Legal
Privacy Policy
How we handle your data — the short version first, then the full policy.
The short version
What we collect
Only what’s needed to verify identity and record consent: your phone number, the verification data you choose to provide (selfie, liveness, and — at the highest tier — on-device government-ID checks), the agreements you create, and basic technical data needed to keep the service secure.
How we use it
To confirm you’re a real adult, to let you create and manage mutual consent agreements, to keep your account secure, and to contact you about the service. That’s it.
What we never do
- We never sell your personal data.
- We never run advertising against your private moments.
- We never use your agreements or documents to train AI models.
How it’s protected
Sensitive documents are encrypted with per-record keys. Access is limited to the parties in an agreement. The highest verification tier checks your government ID on your own device, so it never leaves your phone.
Your controls
You can revoke an agreement at any time, and you can request access to or deletion of your data. We’ll honor those requests in line with applicable law.
Full privacy policy
This policy explains how AffirmPax handles personal data on our website (affirmpax.com) and, when it launches, in the AffirmPax mobile app. Where a practice applies only to one of these, we say so.
1. Who we are
AffirmPax is operated by AffirmPax, Inc., a Delaware corporation (“AffirmPax”, “we”, “us”). We are the controller of the personal data described here. For any privacy question, or to exercise your rights, contact our Privacy Officer at privacy@affirmpax.com or by post at 131 Continental Dr, Suite 305, Newark, Delaware 19713. If we later make AffirmPax available in the EU/EEA or the UK, we will appoint and name a local representative here.
2. The data we collect
We collect different data on the website than we will in the app. Today, only the website is live.
On our website (today)
- Waitlist: the email address you submit.
- Contact form: your name, email address, chosen subject, and message, plus the page you sent it from.
- Security and server logs generated automatically when you visit (such as IP address, browser type, and timestamps).
- Functional storage on your device (your 18+ age-gate confirmation, and your theme and language choices). This stays on your device and is not transmitted to us.
In the AffirmPax app (when it launches)
- Your mobile phone number.
- Verification data you choose to provide: a selfie and liveness check, and — at the highest tier — an on-device check of a government-issued ID.
- The mutual-consent agreements you create, and metadata about them (such as time, the parties, and status).
- Basic device and security data needed to protect your account.
Sensitive data
Biometric data (used for verification) and data about your sex life are treated as “special category” data under the GDPR and UK GDPR, and as “sensitive personal information” under CCPA/CPRA and similar laws. We process them only where you have given explicit consent, and with heightened safeguards.
3. How we use your data, and our legal bases
We use personal data for the purposes below. For users in the EU/EEA and UK, the GDPR legal basis is noted in brackets.
- To answer waitlist sign-ups and contact messages [consent and/or our legitimate interest in responding to you].
- To operate, secure, debug, and improve the service [legitimate interests].
- To verify you are a real adult and to create and record consent agreements in the app [performance of our contract with you; and, for biometric and sexual-activity data, your explicit consent under Art. 9(2)(a)].
- To comply with legal obligations and to protect people from serious harm [legal obligation; and, where applicable, vital or public interests].
4. How we share data
We share personal data only as described in our Data Sharing Policy. In short: we never sell it; we use a small set of vetted service providers under contract to operate the service; and we disclose data to authorities only where the law requires it or to prevent serious harm. We never use your agreements or documents to train AI models, and we never run advertising profiling against your activity.
5. International data transfers
AffirmPax is based in the United States. If you use the service from the EU/EEA, the UK, or elsewhere, your personal data may be processed in the United States or other countries whose laws differ from your own. Where required, we rely on appropriate safeguards — such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — for those transfers. Our website forms are processed through Google (see the Data Sharing Policy for the current list of providers).
6. How long we keep your data
Website
- Waitlist emails: until you ask us to remove you, or until the waitlist closes.
- Contact messages: for as long as needed to handle your enquiry, and a reasonable period afterward.
- Security and server logs: for a short period for security and troubleshooting.
App
- Verification selfie: deleted as soon as it has been used to verify you. Other account data: while your account is active.
- Consent records: as long as needed to serve their purpose and to meet legal requirements, after which they are deleted or anonymized.
- On-device ID checks are designed so the ID document itself never leaves your phone.
7. How we protect your data
- Data is encrypted in transit.
- In the app, sensitive documents are encrypted with per-record keys.
- Access is limited to the parties of an agreement and to staff who genuinely need it.
- The highest verification tier checks your government ID on your own device, so it never reaches our servers.
8. Your privacy rights
Depending on where you live, you have the following rights. We will not discriminate against you for exercising them.
EU/EEA and UK (GDPR / UK GDPR)
- Access, rectification, and erasure of your data.
- Restriction of, and objection to, certain processing.
- Data portability.
- The right to withdraw consent at any time, without affecting prior processing.
- The right to complain to your local supervisory authority (in the UK, the Information Commissioner’s Office).
California (CCPA / CPRA)
- The right to know about and access the personal information we hold.
- The right to delete and to correct your personal information.
- The right to opt out of the “sale” or “sharing” of personal information — we do not sell or share it as those terms are defined.
- The right to limit the use of sensitive personal information.
- The right to non-discrimination for exercising these rights.
How to exercise your rights
Email privacy@affirmpax.com or use our contact form. We will verify your request and respond within the timeframes the law requires. You may use an authorized agent where the law allows.
9. Cookies and tracking
Our website uses no advertising cookies, no third-party analytics, and no tracking pixels. The only information stored on your device is functional local storage — your age-gate confirmation, and your theme and language preferences — which stays on your device. If the app introduces any analytics, we will describe them here before launch.
10. Children
AffirmPax is strictly for adults. The website uses an age gate, and the service is not directed to anyone under 18 (or the age of majority where you live). We do not knowingly collect personal data from minors; if we learn that we have, we delete it.
11. SMS / text messaging
If you provide your mobile phone number, AffirmPax uses it to send (a) a one-time verification passcode when you register, and (b) safety alerts to the emergency contact you designate, only if you trigger a safety check. If someone designates you as their emergency contact, we send you a one-time text explaining this and, if that person triggers a safety alert, the alert itself. Message frequency varies but is very low; most users receive only one verification message. Message and data rates may apply. Reply STOP to any message to opt out of all further texts, or HELP for help. We do not share, sell, rent, or otherwise provide your mobile phone number, SMS consent, or opt-in information to any third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except as necessary to deliver the messages through our SMS service provider.
12. Changes to this policy
We will update this policy as the product and the law evolve, and post the current version here with a new effective date. We will highlight material changes.
13. Contact and complaints
Reach our Privacy Officer at privacy@affirmpax.com or 131 Continental Dr, Suite 305, Newark, Delaware 19713. California residents may contact the California Privacy Protection Agency. (If we later operate in the EU/EEA or UK, users there may lodge a complaint with their data protection authority, such as the UK ICO.)
Contact
Questions about privacy? Email us or use our contact form.