Privacy Policy
Pepperose LTD (“we”, “us”, “our”) respects your privacy. This Privacy Policy explains how we collect, use, share, and protect personal data when you use FlirtMuse at flirtmuse.com (the “Service”), in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, and, where applicable to users in the European Economic Area, the EU General Data Protection Regulation (EU) 2016/679.
1. Who we are
Pepperose LTD, The Maylands Building, Office 42, Maylands Avenue, Hemel Hempstead, England, HP2 7TG (Company No. 06112811), is the data controller for personal data processed through the Service. Contact us at help@flirtmuse.com.
2. Data we collect
- Account data: your email address and any subscription or access identifiers created through our authentication method.
- Usage data: chat messages and prompts you submit, your interactions with AI Companions, custom companion settings, credit balance, and purchase history.
- Technical data: IP address, browser and device information, and cookies (see our Cookie Policy).
- Payment data: transaction references and amounts. We do not store full card details. Card payments are processed on our behalf by a PCI DSS (Payment Card Industry Data Security Standard) compliant payment service provider.
- Moderation and safety data: flags, reports, and review notes generated by our content moderation systems (see our Content Moderation & Monitoring Policy).
- Age-assurance data: where an age or identity verification check is required (see our Content Moderation & Monitoring Policy, Section 1), the check is performed by an independent third-party provider; we receive and store only the outcome of the check (pass/fail and date), not your identity documents.
3. How we use your data and our legal bases
| Purpose | Legal basis (UK GDPR / GDPR Art. 6) |
|---|---|
| Providing and operating the Service, authenticating you, processing purchases | Performance of a contract |
| Preventing fraud, abuse, and underage access; enforcing our Policies; content moderation and safety review | Legitimate interests, and legal obligation where applicable |
| Age or identity verification where required by law | Legal obligation |
| Complying with law enforcement or regulatory requests | Legal obligation |
| Non-essential cookies and similar technologies | Consent |
| Service communications (e.g. security notices, purchase confirmations) | Performance of a contract / legitimate interests |
We do not sell your personal data.
4. AI processing
Your messages may be transmitted to third-party AI infrastructure providers solely to generate responses. These providers are contractually bound to process data only to deliver the Service and are not permitted to use your data to train their own models unless we have specifically agreed otherwise and disclosed this to you. Please do not share sensitive personal data (e.g. government ID numbers, passwords, financial or health details) in chat.
5. Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, applying the following retention periods as a general rule:
| Data type | Retention period |
|---|---|
| Account information | Until account deletion, plus any legally required retention period thereafter |
| Purchase/transaction records | 6 years (UK tax and accounting law) |
| Customer support communications | 3 years from the date of the last communication |
| Moderation logs (flags, reports, review notes) | 2 years, unless a longer period is required for an active investigation or legal proceedings |
| Age-assurance check outcomes | Duration of the account, plus any legally required period |
| Fraud-prevention records | As long as necessary for fraud prevention and any related legal obligations |
These periods may be extended where necessary to establish, exercise, or defend legal claims (including chargeback disputes), or where a longer period is required by applicable law.
6. Sharing
We may share personal data with: hosting and cloud infrastructure providers; payment processors; AI service providers; authentication partners; age-assurance/identity-verification providers (where a check is required); professional advisers; and law enforcement or regulators where legally required. All processors are bound by data processing agreements consistent with Art. 28 UK GDPR/GDPR.
7. International transfers
Where personal data is transferred outside the United Kingdom or the European Economic Area, we rely on adequacy regulations or decisions, or appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, and we take supplementary measures where necessary.
8. Your rights
Subject to conditions under the UK GDPR/GDPR, you have the right to: access your data; rectify inaccurate data; erase your data; restrict or object to processing; data portability; and withdraw consent at any time (without affecting the lawfulness of processing before withdrawal). To exercise these rights, contact help@flirtmuse.com. We respond within one month. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk) or, if you are in the EEA, with the supervisory authority in your country of residence.
9. Security
We use technical and organisational measures, including encryption in transit, access controls, and secure session handling, to protect your data. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
10. Children
FlirtMuse is strictly for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has used the Service or that we hold data about a minor, contact us immediately at help@flirtmuse.com so we can investigate and delete the relevant data.
11. Automated decision-making
AI-generated chat responses are produced by automated systems but do not involve automated decision-making that produces legal or similarly significant effects on you within the meaning of Art. 22 UK GDPR/GDPR. Our moderation systems may automatically flag or restrict content; significant enforcement actions (such as account termination) are subject to human review on request — see our Complaints Policy.
12. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date.
13. Contact and data protection
Data controller: Pepperose LTD. Contact: help@flirtmuse.com.
Company information
Pepperose LTD
The Maylands Building, Office 42
Maylands Avenue
Hemel Hempstead, England, HP2 7TG
Registered in England and Wales — Company No. 06112811
Website: https://pepperoseltd.com/
Email: help@flirtmuse.com
Phone: +44 1494 326040
Last updated August 12, 2026.