DRAFT FOR A LAWYER TO REVIEW. Not final legal advice — Swiss FADP and GDPR applicability have not been confirmed by counsel. Do not publish until reviewed (PLAN.md §11, item L9).
Privacy Policy
Controller: LAGOON Media, [registered address — TBD], Switzerland. We're subject to the Swiss Federal Act on Data Protection (FADP, revised 2023) as a Swiss company, and to the EU General Data Protection Regulation (GDPR) because we offer the service to, and monitor the behavior of, people in the EU (chat, prompts, reactions) — both regimes apply, and where they differ, this policy follows whichever gives you the stronger protection. Which specific FADP/GDPR provisions govern which data category has not been confirmed by counsel — treat every legal-basis statement below as a working draft, not a final position.
What we collect
- Account data: email, password hash, handle, tier.
- Age-verification data: processed by our verification provider (Veriff, at launch) for the mature lane — we receive a pass/fail result and a retention record, not the underlying ID document itself, unless our provider's integration requires otherwise (UNVERIFIED — confirm Veriff's exact data-return shape before launch). See Age Verification Policy.
- Prompts and chat messages: what you type, when, and the broadcast window it produced or attempted to produce, including denied prompts and the category they were denied under.
- Moderation records: an append-only log of every moderation decision our system makes, regardless of account — verdict, category, which model made the call, and a timestamp. This log exists because a moderation system a regulator or a payment processor can't audit isn't one they'll trust; see our Trust & Safety page.
- Technical data: IP address (used for the moderation and abuse-prevention systems, and for jurisdiction-based age-gate routing — see our Age Verification Policy), device/browser info, connection logs.
- Payment data: none, at launch — LAGOON takes no money at launch (see Terms of Service §8). This section will be updated with specifics once a payment processor is live.
Why we process it (legal basis, GDPR framing)
- Account and prompt data: performance of the contract you enter into by using the service (Art. 6(1)(b) GDPR).
- Moderation and safety records: our legitimate interest in operating a legal platform and our legal obligations under the statutes named in our Acceptable Use Policy (Art. 6(1)(c) and (f) GDPR). Balancing-test documentation for the legitimate-interest basis has not been drafted — a lawyer should confirm this is sufficient, particularly for EU users.
- Age-verification data: legal obligation, where a jurisdiction requires it (Art. 6(1)(c) GDPR; UK OSA s.81, Texas HB 1181, EU DSA Art. 28 — see Age Verification Policy).
Who we share it with
Processing happens on infrastructure hosted in the EU where practical (generation and moderation GPUs, VPS) and via named vendors for specific functions: Veriff (age verification), OpenAI (a free, secondary moderation opinion for non-CSAM content categories only — never for CSAM or non-consensual-imagery content, which is checked exclusively on our own hardware; see Trust & Safety), and Cloudflare (content delivery). A full vendor/sub-processor list with each vendor's own data-processing terms has not yet been compiled — this is a launch-blocking gap for a GDPR-compliant policy, not a stylistic one. We do not sell personal data.
International transfers
Switzerland has an EU adequacy decision, so data moving between our Swiss entity and EU infrastructure doesn't require Standard Contractual Clauses on that leg. Where a vendor processes data outside Switzerland/EU (e.g., a US-based service), the applicable transfer mechanism (SCCs, or another safeguard) needs to be confirmed per vendor. Not yet audited — launch-blocking gap, same as the sub-processor list above.
Retention
Account data: for the life of the account plus a reasonable period after closure for legal and safety purposes. Moderation logs: see Record-Keeping Policy for the specific reasoning, including the open question of whether 18 U.S.C. §2257's federal record- keeping regime applies to purely synthetic (no real performer) content. Age-verification pass/fail records: retained per the standard each jurisdiction's law requires (UK OSA's written-record duty is the clearest example — see Age Verification Policy); underlying ID documents, if our provider ever returns them to us, are not retained beyond what verification requires.
Your rights
Access, correction, deletion, and data portability, under FADP and/or GDPR depending on where you're located.
Two of these you can exercise yourself, right now, without asking us or waiting for anyone. On your profile page:
- Download my data gives you a file containing everything this service holds that is keyed to your account — your handle and address, every prompt you submitted (both as you typed it and as it was sent to the model), your reactions, your credit ledger and your tax records. The file also names, in plain words, the things it does not contain and why.
- Delete my account ends the account immediately. It signs out every device, destroys any outstanding password-reset link, and takes your name off everything you put on air — your handle is overwritten, so your prompts and your place on the leaderboard stop being attributable to you. Any credits still on the account end with it, and the page tells you how many before you confirm.
Three things deliberately survive a deletion, and we would rather say so than let you find out later: the clips and prompts themselves stay in the channel's history without your name on them; moderation decisions about content you submitted stay in our append-only compliance log (see Record-Keeping); and tax records for anything you bought stay, because retaining them is a legal obligation we do not have the option to waive (GDPR Art. 17(3)(b)). Age-verification pass/fail records stay for the same reason.
For correction, or for anything the two buttons above don't cover, email [email protected]. We'll respond within the timeframe the applicable law requires. Exact statutory response-time figures for FADP vs. GDPR requests have not been independently confirmed for this document.
Cookies
Session and functional cookies for login and the chat connection. No third-party advertising trackers at launch. This section will expand if that changes.
Children
LAGOON is not for anyone under 18. We don't knowingly collect data from minors; see our Age Verification Policy for how age is checked.
Contact
LAGOON Media, [registered address — TBD], Switzerland. [email protected].
What's still open, honestly
This document has three gaps flagged inline above that block publication as a real, GDPR/FADP-defensible policy: the full sub-processor list, the international-transfer mechanism per non-EU vendor, and confirmation of exact statutory response-time figures. None of these are stylistic — a lawyer needs to close them before this page goes live, not after.