Privacy policy
Which personal data this website and the Noxette app process, why, for how long – and what your rights are. Last updated: 2026-09-27.
1. Controller
The controller responsible for data processing under the General Data Protection Regulation (GDPR) is:
— see the imprint —
2. In short
- We only process what is needed to run the website and the app for you.
- No advertising, no tracking, no analytics, no social media plugins, no third-party fonts or scripts.
- Only cookies that are strictly necessary: the login cookie and a security cookie that recognises your device – no tracking cookies.
- Because Noxette is about intimate life, we ask for your explicit consent to process that kind of data (Art. 9 (2) (a) GDPR). You can withdraw it at any time by deleting your account.
- You can download all of your data and delete your account yourself, at any time, in your profile.
3. Visiting the website
When you open a page, your browser sends technical data to our server: IP address, date and time, the page requested, browser type and language. The server needs this to deliver the page. The application itself does not write access logs. Error messages of the server (without page contents) are kept in the system log of the server for a short time to fix problems. Legal basis: Art. 6 (1) (f) GDPR – our legitimate interest in a secure, working website.
To protect accounts against password guessing, the server keeps the IP address and the username of failed logins in memory for 15 minutes. Legal basis: Art. 6 (1) (f) GDPR.
4. Your account
For an account we store: username, email address, a salted scrypt hash of the login key derived from your password (never the password itself), display name, title, role (dominant or submissive), an optional profile picture, the date you agreed to the terms, and which accounts you are connected with. Legal basis: Art. 6 (1) (b) GDPR – providing the service you signed up for.
Cookies
When you log in, we set noxette_session: a random key that keeps you logged in (for up to 90 days, or until you log out); only a hash of it is stored on our side. With it we set noxette_device: a random number that recognises this browser at the next sign-in, so we can warn you when someone signs in from a device you haven't used before (kept up to 400 days). While you sign in with Google, Apple or X, noxette_sso holds a random value for up to 10 minutes to protect that sign-in. All three are strictly necessary for the service you asked for and its security, so no cookie consent is needed (§ 25 (2) no. 2 TDDDG).
Your email address
We store your email address and whether you confirmed it. We use it only for your account: to confirm it (a link), to reset your password, for sign-in codes if you choose them, for security alerts, and for messages about your account or paid plan. No newsletters, no advertising. The emails are sent through our email service provider, who processes them on our behalf (Art. 28 GDPR). Legal basis: Art. 6 (1) (b) GDPR, and Art. 6 (1) (f) GDPR for security alerts (our and your interest in a secure account).
Sign-in security
For two-factor sign-in we store the secret shared with your authenticator app, or that you chose codes by email, and your recovery codes as hashes only. To protect your account we keep a list of up to 20 devices that signed in (browser and system, e.g. “Safari on iPhone”, the IP address and the times of the first and last sign-in) and count failed sign-ins for 15 minutes. You see the devices in your profile. One-time links and codes expire after 10 minutes to 48 hours and are deleted then. Legal basis: Art. 6 (1) (b) and (f) GDPR.
Signing in with Google, Apple or X
If you choose to sign in with Google (Google Ireland Ltd.), Apple (Apple Distribution International Ltd., Ireland) or X (X Internet Unlimited Company, Ireland), you are sent to that provider to sign in there. The provider then tells us an ID of your account there, your email address (and whether it is confirmed – with Apple possibly a private relay address) and your name. We store the ID and the address with your account to recognise you next time; the name only fills in the registration form. We receive no password, no contacts and no posts, and we tell the provider nothing about your use of Noxette. The providers may transfer data to the USA (EU-U.S. Data Privacy Framework). Their privacy policies apply to what happens on their side. You can remove the connection in your profile at any time. Legal basis: your choice to use it (Art. 6 (1) (a) and (b) GDPR).
5. Data about your sex life
Noxette is used to plan and document consensual BDSM and D/s activities. Depending on how you use it, the following data concern your sex life and are therefore special categories of personal data (Art. 9 GDPR):
- kink ratings and limits,
- toys, outfits and furniture, planned and completed sessions, ratings of sessions, notes,
- chastity status and history, the orgasm log and confessions,
- remote tasks, their completion, and proof photos or videos – these only in end-to-end encrypted form (see below),
- rules and suggestions between you and your partner, journal entries, wishes and requests, Subcoins, rewards and subchievements,
- a pussy-free counter, if the dominant starts one (start date and resets with optional notes),
- if you give it: which body parts you have (penis, testicles, prostate, vagina/vulva, breasts – each optional, "not said" is always possible). A dominant can also fill this in for a submissive they own. It is only used to leave out tasks and toys that don't fit a body, is visible to you and your partner, and is sent to the AI provider with AI suggestions (see below).
We process these data only on the basis of your explicit consent (Art. 9 (2) (a) GDPR), which you give when you register (or on your first login, if your dominant created your account). You can withdraw your consent at any time with effect for the future by deleting your account in your profile. Data your partner enters about you (for example a planned session with you) are processed on the basis of both of your consents.
Who sees what: a dominant sees the data of the submissives they own; a submissive sees their own data and their owner's name and title. Kink lists are only visible to others if you choose so. Proof files can only be opened by the submissive who sent them and their owner. Our administrators manage accounts (names, roles, dates), but the app gives them no view of your kinks, sessions, chastity or proofs. Technically, we could access the database of the service; we do not look at your data unless the law requires it or you ask us to.
End-to-end encryption of pictures and videos: proof pictures and videos are encrypted in your browser before they are uploaded (AES-256-GCM, with keys exchanged via elliptic-curve Diffie-Hellman P-256), for the submissive and their owner only. The key to open them is protected by a key derived from your password on your device (PBKDF2-SHA256 with 600,000 rounds). We store only encrypted files and encrypted keys: we cannot see what a picture or video shows, cannot hand out its content – and cannot restore access if you forget your password. Metadata we need to deliver them remains visible to us: who sent a file to whom, for which task and day, when, and how large it is.
Your password: your password never reaches our servers. Your browser derives a login key from it; we store only a salted scrypt hash of that key.
6. AI suggestions
AI features are optional: they are only used when a dominant asks for them – in the session wizard or for suggestions in the planner and during a live session. Then the relevant parts of the plan are sent to Google LLC (Gemini API) (USA): names and descriptions of tasks and items, the planned steps, the planned length and mood, the wishes a dominant writes for the session wizard, which body parts the submissive and the dominant have (if they stated it, as a short list like “has a penis; no vagina”), whether the submissive is locked in chastity and may come, what is worn, and the kink ratings of the dominant and – if shared – of the submissive (as kink names and stars). No names, usernames, passwords, notes, pictures or proof files are sent. The provider only uses the data to answer the request, according to its terms for API customers: privacy policy of the provider. Where the provider is located outside the EU/EEA, the transfer is based on the EU-U.S. Data Privacy Framework or standard contractual clauses (Art. 45, 46 GDPR). Legal basis: your consent (Art. 6 (1) (a), Art. 9 (2) (a) GDPR); a dominant decides for each request whether to ask the AI. Suggestions are proposals only – no decision with legal effect is made automatically (Art. 22 GDPR).
To find errors, we keep a short technical log of the last 150 AI requests in memory only (time, display name of the requesting dominant, status, duration and the AI's answer); it is deleted with every restart of the service and never written to disk. The data sent to the AI itself is only kept in it for requests made by our administrators. Legal basis: legitimate interest in a working service (Art. 6 (1) (f) GDPR).
7. Paid plans and payments
If you buy a plan, the payment is processed by Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Dublin 2, Ireland). You enter your payment details (and your email address, and a billing address where tax requires it) on Stripe's own checkout page – we never see or store card or bank details. To connect the payment to your account, we send Stripe your account ID, your display name and the plan you chose. From Stripe we receive and store: a customer ID, the status and period of your subscription, which plan you bought, whether a payment was refunded, and the brand and last four digits of your card (to show them to you). Stripe processes payment data as an independent controller, also to prevent fraud and to meet legal obligations: Stripe's privacy policy. Stripe may transfer data to the USA on the basis of the EU-U.S. Data Privacy Framework and standard contractual clauses. On your bank statement, the payment appears under a neutral name. Legal basis: Art. 6 (1) (b) GDPR (the contract) and Art. 6 (1) (c) GDPR (tax and accounting duties).
If you use a discount code, we store which code you used and when, so each code is used once per person. Plans received with a code that covers the whole price are recorded without any payment data.
Invoices and payment records are kept for as long as tax and commercial law require (in Germany up to 10 years, § 147 AO, § 257 HGB), also after an account is deleted – but only these records. When you delete your account, a running subscription is cancelled immediately.
8. Push notifications and storage on your device
Push notifications are off until you switch them on for a device in your profile. Then your browser gives us an address of its push service (run by the browser maker, e.g. Google, Apple or Mozilla), and we send the notices from your bell there – the short text of the notice and a link into the app. The content is encrypted for your device (Web Push encryption), so the push service only sees that a message is delivered, not what it says. You can switch push off, set quiet hours or remove a device at any time. Legal basis: your consent (Art. 6 (1) (a), Art. 9 (2) (a) GDPR).
Storage in your browser: the app keeps a few settings on your device (for example which view you chose or which suggestions you prefer) and, for encrypted pictures, the unlocked keys of this device (in IndexedDB, in a form that cannot be read out, deleted when you log out). The app itself is stored by your browser so it opens quickly and can be installed on the home screen. None of this is sent to us or anyone else; it is strictly necessary for the functions you use (§ 25 (2) no. 2 TDDDG).
9. Suggestion box
If you send a suggestion through the website, we store the text, the type of suggestion, the date and – only if you enter them – a name and an email address, to read it, answer it and, if we mark it as public, show it (without name or email) on the roadmap. Legal basis: Art. 6 (1) (f) GDPR – our interest in improving Noxette, and Art. 6 (1) (a) GDPR for the email address, if you want an answer. We delete suggestions when they are dealt with, at the latest after two years; you can ask for earlier deletion at any time.
10. How long we keep data
- Account data: as long as your account exists.
- If you delete your account, all your data are deleted immediately. Proof files are deleted with it.
- If an admin removes an account, it is kept for 30 days so it can be restored, then deleted automatically.
- Login sessions expire after 90 days.
- Backups are overwritten in their regular cycle; data deleted from the service disappear from them at the latest when the cycle completes.
11. Recipients
We do not sell or share your data. Recipients are only: the people you are connected with in the app, the AI provider named above (only for AI suggestions), Stripe for payments (only if you buy a plan), the push service of your browser (only if you switch push on, and only encrypted), and authorities if we are legally obliged.
12. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). You can withdraw consent at any time with effect for the future (Art. 7 (3) GDPR).
Most of this you can do yourself: in your profile under Your data you can download everything we store about you (as a JSON file) and delete your account. For anything else, contact us.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state where you live or work.
13. Security
Passwords never reach our servers – only a key derived from them, stored as a salted scrypt hash; session tokens are stored only as hashes. Proof pictures and videos are end-to-end encrypted. All connections use HTTPS, and pages are delivered with strict security headers. Failed logins are rate-limited. Proof files are never cached by browsers or proxies.
14. Minors
Noxette is only for adults. We do not knowingly process data of people under 18. If you learn that a minor has an account, please tell us and we will delete it.