Discretion is the policy

Privacy Policy

Last updated: October 9, 2026

The short version

  • This site keeps no client information past 48 hours after your appointment's date and time. That covers your name, email, phone, notes, IP address, browser details, your signed waiver and the time you signed it, any photo, and the emails and calendar entry about it. All of it. No exceptions.
  • Messages sent through the Contact page and chats with Kairo follow the same rule: deleted 48 hours after you send them.
  • No analytics. No tracking. No ads. No marketing list. Nothing is kept "just in case."
  • Two kinds of copies are outside the website's automatic deletion: the copies on my own phone and mailbox, and the copies held by the companies that run this site. Both are described below.

For your privacy and ours

I recommend using an alias instead of your legal name, a private email provider (such as Proton Mail), a second-number service (such as Burner or Sudo), and a VPN when you visit this site or book a session. None of it is required, but it reduces what either of us is exposed to if something outside our control goes wrong.

What I collect, and when it's gone

  • Booking details — the name you enter (an alias is fine), email, phone, location (in-studio or out-of-studio), requested date and time, and any notes you choose to share. Deleted 48 hours after the date and time of the appointment you requested — including if it's cancelled or never happens.
  • Your signed waiver — the alias you typed, the time you signed (recorded by the server, not your device), and your IP address and browser details at that moment. Deleted with the booking.
  • Fraud-prevention data — the IP address and browser details logged with a booking request. Deleted with the booking. Short-lived spam-protection counters tied to an IP address are deleted within 24 hours.
  • Location-verification photo — only if I ask for one before an out-of-studio session. Deleted with the booking.
  • My calendar entry — your name, contact details and notes as you entered them, and the appointment time. The website deletes it with the booking.
  • The log of emails sent to you — deleted within 48 hours of being created, and with the booking.
  • Contact page messages — your name, email and message. Deleted 48 hours after I receive them.
  • Passcode requests — the email you give to receive the site passcode. Deleted within 48 hours.
  • Conversations with Kairo — deleted 48 hours after you send them.
  • Age and password checks — a few entries in your own browser that remember you passed the door (see the Cookie Policy). They live on your device, not in my database, and expire within 24 hours.

That's the complete list. There's no mailing list and no record of who visited.

What's on my phone

Booking requests also reach me as emails and calendar entries, which sync to my phone, and a copy of each booking email goes to a personal Gmail account of mine. Those copies sit in my own mailbox, calendar and devices, outside the website. I delete them myself, separately from the website's automatic deletion — the website can't do it for me, so I'm telling you plainly.

What I do with it

Only what's needed to confirm and deliver your session, check that you're a real adult, prevent fraudulent bookings, and stay in touch about your booking. Nothing is sold, traded, profiled, or shared for advertising.

Email

The only emails this site sends are about your booking — the request confirmation, approval, reminders, arrival details, a thank-you after your session — and, if you ask for it, the site passcode. There is no newsletter, no marketing, and no mailing list.

The companies that run the plumbing — and how long their copies last

I'm one person, and these platforms run the site, send the messages, and deliver the service. Each has its own privacy policy and terms. I can promise how I use your data; I can't promise how they independently handle what passes through their systems. Here is each one, and the copies that outlive my 48-hour deletion:

  • Cloudflare — hosts and serves the website (Cloudflare Workers), and runs Turnstile, the quiet bot-check on the booking form. Cloudflare sees the IP address and request details of every visit, and keeps its own request logs and analytics for at least 31 days (its documented minimum for request analytics; it publishes no fixed maximum). I use none of Cloudflare's analytics features and keep no logs of my own, but I can't delete Cloudflare's. Privacy · Terms.
  • Supabase — the database and file storage behind the site. My project is on the free plan, which keeps no backups — once I delete a row, no copy of it remains. Supabase keeps request logs for 1 day. If I ever move to a plan with backups (the next tier keeps daily backups for 7 days), this page will change first. Privacy · Terms.
  • Proton (Proton Mail / SMTP) — sends the booking emails and holds my mailbox. Booking emails reach me with the details you entered, and anything you write to me directly sits in my Proton mailbox until I delete it, as described above. Your own copies of emails I send you live in your inbox, which I can't reach. Privacy · Terms.
  • Anthropic (Claude) — powers Kairo, the on-site guide. What you type to Kairo is sent to Anthropic's API to generate a reply. Anthropic deletes API inputs and outputs from its systems within 30 days; anything its safety systems flag as a policy violation can be kept for up to 2 years. I can't delete those copies, so keep it anonymous — don't share identifying details with Kairo. Privacy · Terms.
  • Google Calendar — each booking request creates an entry in my private Google Calendar with the details you entered. The website deletes it 48 hours after the appointment; Google then keeps deleted events in its Trash for 30 days before they're gone for good. A personal Gmail account of mine also receives a copy of each booking email. Separately, the ambient music is off until you turn it on: nothing is requested from YouTube (also Google) unless you tap the sound button, and then your browser loads a YouTube player. Privacy · Terms.

Fonts are self-hosted, on the site and in emails, so no font request is ever sent to a third party. This site runs no analytics or visitor-tracking script of any kind — see the Cookie Policy for exactly what's set in your browser. Other than the companies above, no one sees your information.

How long I keep it

The website deletes everything about a booking 48 hours after the appointment's date and time, by an automatic job that runs every few minutes. Messages go 48 hours after they're sent. The only copies that outlast that are the ones on my own phone and mailbox, which I delete myself, and the ones held by the companies above, on the schedules I've listed.

Your rights

Under PIPEDA (Canada) and similar laws you may ask to access, correct, or delete your information. Because I delete everything on the schedule above, there is usually nothing left to access after the window closes — but if you want something gone sooner, write to me through the Contact page and I'll delete it and reply within 30 days. For data held by the companies above on their own behalf, use their policies, linked above.

Security

Data travels over HTTPS and is stored behind access rules. No system is perfectly secure, but I treat your information the way I treat your visit — quietly and carefully.

Children

This site is for adults only. No information is knowingly collected from anyone under 19.

Changes

If this policy changes, the date above will change with it. Material changes will be flagged on the site.