MapPrivacy Policy

Privacy Policy

Last updated 2026-09-01

Working draft. This wording is provided for transparency and is pending legal review; it is not yet final legal advice.

Who is responsible

The data controller is Kaiser Hop s.r.o., Luková 74, 751 03 Brodek u Přerova, Czech Republic (IČ 05086663, DIČ CZ05086663, zapsáno v obchodním rejstříku vedeném Krajským soudem v Ostravě, oddíl C, vložka 66198) (Czech Republic). Contact: hello@lustatlas.com.

Creator profiles built from public sources

Lust Atlas lists creator profiles assembled from information that adult platforms publish openly: display name, declared location, activity figures and, where provided, a public profile image. The legal basis we rely on is legitimate interest in indexing publicly available professional listings. We deliberately do not collect or display:

  • precise locations — we resolve a declared city and show a blurred point;
  • legal names, unless a creator adds one to their own claimed profile;
  • special-category data (ethnicity, sexual orientation and similar), even where a source exposes such fields.

Your rights as a listed creator

You can have your profile removed, corrected, or taken off the map at any time, without an account and free of charge — see Claim & Removal. Safety-related requests hide the profile immediately. You may also exercise GDPR rights (access, rectification, erasure, objection) by contacting us.

Visitors

  • Lust Atlas does not ask you to confirm your age when you enter the directory, and we do not store an age confirmation in your browser or on our servers. Before a link sends you to an external platform, we show a warning that the destination may contain content intended only for adults.
  • We use privacy-bounded analytics to understand aggregate traffic and product use. When Plausible or Google Analytics 4 is configured, the app sends its own pageview events using redacted route families rather than automatic full-URL measurement. Query strings, fragments, search terms, profile or city slugs and account credential pages are not included in those pageview events.
  • We use a fixed, allowlisted set of aggregate product-event labels. We do not send My Atlas email addresses, passwords, saved items, searches, account IDs or activation and sign-in credentials to those analytics services. Google Signals and advertising-personalisation signals are disabled in our Google tag.
  • Outbound clicks are also counted by us with a short-lived, hashed browser-tab value. This helps measure the service without keeping a browsing identity.
  • Server logs are kept only as long as needed for security and abuse prevention.

Browser-only discovery preferences

The discovery deck can remember only choices you make explicitly: creator IDs you skip, platform or tag labels for which you ask to see more or less, and creator IDs recently shown so the deck does not immediately repeat them. This information can reveal sensitive adult-content preferences. It stays only in this browser's local storage and is not sent to our server by the discovery preference module. Recently shown creator IDs expire after seven days. Explicit skips and more/less signals expire no later than 90 days after the last such choice. The current tab also keeps a session-only seen list until that browser session ends.

Use Reset discovery preferences in the discovery deck to remove those browser-only values immediately. Clearing site data in your browser removes them as well. Browser-only saved-profile IDs are likewise kept on that device until you remove/reset them or clear site data; they are not imported into My Atlas without the separate action described below. On a shared device, reset these values or use a private browsing session when you finish.

Optional My Atlas account

My Atlas is optional. A local sign-in account can exist without enabling My Atlas; in particular, a person who first signs in with a provider is not opted in to saved-profile synchronisation merely by doing so. My Atlas starts only after an explicit privacy choice. If you enable it, we store your email address, the time and version of that consent, the creators and cities you choose to save, searches or map areas you explicitly name and save, collections you create, live reminders you enable and recommendations you dismiss. These can sync across signed-in devices. If you choose weekly creator updates, we store that creator-scoped choice and compare only changes to fields already shown on the public profile. Those updates, saved-search matches, city updates and live reminders may appear in a private My Atlas inbox and expire automatically. For a followed city we store the last time you opened that city solely to show profiles added since that visit. This can reveal sensitive preferences, so browser-only saves are never imported automatically. Importing them requires a separate action on the account page. We do not add passive searches, map movement, profiles merely viewed, other city views or outbound-click history to My Atlas.

Device notifications are off by default. If you press the Web Push button and grant browser permission, we store the browser's push endpoint and delivery keys until you turn it off, the browser expires them, or you delete My Atlas. Lock-screen copy is deliberately generic and contains no creator, city or saved search name. On iPhone and iPad this option is available only after you add the web app to the Home Screen. Quiet hours use only the time zone you select; we do not infer it from an IP address, device or map location. A random, HTTP-only journey cookie can live for at most 30 minutes after you open an inbox item so we can count whether that update led to a confirmed outbound visit. The cookie and its database token contain no creator or search identifier.

You can use email and password, a passwordless email link, or a configured sign-in provider. For password sign-in, we keep a one-way password hash, not a readable password. We also keep security metadata needed to protect the account: password-change and successful-sign-in times, a failed-sign-in counter and any short temporary lock, plus a hashed session token, session lifetime and a shortened browser user-agent string. We do not keep an IP address in the session record. Sessions last up to 30 days and are renewed while in use; changing a password invalidates existing sessions.

Signup and password-reset links are one-use inbox proofs that expire after 60 minutes; passwordless email sign-in links expire after 20 minutes. We store only hashes of those credentials in the credential tables, not their working values. The working link is held only long enough to be delivered in an AES-GCM-encrypted transactional outbox; its encrypted copy is redacted after use or revocation, or in the outbox's short cleanup period. A person who begins sign-in with a previously unknown X account must also confirm an email address in the same browser; this short-lived X and inbox challenge expires after 30 minutes. Its credential tables keep only hashes; the encrypted-outbox rule above also applies to the emailed X link.

If you choose Continue with Google or Apple, we receive a stable provider identifier and a provider-verified email address. With X, we receive a stable X identifier; for a new X identity we require the separate inbox confirmation described above. We request no Google Drive, contacts or calendar data, and we never receive your Google, Apple or X password. We keep a provider identifier and the email supplied for that identity while the local account exists, so we can recognise the same sign-in method and prevent accidental account merging. Google and Apple sign-in do not themselves enable saved-profile synchronisation.

Apple may issue a refresh token so that we can revoke Apple authorisation when a local account is deleted and handle verified Apple lifecycle notices. That token is encrypted at rest and decrypted only in server memory when needed to send an Apple revocation request. For those notices, we retain only a minimal idempotency record (event identifier, type and time), not Apple's event payload or a stable Apple identifier in that record. We remove Apple credentials when Apple revokes consent or reports account deletion.

We process sign-in, session and security information to provide the account you request and protect it from misuse. The legal basis for My Atlas preference synchronisation is your explicit consent. You may remove individual saves, searches, reminders and collections, unfollow cities or delete all My Atlas data from the account page at any time. If the account does not manage a claimed creator profile, deleting My Atlas also deletes the visitor account and its sessions. If it does manage a profile, only the visitor feature and saved list are removed so creator access is not destroyed.

To tell whether My Atlas features are useful, we keep append-only records of explicit account actions such as enabling My Atlas, saving a creator, opening a saved profile, opening an inbox update and continuing from it. A saved-profile open is coarsened to at most one record per account, surface and UTC day. These records may include a fixed product rollout label, but never a creator, city, search, map area, URL or passive page view. They remain account-linked only while My Atlas is enabled and are removed with its account data. Separately, notification reporting keeps a coarse daily fact for up to 90 days: a random notification measurement key, its broad kind, channel and delivery step. It contains no account, creator, query, path or exact time. While its private inbox item still exists, the random key can be matched to that item internally; after the private item is deleted, the remaining fact has no account or target link. Private inbox items and their more detailed delivery attempts expire sooner, no later than 60 days.

Retention

Claim and removal requests are kept for as long as needed to handle them and to demonstrate that we did, then deleted or anonymised. Profiles removed at the person's request are not re-imported. Authentication proofs are usable only for the short periods stated above and are then invalid; their hashed records are retained briefly for security, replay prevention and cleanup. Identity links, account-security records and sessions remain only while the local account exists or until they are revoked or expire. Saved creators and followed cities remain only while My Atlas is enabled.

Lust AtlasA playful guide to careful discovery.
DiscoverLiveTrendingTop 1000New creatorsFree OnlyFansNear meInsightsPressOnlyFansCamsCountriesCitiesAboutContactPrivacyTermsAffiliate disclosureRemoval policyReport illegal contentAccount

Lust Atlas is an 18+ directory of adult creators. We host no paid or explicit content; links open external platforms. Locations are approximate and show a city, never an address. Unclaimed profiles are not verified by or affiliated with Lust Atlas.

City reference data © GeoNames, licensed under CC BY 4.0.

Kaiser Hop s.r.o., Luková 74, 751 03 Brodek u Přerova, Czech Republic (IČ 05086663, DIČ CZ05086663, zapsáno v obchodním rejstříku vedeném Krajským soudem v Ostravě, oddíl C, vložka 66198). Contact: hello@lustatlas.com.