Privacy Policy

Last Updated: 12/16/2025

GDPR Compliant (Articles 13 & 14)

Quick Summary

Most users don't need to worry about their personal data!

  • Case submitters: 100% anonymous, no personal data collected
  • Location identifiers: 100% anonymous, no personal data collected
  • Moderators/Admins: Email address only (for platform access)
  • Contact form users: Name and email (to respond to you)

Read our easy-to-understand data processing guide

1. Data Controller Information

Controller: StopCreepshots

Contact Email: contact@stopcreepshots.com

We are the data controller responsible for your personal data. This means we decide how and why your data is processed.

2. Personal Data We Collect

Anonymous Users (No Personal Data)

If you submit cases or identify locations, we do NOT collect any personal data about you. No email, no name, no IP address, no tracking cookies.

What we collect: Case images, descriptions, location guesses, and additional information you provide about cases—but nothing that identifies you as a person.

Moderators & Administrators

Personal data collected:

  • Email address (via Supabase Authentication)
  • Account role (moderator or admin)
  • Account status (active/suspended)
  • Action logs (timestamps of approvals, rejections, and administrative actions)

Source: Directly from you when you create an account

Contact Form Users

Personal data collected:

  • Name
  • Email address
  • Message category
  • Subject line
  • Message content

Source: Directly from you when you submit the contact form

Moderator Applicants

Personal data collected:

  • Name
  • Email address
  • Application responses
  • Discord username (optional)

Source: Directly from you when you submit the application form

3. Why We Process Your Data and Legal Basis

Moderators & Administrators

Purpose: Platform operation, case review, and moderation

Legal basis: Legitimate interest (GDPR Article 6(1)(f))

We need trusted moderators and administrators to review submissions, ensure safety, and maintain platform integrity. This is essential for the platform to operate effectively and protect victims.

Contact Form Users

Purpose: Responding to your inquiries and requests

Legal basis: Consent (GDPR Article 6(1)(a))

By submitting the contact form, you voluntarily provide your information and consent to us processing it to respond to your message.

Moderator Applicants

Purpose: Processing your application to become a moderator

Legal basis: Consent (GDPR Article 6(1)(a))

By submitting your application, you voluntarily provide your information and consent to us processing it to evaluate your application.

Case Data & Images (Non-Personal Data)

Purpose: Facilitate location identification and assist law enforcement

Legal basis: Not applicable (no personal data collected from anonymous submitters)

Case submissions and location identifications are completely anonymous. We keep this data to achieve the platform's mission of identifying locations and assisting law enforcement.

4. Who Has Access to Your Data

Public Information

The following information becomes publicly visible after moderator approval:

  • Blurred images (victim identities protected)
  • Case descriptions and details
  • Location information (country, store, coordinates)
  • Timeframe information

Important: No personal data about submitters or location identifiers is ever made public.

Administrators and Store Owners

Administrators only: Platform administrators have access to original (unblurred) images for platform operation and law enforcement coordination.

Store Owners: When a case location is identified, verified store owners may receive secure, time-limited access keys to view original images. This access:

  • Expires after a set time period
  • Only works for their specific store's cases
  • Is cryptographically secured
  • Is logged for audit purposes

Important: Moderators can NEVER access original (unblurred) images. They only work with blurred versions to protect victim privacy.

Law Enforcement

We may disclose case data to law enforcement agencies when required by law, in response to valid legal requests, or when necessary to protect public safety.

5. How Long We Keep Your Data

Data TypeRetention PeriodReason
Case submissions & images7 years after case closureLegal requirement for evidence preservation
Location identifications7 years after case closureLegal requirement for evidence preservation
Moderator/Admin accountsWhile account is activePlatform operation
Contact form messages2 yearsCommunication records
Moderator applications2 yearsApplication records
Admin action logs1 yearSecurity auditing
Store access keys1 yearAccess audit trail

6. Your Data Protection Rights

If we have collected personal data from you (moderators, contact form users, or applicants), you have the following rights under GDPR:

Right of Access (Article 15)

You can request a copy of all personal data we hold about you.

Right to Rectification (Article 16)

You can ask us to correct any inaccurate personal data about you.

Right to Erasure / "Right to be Forgotten" (Article 17)

You can request deletion of your personal data in certain circumstances, such as when it's no longer necessary for the purposes for which it was collected.

Right to Restriction of Processing (Article 18)

You can request that we limit how we use your personal data in certain situations.

Right to Data Portability (Article 20)

You can request your personal data in a structured, commonly used, and machine-readable format (e.g., JSON or CSV).

Right to Object (Article 21)

You can object to processing of your personal data based on legitimate interests.

Right to Withdraw Consent (Article 7(3))

Where processing is based on consent, you can withdraw your consent at any time. This does not affect the lawfulness of processing before withdrawal.

Right to Lodge a Complaint (Article 77)

You have the right to lodge a complaint with your local data protection authority (supervisory authority) if you believe we have violated your data protection rights.

EU residents: Find your supervisory authority at https://edpb.europa.eu

How to Exercise Your Rights

To exercise any of these rights, please contact us at:

contact@stopcreepshots.com

We will respond to your request within 30 days as required by GDPR Article 12(3).

7. Automated Decision-Making and Profiling

We do NOT use automated decision-making or profiling. All case reviews and moderation decisions are made by human moderators.

8. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA), specifically the United States, where our database and hosting infrastructure operates.

Safeguards in place:

  • Our service providers comply with relevant data protection frameworks
  • Data processing agreements are in place with all service providers
  • Standard Contractual Clauses (SCCs) are used where applicable

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

Row Level Security (RLS)

Database access controlled at the row level

Cryptographic Access Keys

Secure, time-limited keys for authorized access

Encrypted Transmission

All data transmitted over HTTPS

Audit Logging

All admin actions logged with timestamps

Encrypted Storage

Data encrypted at rest by our database provider

Separate Storage Buckets

Original images private, blurred images public

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Notify moderators and admins via email if changes affect them
  • Display a prominent notice on the platform for significant changes

Your continued use of the platform after changes constitutes acceptance of the updated policy.

11. Legal Basis Summary

CategoryLegal BasisGDPR Article
Moderators/AdminsLegitimate interestArticle 6(1)(f)
Contact form usersConsentArticle 6(1)(a)
Moderator applicantsConsentArticle 6(1)(a)
Case submittersN/A (anonymous, no personal data)N/A
Location identifiersN/A (anonymous, no personal data)N/A

12. Contact Us

If you have any questions about this Privacy Policy or want to exercise your data protection rights, please contact us:

We aim to respond to all privacy-related inquiries within 30 days.

GDPR Compliance Statement

This Privacy Policy has been designed to comply with the General Data Protection Regulation (GDPR) EU 2016/679, specifically Articles 13 and 14 regarding information to be provided to data subjects. We are committed to protecting your privacy and handling your data transparently and lawfully.