PRIVACY POLICY
Effective Date: August 2026
Welcome to Stories and Roleplay (www.storiesandroleplay.com). We are deeply committed to protecting your privacy, personal data, and anonymity. Given the highly intimate and sensitive nature of the fictional stories generated on our platform, we have built our system under strict Privacy-by-Design and Data-Minimization principles.
This Privacy Policy explains how Boljoro SL collects, processes, secures, encrypts, and deletes your personal information under the General Data Protection Regulation (GDPR) and applicable Spanish data protection laws (LOPDGDD).
1. Data Controller
The entity legally responsible for processing your personal data is:
Company Name: Boljoro SL
Tax Identification Number (CIF): B66777566
Registered Office Address: Calle Rubio i Ors 15 1-2, 08940 Cornellà de Llobregat, Barcelona, Spain
Commercial Register: Registered in the Commercial Register of Barcelona
Contact Email: [email protected]
2. Information We Collect and Process
We operate on a strict data-minimization principle, processing only the minimum data necessary to deliver our services. All user records are pseudonymized and referenced using a random, non-sequential Universally Unique Identifier (UUID) to prevent data mapping or profiling.
We restrict our data collection to the following high-level categories:
- Account and Service Management Data: This includes basic credentials required to maintain your secure account profile, such as your email address, an encrypted password hash, your birth date (processed for age-verification compliance), the country and, where applicable, state or province you declare at registration, and transactional billing parameters (such as subscription status and token balances).
- Age-verification decision data: In jurisdictions that require more than a self-declared date of birth, a third-party provider (Didit) captures a selfie and, where the law requires it, a government identity document. We never receive those images, document numbers, or the name on the document. What we retain is the decision: whether verification was approved or declined, the estimated or document-derived age, the method used, the date and time, the jurisdiction and minimum age we applied, the Didit session identifier, and a flag if the document date of birth disagreed with the date you declared. If verification is declined, your account is blocked and you may submit an appeal; we store the appeal message so our staff can review it.
- User-Provided Content and Text Generation Data: This consists of the machine-readable creative text prompts, fictional character parameters, and story contextual boundaries you input into our platform, alongside the resulting synthetic text generated by the artificial intelligence. Due to the adult orientation of the service, these inputs may touch upon intimate or sensitive creative themes, which are cryptographically protected at rest and handled under a strict security isolation framework.
3. Legal Basis for Data Processing
Under GDPR Article 6 and Article 9, we process your information under the following authorized legal frameworks:
- Performance of a Contract (Art. 6.1.b): Managing your account creation, processing subscription and token payments through our payment provider, maintaining your token wallet balances, and executing the automated AI text generation. Additionally, processing your self-declared date of birth is a contractual necessity to establish that you meet our mandatory eligibility criteria (18+) required to form a binding contract with us.
- Compliance with a Legal Obligation (Art. 6.1.c): Processing your declared country of residence to ensure accurate tax collection under EU VAT One-Stop Shop (OSS) regulations, retaining issued invoices for the statutory accounting period, and logging your self-declared age to support overarching European youth protection principles that require platforms to restrict minors from adult environments.
- Explicit Consent for Special Category Data (Art. 9.2.a): Because the creative text prompts, traits, or narrative boundaries you input may touch upon your private fantasies, this data is classified under the GDPR as concerning your sex life or sexual orientation. You must click an explicit, separate consent box during registration authorizing us to process this text solely to stream your story responses. Separately, facial analysis used for age estimation or identity matching is biometric data under Article 9. In jurisdictions that require this check, you consent at registration to Didit processing a selfie (and, where required, a government ID) for the sole purpose of confirming you meet the minimum age. We receive only the verification decision, not the biometric images.
- Legitimate Interest (Art. 6.1.f): Utilizing anonymized network metadata to secure our servers, block malicious bots, and monitor application performance. Network geolocation supplied by our CDN (country and region) is used together with the location you declare, taking the stricter of the two, to apply the correct age-verification rule and to refuse service in sanctioned or prohibited territories.
4. Privacy-by-Design & Cryptographic Encryption
To ensure that your intimate fantasies remain entirely private, we implement industrial-grade security measures that isolate your content from our own administrators:
- Envelope Encryption: All prompts, stories, and chat histories inside Database 3 are dynamically encrypted using a unique, user-specific Data Encryption Key (DEK) combined with a secure Master Key. Your private data is completely unreadable at rest.
- Strict No-Sale Policy: Boljoro SL enforces a zero-tolerance policy against data monetization. We never sell, rent, trade, lease, or share your personal profiles, usage habits, or text inputs with any third-party advertisers, data brokers, or external entities.
5. Infrastructure, Data Sub-Processors, and Governance
Your data is processed and secured using GDPR-compliant technical architecture and specialized global infrastructure partners:
- Main Storage: Your core database profiles, metadata logs, and encrypted records are hosted on secure virtual private servers located within the European Economic Area (EEA).
- AI Inference and Cloud Processing: When you execute a text-generation command, the request is processed via high-performance cloud computing networks optimized for privacy. This network operates under strict GDPR governance models. All data pathways are legally bound by European Commission-approved data protection safeguards, ensuring your privacy standards remain completely uncompromised.
- Zero-Retention Processing Policy: The computing layer operates under a strict volatile-memory framework. User text strings are held temporarily in active memory solely to stream the response, and are instantly wiped upon execution. No user data is ever cached, logged, or written to physical storage at this tier.
- Network Traffic and Threat Protection: We utilize an enterprise Content Delivery Network (CDN) and security proxy architecture to prevent server exploitation and block malicious traffic. This proxy network operates under strict international data privacy standards, handles technical connection metadata only, and is structurally isolated from reading or storing the body payloads of your encrypted AI text inputs.
- Payment Processing: Cryptocurrency payments are handled by our payment provider PassimPay, who acts as an independent controller for the payment itself. We send them only the amount, the currency and our own internal order reference. We never send them your email address, your billing details or anything about your creative content, and we never receive or store your wallet credentials, private keys or card details. What comes back to us is the settlement record for the transaction: the transaction hash, the blockchain addresses involved, the amount received and the provider's fees. We keep that record because it is the evidence that your invoice was paid.
- Age and identity verification (Didit): Didit.me / Didit Protocol acts as our processor for age assurance. In regulated jurisdictions the hosted verification flow captures a selfie for age estimation, and in Germany and South Korea a government identity document plus a liveness and face-match check. Didit retains the captured images according to its own retention policy (typically for the duration configured in our Didit console, currently aligned with regulatory audit needs). We receive a signed decision via webhook: approved, declined, or in review, plus an estimated age or a date of birth extracted from the document. You may appeal a declined decision from the verification page; our staff can then allow a retry or delete the account so you can register again.
6. Optional AI Training Opt-In (VIP Supporter)
If you voluntarily check the "VIP Supporter" box in your user dashboard, you grant your explicit consent for Boljoro SL to use your input prompts and generated stories to fine-tune and train our internal, proprietary Large Language Models.
- Complete Anonymization: Before any text is fed into our training pipeline, it undergoes an automated parsing process that permanently scrubs all names, user metadata, and identifying labels to ensure absolute, irreversible anonymity.
- No Sharing: This training data is processed entirely in-house and is never shared or sold to external AI research organizations.
- Right of Revocation: You may uncheck the VIP Supporter status at any time in your settings to instantly withdraw consent for any future text strings you generate.
7. Cookieless Backend Tracking & Functional Cookies
- Strictly Necessary Cookies: We only utilize essential, functional cookies required to maintain your secure authenticated state and keep you logged into your profile. These technical cookies are strictly operational, do not track your behavior on external websites, and do not require a consent banner under applicable digital privacy laws.
- Privacy-First Analytics: We do not use intrusive tracking cookies or cross-site tracking pixels to monitor your behavior. To optimize platform performance, we utilize a privacy-first backend analytics framework that processes connection data into completely anonymous traffic metrics instantly upon server arrival. This allows us to monitor general usage trends without generating a persistent behavioral footprint or tracking individual users.
8. Data Retention and Account Deletion
We retain your profile parameters and creative text histories only for the lifecycle of your active account. You can request permanent account deletion within your user dashboard at any time, subject to a secure identity verification check to prevent unauthorized data destruction.
Upon confirmation, all credentials, account data, and text histories are permanently erased from our active production environments, and any active subscriptions are immediately forfeited. However, to comply with statutory tax and corporate accounting obligations, financial invoices (which retain your email address and transaction details) must be preserved for the legally required period. These billing records are kept strictly isolated and cannot be linked to any creative story content.
9. Billing and Invoice Records
Purchases are the one part of this service where we are legally required to keep data rather than delete it, so we want to be precise about what that means.
- What an invoice record contains: the date, a unique order reference, what you bought, the amount and currency, the VAT rate and amount, the country you selected for tax purposes, the country our security proxy reported for your connection, and the email address the purchase was made under. If you supplied a name and billing address — required for customers outside the EU, optional inside it — those are part of the record too. Nothing about your prompts, characters, or stories is ever attached to an invoice.
- Encryption: your name, address and email on an invoice are encrypted at rest. Unlike your creative content, they are not encrypted with your personal user key, because that key is destroyed when you delete your account and the invoice must remain readable to a tax auditor for years afterwards. They are encrypted with a separate key held only by our billing system.
- Retention: Spanish and EU accounting law requires invoices and their supporting records to be retained for at least six years from the end of the tax year in which they were issued. We keep them for that period and no longer than we must.
- What deleting your account does and does not do: it erases your credentials, your profile, and all of your creative content, permanently and irreversibly. It does not erase invoices already issued to you. This is the one exception to erasure, and GDPR Article 17(3)(b) expressly provides for it: the right to erasure does not override a legal retention obligation. After deletion an invoice is no longer linked to any account — there is nothing left to link it to — and it cannot be used to reconstruct anything you wrote.
- Your IP address: we record a one-way cryptographic hash of the IP address a purchase was made from, as fraud and tax-residency evidence. The address itself is never stored, and a hash cannot be reversed into one.
- Accounting software: invoice records may be transmitted to our accounting provider for the purpose of filing our returns. They receive the invoice and nothing else.
10. Your Rights and Contact Context
Under the GDPR, you have the right to access your data, rectify inaccuracies, request erasure, restrict processing, or port your details. To exercise any of these rights, or to withdraw your processing consent, please email us directly at [email protected].
If you believe your data has been handled improperly, you have the right to file a formal complaint with a European supervisory authority, specifically the Spanish Data Protection Agency (Agencia Española de Protección de Datos - AEPD).