Privacy Policy

Effective Date: March 1, 2026
Service sassyfantasy.com
Company SassyFantasy

This Privacy Policy (“Policy”) explains how SassyFantasy (“Company,” “we,” “us,” “our”) collects, uses, discloses, and retains personal data when you access or use sassyfantasy.com and related services (the “Service”).

By using the Service, you acknowledge that you have read and understood this Policy.

1) Who We Are (Data Controller)

Data Controller: SassyFantasy

Contact (Privacy): support@sassyfantasy.com

Support: support@sassyfantasy.com

If you have any questions, requests, or complaints regarding privacy, contact us at support@sassyfantasy.com.

2) Adults Only

The Service is intended for adults only. You must be at least 18 years old (or the age of majority in your jurisdiction, if higher) to use the Service.

We do not knowingly collect personal data from minors. If we learn that personal data from a minor has been collected, we will take steps to delete it and may suspend/terminate the account.

3) What Data We Collect

We may collect the following categories of personal data:

A) Account Data

  • Email address, internal account ID, and administrator username where applicable.
  • Login/authentication data (stored securely, e.g., hashed passwords where applicable).
  • Age confirmation (18+ self-certification).

B) Transaction & Purchase Data

  • Credit purchases/subscription status (if applicable), timestamps, amounts, currency, crypto invoice status, and payment confirmation metadata.
  • Limited payment metadata provided by our crypto payment processor and, where you choose to use one, third-party card on-ramp or fiat-to-crypto providers.
  • Failed, expired, confirmed, or disputed invoice events and related support records.
Payments
We accept payment through crypto invoices. If you use a third-party card on-ramp or fiat-to-crypto provider, that provider processes the card or fiat transaction under its own terms. We do not store full payment card details and typically do not receive card verification data such as CVV or billing ZIP. Issues with card authorization, identity/KYC review, exchange, fees, delay, decline, reversal, or fiat-side failure should be handled with that provider.

C) User Content & Outputs

  • Prompts and text you submit.
  • Files you upload (if uploads are enabled).
  • AI-generated outputs produced for your account.
Private by default
Your prompts/uploads/outputs are not published by us to a public feed/gallery within the Service by default.

D) Technical, Device & Usage Data

  • IP address, browser type/version, OS, device identifiers.
  • Referring URLs, timestamps, session events, pages/features used.
  • Security/abuse-prevention logs.

E) Welcome Bonus Scoring and Free Credits Anti-Abuse Data

If you take part in a Welcome Bonus or free credits challenge, we may collect and process challenge-specific anti-abuse signals to verify that the challenge was completed by a live, eligible user.

  • Typing cadence and editing signals, such as keydown/keyup/input timing, pauses, corrections, cursor/selection changes, composition events, and answer consistency checks.
  • Pointer, mouse, touch, scroll, and wheel events, including coarse interaction timing, movement patterns, clicks/taps, gesture counts, and field engagement.
  • Focus, visibility, page lifecycle, reload/retry, paste/drop, blocked paste/drop, and other integrity events related to the challenge session.
  • Browser, device, language, screen, user-agent, automation/webdriver, and similar environment signals used to detect inconsistent or synthetic challenge sessions.
  • Derived scoring data, risk reasons, profile vectors/templates, and similarity matches against recent Welcome Bonus sessions to detect duplicate, automated, or abusive free-credit attempts.

F) Support Communications

  • Messages you send to support, and any information you choose to include.

4) How We Use Data (Purposes)

We process personal data to:

  • Provide and operate the Service (account access, generating outputs, delivering Credits/features).
  • Process crypto invoice purchases, handle billing records, confirm payments, and manage purchase-related fraud or disputes.
  • Maintain safety and security, including detecting and preventing abuse, enforcing Terms of Service and Acceptable Use rules.
  • Run Welcome Bonus Scoring and related anti-abuse checks to approve, reduce, deny, or review promotional free credits.
  • Maintain reliability (debugging, error monitoring, service performance).
  • Communicate with you (service messages, support replies, important notices).
  • Comply with legal obligations (accounting, tax, lawful requests).
  • Improve and optimize the Service (analytics, product improvement, troubleshooting).

If we ever offer optional marketing emails, we will do so only where permitted by law and with appropriate consent/opt-out mechanisms.

5) Legal Bases (Where Applicable)

Where data protection laws such as the GDPR/UK GDPR apply, we rely on one or more of the following legal bases:

  • Contract: processing necessary to provide the Service to you.
  • Legitimate Interests: operating, securing, and improving the Service; preventing fraud/abuse; running Welcome Bonus Scoring for promotional free-credit eligibility and abuse prevention.
  • Consent: where required (e.g., certain non-essential cookies/marketing communications).
  • Legal Obligation: compliance with accounting, tax, and lawful requests.

6) Content Rules, “Real-Person” Restrictions, and Moderation

The Service has strict rules for real-person and photo-based workflows. Uploads, camera capture, reference images, swap, undress, and similar workflows may be used only for lawful adult self-content or content involving consenting adults, and must comply with our Terms of Service and Content Policy. Content involving minors, age-ambiguous persons, non-consenting persons, unauthorized real-person likeness use, harassment, exploitation, blackmail, privacy abuse, and other prohibited content defined in the Terms of Service is not allowed.

To enforce our rules and protect the Service, we may use automated and/or manual measures (e.g., security checks, abuse detection, content policy enforcement). This may involve limited review of prompts/uploads/outputs where necessary for safety, compliance, and enforcement.

7) Cookies and Similar Technologies

We may use cookies, local storage, and similar technologies to:

  • Provide essential site functionality, authentication, session continuity, and account access.
  • Maintain security and prevent abuse, including CSRF protection, fraud checks, and service-integrity controls.
  • Remember adult age-gate/self-certification status and other required compliance confirmations.
  • Remember UI preferences, temporary page state, promo/banner/voucher seen state, and similar Service preferences.
  • Measure analytics, performance, reliability, and product usage where enabled and permitted by law.

Your choices: You can control cookies via browser settings. Disabling certain cookies may affect functionality.

Essential, authentication, security, age-gate, and service-preference cookies or local storage may be required for the Service to work. Non-essential analytics, marketing, or similar technologies will be used with consent or opt-out controls where required by applicable law.

8) Sharing and Disclosure

We may share personal data with:

A) Service Providers (Processors)

Vendors who help us operate the Service (e.g., hosting, infrastructure, storage, analytics, customer support tooling, security/anti-fraud). They are authorized to process data only on our instructions and as needed to provide services to us.

B) Payment Providers

Crypto payment processors and, where you choose to use one, third-party card on-ramp or fiat-to-crypto providers, to complete transactions, confirm invoices, and prevent fraud. We do not store full card details and typically do not receive card verification data handled by third-party on-ramp providers.

C) Legal and Safety

We may disclose data if required by law, legal process, or to protect rights, safety, and security of the Company, users, or the public, including enforcing our Terms and investigating abuse.

We do not sell personal data.

9) International Transfers

Your data may be processed in countries where we and/or our service providers operate. We aim to use infrastructure providers that support privacy-focused operations, but specific server locations may vary depending on reliability, security, and vendor availability.

Where applicable law requires safeguards for cross-border transfers, we will use appropriate mechanisms (for example, contractual safeguards such as Standard Contractual Clauses or equivalent measures).

10) Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy, unless a longer retention period is required by law or needed for legal claims/security.

A) Temporary Prompts / Uploads / Outputs

Temporary prompts, uploads, and generated outputs are typically retained for up to twenty-four (24) hours, after which they may be deleted automatically, unless a different period is shown in the Service or longer retention is needed for service operation, safety, abuse prevention, dispute handling, or legal compliance.

If a “Delete Now” or similar feature is available, you may delete earlier; deletion may be irreversible.

Saved characters, saved user assets or settings, Company-created samples, account records, payment records, security logs, and abuse-prevention records may remain longer where needed to provide the Service, maintain records, protect users, prevent abuse, resolve disputes, or comply with law.

B) Account Data

Kept while your account is active. If you request deletion/close your account, we will delete or anonymize account data where feasible, subject to legal obligations.

C) Transaction Records

Retained as required for accounting/tax compliance and dispute/fraud handling (duration depends on applicable laws and payment provider requirements).

D) Technical/Security Logs

Retained for a limited period as necessary for security, abuse prevention, and service integrity.

E) Welcome Bonus Scoring Records

Welcome Bonus challenge events, derived scores, risk reasons, profile vectors/templates, and profile-match records may be retained for limited anti-abuse windows where needed to prevent duplicate or automated free-credit claims, audit scoring outcomes, handle support requests, and protect the Service.

11) Security

We use reasonable technical and organizational measures to protect personal data (e.g., access controls, encryption where appropriate, monitoring, secure storage practices). However, no method of transmission or storage is fully secure, and we cannot guarantee absolute security.

12) Your Rights

Depending on your location, you may have rights such as:

  • Access to your personal data.
  • Correction/rectification.
  • Deletion (subject to legal exceptions).
  • Objection/restriction of processing.
  • Data portability.
  • Withdrawal of consent (where processing is based on consent).

To exercise rights, email: support@sassyfantasy.com. We may request verification before completing a request.

13) Third-Party Links

The Service may contain links to third-party websites or services. Their privacy practices are governed by their own policies. We are not responsible for third-party practices.

14) Changes to This Policy

We may update this Policy to reflect legal, technical, or operational changes. We will post the updated version with a new Effective Date. Material changes may be communicated via the Service or email where required by law.

15) §2257 Notice (If Applicable)

Where applicable, the Service maintains a separate 18 U.S.C. §2257 Compliance Statement available on the Service.

Contact
For privacy requests, contact: support@sassyfantasy.com.