This notice explains how personal data is processed when you browse MuffSniffer, follow an advertising link, submit or appeal a report, make a privacy request, appear in catalogue metadata, or communicate with us.
Controller
Frogduction is the controller for the processing described here. Operator and contact details appear on the Contact page. Privacy and performer-data requests may be sent to [email protected].
Data we process, purposes, and legal bases
Browsing, search, access, and security
We process the page or endpoint requested, request time, response status and latency, a request ID, limited network and device information needed by our hosting, edge, rate-limiting, and anti-abuse services, country or region signals supplied by our trusted edge, and the necessary session data described in our Cookie Notice. A search query is processed to return results, spelling suggestions, and approved catalogue autocomplete suggestions. We do not create individual search histories. For aggregate search-quality reporting, a normalized term is retained only after at least five qualifying searches across at least two dates. Reports use count ranges and suppress country cells below five; no account, IP address, cookie, session, device fingerprint, or exact event time is attached to a reported term. The report also includes exact total searches and a bot/test-filtered browser estimate. To avoid a separate analytics cookie, the existing age-confirmation token is transformed into a day-specific keyed digest used only for deduplication in Redis; the raw token is not stored there, the digest expires within 48 hours, and it cannot be joined to a reported search term. Only hourly/daily search and visitor totals are retained in PostgreSQL. Thresholded term aggregates, anonymous traffic totals, and daily report snapshots are retained for five years and may be sent once daily to the controller's configured reporting address.
When a rotating preview activates—on hover or keyboard focus, or for the centered card on a coarse-pointer device—your browser requests its image frames directly from the approved partner image host shown by that listing. That host receives the ordinary information needed to answer the request, including your IP address, request time, requested frame URL, and browser/network headers, and may receive cookies that it previously set for its own domain. We send no referring-page header and MuffSniffer cookies are not sent to the partner domain. The partner may process the request under its own privacy notice.
We use these data to provide the requested service, apply age and territorial rules, prevent abuse, secure forms and cases, diagnose faults, and maintain service reliability. The legal basis is our legitimate interests in operating and protecting the service and its users (GDPR Article 6(1)(f)) and, where a specific control is legally required, compliance with a legal obligation (Article 6(1)(c)).
Catalogue and performer information
Approved partners provide professional or stage names, titles, tags, categories, studio information, publication dates, descriptions, authorised preview images, source URLs, territory rights, and source-review evidence. Some of this information concerns identifiable performers and may reveal information about a person's sex life or sexual orientation. We use it to operate the catalogue, identify and describe material accurately, prevent duplicates and prohibited republication, honour performer and rights-holder requests, and demonstrate source approval.
Our Article 6 basis is the legitimate interests of the operator, partners, performers, and adult users in a lawful, accurate, rights-reviewed catalogue (Article 6(1)(f)). Where the data are special-category data, we process them only where the documentation and circumstances establish an Article 9 condition—normally the performer's explicit consent for the relevant publication (Article 9(2)(a)), data manifestly made public by the performer (Article 9(2)(e)), or processing necessary for legal claims (Article 9(2)(f)). We do not treat a partner feed alone as proof that an Article 9 condition exists.
Reports, appeals, and communications
We process the selected reason, explanation, listing and destination, submission and decision history, case reference, appeal, and any name and email address you provide. We create keyed pseudonymous fingerprints from a random session value and the submitting IP address to detect repeat or abusive reports; raw IP addresses are not stored in report records or structured application logs. The private case access code is stored only as a one-way hash.
We use these data to receive, investigate, decide, communicate about, and demonstrate the handling of notices and appeals; protect performers, users, right holders, and the service; comply with legal duties; and establish, exercise, or defend legal claims. The bases are Articles 6(1)(c) and 6(1)(f), and Article 9(2)(f) where a report necessarily contains special-category data.
Affiliate measurement and accounting
When you follow an advertising link, we create a random click reference and record the listing, partner, time, whether the event was a synthetic test, and any later partner-validated conversion or reconciliation event. Non-synthetic clicks also increment a decaying per-listing popularity total; that aggregate contains no visitor identifier. We do not put your raw IP address or raw search query in the click record. If privacy-preserving search measurement is enabled, we record the result count, retrieval mode, ranking version, latency, non-sensitive filters, result identifiers and positions, and a random token that can connect one recent result exposure to a matching click. A separate single-use token may count whether a qualifying reported term led to an outbound click and expires within one hour. These events contain no account, raw query, IP address, device fingerprint, session ID, or stable visitor ID.
We use these data to account for commercial referrals, detect invalid attribution, reconcile partner reports, and measure aggregate search quality. The basis is our legitimate interests in operating and evaluating the service and preventing affiliate fraud (Article 6(1)(f)). We do not use this information for behavioural advertising or to build individual sexual-interest profiles.
Privacy requests and compliance records
Our privacy-request register contains the request type, status, handling record, aggregate result, operator action, and a keyed fingerprint of the supplied email rather than the raw address. A verified access export may contain report, appeal, and delivery data associated with that email. Applied erasure replaces matching register fingerprints with random unlinkable values while retaining the non-identifying handling record. We also maintain source reviews, moderation events, security records, aggregate transparency reports, and suppression fingerprints. We use these data to fulfil and demonstrate legal duties, prevent prohibited material from returning, and handle legal claims under Articles 6(1)(c) and 6(1)(f).
Where the data come from
We obtain data directly from you when you browse, report, appeal, request privacy assistance, or contact us; from approved partners, affiliate networks, and their authorised feeds; from the destination and preview safety checks we perform; from service providers involved in security and delivery; and from operators who review sources and cases. Catalogue information about a performer is normally supplied by the approved source rather than collected from the performer directly.
Partner feeds do not normally include reliable private contact details for each performer. Identifying and contacting every person in a large, changing catalogue would require collecting additional personal data and involve disproportionate effort. We therefore provide this public notice under GDPR Article 14(5)(b), together with direct privacy and takedown routes, temporary quarantine for high-risk reports, and permanent suppression controls. We will reassess individual notice if reliable contact details become available or direct notice becomes practical.
Who receives data
Data are available only as needed to authorised operators and contracted providers of hosting, database, cache and rate limiting, email, anti-abuse, alerting, error monitoring, and security services. Catalogue metadata and previews are public. An approved partner image host receives the network request described above only when you activate that listing's rotating preview. Random affiliate references and conversion details are exchanged with the relevant partner or affiliate network. A report may be shared with the relevant source, network, right holder, professional adviser, insurer, court, or authority when necessary and legally permitted. We do not sell visitor or reporter personal data.
International transfers
Some providers may process data outside Denmark or the EEA. Before production use, providers must be documented and reviewed. Where the destination is not covered by an EU adequacy decision, we use an applicable safeguard such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required. You may ask the privacy contact for information about the safeguard relevant to your data and how to obtain a copy.
Retention
- privacy-preserving search measurement events, if enabled: 30 days;
- outbound click records: 90 days;
- validated conversions, postback events, and reconciliation records in the application: 365 days;
- reporter duplicate-detection fingerprints: 30 days after submission;
- completed report bodies and associated reporter details: 365 days after completion;
- completed or rejected privacy-request records: 1095 days;
- sent or failed notification records: 90 days; and
- completed operational and synchronisation records: 90 and 90 days respectively.
Before detailed conversion records expire, revenue is added to monthly partner, event, and currency totals that contain no click token, external transaction identifier, visitor/session identifier, or payload hash. These visitor-anonymous business statistics may be retained while useful. Separate payout statements and transaction evidence that form part of the operator's accounting records are retained in the accounting system for the period required by accounting law.
An open report is kept until it is decided. Audit records, source-rights evidence, published aggregate reports, and non-reversible suppression fingerprints may be retained longer where necessary to prevent republication, demonstrate a decision, comply with law, or address a legal claim. Routine deletion and anonymisation jobs enforce configured periods. Residual copies in protected backups are isolated from ordinary use and expire under the applicable backup schedule.
Your choices and rights
Name and email are optional for ordinary safety or quality reports, but are required for formal copyright, performer or privacy, and other-illegality notices so that we can assess and communicate about the claim. If you omit an optional email, you will not receive email updates and must retain the case credentials to view the decision. A necessary persistent cookie remembers age entry, while a separate session cookie provides form security and private case access. You can remove either by clearing site data.
Subject to applicable law, you may ask for access, correction, deletion, restriction, or portability of your data, or object to processing based on legitimate interests. You may also withdraw consent where consent is the basis; withdrawal does not affect earlier lawful processing. You have the right not to be subject to a solely automated decision that produces legal or similarly significant effects. MuffSniffer's automated high-risk quarantine is temporary and a human makes the final decision.
Send a request to [email protected]. State the right you wish to exercise and provide enough information to locate the relevant data. We may request proportionate verification and normally respond within one month, subject to any lawful extension. Some pseudonymous or aggregate records cannot be linked to you from the information supplied.
You may complain to the data-protection authority where you live, work, or believe an infringement occurred. If the operator is established in Denmark, the lead authority is Datatilsynet.
Adults only and changes
The service is for adults and is not directed to anyone under 18. If you believe a minor has provided personal data to us, contact the privacy address. We will update this notice before materially changing the described purposes, data, or technology and will change the date at the top.