Age Verification Policy
| Document | Age Verification Policy |
| Operator | Romantic Lines LP (SL25636), 5 South Charlotte Street, Edinburgh, EH2 4AN, Scotland |
| Version | 1.5 |
| Service | Hot Muses Universe ("HMU"), hmu.com |
| Effective date | 2026-09-24 |
| Contact | safety: support@hmu.com · appeals: support@hmu.com · DPO: info@hmu.com |
1. Why this policy exists
Hot Muses Universe ("HMU") provides AI-companion content for adults aged 18 and over. Users must be 18 years of age or older (or the higher local age of majority for adult content) to access the service. This policy explains how HMU enforces that age threshold, what kinds of age-assurance steps users may be asked to complete, and what we do when a user's age cannot be verified or when we learn that a minor has accessed the service.
The policy reflects the current regulatory environment, including:
- Australia — Online Safety Act 2021, with mandatory age-assurance obligations for adult-content services taking effect 9 March 2026.
- Brazil — Lei No. 15.211/2025, mandatory age-assurance for adult-content services, effective 17 March 2026.
- United States — state age-verification laws in Texas, Louisiana, Utah, Virginia, Arkansas, Mississippi, North Carolina, Montana, Indiana, and other states. This list changes frequently and we review it regularly.
- European Union and United Kingdom — the UK Online Safety Act 2023 and GDPR / UK GDPR transparency obligations, together with the enforcement practice of European data-protection authorities in relation to AI-companion services.
- United States federal — 18 U.S.C. §2257 record-keeping concepts, applied here in the AI-content context (no real performers; see AI Content Statement).
The category is under active regulatory scrutiny. HMU's design choices in this area are deliberately conservative.
2. Who is eligible to use HMU
- HMU is for users 18 years of age or older.
- Where the age of majority for adult content in a user's jurisdiction is higher than 18 (for example, certain US states or specific national rules), the higher local age applies.
- HMU is not available in any jurisdiction where adult-content services are prohibited by local law. It is the user's responsibility to know the law where they are. See the "Jurisdictional eligibility" rule in our Acceptable Use Policy, Section 2.
3. Initial age gate (click-through)
On first arrival to hmu.com, every visitor sees an age-gate prompt asking them to confirm they are 18+ (and that adult content is lawful where they are). The confirmation is recorded in the visitor's browser as a first-party cookie (age_verified).
This click-through is the minimum assurance layer. We treat it as a contractual representation by the user, not as proof of age. In the jurisdictions described in Section 4 it is supplemented by the age check described there. We acknowledge that a browser-stored flag can be cleared by the user. Where the age check in Section 4 applies, its outcome is recorded against your account on our servers and cannot be cleared this way; a server-side record of the click-through itself is on our roadmap; see Section 11.
4. Age assurance beyond the click-through
4.1 Where a check is required. In some countries and US states the law requires services restricted to adults to confirm a user's age by more than a click-through - at present, for example, the United Kingdom, Australia, Brazil, several countries in Europe and a number of US states. Where our systems indicate, from the IP address of your connection (country and, in the United States, state), that you are in such a place, we ask you to complete the age check described in Section 4.2. We make this estimate when your account is created and may repeat it later. Everywhere else, access to HMU is gated by the age confirmation described in Section 3, supported by the risk signals described in Section 4.3.
4.2 The age check. The check is carried out by Didit (Didit Identity Spain, S.L.), an independent age-assurance vendor acting on our behalf; its handling of your data is described in its Verification Privacy Notice. You can browse, create an account and write to a companion before the check. We ask for it once there is a reply to show you: until the check is passed, your conversations, including companions' replies and any media in them, are not shown. Which of two methods you are offered depends on what the law where you are requires: (a) age estimation from a selfie - software estimates your age from a short selfie and confirms that a live person is in front of the camera; if the estimate is clearly 18 or over the check is passed, and if it is close to the threshold you are also asked for a photo of an identity document, and your face is compared with the photo on it; or (b) identity document and selfie - the date of birth is read from a government-issued identity document, and your face is compared with the photo on it. In every case Didit, not HMU, handles the document and face capture, and HMU receives and keeps the outcome (passed or not passed), the date and time of completion, the method used, Didit's reference identifier, the age Didit's software estimated and the codes of any warnings it raised, but no name, no date of birth and no document number.
4.3 Risk signals in use today. We use payment-instrument signals, connection and device signals, moderation review, and reports from users and third parties to identify accounts that may belong to a person under 18. Where such signals appear, we act under Section 6.
4.4 Data minimisation. HMU does not store identity-document images, face captures, or biometric templates. They are captured and held by Didit on our behalf and deleted within 30 days of the check; no face template is kept for recognising you later; the images are not used for advertising or to create content, and we have instructed Didit not to use them to improve its own models. This is consistent with GDPR Art. 5(1)(c), UK GDPR Art. 5(1)(c), and LGPD Art. 6(III).
5. What happens if age assurance is not passed
Where the age check described in Section 4.2 applies to you:
- Until the check is passed, your conversations are not shown. Your account stays open: you can still browse, manage or delete your account and contact support, and you do not lose your balance.
- The user is shown a clear explanation and a path to retry.
- The number of attempts within a single check is limited, and a check that is not finished lapses; a new check can then be started.
- The outcome of a check is produced automatically. Users who believe they were incorrectly declined may appeal to
support@hmu.com; a person will review the check and give a decision within 7 business days (Monday to Friday, excluding bank holidays in Scotland). - Where the result is uncertain rather than negative, the vendor asks for an identity document in addition to the selfie, or a member of our team reviews the check in the vendor's system before a decision is made; this usually takes less than a day.
- A failed check is not, by itself, treated as proof that a user is under 18. Where a check establishes that a user is under 18 - for example from the date of birth on an identity document - Section 6 applies.
6. Underage discovery
If HMU learns — by any means, including report, payment-instrument flag, self-disclosure, an age check, or moderation review — that a registered user is under 18, regardless of whether age assurance was previously completed:
- The account is closed immediately.
- All user-generated content tied to the account is removed from active service.
- Personal data is purged within 30 calendar days, except (a) information we are required to retain under applicable law (for example, payment-processing records or evidence required by a competent authority), and (b) minimal identifiers needed to prevent the same minor from creating a replacement account.
- If we have reason to believe the minor was exposed to or has uploaded material that may constitute child sexual abuse material, we report to NCMEC (United States), the Internet Watch Foundation (United Kingdom), or the equivalent authority in the user's jurisdiction.
- Any active subscription is cancelled; refund handling follows the Refund Policy, with discretion to issue a goodwill refund.
7. Parents, guardians, and concerned third parties
If you believe a person under 18 is using HMU, contact support@hmu.com with as much detail as you can provide: a username if known, a likely email or phone, the basis for your belief, and your relationship to the minor. We will investigate: we confirm receipt within 2 business days and complete our review within 7 business days (see our Acceptable Use Policy, Section 3). Privacy law (GDPR, UK GDPR, CCPA/CPRA, LGPD, Australian Privacy Act) limits what we can confirm to you about another user's account, but we will act on credible reports and we will tell you the case is closed once it is.
If you believe a minor is in immediate danger, contact local emergency services first. Reports to us do not substitute for an emergency call.
8. Jurisdiction-specific notes
This section summarises the principal regional rules HMU is built for. It is a high-level guide and is not a substitute for jurisdiction-by-jurisdiction legal advice.
8.1 Australia — Online Safety Act 2021 and Industry Codes
- Effective 9 March 2026, adult-content services accessible in Australia must apply age-assurance measures that go beyond self-attestation.
- Australian users are subject to the age confirmation in Section 3, the age check described in Section 4.2 and the risk signals in Section 4.3.
- The eSafety Commissioner has investigatory and enforcement powers, including civil penalties.
8.2 Brazil — Lei No. 15.211/2025
- Effective 17 March 2026, adult-content platforms must implement age assurance for Brazilian users.
- Brazilian users are subject to the age confirmation in Section 3, the age check described in Section 4.2 and the risk signals in Section 4.3.
- LGPD applies; our Data Protection Officer acts as encarregado and is reachable at
info@hmu.com.
8.3 European Union and United Kingdom
- GDPR Art. 8 sets specific protections for children's data; UK GDPR mirrors these.
- European regulators have made clear that AI-companion services must give priority to child-protection measures and to clear Art. 13 transparency.
- UK Online Safety Act includes "highly effective age assurance" requirements for parts of regulated services. Ofcom guidance applies.
- Where local rules require assurance beyond the click-through, the age check in Section 4.2 applies. We maintain a per-country matrix of which territories trigger it.
8.4 United States — state laws
- Several US states require age verification for online services that make sexual or other material harmful to minors available, with the list and the precise definitions changing. This currently includes Texas, Louisiana, Utah, Virginia, Arkansas, Mississippi, North Carolina, Montana, Indiana, and others.
- Users connecting from those states are subject to the age check in Section 4.2 and to the risk signals in Section 4.3.
- Federal law: 18 U.S.C. §2257 record-keeping concepts; HMU's content is AI-generated and depicts no real performers — see AI Content Statement for the formal position.
8.5 Other jurisdictions
- HMU is not made available in countries or territories where adult-content services are unlawful (see the "Jurisdictional eligibility" rule in our Acceptable Use Policy, Section 2).
- The assurance matrix currently also covers Germany, France, Italy, Switzerland and Liechtenstein; users connecting from those countries are subject to the age check in Section 4.2. For countries not in the matrix, the click-through gate in Section 3 and our general moderation systems apply. We add countries to the matrix as their regulatory frameworks come into effect.
9. Privacy
Age-assurance data is handled as follows:
- Lawful basis (GDPR / UK GDPR). Compliance with a legal obligation (Art. 6(1)(c)) where assurance is mandated by local law; otherwise performance of a contract (Art. 6(1)(b)), because we cannot provide a service restricted to adults without confirming that you are 18 or over. This matches the lawful bases set out in our Privacy Policy.
- Biometric data. Face-photo liveness, age estimation and the comparison of a face with a document photo rely on biometric processing. This is special-category data under GDPR Art. 9 / UK GDPR Art. 9 and sensitive data under LGPD Art. 11. It is processed by our age-assurance vendor on the basis of the user's explicit consent, given on the screen shown immediately before the check starts. A user may decline; Section 5 describes what then happens. Consent may be withdrawn afterwards by writing to
info@hmu.com, in which case we ask the vendor to delete the images within seven days and in any case within one month. - Retention. HMU stores the assurance outcome, the timestamp, the vendor's reference, the method used, the age the vendor's software estimated and the codes of any warnings it raised. We do not store ID images or biometric templates. The vendor holds the images, and the details read from a document, on our behalf and deletes them within 30 days of the check.
- Third-country transfers. The vendor is contracted to store age-assurance data in the European Union; where it processes data elsewhere, the transfer is covered by the safeguards in our agreement with it. Where data is processed outside the user's jurisdiction, transfers rely on Standard Contractual Clauses (EU/UK), the LGPD's transfer mechanism, and equivalent safeguards.
- User rights. Users have rights of access, rectification, erasure, restriction, objection, and portability under applicable law, and the right to have the automated outcome of an age check reviewed by a person (Section 5); see Privacy Policy.
- Children's data. If we inadvertently collect personal data from a user later determined to be under 18, that data is deleted in accordance with Section 6.
10. Vendor selection and incident transparency
- Any vendor we select must hold the relevant industry certifications (e.g., ISO/IEC 27001; SOC 2 Type II; the ACCS age-assurance standard once recognised) and must contract on terms that include sub-processor disclosure, audit rights, and breach-notification SLAs.
- Our age-assurance vendor is Didit (Didit Identity Spain, S.L.). Its Verification Privacy Notice is available at https://didit.me/terms/verification-privacy-notice and is incorporated by reference into our Privacy Policy.
- In the event of a security incident affecting age-assurance data — at the vendor, at HMU, or at any sub-processor — we will notify affected users in accordance with GDPR Art. 34 / UK GDPR Art. 34 / LGPD Art. 48 / applicable US state breach-notification laws, and we will publish an incident summary in this Policy.
- We do not accept user-uploaded face photographs for content generation, which materially reduces the data we hold and therefore the data that could be exposed (see Community Guidelines §3.3).
11. Planned improvements
- Server-side assurance state. Migration from the
age_verifiedbrowser cookie to a server-side acknowledgement keyed to the user account, so that assurance state is not lost on clearing browser storage and so that the click-through gate is not the sole technical barrier. - Re-verification on material change. Where a user's connection signals shift to a higher-assurance jurisdiction (for example, travel from a non-listed country into Australia after 9 March 2026), we will trigger re-assurance.