VELVET ROOMLEGAL • DRAFT
§

Privacy Policy

Version 0.3 | 21 August 2026
Development legal draft. This document is installed in the development app for review and architecture alignment. It is not publication-ready, is not wired as the final acceptance document, and remains subject to unresolved publication blockers and qualified counsel review.

1. Scope and Operator

This Privacy Policy explains how Velvet Room processes personal information when you use the Velvet Room Service, including accounts, persona profiles, Profile Preview, Channels, Feed, posts/media, communications, Radar/proximity features, sessions, subscriptions, notifications, Vault, and other features that reference this Policy.

The data controller/operator for the Service is GGIRL Technologies LLC, a New Hampshire single-member limited liability company organized in New Hampshire, United States, with privacy contact [PRIVACY CONTACT] and legal notice address [LEGAL NOTICE ADDRESS].

2. 18+ Service

Velvet Room is intended only for adults age 18 and older. We do not permit people under 18 to create or maintain accounts. If we reasonably determine that an account is controlled by a person under 18, we may restrict or close the account and take appropriate steps regarding associated information, subject to applicable law and our retention obligations.

[FINAL AGE-ASSURANCE AND UNDERAGE-REPORTING WORKFLOW MUST BE IMPLEMENTED AND DOCUMENTED BEFORE PUBLICATION.]

3. Information We Process

The exact information depends on which features you use. Categories may include:

4. How We Collect Information

5. Why We Process Information

6. Persona Privacy and Contextual Separation

One Velvet Room account may maintain separate Social, Friends, and Work persona profiles. The Service is designed to reduce unintended cross-context disclosure and to avoid treating the root account as a public sibling-persona directory.

Persona separation is a privacy design discipline, not an absolute anonymity guarantee. Personas may become associated through information you publish, shared identifiers, outside information, interactions, legal process, security incidents, or other circumstances. We do not promise that correlation is impossible.

When you explicitly share a persona, profile, Channel, link, or access grant, the recipient may learn the information made available by that specific share. A share of one persona is not intended to authorize discovery of sibling personas.

7. Location, Radar, and Proximity

Location features receive conspicuous treatment because they can involve sensitive information. When a location-enabled feature is used, the Service may process precise or approximate location, presence, proximity, distance, timestamps, and related state needed to provide the feature.

Location processing should occur only after the relevant permission/choice is enabled. You can stop future collection by disabling the relevant feature and/or device permission, although previously created records may remain for the period required by the retention policy, security needs, disputes, or law.

Location may be inaccurate, delayed, stale, or affected by device/network conditions. Velvet Room location features are not emergency-location services.

8. Communications and User Content

We process User Content and communication information as needed to store, transmit, display, deliver, secure, moderate, and enforce the audience/access choices associated with the feature.

Private, gated, or restricted content is subject to authorization controls, but authorized safety/moderation personnel may review restricted content when necessary to investigate abuse, enforce policies, comply with law, or protect users. Access should be role-controlled and auditable.

Velvet Room prohibits users from taking screenshots and treats screen recording or comparable capture methods used to evade that rule as equivalent circumvention. Where the Service implements capture-protection or screenshot-discipline features, we may process security or integrity signals associated with capture attempts or enforcement. We do not promise that every device, browser, operating system, external camera, or capture method can be detected or prevented.

9. Payments, Subscriptions, GGIRL, WinQ, and Transactions

Where paid or value-bearing features are enabled, we and our transaction providers may process information needed to authorize, record, settle, refund, dispute, or audit the transaction. Velvet Room should avoid storing full payment-card details when a payment processor can handle them directly.

GGIRL/WinQ or related ledger information may be retained longer than ordinary social content where necessary for transaction integrity, accounting, fraud prevention, dispute handling, tax/legal obligations, or security. Exact periods require the final retention matrix.

10. Notifications, Devices, and Security

We may process notification preferences, push subscription/token information, device/browser details, authentication/session data, IP/network information, and security/audit records to deliver alerts, maintain sessions, prevent abuse, and protect accounts. Security/integrity records may also include screenshot or capture-discipline signals where that functionality is implemented.

You can change available notification preferences in Settings. Device-level notification permissions are also controlled by your operating system/browser.

11. Private Vault

Vault data may include references to items you saved, archived/draft content, scheduled/session records, and records showing legitimate access or unlock status. The Vault is private to the account owner subject to authentication and authorization controls, but it is not a promise of permanent storage.

12. When We Share Information

We may disclose personal information in the following categories of circumstances, subject to applicable law:

13. Advertising, Promotion, and Commercial Data - BLOCKED

Velvet Room has unresolved product decisions around paid placement/promotion and must not publish a broad advertising-data statement until the live distribution authority and data flows are verified. The final Policy must state whether and how information is used for advertising, sponsorship, paid placement, or measurement before those features are publicly enabled.

14. Retention - FINAL MATRIX REQUIRED

We intend to retain information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, maintaining security, preserving transaction integrity, resolving disputes, enforcing agreements, and meeting legal obligations.

Before publication, Velvet Room must adopt and technically support a category-by-category retention matrix for account data, profiles/content, messages/communications, location/presence, security/audit logs, moderation evidence, sessions, subscription/payment/value records, Vault records, backups, and legal holds. [EXACT PERIODS ARE CURRENTLY BLOCKED.]

15. Account Deletion, Export, and Other Data Rights - WORKFLOW REQUIRED

Depending on your location, applicable law may give you rights to access, correct, delete, obtain a copy of, restrict, or object to certain processing of personal information. The final Policy will describe the rights available in each launch jurisdiction and the verified request process.

A real account-deletion/export workflow and operational timelines must exist before Velvet Room promises specific completion periods. Deleting an account may not immediately remove information that must be retained for security, transaction integrity, disputes, legal obligations, backups, or content another user has independently retained or lawfully reshared.

16. Security

We use administrative, technical, and organizational measures designed to protect information appropriate to the nature of the Service. No system is completely secure, and we do not promise that unauthorized access, loss, or misuse can never occur.

Security-sensitive implementation details are not disclosed publicly where doing so could weaken protections.

17. International Use and Transfers - JURISDICTIONS BLOCKED

The launch countries/regions and operator jurisdiction have not been locked in this draft. Before publication, Velvet Room must identify where information is processed and add any transfer mechanisms, regional notices, or representative/contact information required for the launch jurisdictions.

18. Legal, Safety, and Emergency Requests

We may preserve or disclose information when we reasonably believe it is necessary to comply with valid legal process or applicable law, protect rights and safety, investigate fraud/abuse, or respond to a genuine emergency request, subject to legal and operational safeguards.

A separate Law Enforcement / Emergency Request Guideline should define request intake, verification, preservation, emergency escalation, and documentation procedures before launch.

19. Third-Party Links and Services

Velvet Room users may link to external profiles, websites, or services. We may also use third-party service providers. Third-party services have their own terms and privacy practices. Review those policies before providing information to them.

20. Changes to This Policy and Acceptance Evidence

We may update this Policy as the Service changes. Material changes will receive appropriate notice and, where required, renewed consent or acceptance. Velvet Room should store policy version/hash and acceptance timestamps so the legal package accepted by an account can be audited.

21. Contact

Privacy requests: [PRIVACY CONTACT]
Legal notices: [LEGAL NOTICE ADDRESS]
Support: [SUPPORT CONTACT]
Operator: GGIRL Technologies LLC