Privacy Policy
Last updated: June 2026 · Data Controller: FanChecked (fanchecked.com)

This site is intended exclusively for adults (18+). We collect and process your personal data in compliance with EU Regulation 2016/679 (GDPR) and applicable Italian data protection law.

1. Data Controller

The data controller is FanChecked, reachable at [email protected].

2. Data Collected & Purposes

We collect the following categories of personal data:

DataPurposeLegal Basis
EmailRegistration, authentication, service communicationsPerformance of contract
UsernamePublic identification on the platformPerformance of contract
Date of birthAge verification (18+ access requirement)Legitimate interest (protection of minors)
GenderContent personalisation and aggregate statisticsConsent (Art. 6 GDPR)
Content preferencesUser experience personalisationExplicit consent (Art. 9 GDPR)
Written reviewsPublication on the platformPerformance of contract
IP addressSecurity, abuse and fraud preventionLegitimate interest
Navigation data (clicks)Anonymised aggregate statisticsLegitimate interest
Support messages, attachments & ratingsHandling support requests via our help desk (ticket messages, uploaded images, satisfaction ratings)Performance of contract
Session cookiesMaintaining authenticated sessionsPerformance of contract

Gender is an ordinary personal data point processed under Art. 6 GDPR on the basis of your consent, which is revocable at any time from account settings.

Content preferences are the optional content categories you may choose in your account settings (for example "cosplay" and similar tags) to personalise your experience. They fall under the category of special category data under Art. 9 GDPR, as on an adult content platform they may indirectly reveal information about your interests or sexual orientation. Providing them is entirely optional: by voluntarily entering and saving your preferences, you give your explicit consent (Art. 9 GDPR) to their processing. You can view, change or delete them at any time from your settings; deletion withdraws your consent for the future and does not affect the lawfulness of processing carried out beforehand.

3. Processing Methods & Retention

Data is processed by electronic means and stored on secure servers located within the European Union. We adopt appropriate technical and organisational measures to ensure data security, including encrypted communications (HTTPS/TLS) and access controls.

Data is retained for the minimum period necessary for the stated purposes:

  • Account data: until account deletion
  • Reviews: retained in anonymised form even after account deletion
  • Access logs (IP): retained for a maximum of 12 months for security and abuse-prevention purposes (legitimate interest), then deleted or anonymised
  • Aggregate navigation data: retained in anonymised form without time limit. "Anonymisation" means the irreversible removal of any element that could identify the user; merely pseudonymised data (e.g. linked to an internal ID) is subject to the same retention limits as account data
  • Support messages and attachments: retained for the duration of the support relationship and deleted when no longer necessary, and in any case upon account deletion

4. Third-Party Sharing & International Transfers

Your personal data is not sold or transferred to third parties for commercial purposes. It is shared exclusively with the following technical service providers, appointed as Data Processors under Art. 28 GDPR:

ProviderServiceLocationTransfer Safeguard
Hetzner Online GmbHServer hostingGermany (EU)No extra-EU transfer
Supabase Inc.Database & authenticationUSA (EU servers)Standard Contractual Clauses (SCC) — Art. 46 GDPR
Google LLCOAuth & Analytics (with consent only)USAEU–US Data Privacy Framework & SCC — Art. 46 GDPR
Resend Inc.Transactional email deliveryUSAStandard Contractual Clauses (SCC) — Art. 46 GDPR

US-based providers process data in compliance with the EU–US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) and/or via Standard Contractual Clauses (SCC) adopted by the European Commission under Art. 46 GDPR, ensuring a level of protection equivalent to that within the EU.

Automatic translation of support messages. To provide multilingual support, the text of support messages, ticket subjects and review/feedback comments may be transmitted to an automatic translation service provided by Google, so that our team and users can communicate across languages. Only the text strictly necessary for translation is sent. Please avoid including unnecessary personal data in support messages.

6. Data Security

We adopt appropriate technical and organisational measures to protect your personal data from unauthorised access, alteration, disclosure or destruction. In particular:

  • All communications use HTTPS/TLS encryption
  • Passwords are stored in hashed cryptographic form (managed by Supabase Auth)
  • Data access is limited to strictly necessary personnel (least privilege principle)
  • Session tokens expire automatically (24 hours)
  • Hosting servers are located in ISO 27001-certified data centres (Hetzner, Germany)

In the event of a personal data breach that poses risks to your rights and freedoms, we will notify the supervisory authority within 72 hours under Art. 33 GDPR, and will inform you directly if the risk is high (Art. 34 GDPR).

7. Automated Decisions & Profiling

FanChecked does not carry out automated decision-making that produces legal effects or significantly affects you, as referred to in Art. 22 GDPR.

Content preferences you voluntarily provide are used solely to personalise the content shown during your visit. No profiling for advertising purposes is carried out, nor is any information shared with third-party advertising networks.

8. Your Rights

Under Arts. 15–22 GDPR, you have the right to:

  • Access (Art. 15): obtain confirmation that your data is being processed and receive a free copy
  • Rectification (Art. 16): correct inaccurate or incomplete data
  • Erasure (Art. 17 — right to be forgotten): request deletion of your personal data when it is no longer necessary or you withdraw consent
  • Restriction (Art. 18): request restriction of processing in case of dispute, unlawfulness or objection
  • Portability (Art. 20): receive your data in a structured, machine-readable format transferable to another controller
  • Objection (Art. 21): object to processing based on legitimate interest
  • Withdrawal of consent (Art. 7): withdraw consent at any time without affecting the lawfulness of prior processing

To exercise your rights, write to [email protected]. We will respond within 30 days of receiving your request (extendable by a further 60 days for complex cases, with a reasoned notice).

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante) — Piazza Venezia 11, 00187 Rome — garanteprivacy.it — or with the supervisory authority of the EU Member State where you habitually reside.

9. Data Protection Officer (DPO)

Given the nature and current scale of processing, FanChecked is not required to appoint a Data Protection Officer under Art. 37 GDPR. For any data protection matter, please contact the data controller directly at [email protected].

10. Minors

The service is reserved exclusively for persons who have reached the age of 18. We do not knowingly collect data from minors. If we become aware that a user is underage, we will immediately delete their account and all associated data.

11. Changes to this Privacy Policy

We reserve the right to modify this Privacy Policy at any time. Changes will be published on this page with the updated date. In the case of material changes, registered users will be notified by email with at least 15 days' notice before the changes take effect.