer be publicly accessible. To permanently delete all Link Hub data, please use the account deletion function (see Section 2) or contact us via the contact form.
The domain ahf.to is served via the Cloudflare network
(see Section 13).
Legal basis: Art. 6(1)(a) GDPR (consent – providers voluntarily
create and publish their Link Hub page) for the Link Hub feature;
Art. 6(1)(f) GDPR (legitimate interest in providing user-friendly short links)
for redirect-only short links.