Privacy Policy
Last updated: August 11, 2026
Jump to: Data controller · What we collect · Why we're allowed to · Who we share it with · International transfers · Retention & deletion · Security · Your rights · Cookies · Children · Changes · Contact
1. Data controller
Domyrian ("Domyrian," "we," "us") is the data controller responsible for your personal data under the General Data Protection Regulation (GDPR) and equivalent UK law, for anyone who visits or registers on Domyrian (the "Service"). Our registered address is N/A. This policy should be read alongside our Terms of Service.
2. What we collect
Only what the Service actually needs to work:
- Account information — email address, a hashed (never plaintext) password, display name, and account role (Master/Owner, Sub/Slave, or admin).
- Profile information you choose to add — bio, interests, boundaries, timezone, availability notes, avatar.
- Portal & membership data — applications you submit, answers to a portal's custom questions, rules/contract acknowledgment records, and (if you're a Master) private notes and tags you write about your own members.
- Communications — private messages between you and another user, and messages you post in a portal's group chat or blog comments.
- Content you upload — task-submission photos, portal gallery images, and blog posts, stored on our own servers (we don't use a third-party media host).
- Billing metadata — if you're a Master with a subscription, we store a reference ID Stripe gives us for your customer and subscription record. We never receive or store your card number; that lives entirely with Stripe.
- Basic security logs — the email and IP address on a failed login attempt, kept briefly to rate-limit and detect abuse.
- Anything you send us directly — support emails, reports you file against another user or portal.
We don't run any advertising or analytics tracker on the Service — no Google Analytics, no ad pixels, nothing that profiles you across other sites. The only page-view data we keep is an aggregate daily count per portal, for the portal owner's own stats. We don't carry out automated decision-making or profiling that produces legal or similarly significant effects on you.
3. Why we're allowed to process it (legal basis)
- Performance of a contract — running the account and Service you signed up for: your profile, applications, messages, tasks, and billing.
- Legitimate interests — securing the Service (rate-limiting, abuse detection), responding to reports, and improving what we've built — balanced against your right to privacy, and never overriding it.
- Consent — anything optional you switch on yourself, such as being listed in a portal's member directory or being featured as a spotlight member. You can withdraw this at any time from the same setting.
- Legal obligation — where we're required to keep or disclose data by law, such as billing records for tax purposes.
5. International transfers
Where a processor we use (such as Stripe) is based or processes data outside the EU/EEA or UK, we rely on the safeguards that processor offers for such transfers — such as the European Commission's Standard Contractual Clauses, or the processor's own adequacy certification. You can ask us for details of the specific safeguard that applies to a given transfer.
6. Retention & deletion
We keep your data only for as long as we need it for the purposes described above. You can download a full export of your own data any time, instantly, from your account's data page — no need to ask us first. We don't currently have a self-service "delete my account" button in the app, though — to request deletion, contact us at the address below and we'll handle it within one month, as required by the GDPR. We may keep a minimal record after deletion where we're legally required to (e.g. billing records for tax purposes, typically several years), or where content you posted is still meaningfully part of another user's own record (a report you filed, a message another user is entitled to keep).
7. Security
Passwords are hashed, never stored in plain text. Access to the admin area is role-restricted. Like any service, we can't guarantee perfect security — if we ever experience a breach affecting your data, we'll notify the relevant supervisory authority and you, as required by the GDPR.
8. Your rights
Under the GDPR (and equivalent UK law), you have the right to:
- Access the personal data we hold about you — instantly and self-service, from your account's data page, no need to wait on a request.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), subject to the retention exceptions above.
- Restrict or object to processing in certain circumstances.
- Port your data to another service in a structured, machine-readable format — the same data page downloads a single JSON file with everything, ready to hand to another service.
- Withdraw consent at any time, for anything we process on that basis.
- Lodge a complaint with your local data protection supervisory authority if you think we've mishandled your data.
Access and portability are self-service, any time, from your account's data page. For anything else on this list, contact us at the address below and we'll respond within one month. These rights are available to everyone who uses the Service, regardless of where you're located, not only EU/UK residents.
10. Children's privacy
The Service is for adults 18 and older only, and isn't directed at children. We don't knowingly collect data from anyone under 18. If we learn an account belongs to a minor, we'll delete the account and associated data.
11. Changes to this policy
We'll update the date at the top of this page whenever we make changes, and flag material changes more visibly (an announcement banner or email) rather than relying on you to re-check this page.
12. Contact
Questions about this policy, or a request about your data? Reach us at ceo@domyrian.com, or by mail at N/A.