Age Verification Policy
| Document | Age Verification Policy |
| Operator | Romantic Lines LP (SL25636), 5 South Charlotte Street, Edinburgh, EH2 4AN, Scotland |
| Version | 1.1 |
| Service | Hot Muses Universe ("HMU"), hmu.com |
| Effective date | 2026-08-14 |
| Contact | safety: [email protected] · appeals: [email protected] · DPO: [email protected] |
1. Why this policy exists
Hot Muses ("HMU") provides adult-oriented AI-companion content. Users must be 18 years of age or older (or the higher local age of majority for adult content) to access the service. This policy explains how HMU enforces that age threshold, what kinds of age-assurance steps users may be asked to complete, and what we do when a user's age cannot be verified or when we learn that a minor has accessed the service.
The policy reflects the current regulatory environment, including:
- Australia — Online Safety Act 2021, with mandatory age-assurance obligations for adult-content services taking effect 9 March 2026.
- Brazil — Lei No. 15.211/2025, mandatory age-assurance for adult-content services, effective 17 March 2026.
- United States — state age-verification laws in Texas, Louisiana, Utah, Virginia, Arkansas, Mississippi, North Carolina, Montana, Indiana, and other states. This list changes frequently and we review it regularly.
- European Union and United Kingdom — the UK Online Safety Act 2023 and GDPR / UK GDPR transparency obligations, together with the enforcement practice of European data-protection authorities in relation to AI-companion services.
- United States federal — 18 U.S.C. §2257 record-keeping concepts, applied here in the AI-content context (no real performers; see AI Content Statement).
The category is under active regulatory scrutiny. HMU's design choices in this area are deliberately conservative.
2. Who is eligible to use HMU
- HMU is for users 18 years of age or older.
- Where the age of majority for adult content in a user's jurisdiction is higher than 18 (for example, certain US states or specific national rules), the higher local age applies.
- HMU is not available in any jurisdiction where adult-content services are prohibited by local law. It is the user's responsibility to know the law where they are. See the "Jurisdictional eligibility" rule in our Acceptable Use Policy, Section 2.
3. Initial age gate (click-through)
On first arrival to hmu.com, every visitor sees an age-gate prompt asking them to confirm they are 18+ (and that adult content is lawful where they are). The confirmation is recorded in the visitor's browser as a first-party cookie (age_verified).
This click-through is the minimum assurance layer. We treat it as a contractual representation by the user, not as proof of age. It is supplemented in higher-risk jurisdictions by the assurance flow described in Section 4. We acknowledge that a browser-stored flag can be cleared by the user. A server-side acknowledgement tied to the account is on our roadmap; see Section 11.
4. Age assurance beyond the click-through
4.1 Current state. Access to HMU is currently gated by the age confirmation described in Section 3, supported by the risk signals described in Section 4.3. We do not at present operate document-based or biometric age verification.
4.2 Planned assurance flow. We plan to introduce verification through an independent age-assurance vendor for users connecting from jurisdictions that mandate it. When that flow is live, this Policy will be updated to name the vendor, link its privacy notice, and set out the methods offered. We expect those methods to be: (a) verification of a government-issued identity document; (b) a face capture with liveness detection and age estimation; and (c) corroboration through a verified adult payment instrument, used only as a supplementary signal and never as the sole basis for assurance where a regulator requires document- or face-based verification. In every case the vendor, not HMU, will handle the document or biometric capture, and HMU will receive only a pass/fail decision, an age band, the date and time of completion, the method used, and the vendor's reference identifier.
4.3 Risk signals in use today. We use payment-instrument signals, connection and device signals, moderation review, and reports from users and third parties to identify accounts that may belong to a person under 18. Where such signals appear, we act under Section 6.
4.4 Data minimisation. HMU does not store identity-document images, face captures, or biometric templates, and will not store them when the flow in Section 4.2 is live. This is consistent with GDPR Art. 5(1)(c), UK GDPR Art. 5(1)(c), and LGPD Art. 6(III).
5. What happens if age assurance is not passed
Where the assurance flow described in Section 4.2 is in operation:
- Access to the service is blocked.
- The user is shown a clear explanation and a path to retry, including a different assurance method if available.
- Repeated failed attempts within 24 hours trigger a cool-down to deter brute-force document uploads.
- Users who believe they were incorrectly declined may appeal to
[email protected]. We aim to respond within 14 calendar days. - Where the vendor's confidence is low rather than negative (an "uncertain" outcome), HMU may request a second assurance method before granting access.
6. Underage discovery
If HMU learns — by any means, including report, payment-instrument flag, self-disclosure, or moderation review — that a registered user is under 18, regardless of whether age assurance was previously completed:
- The account is closed immediately.
- All user-generated content tied to the account is removed from active service.
- Personal data is purged within 30 calendar days, except (a) information we are required to retain under applicable law (for example, payment-processing records or evidence required by a competent authority), and (b) minimal identifiers needed to prevent the same minor from creating a replacement account.
- If we have reason to believe the minor was exposed to or has uploaded material that may constitute child sexual abuse material, we report to NCMEC (United States), the Internet Watch Foundation (United Kingdom), or the equivalent authority in the user's jurisdiction.
- Any active subscription is cancelled; refund handling follows the Refund Policy, with discretion to issue a goodwill refund.
7. Parents, guardians, and concerned third parties
If you believe a person under 18 is using HMU, contact [email protected] with as much detail as you can provide: a username if known, a likely email or phone, the basis for your belief, and your relationship to the minor. We will investigate. Privacy law (GDPR, UK GDPR, CCPA/CPRA, LGPD, Australian Privacy Act) limits what we can confirm to you about another user's account, but we will act on credible reports and we will tell you the case is closed once it is.
If you believe a minor is in immediate danger, contact local emergency services first. Reports to us do not substitute for an emergency call.
8. Jurisdiction-specific notes
This section summarises the principal regional rules HMU is built for. It is a high-level guide and is not a substitute for jurisdiction-by-jurisdiction legal advice.
8.1 Australia — Online Safety Act 2021 and Industry Codes
- Effective 9 March 2026, adult-content services accessible in Australia must apply age-assurance measures that go beyond self-attestation.
- Australian users are subject to the age confirmation in Section 3 and the risk signals in Section 4.3. The vendor flow described in Section 4.2 will apply to this market when it is live.
- The eSafety Commissioner has investigatory and enforcement powers, including civil penalties.
8.2 Brazil — Lei No. 15.211/2025
- Effective 17 March 2026, adult-content platforms must implement age assurance for Brazilian users.
- Brazilian users are subject to the age confirmation in Section 3 and the risk signals in Section 4.3. The vendor flow described in Section 4.2 will apply to this market when it is live.
- LGPD applies; our Data Protection Officer acts as encarregado and is reachable at
[email protected].
8.3 European Union and United Kingdom
- GDPR Art. 8 sets specific protections for children's data; UK GDPR mirrors these.
- European regulators have made clear that AI-companion services must give priority to child-protection measures and to clear Art. 13 transparency.
- UK Online Safety Act includes "highly effective age assurance" requirements for parts of regulated services. Ofcom guidance applies.
- Where local rules require assurance beyond the click-through, the flow in Section 4.2 applies once live. We maintain a per-country matrix of which territories trigger it.
8.4 United States — state laws
- Several US states require age verification for users to access pornographic content, with the list and the precise definitions changing. This currently includes Texas, Louisiana, Utah, Virginia, Arkansas, Mississippi, North Carolina, Montana, Indiana, and others.
- Users connecting from those states are subject to the flow in Section 4.2 once it is live, and to the risk signals in Section 4.3 in the meantime.
- Federal law: 18 U.S.C. §2257 record-keeping concepts; HMU's content is AI-generated and depicts no real performers — see AI Content Statement for the formal position.
8.5 Other jurisdictions
- HMU is not made available in countries or territories where adult-content services are unlawful (see the "Jurisdictional eligibility" rule in our Acceptable Use Policy, Section 2).
- For countries not specifically listed above, the click-through gate in Section 3 and our general moderation systems apply. We add countries to the assurance matrix as their regulatory frameworks come into effect.
9. Privacy
Age-assurance data is handled as follows:
- Lawful basis (GDPR / UK GDPR). Compliance with a legal obligation (Art. 6(1)(c)) where assurance is mandated by local law; legitimate interest (Art. 6(1)(f)) in protecting the service and meeting industry standards elsewhere.
- Biometric data. Face-photo liveness and age estimation rely on biometric processing. This is special-category data under GDPR Art. 9 / UK GDPR Art. 9 and sensitive data under LGPD Art. 11. Where the flow in Section 4.2 is live, biometric processing is conducted by our age-assurance vendor on the basis of the user's explicit consent at the moment of assurance, with a non-biometric alternative (document or payment method) always offered.
- Retention. HMU stores only the assurance outcome, the timestamp, the vendor's reference, and the method used. We do not store ID images or biometric templates. The vendor's own retention is governed by its data-protection terms and is documented in its privacy notice.
- Third-country transfers. Where the vendor processes data outside the user's jurisdiction, transfers rely on Standard Contractual Clauses (EU/UK), the LGPD's transfer mechanism, and equivalent safeguards.
- User rights. Users have rights of access, rectification, erasure, restriction, objection, and portability under applicable law; see Privacy Policy.
- Children's data. If we inadvertently collect personal data from a user later determined to be under 18, that data is deleted in accordance with Section 6.
10. Vendor selection and incident transparency
- Any vendor we select must hold the relevant industry certifications (e.g., ISO/IEC 27001; SOC 2 Type II; the ACCS age-assurance standard once recognised) and must contract on terms that include sub-processor disclosure, audit rights, and breach-notification SLAs.
- When a vendor is appointed, we will publish a link to its privacy notice in this Policy and incorporate that notice by reference into our Privacy Policy.
- In the event of a security incident affecting age-assurance data — at the vendor, at HMU, or at any sub-processor — we will notify affected users in accordance with GDPR Art. 34 / UK GDPR Art. 34 / LGPD Art. 48 / applicable US state breach-notification laws, and we will publish an incident summary in this Policy.
- We do not accept user-uploaded face photographs for content generation, which materially reduces the data we hold and therefore the data that could be exposed (see Community Guidelines §3.3).
11. Planned improvements
- Server-side assurance state. Migration from the
age_verifiedbrowser cookie to a server-side acknowledgement keyed to the user account, so that assurance state is not lost on clearing browser storage and so that the click-through gate is not the sole technical barrier. - Per-region assurance matrix.A maintained list of which countries / states / territories trigger the Section 4.2 flow at sign-in, refreshed quarterly by Trust & Safety.
- Re-verification on material change. Where a user's connection signals shift to a higher-assurance jurisdiction (for example, travel from a non-listed country into Australia after 9 March 2026), we will trigger re-assurance.