ExploreChats

HMU — Privacy Policy

Last updated: 2026-05-25 Operator: Romantic Lines LP Contact: [email protected]


1. Introduction and scope

Hot Muses ("HMU", "we", "us", "our") is an adult (18+) AI-companion chat service operated by Romantic Lines LP, a limited partnership registered in Scotland under number SL25636, with its registered office at 5 South Charlotte Street, Edinburgh, EH2 4AN, Scotland.

This Privacy Policy explains what Personal Data we collect about you when you use hmu.com (the "Service"), why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have.

Who this Policy applies to. This Policy applies to anyone who:

  • Visits hmu.com or any of our subdomains;
  • Creates an account on the Service;
  • Sends or receives messages on the Service;
  • Uploads any document (including a government ID or selfie) to verify their age;
  • Makes a payment to us through our payment processor; or
  • Contacts us by email or any other means.

Adults only. The Service is strictly limited to users aged 18 or over. We do not knowingly collect Personal Data from minors. If you are under 18, do not use the Service and do not provide any information to us. See Section 13 below.

Key terms. Where this Policy uses the term "Personal Data", we mean any information that relates to an identified or identifiable natural person, as defined in the EU and UK General Data Protection Regulations (GDPR / UK GDPR). "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure and deletion. "You" means the person whose Personal Data is being processed.


2. Who controls your data (controller information)

Romantic Lines LP is the "controller" of your Personal Data — meaning we decide what data is collected and what it is used for.

RoleEntity / contact
ControllerRomantic Lines LP, 5 South Charlotte Street, Edinburgh, EH2 4AN, Scotland
Data Protection Officer (DPO)Contactable at [email protected]
EU representative (GDPR Art. 27)[EU REPRESENTATIVE], [EU REPRESENTATIVE ADDRESS]
UK representative (UK GDPR Art. 27)[UK REPRESENTATIVE], [UK REPRESENTATIVE ADDRESS]
Brazil representative / DPO (LGPD Art. 41)[BRAZIL DPO/REPRESENTATIVE], [ADDRESS]
Privacy general inbox[email protected]

If you are in the European Economic Area, the United Kingdom or Brazil and you would prefer to contact a local representative, please use the address corresponding to your region above. You can always reach us at [email protected].


3. What we collect

We group the data we collect into the categories below. For each category we say what it is, where it comes from, why we process it, our lawful basis under GDPR / UK GDPR, and how long we keep it.

3.1 Account identifiers

FieldExamples
WhatEmail address, hashed password (we never see or store plaintext passwords), optional display name, a unique user ID assigned to your account.
SourceYou provide it when you sign up.
WhyTo create and secure your account; to let you log in; to send essential service emails (security alerts, password resets, billing).
Lawful basis (GDPR / UK GDPR)Performance of a contract (Art. 6(1)(b)) — we cannot provide the Service without it.
RetentionWhile your account is active, plus up to 6 years after closure for tax, fraud and legal-defence purposes (UK Limitation Act 1980 and equivalents in your jurisdiction).

3.2 Profile data

FieldExamples
WhatDisplay name, biography text, kinks/preferences you select, language and theme preferences.
SourceYou provide it through the profile screen. The kinks field is optional — you may use the Service without filling it in.
WhyTo personalise companion behaviour and to recommend companions you may enjoy.
Lawful basis (GDPR / UK GDPR)For non-sensitive fields: performance of a contract (Art. 6(1)(b)). For the kinks field and any other content from which your sex life or sexual orientation may be inferred: your explicit consent under Art. 9(2)(a) — see Section 6 below.
RetentionWhile your account is active; you can delete this content at any time from the profile screen with effect on our live database within 24 hours and on backups within 30 days.

3.3 Conversation data

FieldExamples
WhatThe text of every message you send, the text of AI replies generated for you, conversation timestamps, the companion(s) you converse with, message-level metadata such as message length and moderation flags.
SourceGenerated when you use the chat feature.
WhyTo provide the chat service; to detect and prevent abuse (including content that breaches our Acceptable Use Policy such as content sexualising minors, real-person impersonation, self-harm escalation); to improve safety classifiers in aggregated and de-identified form.
Lawful basis (GDPR / UK GDPR)Performance of a contract (Art. 6(1)(b)) for service delivery; legitimate interests (Art. 6(1)(f)) for safety, balanced against your right not to be surveilled — see our Legitimate Interest Assessment summary at Section 5. Where the content of a conversation reveals sex life or sexual orientation, your continued use of the chat feature constitutes explicit consent under Art. 9(2)(a), reinforced by the explicit opt-in shown at sign-up and at the start of each chat session.
RetentionWhile the conversation exists. You can delete an individual message or a whole conversation at any time. Deleted content is removed from our live database within 24 hours and from backups within 30 days. We may retain a moderation copy of a message that triggered a safety review for up to 12 months in a restricted-access audit store, even if you delete it, to defend ourselves against legal claims or regulatory enquiry.

3.4 Generated media metadata

FieldExamples
WhatThe prompt text you submit when you ask a companion for a photo or video; the job ID and status returned by our AI image & video generation provider; the storage path of the resulting media file; MIME type and size; any error message returned.
SourceGenerated when you use the "Ask photo" or "Ask video" feature.
WhyTo produce the requested media and display it inside the chat; to bill the credits used; to operate quotas; to investigate failures.
Lawful basis (GDPR / UK GDPR)Performance of a contract (Art. 6(1)(b)). Prompts that reveal sex life or sexual orientation are processed under Art. 9(2)(a) explicit consent as described in Section 6.
RetentionWhile you have the media visible in your chat, plus 30 days after deletion for backups. Failed jobs are retained 90 days for diagnostic purposes.

3.5 Billing data

FieldExamples
WhatSubscription tier and renewal date; monthly message quota remaining; credit balance; transaction IDs returned by our payment processor; invoice records; partial card data limited to brand and last four digits as displayed to you for receipts.
SourceOur payment processor returns these fields to us after each transaction.
WhyTo provision your subscription; to bill you correctly; to handle refunds and chargebacks; to comply with tax and accounting law.
Lawful basis (GDPR / UK GDPR)Performance of a contract (Art. 6(1)(b)) for billing; legal obligation (Art. 6(1)(c)) for tax and anti-money-laundering record-keeping.
Retention6 years from the end of the tax year in which the transaction occurred (UK and most EU jurisdictions). Some refund-window data may be retained longer at the request of the payment processor.

3.6 Payment card data

We do not collect, store or process full payment-card numbers, expiry dates or card security codes (CVV). These fields are collected directly by our PCI-DSS-compliant payment processor inside an iframe or redirect that they host. We receive back from the processor only the tokenised reference, the card brand, the last four digits, and the transaction outcome.

If you wish to update or delete your card on file, you must do so through the payment-processor portal linked from the billing screen.

3.7 Device and technical data

FieldExamples
WhatIP address; user-agent string; approximate location derived from IP (country and region only — we do not use GPS); device type and screen size; referrer URL; pages visited and time spent; events such as message sends and clicks; session cookie identifiers; analytics identifiers if you have consented to analytics cookies (see Section 12).
SourceAutomatically collected from your browser by our cloud hosting & infrastructure provider, by the authentication layer that signs you in, and by our web analytics provider where you have consented to analytics.
WhyTo deliver pages over the network; to keep you logged in; to detect abuse and fraud (e.g. repeated failed logins, bot scraping); with your consent, to measure how the Service is used and improve it.
Lawful basis (GDPR / UK GDPR)Performance of a contract (Art. 6(1)(b)) for delivery and security-relevant logs; legitimate interests (Art. 6(1)(f)) for fraud prevention and infrastructure security; consent (Art. 6(1)(a)) for analytics and any non-essential trackers.
RetentionServer access logs: 90 days. Security and fraud logs: 12 months. Analytics aggregates (no IP): up to 26 months.

3.8 Age-verification data

FieldExamples
WhatA photo of your face, a scan of a government-issued identity document, a liveness video, or — depending on the assurance method offered — a probabilistic age estimate, a cryptographic age token, or a "pass / fail" result. We never store the raw ID image or selfie ourselves: it is handled by our age-verification provider and only the verification outcome and a tokenised reference are returned to us.
SourceYou provide it directly to our age-verification provider when prompted by the Service.
WhyTo verify that you are 18 or over before granting access to adult content. This is required by the Australian Online Safety Act (effective 9 March 2026), Brazilian Lei 15.211/2025 (effective 17 March 2026), the UK Online Safety Act 2023, and a growing number of US state laws (Texas, Louisiana, Utah, Virginia, Arkansas, Mississippi, North Carolina, Montana, Indiana and others).
Lawful basis (GDPR / UK GDPR)Legal obligation (Art. 6(1)(c)) and the corresponding Art. 9(2)(g) "substantial public interest" exemption for biometric data, where required by law. Where no such legal obligation applies but verification is still performed, we rely on Art. 6(1)(b) contract and Art. 9(2)(a) explicit consent.
RetentionThe verification outcome and tokenised reference are retained for the lifetime of your account plus 12 months, so we can prove to a regulator that we verified your age. The underlying biometric data is deleted by our age-verification provider within the retention period stipulated in their privacy notice (typically 7–30 days).

3.9 Support communications

When you email [email protected] or use any in-product help form, we collect the content of your message, any attachments, your email address, and the date and time of contact. We use this to respond to your enquiry, to track recurring issues, and to defend ourselves against complaints. Lawful basis: performance of a contract and legitimate interests. Retention: 3 years from the last contact.

3.10 Marketing data (where applicable)

If you opt in to marketing emails, we hold your email address and your opt-in record (timestamp, IP, source) with our marketing email provider. Lawful basis: consent (Art. 6(1)(a)). Retention: until you unsubscribe, plus 3 years after to honour your suppression preference.


4. How we use your data (purposes)

We use the data described in Section 3 for the following purposes:

  1. To provide the Service. Authentication; delivering chat messages and generated media; managing your wallet of subscription messages and credits; remembering your preferences.
  2. To bill you. Calculating subscription quotas, processing payments through our payment processor, issuing receipts, handling refunds and chargebacks.
  3. To keep the Service safe. Content moderation against our Acceptable Use Policy, detection of abuse, prevention of generation of minor-coded or non-consensual content, account-takeover detection, rate-limiting and bot prevention.
  4. To comply with law. Age verification; tax record-keeping; responses to lawful subpoenas, court orders and regulator requests; transparency reporting where required (e.g. EU DSA Art. 24).
  5. To improve the Service. Analytics on aggregate use patterns; A/B testing of UI changes; in-house tuning of safety classifiers using de-identified conversation samples.
  6. To communicate with you. Transactional emails (sign-up, billing, security, content take-downs), and — only with your separate consent — marketing emails about new companions, features or offers.
  7. To exercise and defend legal claims. Retaining records that we may need to defend against complaints, regulatory enquiries or litigation.

We will never use your conversation content, profile kinks, or generated-media prompts to train a general-purpose AI model that is sold or distributed outside the Service. Where we use conversation samples to improve safety classifiers, the samples are first stripped of direct identifiers and aggregated.


5. Lawful bases under GDPR / UK GDPR (summary)

The table below maps each processing purpose to its lawful basis under Art. 6 GDPR / UK GDPR. Where the processing involves "special category" data (Art. 9), we also identify the Art. 9 condition.

PurposeArt. 6 basisArt. 9 condition (if special-category data involved)
Account creation, login, password resetContract (Art. 6(1)(b))n/a
Storing your profile (incl. kinks)Contract for non-sensitive; Consent (Art. 6(1)(a)) for the kinks fieldExplicit consent (Art. 9(2)(a))
Sending / receiving chat messagesContract (Art. 6(1)(b))Explicit consent (Art. 9(2)(a)) for any content revealing sex life / orientation
Content moderationLegitimate interests (Art. 6(1)(f)) — protecting users and the Service from harmSubstantial public interest (Art. 9(2)(g)) — safeguarding
Generating photos and videosContract (Art. 6(1)(b))Explicit consent (Art. 9(2)(a))
Billing and tax recordsContract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c))n/a
Fraud and abuse detectionLegitimate interests (Art. 6(1)(f))n/a
Age verificationLegal obligation (Art. 6(1)(c)) where mandated; otherwise Contract + ConsentSubstantial public interest (Art. 9(2)(g))
Analytics cookiesConsent (Art. 6(1)(a))n/a
Marketing emailsConsent (Art. 6(1)(a))n/a
Defence of legal claimsLegitimate interests (Art. 6(1)(f))Art. 9(2)(f)

Legitimate Interest Assessment summary. Where we rely on legitimate interests, we have performed a balancing test. In summary: (a) the purpose (e.g. preventing illegal content, fraud, account takeover) is a legitimate business and societal interest; (b) the processing is necessary because no less intrusive means achieves the same end; (c) your fundamental rights are protected by the safeguards listed in Section 14 (encryption, access controls, retention limits, the right to object). We will share the full LIA on written request to [email protected].


6. Sensitive data — explicit consent

The Service is, by its nature, designed for adult conversation. The Personal Data we process therefore frequently includes information that GDPR / UK GDPR Art. 9 classifies as "special category" — in particular, data revealing sex life or sexual orientation, and biometric data (used by our age-assurance vendor to confirm you are 18+).

By creating an account on HMU and using the chat feature, you give your explicit, informed and freely-given consent under Art. 9(2)(a) to our processing of:

  • The contents of any profile field you fill in that reveals your sex life, sexual orientation or sexual preferences (in particular the kinks field);
  • The contents of any chat message you send to a companion or that a companion sends to you;
  • The contents of any prompt you submit to the "Ask photo" or "Ask video" feature;
  • The generated media that results from those prompts;
  • Biometric data submitted to our age-verification provider for the purpose of age verification.

This consent is separate from your acceptance of our Terms of Service. You will be shown a dedicated consent checkbox when you sign up. You may withdraw this consent at any time by deleting your account or by emailing [email protected]. Withdrawal does not affect the lawfulness of processing that occurred before the withdrawal. Withdrawal will, however, terminate your access to the chat feature, because we cannot lawfully provide it without your consent to process Art. 9 data.


7. Who we share your data with (sharing and disclosure)

We share Personal Data with the categories of recipients listed below. Each recipient acts as a processor on our behalf, processing your data only on our documented instructions, except where indicated. We disclose these recipients by category rather than by company name; the table identifies, for each category, what data flows to it, why, the country or region where the data is processed, and the safeguard applied to any international transfer.

7.1 Categories of recipient (processors acting on our behalf)

Category of recipientWhat we shareWhyLocation / region of processingTransfer safeguard
Cloud hosting & infrastructure providerAll request data, IP addresses, technical logs; account, profile, conversation and billing data held in our database and file storageWeb hosting, edge delivery, database, authentication and file storageUnited StatesEU Standard Contractual Clauses + EU–US Data Privacy Framework + UK International Data Transfer Addendum
AI chat-model providersChat message content; a minimal user identifier; the companion identifierTo generate AI companion repliesUnited States and other regions outside the EEA/UK, depending on the providerEU Standard Contractual Clauses where the region is non-EEA; data-processing agreement in place
AI image & video generation providerMedia prompts; a minimal user identifierTo generate the photos and videos you requestUnited KingdomEU–UK adequacy decision for EU exports; EU Standard Contractual Clauses for any onward transfer
Payment processorCard data (collected directly by the processor), billing email, transaction detailsPayment processing for adult merchantsEuropean Economic Area / United KingdomEU Standard Contractual Clauses + adult-merchant agreement; the processor acts as an independent controller for fraud-prevention purposes
Age-verification providerGovernment-ID image, selfie, liveness video, IP addressTo verify that you are 18 or overEuropean Economic Area / United KingdomEU Standard Contractual Clauses; GDPR Art. 9 explicit consent collected before processing
Transactional email providerEmail address, message contentTo send essential service emails (sign-up, billing, security, content take-downs)United StatesEU Standard Contractual Clauses + EU–US Data Privacy Framework + UK International Data Transfer Addendum
Marketing email providerEmail address, opt-in record, engagement dataTo send marketing emails to consented users onlyEuropean Economic Area and IsraelEU adequacy decision in favour of Israel and/or EU Standard Contractual Clauses
Web analytics providerPseudonymous analytics identifiers, IP-derived approximate location, page and event dataTo measure how the Service is used and improve it (only where you have consented to analytics cookies)United StatesEU Standard Contractual Clauses + EU–US Data Privacy Framework

Each recipient is bound by a written data-processing agreement (DPA) that obliges them to process your data only on our documented instructions, to apply appropriate technical and organisational measures, and to notify us of any personal-data breach. We disclose recipients by category in this Policy; we do not publish the identities of the specific vendors we engage, as our selection of vendors is commercially confidential. We will, however, identify the specific recipient of a given category of your data on a reasoned request — see Section 18.

7.2 Legal disclosures

We may disclose your Personal Data to law-enforcement agencies, regulators, courts or other competent authorities where we believe in good faith that we are required to do so by law, court order or properly served subpoena, or where disclosure is necessary to protect our rights, the safety of users or the public, or to investigate suspected fraud or abuse. We resist over-broad requests and we publish a transparency report annually.

7.3 Business transfers

If we are involved in a merger, acquisition, financing, reorganisation, insolvency, receivership or sale of assets, your Personal Data may be transferred as part of that transaction. We will notify you in advance and you will have the opportunity to delete your account before the transfer takes effect.

7.4 No sale or "share" for cross-context behavioural advertising

We do not sell your Personal Data for money or other valuable consideration. We do not "share" (as defined under CCPA/CPRA) your Personal Data for cross-context behavioural advertising. California residents see also Section 14 below.


8. International transfers

We are based in the United Kingdom and several of our recipients are located in the United States and elsewhere outside the European Economic Area, the United Kingdom and Brazil. Whenever we transfer your Personal Data outside its country of origin, we rely on one or more of the following mechanisms:

  • The EU–US Data Privacy Frameworkfor transfers to certified US recipients (our cloud hosting & infrastructure provider, transactional email provider and web analytics provider, where each is self-certified);
  • The European Commission's Standard Contractual Clauses (2021/914) for transfers to non-DPF countries;
  • The UK Information Commissioner's Office International Data Transfer Addendum and/or the UK IDTA for transfers from the UK;
  • For transfers concerning Brazilian residents, the safeguards required by ANPD Resolution CD/ANPD No. 19/2024 (or successor instrument), including transfer-specific contractual clauses and a transfer impact assessment.

You may request a copy of the safeguards in place for a specific transfer by writing to [email protected].


9. Retention

We keep your Personal Data only for as long as is necessary for the purposes for which we collected it, plus any further period required by law or to defend legal claims.

DataRetention
Active account data (identifiers, profile, preferences)While the account is active
Account data after closure6 years (tax, statute of limitations) — limited to billing and identifier records, with conversation content deleted
Conversation contentWhile the conversation exists; deleted on user request within 24h (live DB) and 30 days (backups)
Moderation copies of flagged messagesUp to 12 months in a restricted-access audit store
Generated mediaWhile visible in chat; 30 days after deletion
Billing records6 years from end of the relevant tax year
Payment-card tokensHeld by our payment processor, not by us
Server access logs90 days
Security and fraud logs12 months
Aggregated analytics (no IP)Up to 26 months
Age-verification outcome recordAccount lifetime + 12 months
Underlying biometric dataDeleted by our age-verification provider per their notice (typically 7–30 days)
Support tickets3 years from last contact
Marketing-email consent recordUntil unsubscribe, then 3 years for suppression

You can ask us to delete data sooner; we will do so unless we have a legal obligation to retain it, in which case we will tell you what we must keep and for how long.


10. Your rights

Your rights depend on where you live. The rights below are cumulative — if you live in a place where more than one regime applies, you can use whichever right is most favourable.

10.1 Rights under GDPR (EEA) and UK GDPR (United Kingdom)

You have the right to:

  • Access (Art. 15) — a copy of the Personal Data we hold about you;
  • Rectification (Art. 16) — correct inaccurate data;
  • Erasure (Art. 17, the "right to be forgotten") — delete data we no longer need or that you have withdrawn consent for;
  • Restriction (Art. 18) — limit our processing while a dispute is resolved;
  • Portability (Art. 20) — receive your data in a structured, machine-readable format and have it transmitted to another controller where technically feasible;
  • Object (Art. 21) — to processing based on legitimate interests, including profiling for marketing;
  • Withdraw consent (Art. 7(3)) — at any time, without affecting the lawfulness of past processing;
  • Lodge a complaint with a supervisory authority. The lead authority for the operator is the UK Information Commissioner's Office (https://ico.org.uk). EEA residents may complain to their local authority — for example the Italian Garante per la protezione dei dati personali, the French CNIL, the German BfDI or its state equivalent, the Irish DPC, etc. A full list is maintained by the European Data Protection Board at edpb.europa.eu.

To exercise any of these rights, email [email protected] or use the in-product "Download my data" and "Delete my account" buttons in the profile screen. We will respond within one month (GDPR Art. 12(3)); we may extend by a further two months for complex requests, and we will tell you if we do.

10.2 Rights under CCPA / CPRA (California)

If you are a California resident, you have the right to:

  • Know what categories and specific pieces of Personal Information we collect, the sources, the business or commercial purposes, and the categories of third parties with whom we share it;
  • Delete Personal Information we have collected from you, subject to statutory exceptions;
  • Correct inaccurate Personal Information;
  • Opt out of sale or sharing. We do not sell or share Personal Information for cross-context behavioural advertising. A "Do Not Sell or Share My Personal Information" link is still made available on every page of the Service for transparency;
  • Limit the use of sensitive Personal Information. A "Limit the Use of My Sensitive Personal Information" link is provided. Note that, because adult content is the core purpose of the Service, certain sensitive PI (e.g. the content of your sexual chats) cannot be processed at a reduced scope without making the Service impossible to deliver. We will honour limitation requests by closing the affected account if the user prefers that outcome to continued processing;
  • Non-discrimination for exercising any of the above. We will not deny service, charge different prices, or provide a lower quality of service because you exercised your rights, except where the difference is reasonably related to the value of the data;
  • No financial incentives. We do not offer financial incentives in exchange for the collection, retention, sale or sharing of Personal Information.

To exercise California rights, email [email protected] or use the dedicated form at hmu.com/california-rights. We will verify your identity before fulfilling a request, in line with the regulations. You may also use an authorised agent — we will require proof of authorisation.

10.3 Rights under LGPD (Brazil)

If you are in Brazil, you have the right to:

  • Confirm the existence of processing;
  • Access your data;
  • Correct incomplete, inaccurate or outdated data;
  • Anonymise, block or delete unnecessary, excessive or unlawfully processed data;
  • Portability of your data to another service or product provider;
  • Delete data processed on the basis of consent;
  • Be informed of the public and private entities with whom we share your data;
  • Be informed about the possibility of refusing to consent and the consequences of refusal;
  • Revoke consent.

To exercise LGPD rights, contact our Brazilian representative at [BRAZIL DPO/REPRESENTATIVE] or [email protected]. You may also lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.

10.4 Rights under the Australian Privacy Act / Australian Privacy Principles

If you are in Australia, you have the right to:

  • Access the Personal Information we hold about you (APP 12);
  • Request correction of inaccurate, out-of-date, incomplete, irrelevant or misleading Personal Information (APP 13);
  • Make a complaint about how we handle Personal Information.

Send Australian requests to [email protected]. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.


11. Children

The Service is strictly limited to users aged 18 and over. We do not knowingly collect Personal Data from anyone under 18. We use age-assurance technology described in Section 3.8 and in our Age Verification Policy to enforce this.

If we learn that we have collected Personal Data from a person under 18, we will delete that data immediately and close the account. If you believe a minor has provided us with Personal Data, please contact [email protected] so we can act.


12. Cookies and similar technologies

We use cookies, local storage and similar technologies on the Service. A full description, including the categories of cookie, what each does, the retention period and how to manage your preferences, is set out in our Cookie Policy.


13. Security

We apply technical and organisational measures appropriate to the risk of the processing, in line with GDPR Art. 32 and equivalents. These include:

  • Encryption in transit: TLS 1.2+ for all browser and API traffic.
  • Encryption at rest: Database and storage encryption at the infrastructure level, using provider-managed keys.
  • Access control: Row-Level Security policies on every table containing user data; principle of least privilege for internal staff; multi-factor authentication for administrative access.
  • Network controls: Web application firewall; rate-limiting; bot detection; secure secret management.
  • Operational controls: Documented incident-response plan; periodic backups; regular dependency scanning; a separate restricted-access store for moderation-flagged content.
  • People controls: Confidentiality undertakings in employment and contractor agreements; training for staff who handle Personal Data.

No system is 100% secure. Despite these measures, the transmission of information over the internet and the storage of information always carry some risk. Where required by law (GDPR Arts. 33–34; UK GDPR; CCPA; LGPD; Australia's Notifiable Data Breaches scheme), we will notify the relevant supervisory authority within 72 hours of becoming aware of a Personal Data breach that is likely to result in a risk to your rights and freedoms, and we will notify affected users without undue delay where the risk is high.


14. California (CCPA / CPRA) notice at collection

This section is provided in addition to Section 10.2 and summarises the disclosures required by Cal. Civ. Code §1798.100 et seq.

CCPA/CPRA categoryExamples on HMUSourcesBusiness / commercial purposeCategories of third parties
IdentifiersEmail, user ID, IPYou; your browserService delivery; billing; securitySubprocessors (§7.1)
Customer records (Cal. Civ. Code §1798.80(e))Email, billing recordYou; payment processorBilling; taxPayment processor; tax authorities
Commercial informationSubscription tier, credits, transaction historyYou; payment processorBillingPayment processor
Internet or network activityPages visited; messages sentYour browser; the ServiceService delivery; analytics with consentHosting and analytics subprocessors
Geolocation (approximate, IP-derived)Country and regionYour browserCompliance; fraud; localisationHosting subprocessor
Sensory dataSelfie or ID for age verificationYou via our age-verification providerAge verificationAge-verification provider
InferencesCompanion recommendationsDerived from your activityPersonalisationNone
Sensitive personal informationSex life; sexual orientation; biometric dataYouService delivery (chat is sexual by nature); age verificationSubprocessors (§7.1)
  • Categories sold or shared: None.
  • Retention: See Section 9.
  • Right to limit use of sensitive PI: Available — Section 10.2.
  • Financial incentives: None offered.

15. Brazil (LGPD) notice

In compliance with LGPD Arts. 9, 18 and 41:

  • Controller: Romantic Lines LP.
  • Brazilian representative / DPO: [BRAZIL DPO/REPRESENTATIVE], reachable at the address above.
  • Purpose of processing: As set out in Section 4.
  • Form and duration of processing: Automated processing as described in this Policy; retention as in Section 9.
  • Sharing: With the subprocessors in Section 7.1.
  • Rights: As set out in Section 10.3.
  • Right to refuse consent: You may refuse the explicit consent requested in Section 6. If you refuse, we cannot lawfully provide the chat feature to you.

You may complain to the ANPD at gov.br/anpd.


16. Australia (APP) notice

In compliance with Australian Privacy Principles 1 and 5:

  • We are committed to managing Personal Information in an open and transparent way. This Policy is freely available at hmu.com/privacy-policy.
  • Collection notice: At the point of collection we tell you what data we collect, why, who we share it with, the consequences of not providing it, and that this Policy describes how to access, correct or complain about our handling of your data.
  • Cross-border disclosure: We disclose Personal Information to the recipients in Section 7.1 located outside Australia.
  • Complaints: Email [email protected]. If you are dissatisfied, you may complain to the OAIC at oaic.gov.au.

17. Changes to this Policy

We may update this Policy from time to time. If we make a material change — for example a change to the categories of data we collect, a new processing purpose, a new subprocessor in a new jurisdiction, or a change that reduces your rights — we will notify you by email at least 30 days before the change takes effect, and we will display a prominent notice in the Service. Continued use of the Service after the effective date constitutes acceptance, except where applicable law requires fresh consent (in which case we will ask for it).

Non-material changes (e.g. typographical corrections, clarifications, additions of beneficial rights) may be made without prior notice; we will update the "Last updated" date at the top.

A version history is maintained at hmu.com/privacy-policy/changelog.


18. Contact

For any question about this Policy, your data, or how to exercise your rights:

  • Email: [email protected]
  • Data Protection Officer: [email protected]
  • Postal: Romantic Lines LP, 5 South Charlotte Street, Edinburgh, EH2 4AN, Scotland
  • EU representative: [EU REPRESENTATIVE]
  • UK representative: [UK REPRESENTATIVE]
  • Brazil representative / DPO: [BRAZIL DPO/REPRESENTATIVE]

Supervisory authorities:

  • UK ICO — https://ico.org.uk — 0303 123 1113
  • Italian Garante — https://www.garanteprivacy.it
  • French CNIL — https://www.cnil.fr
  • German BfDI — https://www.bfdi.bund.de
  • Irish DPC — https://www.dataprotection.ie
  • California Privacy Protection Agency — https://cppa.ca.gov
  • Brazil ANPD — https://www.gov.br/anpd
  • Australia OAIC — https://www.oaic.gov.au

A full list of EEA supervisory authorities is maintained by the European Data Protection Board at https://edpb.europa.eu.


This document is part of the HMU legal pack. See also: Terms of Service, Cookie Policy, Acceptable Use Policy, Age Verification Policy, DMCA Policy.

Your gateway to meaningful AI connections.

Product

  • Explore
  • Chat
  • Feed
  • Premium

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • DMCA

Support

  • Help Center
  • Contact Us
  • Community Guidelines
  • Safety

© 2026 Hot Muses. All rights reserved.

This site is for users 18+ only. By using this site, you agree to our Terms of Service.