This Privacy Policy explains how Marydan Vision LTD (company number 16855640, registered office: Medius House, 2 Sheraton Street, London, England, W1F 8BH — “HoneyDolly”, “we”, “us”) collects, uses, and shares personal data when you use https://honeydolly.com (the “Service”).
We are the data controller for the purposes of the UK GDPR and, where applicable, the EU GDPR. Contact for all privacy matters: support@honeydolly.com.
The Service is for adults only (18+). Because the Service provides adult content, the fact that you use it — and the content you generate — may reveal information about your sexual preferences. We treat such data with heightened care, as described below.
1. Data we collect
Account data. Your email address and account identifiers. We use passwordless sign-in (one-time email links), so we never store a password.
Content data. Text prompts you submit, character configurations you create, and the AI-generated images produced for you, together with associated metadata (timestamps, generation parameters, moderation flags).
Payment data. Purchases, subscription status, and transaction history. Card details are collected and processed by our payment providers; we do not store your full card number. We receive limited transaction data (such as amount, status, payment method type, and partial card digits) needed for billing, support, refunds, and fraud prevention.
Technical data. IP address, device and browser information, approximate (country-level) location derived from IP, log data, and cookies (see the Cookie Policy).
Age-verification data (where applicable). Where law or payment partner requirements oblige us to verify age, verification is performed by a specialised third-party provider and we receive and store only the result (a “verified 18+” signal and a reference identifier) — not your identity documents or biometric data.
Communications. Messages you send to support, complaints, and removal requests.
We do not knowingly collect data from anyone under 18 (see Section 9).
2. How we use data and legal bases
| Purpose | Data | Legal basis (UK/EU GDPR) |
|---|---|---|
| Providing the Service: accounts, sign-in, generating content, storing your results | Account, Content, Technical | Performance of a contract (Art. 6(1)(b)) |
| Billing, subscriptions, refunds | Account, Payment | Performance of a contract; legal obligation (tax/accounting) |
| Closing and deleting accounts, handling late payments and refunds, and preventing repeat claims of one-time benefits | Account, Payment | Performance of a contract; legitimate interests in fraud prevention and transaction integrity; legal obligation where applicable |
| Content moderation and safety: automated screening of prompts and outputs, human review of flagged content, detection and reporting of illegal content (including CSAM) | Content, Account, Technical | Legitimate interests (Art. 6(1)(f)) — keeping the Service lawful and safe; legal obligation where reporting is required |
| Fraud prevention, chargeback handling, security | Payment, Technical, Account | Legitimate interests; legal obligation |
| Age assurance where required | Age-verification result | Legal obligation; legitimate interests |
| Service communications (login links, receipts, policy changes) | Account | Performance of a contract |
| Marketing emails (only if you opt in) | Account | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Service analytics and improvement | Technical, aggregated usage data | Legitimate interests; consent where required for cookies |
| Establishing, exercising, or defending legal claims; responding to lawful requests | As relevant | Legitimate interests; legal obligation |
AI training. We do not use your prompts or generated content to train AI models. If this ever changes, we will update this Policy and, where required, ask for your consent first.
Sensitive data. Your prompts and generated content may reflect sexual preferences (special category data under Art. 9 GDPR). We process such content only as needed to provide the Service you explicitly request, to moderate for illegal content, and to comply with law. Access by staff is restricted to flagged or reported content.
Automated decision-making. Automated content filters may block a prompt or an output. You can contest any moderation decision through the appeal process in our Complaint Policy — appeals are reviewed by a human.
3. Who we share data with
We do not sell personal data, and we do not share your prompts or generated content with advertisers.
We share data with:
- Service providers (processors) acting under contract: cloud hosting and storage, GPU inference providers that execute generation jobs, email delivery, customer support tooling, analytics (if enabled), and age-verification providers. Providers receive only what they need to perform their function.
- Payment providers and acquirers, to process payments, prevent fraud, and handle disputes. If you initiate a chargeback, we may share relevant account and transaction records (including evidence of Service usage) with the payment provider or bank to the extent necessary to respond to the dispute.
- Authorities and other parties where required by law — including reporting child sexual abuse material to NCMEC, IWF, or law enforcement, and responding to valid legal process (see the Anti-Trafficking Statement and Content Moderation Policy).
- A buyer or successor in the event of a merger, acquisition, or sale of assets, subject to this Policy.
4. International transfers
We are based in the United Kingdom. Where our providers process data outside the UK/EEA, we rely on adequacy regulations or appropriate safeguards (such as the UK International Data Transfer Agreement / Addendum or EU Standard Contractual Clauses).
5. Retention and account deletion
- Closing an account. Whether you use ordinary deletion or an eligible “Refund & close account” action, sign-in and access end immediately, all Credits are forfeited, stored content is removed from the account and scheduled for deletion, active entitlements end, and marketing emails are disabled. Closure is irreversible and the account cannot be restored during the deletion period.
- 30-day deletion period. We retain the account record and remaining non-content account data for 30 days after closure so that we can preserve transaction integrity, process late payment confirmations and refunds, secure the deletion process, and meet legal obligations. After 30 days, the user record and associated subscriptions, Credit ledger, consent records, offers, and remaining non-financial account data are permanently deleted. Residual copies in encrypted backups are purged on backup rotation.
- Financial, payment, refund, dispute, and audit records. Orders, payments, refunds, payment confirmations, billing cases, and relevant audit records may remain after the user record is deleted. The direct account link is removed, but transaction snapshots needed to identify and document the purchase, process a late or duplicate payment, issue a refund, prevent fraud, respond to disputes, and meet tax, accounting, and legal obligations are retained as necessary. Financial and transaction records are ordinarily retained for 6 years after the transaction where UK tax and accounting rules require it; another period may apply where necessary for a dispute, legal claim, or mandatory obligation.
- Prevention of repeat one-time benefits. We retain a limited email-based abuse-prevention record for as long as reasonably necessary to prevent repeat claims of sign-up Credits, trials, and welcome discounts. After the 30-day deletion period you may create a new account with the same email, but it will not receive those one-time benefits. The new account is not linked to the old account’s purchases, Credits, or content.
- Generated content after a Subscription ends. If a paid term expires without a next plan taking effect, generated content and associated stored data may be permanently and irreversibly deleted, as described in the Terms of Service. Account closure removes stored content immediately as described above. Keep your own copies of anything you want to preserve.
- Moderation records concerning illegal content or serious violations: retained as necessary to comply with legal obligations, support investigations, and prevent banned users from returning.
- Server logs: up to 30 days, unless needed for an ongoing security investigation.
- Support correspondence: up to 2 years after the matter is closed.
6. Your rights
Under the UK/EU GDPR you have the right to: access your data; correct it; delete it; restrict or object to processing (including processing based on legitimate interests); data portability; and to withdraw consent at any time where processing is based on consent.
These rights are not absolute. For example, we may retain limited data where processing is necessary to comply with law, establish or defend legal claims, complete a payment or refund, maintain transaction records, or pursue proportionate fraud-prevention interests. We assess each request under the law that applies to it; the product’s 30-day account-deletion schedule does not limit any right to request earlier erasure where the law requires it.
To exercise any right, email support@honeydolly.com. We respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity before acting on a request.
You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner’s Office (ICO), https://ico.org.uk; in the EEA, your local data protection authority.
You can delete your account yourself at any time from your profile page.
7. US state privacy rights
If you are a resident of California or another US state with a comprehensive privacy law, you have equivalent rights of access, deletion, correction, and portability, exercisable as described in Section 6. We do not “sell” or “share” personal information as defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information other than to provide the Service. We do not discriminate against you for exercising your rights. Authorized agents may submit requests with proof of authorization.
8. Security
Data is encrypted in transit (TLS) and at rest. Authentication uses one-time links and httpOnly session cookies. Access to production data is limited to authorised personnel. No method of transmission or storage is completely secure; if a breach affecting your data occurs, we will notify you and the regulator where required by law.
9. Children
The Service is not intended for, and must not be used by, anyone under 18. We do not knowingly collect data from minors. If we learn that a person under 18 has created an account, we block access immediately and delete the account and associated personal data under Section 5, subject only to limited retention required for legal obligations, safety investigations, abuse prevention, or legal claims. If you believe a minor has used the Service, contact support@honeydolly.com.
10. Cookies
We use strictly necessary cookies for sign-in and session management, and optional analytics only with consent where required. Details, including a list of cookies and local-storage keys, are in the Cookie Policy.
11. Changes
We will post any changes to this Policy on this page and update the date above. For material changes we will notify you by email or in-Service notice before they take effect.
12. Contact
Marydan Vision LTD — Medius House, 2 Sheraton Street, London, England, W1F 8BH Email: support@honeydolly.com