This version is a translation for your orientation. The German version is legally binding.

Privacy policy

As of 21. September 2026 um 15:30

This policy describes which personal data we process when you use DaddyBoy, why we do so and which rights you have. It applies to the web app at daddyboy.eu including the installable app version.

1. Controller

Bedrijf voor lekker internetten B.V., Markt 19, 6071 JD Swalmen, Niederlande. Email: info@bvli.nl.

Contact for data protection: Thorsten Norman Sommer, datenschutz@daddyboy.eu.

2. Principles

  • We do not sell data and do not show personalised advertising.
  • We do not use third-party tracking services. Reach measurement, if any, happens exclusively on our own servers without cookies.
  • All servers are located in the Netherlands. Service providers are based in the EU or are covered by an adequacy decision.
  • You use the platform under a pseudonym. Your real name is not required.

3. Which data we process

3.1 Account

Username (pseudonym), email address, password (as a hash only), date of birth, language setting, account status, time of the last login. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

3.2 Consents

We store which consents you gave, when and in which version, together with IP address and browser identifier. This serves as proof under Art. 7(1) GDPR. Legal basis: legal obligation (Art. 6(1)(c) GDPR).

3.3 Special categories of personal data

Using a platform for gay men allows conclusions about your sexual orientation. Voluntary profile details may contain information about your sex life. Both are special categories under Art. 9 GDPR. We process them exclusively on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give separately for both purposes at registration and can withdraw at any time in your account. Without consent to the processing of details about your sex life you cannot use the corresponding profile fields. The profile area “Outlook” (political outlook, worldview) is a special category too; you unlock it only with a separate, optional consent that we do not ask for at registration. These details are never a search filter and count in the matching only as something in common; on withdrawal we delete them immediately.

3.4 Security and login

Passkeys: we store the public key, an identifier and the name you gave it. Biometric data stays on your device and never reaches us. Two-factor authentication: encrypted secret and recovery codes. Sessions: session identifier, IP address, browser identifier and time of the last activity, so that you can see and log out logged-in devices. Legal basis: performance of the contract and legitimate interest in account security (Art. 6(1)(b) and (f) GDPR).

3.5 Log data

When you access the platform, our server processes IP address, time, requested address, browser identifier and status code in log files. They serve operational security and error analysis and are deleted after 14 days at the latest. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

3.6 Profile details

Your profile consists of your pseudonym, your role (Daddy, Boy or both), what you are looking for, free texts and the traits you select from the offered categories (for example physical details, interests, personality). All traits are voluntary. Details about sexual preferences are data about your sex life (Art. 9 GDPR); we process them only on the basis of the explicit consent from registration, which you can withdraw at any time. Without this consent the relevant fields are not shown. Details about gender identity and pronouns are also voluntary, visible only to you by default and appear to other members only when you switch them on; they are never used as a filter against people. During age verification we do not store ID data such as name or gender entry, only the result. We use your search profile (“I'm looking for”) to suggest matching profiles; other members do not see it in clear text. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and, for special categories, your consent (Art. 9(2)(a) GDPR).

3.7 Pictures

Pictures you upload are re-encoded by us; in doing so we remove all embedded metadata such as location, camera and timestamp. When uploading you must classify each picture (clothed, nudity without genital focus, explicit). We store this classification, the review status and a checksum with the picture. Pictures are stored outside the public web area and are delivered only via short-lived, signed addresses to entitled members; which members may see a picture depends on the classification, age verification, membership and your gallery releases. Pictures with nudity or sexual references allow conclusions about your sex life; the legal basis here is also your consent (Art. 9(2)(a) GDPR). Legal basis otherwise: performance of the contract (Art. 6(1)(b) GDPR).

No picture is visible before it has been reviewed. First our own software on our server checks it: it recognises nudity and assigns the picture to a category, and on recognisable faces it estimates the age to give the team a hint. Nobody is identified, no facial features are stored and no picture leaves our server. Clearly clothed pictures are released by the software; everything else is seen by people: borderline cases first by verified members of the community pre-review, the decision is made by our team. Every look the team takes at a picture is logged. If a picture is classified differently or removed, you receive the reason and can appeal. Legal basis: performance of the contract (Art. 6(1)(b) GDPR), the protection of minors as a legal obligation (Art. 6(1)(c) GDPR) and our legitimate interest in protecting members (Art. 6(1)(f) GDPR).

Short link and invitation page: if you create a short link under Account › Short link, anyone who knows it reaches, without login, an invitation page with your pseudonym, age, role, town and profile headline. Whether your main picture appears there is your decision: not at all, pixelated at one of three levels, or sharp (sharp only for a clothed picture). The picture is then visible without login to anyone with the link; we count visits to the page without IP addresses. You can withdraw the picture release and the link at any time, after which both are no longer reachable at once. Legal basis: your consent (Art. 6(1)(a) GDPR).

3.8 Location

Your postcode is required for the radius search. We map it to the geographic centre of the postcode area and store only this point and the place name, never an address. Other members see only the place. The mapping of postcodes to coordinates comes from the postcode data of GeoNames, licensed under CC BY 4.0. Optionally you can also share your device location. We round it to a grid of about one kilometre before storing; the exact position reaches our server but is not stored. You can remove the device location in your profile at any time. Legal basis: performance of the contract (postcode, Art. 6(1)(b) GDPR) and consent (device location, Art. 6(1)(a) GDPR).

3.9 Messages

Chats, chat requests and voice messages are stored on our server so that you can read and listen to them on all your devices. The moderation team sees the content of a chat only if a message from it is reported. Self-destructing pictures are removed from the server after viewing or after 24 hours at the latest. Legal basis: performance of the contract (Art. 6(1)(b) GDPR); for content relating to your sex life, your consent (Art. 9(2)(a) GDPR).

Whether you currently have a chat open we detect through your browser's live connection, so that you receive no push notification and no email for that chat. This is not stored.

Under Account › Settings you can decide that only members with a verified age may start a new chat with you. If someone without tries, we check only whether their age is verified and show them that you accept new chats only from verified members; you learn nothing about the attempt.

3.10 Age verification

We check it ourselves – there is no external service for it, and your recordings never leave our server. You take a picture of your identity document, a short video in which you tilt it, and a selfie video in which you make two given head movements. You cover the document number and the machine-readable zone yourself before uploading, with our tool; we do not need them. We strip the sound and every camera detail from the recordings, and they are stored encrypted in a separate area with its own key, outside the platform's pictures and outside the backups. Only someone who holds the review right personally can open them, and every access is logged.

All recordings are deleted the moment the decision is made. What remains for good is only the record that a check took place: the time, the result, the verified date of birth, the kind of document and its issuing country, who decided, and a checksum showing that the entry was not changed afterwards. We never store the document number, a name or an address, and no image. We need this record to be able to show the authorities that we checked the age; it cannot be deleted while the check stands, and it is part of your data export. Legal basis: legal obligation to protect minors and performance of the contract (Art. 6(1)(c) and (b) GDPR); for the image of your face your explicit consent (Art. 9(2)(a) GDPR), which you give before recording and without which the check does not start.

3.11 Membership and payment

You pay for Premium membership and the single verification through a payment service provider. You enter payment details and billing address there; they stay with the payment service provider, which processes them under its own responsibility. We receive the payment confirmation, a customer number, the amount and the country the provider reports for your payment. For every payment we issue an invoice with the VAT of your country; it states your pseudonym, a member number and a neutral service description, no name and no address. The payment service provider and your bank statement show the operator, not DaddyBoy. Legal basis: performance of the contract (Art. 6(1)(b) GDPR); for invoices the statutory retention obligation (Art. 6(1)(c) GDPR).

While Premium runs, a small “Premium” appears next to your name on your profile. This lets other members see that, for example, longer video calls are possible with you. You can hide it at any time under Account › Settings; while you are invisible it never shows. Legal basis: our legitimate interest in reliable contact between members (Art. 6(1)(f) GDPR), to which you object at any time with the switch.

3.12 Notifications and emails

Under Account › Notifications you choose which notices you receive about messages, requests, matches, likes, profile visits, resonance, handshakes and saved searches (instantly, in a digest or not at all). For this we store these settings, the time zone your browser reports once (for the hour of the digest), the time of the last digest and your reminder stage. Instant notices are sent as push notifications to devices on which you switched push on; for this we store the push address and the keys your browser gives us. The content is transmitted encrypted; the push service of your browser (Apple, Google or Mozilla) only sees that a notification arrives. Without a push device, and only while you are not signed in, we send an email instead, at most one per chat until you open it. Emails never contain message texts; other members’ profile pictures only if they allowed it, and your profile picture in emails to others only with your consent (default: off). With the switch “Keep e-mails neutral” or with camouflage switched on (Account › Settings › Camouflage) every email arrives neutral: from a different sender address, with a neutral sender name and subject, without names and pictures.

If you have not signed in for 3, 14 or 60 days we remind you of your account by email once each, then no more; you can switch these reminders off under Account › Notifications. News from us is sent only with your consent, which is not pre-ticked at registration and which you can withdraw at any time. Each of these emails contains an unsubscribe link that works without signing in. Notices about security, contract, payment and moderation are mandatory and cannot be unsubscribed. Legal basis: performance of the contract (Art. 6(1)(b) GDPR); reminders: legitimate interest (Art. 6(1)(f) GDPR) with the right to object; news: consent (Art. 6(1)(a) GDPR).

Delivery is handled by Eigener Mailserver; as with any mail delivery, your email address and the content of our emails to you pass through there. Pictures are attached as part of the email, nothing is loaded from our server when you open it; we use no tracking pixels and no click measurement, so we do not learn whether or when you open an email. The digest is assembled only at the moment of sending and is not stored; notices held back because of your quiet hours are deleted as soon as they are delivered. An unsubscribe link contains only an identifier of your account, the type of event and a signature, and is valid for 90 days.

3.13 Bug reports

If you report a problem via “Report a bug” we store your description, the address of the page, technical details of your browser (user agent, window size, language, display mode, last error message), your IP address and, if you are signed in, your account, otherwise the email address you give voluntarily. We store a screenshot only if you attach one yourself; it lies outside the web directory and is visible to the team only. Legal basis: legitimate interest in error-free operation (Art. 6(1)(f) GDPR).

3.14 Handshake (“known in person”)

With the handshake you can state on another member's profile that you know each other in person. It only counts once the other member confirms it. For this we store only who offered the handshake to whom and when it was confirmed or declined; no place, no text. Confirmed handshakes are visible only to the two of you, on each other's profile and in the chat. Publicly, your trust line shows at most the words “known in person” once at least two verified members have confirmed; never a number, never a list. You can hide the words under Account › Settings and withdraw any handshake at any time, after which it is gone for both of you. If you block a member or delete your account, we delete the handshake. Because a confirmed handshake documents a personal acquaintance on a platform for gay men, it counts as special category data; the legal basis is your consent, which you give by offering or confirming and revoke by withdrawing (Art. 9(2)(a) GDPR).

3.15 Voice hello

You can record a short voice hello (“Let me introduce myself”) on your profile. We store the recording on our server; other members can hear it only after our team has approved it. For this review our own software on our server produces a transcript and marks anything conspicuous (contact details, hints at minors or coercion, sexual content, insults or hate speech); the transcript is used neither for search nor for matching. Every listening by the team is logged. If the recording is approved, we delete the transcript at once. If it is declined, you receive the reason; the recording and the transcript are then kept for six months, audible only to you and the team, so that you can object and we can review the decision. After that we delete both. You can remove or replace the voice hello at any time, a declined one too; the recording is then gone at once. Legal basis: performance of the contract (Art. 6(1)(b) GDPR); the review serves the protection of minors and of other members (Art. 6(1)(c) and (f) GDPR).

3.16 Members of the old daddyboy.de

Anyone who had an account on the previous platform daddyboy.de is informed once by email about the move and can take over their pseudonym on the new platform. For this we took from the old data: the pseudonym, the email address, the role, the time of registration and of the last login, and the previous profile picture. We store the email address in plain text only until the invitation is sent, afterwards solely as a checksum with which we recognise you when you sign up. The old profile picture is held privately until you adopt or discard it after signing up; nobody else sees it. If you do not take over your pseudonym, we delete all of this once the reservation period has expired; a link in the invitation also lets you have it deleted immediately and without signing in. After the takeover only the time of your old registration (“with DaddyBoy since”) stays with your account. Legal basis: continuation of the existing contract on new technology (Art. 6(1)(b) GDPR) and our legitimate interest in informing existing members about the move (Art. 6(1)(f) GDPR).

3.17 Video calls

Two members who chat with each other can make video calls once both have allowed them in that chat. Picture and sound travel directly between your devices and are encrypted on the way; they never reach our server, and we can neither see nor store them. Our server only brokers the call: it records who called whom and when, whether the call was answered and how long it lasted, and it passes the technical connection data of the two browsers (network addresses, codecs) on once without keeping it. If no direct connection comes about, for instance on mobile networks, the still encrypted packets may pass through a relay server we operate; the content is not readable there either and is not stored. Whoever does not have the chat open receives a push notification while it rings, if push is switched on. We cannot technically prevent a recording by the other side; we point this out before every call. You can report behaviour in a call from the call line in the chat; we then see only the connection data, no content. The possible call duration depends on the membership (terms of use). Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

3.18 Partner profile

You can name another member as your partner. The link only counts once the other member confirms it; each account has at most one partner. For this we store only who asked whom and when it was confirmed or declined; no text. A confirmed link appears as “Partner” with a link on both your profiles and is therefore visible to every signed-in member; under Account › Settings either of you can hide it, after which it disappears on both profiles. Either side can dissolve the link at any time, after which it is gone for both. If you block the member or delete your account, we delete the link. Because it documents a couple relationship on a platform for gay men, it counts as special category data; the legal basis is your consent, which you give by asking or confirming and revoke by dissolving (Art. 9(2)(a) GDPR).

3.19 Statistics

Under Account › Statistics you see how your profile lands: profile visits per day, sympathies, winks, reactions, ratings and handshakes received, how often your pictures were opened large and your voice intro played, visits to your short link. For this we increment one number per member, metric and day, per picture for pictures. We do not store who viewed; your own views and views by members who set themselves invisible are not counted. The daily counters are deleted after 90 days. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

3.20 My shelf: music, books, films and games

In your profile you can put artists, bands, books, films, series and games on a shelf and say what they mean to you (“fan”, “seen live”, “reading now”, “favourite book”). This is voluntary. For each entry we store only which work you chose, what you said about it and when. Logged-in members see your shelf under the same conditions as your other interests. In the matching we compare your shelf only with the shelf of the member whose profile or search result you are looking at, and tell both of you what you have in common. We do not sort works into topics, we do not derive traits, views or preferences from your shelf, and we do not build recommendations from it. Please bear in mind that individual works may still allow conclusions, for instance about political or religious views; you decide what you add, and you can remove any entry at any time.

The works themselves come from open catalogues: artists from MusicBrainz, books, films, series and games from Wikidata and, if you do not find a book there and search further, from Open Library. Our server sends the search, not your browser; only the search term goes to the catalogue (see section 5). We keep the catalogues’ answers in a temporary store for up to a week, without recording who searched. From the catalogue we take only the identifier of the work, title, creator, year, the kind (such as film, series, video game or band) and, for artists, the country, no cover images or posters. The team can block a work that must not appear here; it then disappears from all shelves, while your entry stays stored. Your shelf is part of your data export. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

3.21 Profile visits and activity

When you open another member's profile, we store per pair who last visited whom and how often. Premium members see who visited them under “Who visited my profile”, on the tiles under “Discover” and in the notification about it; free members see only the number. Visits from the last 30 days are shown, after that we delete them. If you have made yourself invisible (Premium), your visits leave no entry.

From your latest activity we show other members on cards, tiles, your profile and in the chat whether you are online right now (active in the last 15 minutes) or were active today. Premium members see “online now”, and so does everyone while you have set a status that invites contact. With “Hide activity” under Account › Settings you switch both off, free members too. Legal basis for both: performance of the contract (Art. 6(1)(b) GDPR).

4. Cookies and local storage

We set only technically necessary cookies: a session identifier, a protection token against cross-site request forgery, a login token if you choose “Stay logged in”, a device cookie for one year after every login (a random value by which we recognise your browser, so that we only warn you about a login from a genuinely new device) and, only if you deliberately switch the language, a language cookie for one year. Your display setting (light/dark) and the tile size you chose are stored locally by the browser; they never reach our server. No consent is required for this (Art. 11.7a Telecommunicatiewet).

5. Recipients

Within the company only people who need access for operation, support or moderation receive it. Every time a staff member opens your account in the administration, the person, time and purpose are logged; the administration never sees chats. Support staff do not see content with nudity or sexual references. The team may keep internal notes on your account, for example about a support request; they are factual, visible to the team only and part of your data export. A permanent ban or an immediate deletion of your account by us is proposed by one person and confirmed by a second one as soon as the team consists of more than one person; both are logged. External recipients are the payment service provider and, if you switch push on, the push service of your browser (Apple, Google or Mozilla). The payment service provideris a controller in its own right. We carry out the age check ourselves (3.10); there is no recipient for it. Hosting and email delivery (Eigener Mailserver) we run ourselves on our own servers in the Netherlands; there is no external provider and no data processing agreement for them. Our servers are located in the EU; we ourselves do not transfer data to third countries. The push service of your browser may be located outside the EU and receives only the push address of your device and encrypted notifications. If you start a station under Radio, your browser connects directly to the station’s server; the station sees your IP address and your browser, nothing from your account, and is a separate controller. As long as you play nothing, it learns nothing. If you search in your profile for artists, books, films, series or games for your shelf, our server queries the open catalogues MusicBrainz (MetaBrainz Foundation, USA), Wikidata (Wikimedia Foundation, USA) and Open Library (Internet Archive, USA). Only the search term you typed goes there: not your IP address, not your browser and nothing that points to you or your account. We store only what you put on your shelf. The catalogue cannot attribute the search term to any person; none of your data is transferred to a third country in the process.

6. Retention period

  • Account data, profile and pictures: until your account is deleted; you can remove individual details and pictures yourself at any time.
  • Messages and voice messages: until your account is deleted; self-destructing pictures after viewing or after 24 hours.
  • Age verification result and notification settings: until your account is deleted.
  • Push addresses: until you switch push off on the device or the push service declares the address invalid.
  • Paused account: indefinitely, until you reactivate or delete it.
  • Account whose email address was never confirmed: 14 days after sign-up, following a reminder with the exact date.
  • Account deletion: after a period of 14 days, during which you can revoke the deletion, all data is irrevocably deleted.
  • Invoices: seven years after the end of the financial year (Dutch retention obligation), kept separately from the account and without a link to the profile once the account is deleted.
  • Bug reports: the screenshot is deleted when the report is closed, the report itself 30 days later.
  • Further exceptions: ongoing proceedings about reported legal violations.
  • Log data: 14 days.
  • Notifications in the bell: 90 days; you can remove read ones at any time.
  • Handshake: until one side withdraws it, a block occurs or an account is deleted.
  • Partner profile: until one side dissolves the link, a block occurs or an account is deleted.
  • Voice hello: until you remove or replace it; the review transcript is deleted at once on approval, after a decline the recording and the transcript stay for six months for an objection.
  • Video calls: only participants, time and duration, for as long as the chat history; picture and sound are never stored.
  • Data from the old daddyboy.de: until the pseudonym is taken over or the reservation period expires.
  • Profile visits: 30 days after the last visit.
  • Internal team notes on your account: until the account is deleted.
  • My shelf (music, books, films, games): each entry until you remove it or your account is deleted; the catalogues’ answers for up to a week, without any link to you.

7. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can withdraw consents you have given at any time with effect for the future. Access and data export are available as self-service in your account; data of other people is pseudonymised in the process (Art. 15(4) GDPR). Otherwise contact datenschutz@daddyboy.eu.

You can lodge a complaint with a supervisory authority, in particular the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or the supervisory authority of your country of residence.

8. Security

Encrypted transmission (TLS), encrypted storage of sensitive content, passkeys as the recommended login method, two-factor authentication, role-based access control and logging of every access to sensitive content by our staff.

9. Changes

We adapt this policy when functions or the legal situation change. The applicable version carries the date of its last change. In case of material changes we inform you in the app or by email.