Privacy Policy & Data Protection
Operator: INM Conquests · Effective: July 16, 2026
This Privacy Policy describes how INM Conquests("we," "us," or "our") collects, uses, stores, and shares information when you use the Mistress.to website and related services (the "Service"). By using the Service, you agree to this Policy. If you do not agree, do not use the Service.
1. Who we are
Controller: INM Conquests, 15 North Park Rd., Vaughan, Ontario, Canada. Contact: [email protected].
2. Information we collect
2.1 Account and profile data
When you register or update your profile, we may collect identifiers such as email address, display name, authentication tokens, and preferences you choose to save (for example, nickname, relationship context, location or timezone fields, kink or content preferences, and character configuration choices). If you opt in to promotional emails, we record that choice and related marketing preferences.
2.2 Google user data
If you choose to sign in using your Google Account, we access and collect certain Google user data through Google API Services, including:
- Data accessed: Your primary Google email address, your name, and your profile picture URL.
- Purpose: We use this data solely to create your account, authenticate your identity during sign-in, and personalize your user profile (for example, displaying your name).
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2.3 Discord and other authentication
If you sign in with Discord or another supported identity provider, we receive identifiers and profile fields needed to create or link your account (such as email, username, and avatar where provided). Those providers process credentials and session data under their own terms.
2.4 Affiliate program data
If you apply to the Affiliate Program, we collect the application information you provide, including your name, email address, business or channel name, website or social link, country, promotion description, requested commission model, payout-method preference, and Terms acceptance record. After approval, we record affiliate link visits, referral attribution, commission activity, and payout history.
Payout destination details, such as a PayPal email address or cryptocurrency wallet and network, are collected only when needed for payout and are stored separately with restricted access. We do not request or store SSNs in the Affiliate Program application form. We may request identity, tax, address, invoice, wallet-ownership, or other compliance information before releasing affiliate payouts.
2.5 Chat logs, conversational memory, and continuity data
To operate interactive sessions and maintain character continuity, we store chat-related data in our primary database, including:
- Chat messages between you and the AI (user and assistant roles), associated with your account and specific conversations;
- Session and memory fields used for narrative continuity, such as short-term scene summaries, long-term psychological notes, unresolved narrative threads, scene metadata, and related session state;
- Progression and engagement metrics tied to your account or conversations (for example, scores or tallies used to adapt pacing or pricing mechanics);
- In-app purchase records for virtual gifts or similar items linked to conversations, and transaction history for token purchases or subscriptions.
This processing is necessary to provide the core Service you request—persistent, personalized adult AI chat—and to secure and improve the platform.
2.6 Voice, image, video, and moderation data
Depending on the features you use, we may process voice or call audio and related transcripts; image or video generation prompts and outputs; unlock or gallery metadata; and automated moderation signals. We may use third-party safety or moderation providers (including Hotmate where configured) to help detect abuse, illegal content, or Terms violations. Flagged results may be retained for safety, fraud prevention, and legal compliance.
2.7 Technical, usage, and analytics data
We may collect device, browser, IP-derived information, timestamps, diagnostic logs, and analytics events to secure the Service, measure performance, and understand aggregate usage. We use third-party analytics tools (including PostHog) to understand how users interact with the platform, including feature usage, navigation patterns, and subscription performance. For authenticated users, this data helps us troubleshoot technical issues and personalize your experience. Behavioral data is handled with confidentiality and used for platform operation, optimization, and security.
Where local law requires consent for analytics cookies or similar browser storage, we show a cookie consent banner before enabling non-essential analytics. You can accept or reject analytics cookies, and eligible users can change that choice later from account settings. Essential cookies for authentication, security, age verification, bot protection, and core Service operation may still be used.
2.8 First-party paid-acquisition attribution
When you arrive through a paid advertisement, we may record the advertising network or tracker, click identifier, campaign, creative or variation, placement or zone, device, country, landing page, offer, and reported click cost. We use this first-party attribution information to measure advertising effectiveness, prevent fraud, reconcile conversions, and understand aggregate acquisition economics. Raw click identifiers are retained in our internal application records for attribution and conversion feedback; they are not sent in the new PostHog analytics events described above.
This first-party paid-attribution record is separate from optional browser analytics and may be collected when a paid landing reaches the Service, including if you decline optional analytics cookies. We retain it only as reasonably necessary for campaign measurement, financial reconciliation, fraud prevention, and legal obligations.
2.9 Bot protection and security
This website uses Cloudflare Turnstile to protect against spam, malicious bot traffic, and automated abuse. Turnstile may operate in the background or present a challenge to verify that you are a human user. By accessing this website, your use of Turnstile is subject to the Cloudflare Turnstile Privacy Addendum.
3. How we use information
We use the information above (including Google user data where applicable) to:
- Provide, operate, personalize, and secure the Service;
- Maintain chat history and memory so characters and scenes remain coherent across sessions;
- Process token deductions, tributes, subscriptions, Lifetime entitlements, and related billing events;
- Detect, investigate, and prevent fraud, abuse, illegal activity, and violations of our Terms;
- Comply with legal obligations and respond to lawful requests;
- Communicate with you about the Service, support tickets, and policy changes;
- Send promotional emails only when you have opted in (you may unsubscribe anytime);
- Review affiliate applications, attribute approved referrals, calculate commissions, process payouts, and prevent affiliate fraud.
AI and machine learning: We do not use Google user data (such as your email address or name) to train, retrain, or fine-tune any AI or machine learning models. We do not use your chat logs, memories, voice, or generated media to train or fine-tune foundation models. We may use aggregated or de-identified metrics to operate and improve the Service. Third-party inference or moderation providers may process prompts and outputs under their own policies for abuse monitoring, safety, or temporary logging.
4. Third-party large language models (LLMs) and media providers
When you send messages or use generative features, our servers construct prompts that include your text and relevant context (such as recent conversation history and stored memory fields) and transmit those prompts to third-party inference providers via API over encrypted connections. Image, video, or voice features may likewise send prompts, audio, or media to third-party providers. The exact provider and model may change over time.
Retention on third-party systems:We do not control those providers' internal logging, training, abuse-monitoring, or retention practices. Prompts and outputs may be temporarily or longer retained by the provider in accordance with their policies, independent of our systems.
We may change providers or models to maintain quality, safety, or availability. When we do, the categories of data disclosed remain substantially the same (inputs and contextual fields needed to generate a reply or media output).
Some features may trigger additional automated analysis calls (for example, background summarization, scoring, or moderation). Those calls also send relevant text or media to a provider API under the same framework.
5. Sharing of information
We share information (including Google user data where necessary to provide the Service) with:
- Service providers who host infrastructure, databases, authentication, email (including transactional and, where you opt in, marketing tools such as Kit or Resend), analytics (including PostHog), bot protection (including Cloudflare Turnstile), moderation, or security tools, solely to process data on our instructions;
- Centrobilland related payment infrastructure for checkout, subscriptions, refunds, chargebacks, and fraud prevention, subject to Centrobill's privacy notices;
- Affiliate payout providers where needed to issue an approved payout, using only the information required for that payment;
- Law enforcement or regulators when required by law or to protect rights, safety, and integrity of users and the public.
We do not share Google user data with third parties for their own independent advertising or marketing purposes. We do not sell your personal information in the traditional sense of exchanging data for money.
6. Retention
We retain account data (including Google-supplied profile fields where you signed in with Google), chat, memory, media-related records, moderation flags, and transaction data for as long as your account is active and for a reasonable period afterward for security, dispute resolution, and legal compliance, unless you request deletion as described below. Some backups may persist for a limited technical window before rotation.
Affiliate application, attribution, commission, payout, and audit records may be retained longer where needed for tax, fraud prevention, chargeback, dispute-resolution, or legal-compliance obligations.
7. Security and protection
We implement administrative, technical, and organizational measures designed to protect information, including Google user data. This includes encryption of data in transit and industry-standard protections for stored data. No method of transmission or storage is completely secure; you use the Service at your own risk.
8. International transfers
We are based in Ontario, Canada. If you access the Service from outside Canada, or if we use processors in other countries, your information may be transferred across borders. We rely on appropriate safeguards where required by law.
9. Your rights, retention, and deletion
Depending on your jurisdiction (including rights that may apply under Canadian privacy law), you may have rights to access, correct, delete, or export certain personal data, or to object to or restrict certain processing. Many controls are available in your account settings (for example, clearing chat history or managing analytics cookie preferences).
For a comprehensive request—including deletion of your account, associated chat logs, and Google-linked profile data from our active systems—email [email protected] from the address on file with your account, with the subject line "Data Deletion Request." We will verify ownership and respond within a reasonable timeframe, subject to legal exceptions (for example, records we must retain for fraud prevention, chargebacks, or lawful investigations).
10. Children
The Service is strictly for adults aged eighteen (18)+. We do not knowingly collect personal information from minors. If you believe we have collected information from a minor, contact us immediately.
11. Changes to this Policy
We may update this Policy from time to time. We will post the revised version and revise the effective date. For material changes, we may also notify you at the email on your account where practical and where legally required.
12. Effective date
Effective as of July 16, 2026.