Last Updated:

Mar 25, 2024

Privacy Policy

Introduction

Level5 Media GmbH d/b/a Hush (“Hush,” “we,” “us,” or “our”) respect your privacy and are committed to protecting it through our compliance with this policy. Hush is a subscription-based social media platform that enables content creators (“Creators”) to share and monetize their own content and fans (“Fans”) to subscribe to and view the content of Creators.

This policy describes the types of information we might collect from you or that you might provide when you visit the website https://hush.space/ (our “Website”) and our practices for collecting, using, maintaining, protecting, and disclosing that information. Some parts of the policy are specifically aimed at Creators, and some parts are specifically aimed at Fans. It also applies to how we process the personal data of individuals that feature in content uploaded by a Creator (“Content Collaborators”), and where we process personal data about you in the context of our business relationships.

This policy applies to information we collect:

  • On this Website.

  • In email, text, and other electronic messages between you and this Website.

  • When you interact with us through our social media pages on third-party websites.

It does not apply to information collected by:

  • Us offline or through any other means, including on any other website operated by Hush or any nonparty; or

  • Any nonparty, including through any application or content (including advertising) that might link to or be accessible from or through the Website.

Hush is the controller and responsible for your personal data.

Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. If you disagree with our policies and practices, your choice is not to use our Website. By accessing or using this Website, you agree to this privacy policy. We may change this policy on one or more occasions (see Changes to Our Privacy Policy). We consider your continued use of this Website after we make changes to be acceptance of those changes, so please check the policy periodically for updates.

Individuals Under the Age of 18

Our Website is not intended for individuals under 18 years of age. No one under the age of 18 may provide any information to or on the Website. We do not knowingly collect personal information from individuals under 18. If you are under 18, do not use or provide any information on this Website or through any of its features, register on the Website, make any purchases through the Website, use any interactive or public comment features of this Website, or provide any information about yourself to us, including your name, address, telephone number, email address, or any screen name or username you might use. If we learn we have collected or received personal information from an individual under 18, we will delete that information. If you believe we might have any information from or about an individual under 18, please contact us at support@hush.space.

The Types of Personal Data We Collect About You

Personal information, or personal data, means any information about an individual from which that person can be identified. It does not include information where the identity has been removed (anonymous data).

Depending on whether you are a Creator or a Fan, we collect several types of information from and about users of our Website that we have grouped together as follows:

Category
Description
User Data
Creators and Content Collaborators
full name
alias (if applicable)
mailing addresscountry of citizenshipemail addresstelephone numbergovernment-issued photo identification cardselfie photo of you holding your IDthird-party social media handle / personal website address (used to further verify your age and identity and to help us better understand the content that you are likely to share on our Website)signature on release forms if you feature in another Creator’s contentFansemail addresstelephone numberThird-Party Onboarding DataThe third-party providers collect the following personal data during onboarding:Creatorsa copy of the government-issued photo identification card that you provide to our third-party providersa short .gif, taken from a selfie that you provide to our third-party providersthe results of the third-party age and identity verification process (pass/fail and reason for failing)metadata associated with the third-party age and identity verification process (e.g. start and finish time)Fansa copy of the government identity document that you provide to our third-party providersa short .gif, taken from a selfie that you provide to our third-party providersthe results of the third-party age estimation process or third-party age and identity verification process (pass/fail and reason for failing)metadata associated with the third-party age estimation process or third-party age and identity verification process (e.g. user start and finish time)Account DataCreatorsprofile namepasswordavatars and headers of your Creator accountyour subscriptions and subscribersposts that you have made to your Creator accountcomments on posts made from your Creator accountchat messages between you and other userscustomer support queries that you submit to usFansprofile namepasswordavatars and headers of your Fan accountyour subscriptionscomments on posts made from your Fan accountchat messages between you and other userscustomer support queries that you submit to usFinancial DataCreatorspayment card details*billing addressfunds added to your walletbank account informationpayout countrycorporate or business entity if registered for tax purposessocial security number (for US Creators only) or other relevant tax informationW-9 form (for US Creators only)1099-NEC form (for US Creators only)Fanspayment card details*billing addressfunds added to your wallet*Please note: When you make a payment to access the content of Creators, our third-party payment providers process it. We do not receive your complete payment card number, payment card expiration date, or the security code. Instead, the payment provider gives us a “token” that represents your account, your payment card’s expiration date, payment card type, and the first six and last four digits of your card number.Transaction DataCreatorsearningspayout requestspayments made to your Creator accountpayments made from your Creator account to other Creatorsany failed paymentsFanspayments made from your Fan account to Creatorsany failed paymentsTechnical DataCreators and Fansinternet protocol (IP) address (and associated location data)Internet Service Provider (ISP)your login databrowser type and versiontime zone setting and locationbrowser plug-in types and versionsoperating system and platformdevice IDother technology on the devices you use to access this websiteUsage DataCreators and FansInformation about how you interact with and use our Website, products, and services.Face Recognition DataCreators and FansDuring onboarding, our third-party providers may use face recognition technology, so they can digitally verify you.The Face Recognition Data remains with our third-party provider, and we do not collect, receive, possess, or have access to Face Recognition Data at any time.

We also collect, use, and share aggregated data including statistical or demographic data that is not personal data as it does not directly (or indirectly) reveal your identity. For example, we may aggregate individuals’ Usage Data to calculate the percentage of users accessing a specific website feature to analyze general trends in how users are interacting with our Website to help improve the website and our service offering.

How Your Personal Data Is Collected

We use different methods to collect data from and about you including through:

  • Directly from you when you provide it to us.

  • Automatically as you navigate through the Website. Information collected automatically might include Technical and Usage Data and information collected through cookies, web beacons, and other tracking technologies.

  • From our service providers, for example, where permitted by law, we received Third-Party Onboarding Data and certain Technical Data from our third-party age and identity verification providers.

Data You Provide to Us

The information we collect on or through our Website may include the following:

  • Information that you provide by filling in forms on our Website. This includes information provided when registering to use our Website, creating a user profile, when you update your personal data in your account, or requesting further services. We may also ask you for information when you report a problem with our Website.

  • Records and copies of your correspondence (including email addresses), if you contact us.

  • Your responses to surveys that we might ask you to complete for research purposes.

  • Details of transactions you carry out through our Website and of the fulfillment of your orders. You might be required to provide Financial Data before placing an order through our Website. As mentioned, we do not collect or store your payment card details. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their privacy policy. These third-party payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council.

  • Your search queries on the Website.

You also may provide information to be published or displayed (“posted”) on public areas of the Website, or transmitted to other users of the Website or nonparties (collectively, “User Contributions”). Your User Contributions are posted on and transmitted to others at your own risk. Although you may set certain privacy settings for that information by logging into your account profile, please be aware that no security measures are perfect or impenetrable. Additionally, we cannot control the actions of other users of the Website with whom you may choose to share your User Contributions. Therefore, we cannot and do not guarantee that unauthorized persons will not view your User Contributions.

Data We Collect Through Automatic Data Collection Technologies

As you navigate through and interact with our Website, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including Technical Data and Usage Data.

Please note that we do not recognize or respond to any do not track signals (DNT). For more information about DNT, visit www.allaboutdnt.com.

The information we collect automatically is only statistical data and does not include personal information. It helps us to improve our Website and to deliver a better and more personalized service, including by enabling us to:

  • Estimate our audience size and usage patterns.

  • Store information about your preferences, allowing us to customize our Website according to your individual interests.

  • Speed up your searches.

  • Recognize you when you return to our Website.

The technologies we use for this automatic data collection might include:

  • Cookies (or browser cookies). A cookie is a small file placed on your computer’s hard drive. You may refuse to accept browser cookies by activating the appropriate setting on your browser. However, if you select this setting you might be unable to access certain parts of our Website. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Website. For detailed information on the cookies we use and the purposes for which we use them, see our Cookie Use Policy.

  • Web Beacons. Pages of our Website and our emails might contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit Hush, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of certain website content and verifying system and server integrity).

How We Use Your Personal Data

Legal Basis

The law requires us to have a legal basis for collecting and using your personal data. We rely on one or more of the following legal bases:

  • Performance of a contract with you: Where we need to perform the contract we are about to enter into or have entered into with you. By using the Website, you have contracted with us through our Terms of Service, and we will process personal data to perform that contract (that is, to fulfill transactions between Fans and Creators and process Creator earnings) and to enforce the terms of that contract.

  • Legitimate interests: We may use your personal data where it is necessary to conduct our business and pursue our legitimate interests, for example, to prevent fraud, investigating and responding to a report made through our DMCA Policy to protect a Creator’s intellectual property rights, and enable us to give you the best and most secure customer experience. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).

  • Legal obligation: We may use your personal data where it is necessary for compliance with a legal obligation that we are subject to. We will identify the relevant legal obligation when we rely on this legal basis.

  • Public interest: We may process personal data as necessary for a task carried out in the public interest. This may include, for example, reporting illegal activity to relevant law enforcement authorities, other governmental agencies, and non-governmental organizations.

  • Consent: We rely on consent only where we have obtained your active agreement to use your personal data for a specified purpose, for example, processing (1) Face Recognition Data by our third-party providers as part of the age and identity verification process for all Creators (and for Fans in certain locations); and (2) age estimation captures (that might involve the use of Face Recognition Data) by our third-party providers for Fans in certain locations.

Purposes We Will Use Your Personal Data

We have set out below, in table format, a description of all the ways we plan to use the various categories of your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

Purpose/UseType of dataLegal basisAccount creationUser DataThird-Party Onboarding DataAccount DataPerformance of a contractAge and identity verification and where applicable, later authenticationUser DataThird-Party Onboarding DataFace Recognition DataConsentFan age estimationUser DataThird-Party Onboarding DataFace Recognition DataConsentFan age verification (if we can do so without third-party age and identity verification or third-party age estimation)User DataPerformance of a contractGovernment identity document validity check, and maintaining a record of the age and identity verification process (for Creators and Fans)User DataThird-Party Onboarding DataPerformance of a contractMaintaining a record of the age estimation processUser DataThird-Party Onboarding DataFace Recognition DataPerformance of a contractProviding the Website, including the hosting of Creator content, the fulfillment of transactions between Fans and Creators, and processing Creator earningsUser DataAccount DataFinancial DataTransaction DataPerformance of a contractProviding technical support to Fans and CreatorsUser DataAccount DataTechnical DataPerformance of a contractCommunicating with you about the Website, responding to support requests, or sharing information about the Website (e.g., providing you with updates to our Terms of Service or this policy)User DataAccount DataPerformance of a contractEnsuring compliance with, and enforcing, our Terms of Service, and other usage policies (e.g., our Acceptable Use Policy)User DataAccount DataPerformance of a contractModeration and filtration:text and content uploaded to the Websitelive streaming on the Websitecontent sent in chat messages on the Websiteto monitor and investigate violations of our Terms of Service

Account DataUsage DataPerformance of a contractFiltration of text sent in direct messages on the Website to investigate violations of our Terms of Service

Account DataPerformance of a contractRemoval from the Website of text and content uploaded by users that is identified as illegal and suspending or deactivating those user accountsAccount DataTechnical DataCompliance with legal obligationsPerformance of a contractRemoval from the Website of text and content uploaded by users that is identified as violating our Terms of Service and where appropriate, suspending or deactivating user accountsAccount DataTechnical DataPerformance of a contractMaintaining a record of banned users, to prevent further access to the WebsiteUser DataAccount DataTechnical DataLegitimate interestsReporting illegal activity to relevant law enforcement authorities, other governmental agencies, and non-governmental organizationsUser DataAccount DataTechnical DataLegitimate interestsTask carried out in the public interestsComplying with laws, rules, and regulationsUser DataAccount DataCompliance with legal obligationsLegitimate interestsMonitoring transactions and company network, systems, applications, and data, to (1) detect malicious, deceptive, fraudulent, or illegal activity to protect information security and integrity, and user safety; and (2) respond to / investigate incidents where appropriateUser DataAccount DataTransaction DataLegitimate interestsTasks carried out in the public interestsData analysis and testing, system maintenance, reporting, and hosting of data, to maintain, develop, and improve the Website and the services (e.g., safety, performance, and functionality)Technical DataUsage DataConsent (where collected by cookies)Legitimate interests

Disclosure of Your Personal Data

We may share your personal data where necessary with the following categories of third parties set out below for the purposes set out in the table above.

  • Our subsidiaries and affiliates. These recipients will process personal data in the same way as set out in this policy. The lawful basis we rely on for sharing personal data with these recipients is that it is necessary for our legitimate interests (that is, coordinating the operations of our business).

  • Third-party service providers, including our IT, payment processing, customer support, content and text moderation, and age and identity verification/age estimation service providers. The lawful basis we rely on for sharing personal data with these recipients is that it is necessary for our legitimate interests (that is, the receipt of services to support business functionality).

  • Our professional advisers, including our legal advisors, bankers, auditors, accountants, consultants, and insurers. Our professional advisers will process personal data as necessary to provide their services to us. The lawful basis we rely on for sharing personal data with these recipients is that it is necessary for our legitimate interests (that is, the receipt of professional services).

  • Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this policy. The lawful basis we rely on for sharing personal data with these recipients is that it is necessary for our and the relevant third parties’ legitimate interests (that is, assessing and putting into effect potential transactions).

  • Relevant authorities, regulators, and organizations in response to requests from governmental authorities (including law enforcement and tax authorities), regulators, and certain nongovernmental organizations (including the National Center for Missing & Exploited Children (NCMEC)). These recipients will use your personal data in the performance of their regulatory, law enforcement, or otherwise charitable or not-for-profit roles. The lawful basis we rely on for sharing personal data with these recipients is that the processing is either necessary to comply with a legal obligation to which we are subject, or necessary for our, or a third party’s, legitimate interests, or where it is in the interests of the wider public to do so (that is, reporting illegal content to, and assisting with requests from, those authorities, regulators, and organizations, to protect the safety of our users and third parties).

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

International Transfers

We may transfer your personal data to service providers that carry out certain functions for us. This might involve transferring personal data outside the EU to countries that have laws that do not provide the same level of data protection as EU law.

Whenever we transfer your personal data out of the EU to service providers, we ensure a similar degree of protection is afforded to it by ensuring that the following safeguards are in place:

  • We will only transfer your personal data to countries that have been deemed by the EU to provide an adequate level of protection for personal data; or

  • We may use specific standard contractual terms approved for use in the EU that give the transferred personal data the same protection as it has in the EU. To obtain a copy of these contractual safeguards, please contact us at support@hush.space.

Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

Data Retention

We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation regarding our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting, or other requirements.

By law, we have to keep basic information about our users (including User Data, Financial Data, and Transaction Data) for seven years after they stop being users for tax purposes.

In some circumstances you can ask us to delete your data: see below for further information.

In some circumstances we will anonymize your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

Your Legal Rights

You have a number of rights under data protection laws regarding your personal data.

You have the right to:

  • Request access to your personal data (commonly known as a “subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

  • Request erasure of your personal data in certain circumstances. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully, or where we are required to erase your personal data to comply with local law. Note, however, that we might not always be able to comply with your request of erasure for specific legal reasons that will be notified to you, if applicable, at the time of your request.

  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) as the legal basis for that particular use of your data (including carrying out profiling based on our legitimate interests). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information that override your right to object.

  • You also have the absolute right to object any time to the processing of your personal data for direct marketing purposes. We currently do not send emails for direct marketing purposes. However, we do send email notifications that are related to your account (e.g., for Creators, where you have a new subscriber, you have received a new tip, or somebody has renewed their subscription with you). You may opt-out of receiving certain types of email communications from us by changing your notification preferences on our Website. You may also email us at support@hush.space. Please include “E-mail notification opt-out” in the email’s subject line and include your name and your account email address in the body of the email. Please note that you cannot opt-out of certain automated email notifications that are essential for administrative or customer service purposes or are otherwise required in accordance with law. For example, you will still receive emails relating to account verification, transactional communications, changes/updates to features of the Website, and technical and security notices.

  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information that you initially provided consent for us to use or where we used the information to perform a contract with you.

  • Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we might not be able to provide certain products or services to you. We will advise you if this is the case when you withdraw your consent.

  • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in one of the following scenarios:

  • If you want us to establish the data’s accuracy;

  • Where our use of the data is unlawful but you do not want us to erase it;

  • Where you need us to hold the data even if we no longer require it as you need it to establish, exercise, or defend legal claims; or

  • You have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.

If you wish to exercise any of the rights set out above, please contact us at support@hush.space.

No Fee Usually Required

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we could refuse to comply with your request in these circumstances.

What We Might Need From You

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

Time Limit to Respond

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

US State Privacy Rights

US State consumer privacy laws might provide their residents with additional rights regarding our use of their personal information.

California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, and Virginia provide (now or in the future) their state residents with rights to:

  • Confirm whether we process their personal information.

  • Access and delete certain personal information.

  • Correct inaccuracies in their personal information, taking into account the information’s nature processing purpose (excluding Iowa and Utah).

  • Data portability.

  • Opt-out of personal data processing for:

    • targeted advertising (excluding Iowa);

    • sales; or

    • profiling in furtherance of decisions that produce legal or similarly significant effects (excluding Iowa and Utah).

  • Either limit (opt-out of) or require consent to process sensitive personal data.

The exact scope of these rights might vary by state. To exercise any of these rights please email us at support@hush.space. To appeal a decision regarding a consumer rights request, please email us at support@hush.space.

Nevada provides its residents with a limited right to opt-out of certain personal information sales. Residents who wish to exercise this sale opt-out rights may submit a request to this designated address: support@hush.space. However, please know we do not currently sell data triggering that statute’s opt-out requirements.

Contact Details

If you have any questions about this privacy policy or about the use of your personal data or you want to exercise your privacy rights, please contact us using the contact information set out at Imprint or through the Website at Contact.

Complaints

You have the right to make a complaint at any time to the Federal Commissioner for Data Protection and Freedom of Information (BfDI), the German regulator for data protection issues (www.bfdi.bund.de). However, we would appreciate the opportunity to address your concerns before you approach the BfDI, so please contact us in the first instance.

Changes to Our Privacy Policy

Our policy is to post any changes we make to our privacy policy on this page. If we make material changes to how we treat our users’ personal information, we will notify you by email to the email address specified in your account or through a notice on the Website home page. The date the privacy policy was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting our Website and this privacy policy to check for any changes.

Duty to Inform Us of Changes

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example, a new address or email address.

Third-Party Links

This Website might include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections might allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.