Logo
ES EN DE FR IT PT
Messages
No conversations yet.
—

Privacy policy

This policy describes how Makiporn processes personal data under Regulation (EU) 2016/679 (GDPR) and applicable Spanish regulations. Owner legal information: Legal notice.

Language: these texts may be provided in multiple languages for convenience. In case of discrepancies, the Spanish version prevails.

1. Data controller

  • Controller: Sergio Megias Cabañas
  • Tax ID: 46799207A
  • Address: Calle Comtes de Santa Coloma 17, Bloque 2, Escalera 3, 2B, 43830 Torredembarra (Tarragona), España
  • Privacy contact: privacy@makiporn.com

2. Privacy principles (summary)

  • Data minimization: we avoid mandatory registration and collect only the technical data necessary.
  • Ephemerality: rooms and content are automatically deleted when they expire.
  • Pseudonymization: when we keep moderation traces, we store IPs as an HMAC (keyed hash) to reduce direct identifiability.
  • Security: we apply anti-abuse measures, access control, and protection against direct file access.

3. Personal data we process

  • Technical and security data: IP address, date/time, session identifiers, user-agent and security events (e.g., anti-abuse limits).
  • Anonymous identifier: a persistent UID cookie (maki_uid) to enable private messages (DM) and strengthen anti-abuse measures without creating accounts.
  • User-provided data: images, comments, aliases and room names. Important: if users include personal data in content, it will also be processed.
  • Reports: if you contact us (e.g., to report content), we process the message and your reply email address.
  • 18+ check: date of birth is used only to verify adulthood at access time; it is not stored. A technical access cookie is stored (see cookies).

4. Data we do not intend to process

We do not ask for real name, address, phone number, or documents. There are no mandatory accounts. However, if a user publishes personal data in content, such processing may occur due to the nature of the service. For this reason, please do not upload third-party personal data or non-consensual content (see Terms).

5. Purposes and legal bases

  • Service provision (display rooms, upload content, chat/comments, access tokens): GDPR art. 6(1)(b) (performance of the requested service).
  • Security and abuse prevention (rate limiting, access control, technical auditing, scraping mitigation): GDPR art. 6(1)(f) (legitimate interest).
  • Handling illegal / non-consensual content (notice handling, removal, cooperation with authorities): GDPR art. 6(1)(c) (legal obligation) and/or 6(1)(f) (legitimate interest in a safe environment).
  • Request handling (contact and support): GDPR art. 6(1)(b) or 6(1)(f) depending on the case.
  • Defense against claims (limited retention of technical evidence when necessary): GDPR art. 6(1)(f).

6. Retention

The service is designed to be ephemeral: rooms and their content are automatically deleted when they expire. We also follow a limited-retention approach for technical and moderation data.

  • Rooms, posts and comments: until room expiry or removal due to moderation / legitimate request.
  • Application security / anti-abuse records: generally up to 30 days from creation (e.g., technical events and anti-abuse limits), unless temporarily needed to investigate incidents or prevent recurrence.
  • Pseudonymized moderation logs (reports and quarantines): generally up to 6 months from the event for traceability, audit and defense against claims.
  • Support / report communications: for the duration of handling and, generally, up to 12 months, unless a legal obligation or ongoing claim applies.

If there is a legal obligation or an ongoing claim / request from authorities, certain data may be retained for the strictly necessary time to comply and to assert/defend rights.

7. Recipients and processors

We do not share data with third parties unless required by law. The service is hosted by IONOS (Alemania (UE)), who may process data as a processor to provide hosting and support.

8. International transfers

In principle, hosting is located in the EU, so no international transfers outside the EEA are expected. If a support provider implies access from outside the EEA, appropriate safeguards under the GDPR will be applied.

9. Automated decisions

We do not make automated decisions with significant legal effects. We may apply automated security measures (e.g., rate limiting, temporary blocks) to prevent abuse.

10. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction and portability by emailing privacy@makiporn.com. To protect information, we may ask for minimal data to verify your identity. We will generally respond within the legal time limits.

If you believe your rights have not been properly addressed, you may lodge a complaint with the Spanish Data Protection Authority (AEPD).

11. Minors

This site is not intended for minors. Access and use by persons under 18 is prohibited.

12. Security measures (summary)

  • Access control (authorized session, tokens, master role and creator-by-IP).
  • Protection against direct file access and hotlinking.
  • CSRF protection for state-changing actions and input validation in endpoints.
  • Rate limiting on sensitive actions (upload, comments, etc.).
  • Image re-encoding on upload to remove metadata/EXIF.

No system is infallible. If you find a vulnerability, report it via Contact.

13. Changes to this policy

We may update this policy to reflect technical or legal changes. We will publish the date of the last update.

Last updated: 2026-02-12

Legal notice • Terms • Privacy • Cookies • Contact
Adults only (18+) © 2026 Makiporn