ExploreChats

Age Verification Policy

DocumentAge Verification Policy
OperatorRomantic Lines LP (SL25636), 5 South Charlotte Street, Edinburgh, EH2 4AN, Scotland
ServiceHot Muses ("HMU"), hmu.com
Effective date2026-05-25
Contactsafety: [email protected] · appeals: [email protected] · DPO: [email protected]

1. Why this policy exists

Hot Muses ("HMU") provides adult-oriented AI-companion content. Users must be 18 years of age or older (or the higher local age of majority for adult content) to access the service. This policy explains how HMU enforces that age threshold, what kinds of age-assurance steps users may be asked to complete, and what we do when a user's age cannot be verified or when we learn that a minor has accessed the service.

The policy reflects the current regulatory environment, including:

  • Australia — Online Safety Act 2021, with mandatory age-assurance obligations for adult-content services taking effect 9 March 2026.
  • Brazil — Lei No. 15.211/2025, mandatory age-assurance for adult-content services, effective 17 March 2026.
  • United States — state age-verification laws in Texas, Louisiana, Utah, Virginia, Arkansas, Mississippi, North Carolina, Montana, Indiana, and other states (the list is changing — counsel should refresh on each material policy update).
  • European Union and United Kingdom — the UK Online Safety Act, GDPR/UK GDPR transparency obligations, and the regulatory trajectory following the Italian Garante's 2023 processing ban and 2025 €5,000,000 fine against Luka Inc. (Replika) in respect of child-safety failures and transparency.
  • United States federal — 18 U.S.C. §2257 record-keeping concepts, applied here in the AI-content context (no real performers; see AI Content Statement).

The category is under active regulatory scrutiny. HMU's design choices in this area are deliberately conservative.

2. Who is eligible to use HMU

  • HMU is for users 18 years of age or older.
  • Where the age of majority for adult content in a user's jurisdiction is higher than 18 (for example, certain US states or specific national rules), the higher local age applies.
  • HMU is not available in any jurisdiction where adult-content services are prohibited by local law. It is the user's responsibility to know the law where they are. See Acceptable Use Policy §2(11).

3. Initial age gate (click-through)

On first arrival to hmu.com, every visitor sees an age-gate prompt asking them to confirm they are 18+ (and that adult content is lawful where they are). The confirmation is recorded in the visitor's browser via a local-storage flag (hmu_age_confirmed).

This click-through is the minimum assurance layer. We treat it as a contractual representation by the user, not as proof of age. It is supplemented in higher-risk jurisdictions by the assurance flow described in Section 4. We acknowledge that browser-local storage can be cleared by the user, and the assurance hierarchy below does not depend on it. Product and counsel are jointly planning a migration from this mechanism to a more robust server-side acknowledgement; see Section 11.

4. Stronger age assurance (where required)

For users connecting from jurisdictions that mandate age assurance, or where our risk signals indicate stronger verification is warranted, HMU uses an independent age-assurance vendor: [AGE ASSURANCE VENDOR]. Candidate vendors include Persona, Yoti, Veriff, and equivalent providers; the final vendor selection and contract are subject to counsel review.

The user may choose one of three assurance methods:

  1. Government-issued identity document. Upload a photograph or scan of a passport, driver's licence, or national identity card. The vendor extracts and verifies the date of birth and the document's authenticity signals. HMU does not receive the document itself. The vendor returns a yes/no decision and an age band (e.g. "18+ confirmed").

  2. Face-photo with liveness check and age estimation. The vendor captures a real-time selfie with liveness signals (motion, depth, anti-spoof). It returns an estimated age band. If the estimated band sits comfortably above 18, the user is admitted. If the band is borderline, the vendor falls back to method (1).

  3. Credit-card or recurring-payment verification. Where the user has a payment relationship with HMU (Starter, Plus, Premium, or VIP subscription, or a credit top-up), the existence of a verified adult payment instrument is treated as a corroborating age signal. This method is supplementary; it is not used as the sole assurance for jurisdictions where regulators require document- or face-based assurance.

Data minimisation principle. HMU does not store ID document images, face-photo captures, or biometric templates. The vendor returns a binary admission decision plus an age-band hint. HMU stores: (a) the fact that assurance was completed; (b) the date and time of completion; (c) the vendor's reference identifier for audit; (d) the assurance method used. This is consistent with GDPR Art. 5(1)(c), UK GDPR Art. 5(1)(c), and LGPD Art. 6(III).

5. What happens if verification fails

  • Access to the service is blocked.
  • The user is shown a clear explanation and a path to retry, including a different assurance method if available.
  • Repeated failed attempts within 24 hours trigger a cool-down to deter brute-force document uploads.
  • Users who believe they were incorrectly declined may appeal to [email protected]. We aim to respond within 14 calendar days.
  • Where the vendor's confidence is low rather than negative (an "uncertain" outcome), HMU may request a second assurance method before granting access.

6. Underage discovery

If HMU learns — by any means, including report, payment-instrument flag, self-disclosure, or moderation review — that a registered user is under 18, regardless of whether age assurance was previously completed:

  • The account is closed immediately.
  • All user-generated content tied to the account is removed from active service.
  • Personal data is purged within 30 calendar days, except (a) information we are required to retain under applicable law (for example, payment-processing records or evidence required by a competent authority), and (b) minimal identifiers needed to prevent the same minor from creating a replacement account.
  • If we have reason to believe the minor was exposed to or has uploaded material that may constitute child sexual abuse material, we report to NCMEC (United States), the Internet Watch Foundation (United Kingdom), or the equivalent authority in the user's jurisdiction.
  • Any active subscription is cancelled; refund handling follows the Refund Policy, with discretion to issue a goodwill refund.

7. Parents, guardians, and concerned third parties

If you believe a person under 18 is using HMU, contact [email protected] with as much detail as you can provide: a username if known, a likely email or phone, the basis for your belief, and your relationship to the minor. We will investigate. Privacy law (GDPR, UK GDPR, CCPA/CPRA, LGPD, Australian Privacy Act) limits what we can confirm to you about another user's account, but we will act on credible reports and we will tell you the case is closed once it is.

If you believe a minor is in immediate danger, contact local emergency services first. Reports to us do not substitute for an emergency call.

8. Jurisdiction-specific notes

This section summarises the principal regional rules HMU is built for. It is a high-level guide and is not a substitute for jurisdiction-by-jurisdiction legal advice.

8.1 Australia — Online Safety Act 2021 and Industry Codes

  • Effective 9 March 2026, adult-content services accessible in Australia must apply age-assurance measures that go beyond self-attestation.
  • HMU applies the assurance flow in Section 4 to users whose connection signals indicate an Australian location.
  • The eSafety Commissioner has investigatory and enforcement powers, including civil penalties.

8.2 Brazil — Lei No. 15.211/2025

  • Effective 17 March 2026, adult-content platforms must implement age assurance for Brazilian users.
  • We apply Section 4 assurance to users on Brazilian connections.
  • LGPD applies; we maintain a Brazilian representative ([BRAZIL DPO/REPRESENTATIVE]).

8.3 European Union and United Kingdom

  • GDPR Art. 8 sets specific protections for children's data; UK GDPR mirrors these.
  • The Italian Garante's 2023 processing ban and 2025 €5M fine on Luka Inc. (Replika) make clear that AI-companion services must give priority to child-protection measures and to clear Art. 13 transparency.
  • UK Online Safety Act includes "highly effective age assurance" requirements for parts of regulated services. Ofcom guidance applies.
  • HMU applies the Section 4 assurance for users whose connection indicates EEA or UK origin where local rules require it; counsel and product to maintain the per-country matrix.
  • An EU representative ([EU REPRESENTATIVE]) and UK representative ([UK REPRESENTATIVE]) are appointed where the operator is non-EU/non-UK.

8.4 United States — state laws

  • Several US states require age verification for users to access pornographic content, with the list and the precise definitions changing. As of drafting, this includes Texas, Louisiana, Utah, Virginia, Arkansas, Mississippi, North Carolina, Montana, Indiana, and others.
  • HMU applies the Section 4 assurance to users whose connection indicates one of those states.
  • Federal law: 18 U.S.C. §2257 record-keeping concepts; HMU's content is AI-generated and depicts no real performers — see AI Content Statement for the formal position.

8.5 Other jurisdictions

  • HMU is not made available in countries or territories where adult-content services are unlawful (see Acceptable Use Policy §2(11)).
  • For countries not specifically listed above, the click-through gate in Section 3 and our general moderation systems apply. Counsel and product will add countries to the assurance matrix as their regulatory frameworks come into effect.

9. Privacy

Age-assurance data is handled as follows:

  • Lawful basis (GDPR / UK GDPR). Compliance with a legal obligation (Art. 6(1)(c)) where assurance is mandated by local law; legitimate interest (Art. 6(1)(f)) in protecting the service and meeting industry standards elsewhere.
  • Biometric data. Face-photo liveness and age estimation rely on biometric processing. This is special-category data under GDPR Art. 9 / UK GDPR Art. 9 and sensitive data under LGPD Art. 11. Processing is conducted by [AGE ASSURANCE VENDOR] on the basis of the user's explicit consent at the moment of assurance, with a non-biometric alternative (document or payment method) offered.
  • Retention. HMU stores only the assurance outcome, the timestamp, the vendor's reference, and the method used. We do not store ID images or biometric templates. The vendor's own retention is governed by its data-protection terms and is documented in its privacy notice.
  • Third-country transfers. Where the vendor processes data outside the user's jurisdiction, transfers rely on Standard Contractual Clauses (EU/UK), the LGPD's transfer mechanism, and equivalent safeguards.
  • User rights. Users have rights of access, rectification, erasure, restriction, objection, and portability under applicable law; see Privacy Policy.
  • Children's data. If we inadvertently collect personal data from a user later determined to be under 18, that data is deleted in accordance with Section 6.

10. Vendor selection and incident transparency

  • The selected vendor ([AGE ASSURANCE VENDOR]) must hold the relevant industry certifications (e.g., ISO/IEC 27001; SOC 2 Type II; the ACCS age-assurance standard once recognised) and must contract on terms that include sub-processor disclosure, audit rights, and breach-notification SLAs.
  • The vendor's privacy notice is available at [AGE ASSURANCE VENDOR PRIVACY URL] and is incorporated by reference into Privacy Policy.
  • In the event of a security incident affecting age-assurance data — at the vendor, at HMU, or at any sub-processor — we will notify affected users in accordance with GDPR Art. 34 / UK GDPR Art. 34 / LGPD Art. 48 / applicable US state breach-notification laws, and we will publish an incident summary on hmu.com/incidents/.
  • We hold ourselves to the breach-disclosure expectations highlighted by the November 2025 Secret Desires AI incident. We do not accept user-uploaded face photographs for content generation, which materially reduces the data we hold (see Community Guidelines §3.3).

11. Planned improvements

  • Server-side assurance state. Migration from the browser-local hmu_age_confirmed flag to a server-side acknowledgement keyed to the user account, so that assurance state is not lost on clearing browser storage and so that the click-through gate is not the sole technical barrier.
  • Per-region assurance matrix in production.A maintained list of which countries / states / territories trigger the Section 4 flow at sign-in, refreshed quarterly by Trust & Safety and counsel.
  • Re-verification on material change. Where a user's connection signals shift to a higher-assurance jurisdiction (for example, travel from a non-listed country into Australia after 9 March 2026), we will trigger re-assurance.
  • Annual transparency report. Aggregated statistics on age-assurance outcomes (pass / fail / appeal) published annually, consistent with the operator commitments in Self-Harm Resources Policy §8.

12. Cross-references

  • Acceptable Use Policy
  • Community Guidelines
  • Privacy Policy
  • Terms of Service
  • AI Content Statement
  • Self-Harm Resources Policy

Your gateway to meaningful AI connections.

Product

  • Explore
  • Chat
  • Feed
  • Premium

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • DMCA

Support

  • Help Center
  • Contact Us
  • Community Guidelines
  • Safety

© 2026 Hot Muses. All rights reserved.

This site is for users 18+ only. By using this site, you agree to our Terms of Service.