← Back

Privacy Policy

Last updated 12 September 2026

DebtKeeper is built and operated by Red Ink Lab, an independent studio established in the European Union and run by its founder, and it lets people track private debt and tribute arrangements between themselves. This policy explains what personal data we process, why, and the rights you have over it. The operator of DebtKeeper is the data controller for the purposes of the EU/UK GDPR; you can reach the controller at [email protected], and the About page says who we are, where DebtKeeper runs, and how it is built.

What we collect

  • Account data — your name, email address, and password (stored only as a salted bcrypt hash, never in plain text).
  • Profile data — your display name, avatar or profile image, pronouns, and, if you claim one, your @handle. A Domme's public page adds what she publishes on it: banner and tier images, tiers, links, writings, testimonials. A sub's profile, if he writes one, can list kinks, limits and an introduction — that is information about your sex life, and the section “Sensitive information” below says how we treat it.
  • Agreement details — if a Domme requires them when you sign her contract: your full name, phone number, any details she asked for, and the signature you draw. They are shown to her and to nobody else, snapshotted with the terms you signed, and erased with your account.
  • Activity and scores — what you do in the features you use: games, tasks, keyholding, auctions, drives, claims and the confirmations, rejections and outcomes attached to them; and the scores worked out from those records — reputation, trust, danger, obedience. “Scores, and what they change” below explains them. Dommes you share a tracker with can review you (shown to other Dommes only as “anonymous · date”, never to you); blocks and mutes are recorded so they can be enforced.
  • X — only if you connect X to prove a handle is yours: your numeric X id and @handle. We never receive a standing ability to act on your account, and the public link always uses the id, which survives a rename.
  • Support, feedback and reports — what you send us, the private conversation that can follow, and, if you report someone or are reported, the report and what a moderator was allowed to see, as described under “Private messages”.
  • Contract data — the debts, payments, charges, demands and notes you and the other party record. This is shared between the two participants of each contract.
  • Preferences — display settings such as currency, timezone and text size.
  • Technical data — your IP address (used briefly to rate-limit sign-in and protect against abuse) and, if you enable them, push-notification tokens.
  • Telegram — only if you choose to connect Telegram, we store your Telegram chat id (and public @username, if any) so we can deliver your alerts there. You can disconnect any time from Profile → Notifications, or by sending /stop to the bot.
  • Discord — only if you choose to connect Discord, we store your Discord account id and your public username and display name, so we can deliver your alerts there. We ask Discord for your identity and nothing else: not your email, not your server list, not your messages. The access token is used once to read that identity and then discarded, so DebtKeeper cannot act as your Discord account afterwards. You can disconnect any time from Profile → Discord, and doing so deletes what we stored.
  • The DebtKeeper Discord server — only if you choose to join it. Joining asks Discord for one extra permission, to add you to servers; that permission cannot read anything about your account, and we discard it immediately after adding you. Inside the server we publish, by default, only things that are already public here: whether you are a Domme or a sub, that you are 18+ verified, the name you chose when joining, and — only if you tick the box — your public marks. The one thing that is not already public is your games, and that is a separate opt-in described in the next point — with one exception noted there, a Click Tax drive you have already made public. We never publish your reputation, obedience or trust score, and we never publish any balance — how much anybody owes is not shown there, ever. If your account is closed, suspended or put on an age-review hold, or you disconnect Discord, we remove you from the server. One deliberate exception to deletion: if that removal has not completed yet, we keep your Discord account id — and nothing else — until it has, because we are obliged to be able to remove you from an 18+ space. It is deleted the moment the removal succeeds.
  • Your games, in the DebtKeeper server — only if you switch it on, and only for the kinds you leave switched on. A game is posted in the server's game channels only when both you and the other person have that kind switched on. One thing works differently: a Click Tax drive that is already public on DebtKeeper. It has its own public page and its own name setting, so its card in the server follows the drive rather than these switches — it always names the Domme, and it names you only when the drive already shows your name. Everything else on this page describes the switches, and applies to every other kind of game. If you have never answered that question, a game you played may be posted with your name left out — it identifies you only as one of that person's subs, in the pronoun they have set — “one of her subs”, “one of his subs”, “one of their subs” — and it reads identically for every unnamed sub of that same person, every time, with no number, nickname or emoji standing in for you, because a stand-in that is consistent is just a name you did not choose. We used to require a Domme to have at least three subs before doing this, so that an unnamed post could not name you by elimination; that requirement has been removed, so an unnamed post can now happen in a stable of any size, including one where you are the only sub. If that matters to you, say no — a refusal keeps you out entirely, as below. Your Domme is always named. For every kind but a public Click Tax drive she has also switched it on, and a post nobody's Domme agreed to does not exist; for a public drive it is the drive she made public that stands in for that answer. If you have answered and said no, that is a no — a refusal is never read as “yes, without my name”, and it keeps everything about you out, unnamed posts included. (Except a public Click Tax drive, above: a refusal here does not take down a card about a drive that is already public, and the way to change what that card says is the drive's own name setting.) Chastity is posted only when you have both switched it on — or, if you were never asked, without your name, and never even unnamed if you have the cage-hall setting switched on, or your wall with her is set to name you — either one on its own is enough. You can switch this off, or switch the whole thing on, at any time with /dk public or in Profile → Discord. A post says what a game did — who played, which game, what it moved or decided — and it can quote the game's own content: the label of a receipt you covered, a question you got wrong, how long a lock lasted. One is posted before the money rather than after it — a receipt spin appears as you spin, and says only that you are spinning: never which bill, never the amount, never whether you paid. Those appear in the same post if and when she confirms your payment, and if nothing is sent the post comes down on its own. It never says what anybody owes, and it never gives away what a game deliberately keeps from its own player — a random lock's release date, an ATM's remaining balance. Your leaderboard hall-of-fame settings do not affect what is posted in this server, with one exception: a wall set to name you is one of the two things above that stop a chastity post being anonymous. They used to: if you were anonymous or hidden on a Domme's leaderboard, nothing was posted about you here, even with every kind switched on — a second answer, on a different page, that nobody was told about. The switches on your Discord settings are the whole question now. (Your hall setting still applies to a Domme's own server — see the next point.) You can switch any other kind off on your own at any time, with /dk public or in Profile → Discord; you do not need the other person's agreement. Switching a kind off deletes the posts it already made, and so does deleting your account, being suspended, or being put on an age-review hold. A public Click Tax card comes down when the drive ends, when the Domme leaves the server, or on any of those same account events — not from a switch. We cannot recall a screenshot somebody already took, and we do not pretend otherwise.
  • A Domme's own Discord server — a Domme can connect her own server so her feed posts there: confirmed tributes, leaderboard changes, auctions and live drives. Nothing posts until a server admin has approved it, and only into the channels she picked. Amounts are shown as they are shown here. For a confirmed tribute or a change at the top of her leaderboard, who is named follows the same wall settings as her public hall — if you are hidden there you are not named; if you are shown without your name the post says “Someone”. For a game she runs for her whole stable — an auction or a raffle — the winner is named, exactly as that result is already announced to her group chat today. We keep a record of each post we make so we can edit or delete it later: if you delete your account, we delete the posts that name you before we discard the link between them and you. We cannot un-see a screenshot somebody already took, and we do not pretend otherwise. This is separate from the DebtKeeper server above: her feed carries her whole stable's activity because she asked for it in a server she chose, and an admin of that server approved it, whereas the DebtKeeper server posts a game only when both people in it have switched that kind on — with the one exception described above, a Click Tax drive that is already public on DebtKeeper. To be exact about what that does and does not guarantee: we check that the Domme asked for the feed and that someone who runs that server approved it and picked the channels. We do not verify that the server belongs to her, and a channel a feed posts into has to be one Discord itself treats as age-restricted. We never ask for permission to read message history, and DebtKeeper never reads messages in her server — it only posts. A Domme cannot point her feed at the DebtKeeper server.
  • USDC payments — only if you choose to use them. To let you pay, or be paid, with USDC we store: the wallet address you verified, when and how you verified it, and a fingerprint of the message you signed to prove it is yours — never the signature itself, and never a key or seed phrase; each payment request (“quote”) — the amount, the currency it was priced in and the exchange rate and date used, who it was for, when it expires and what happened to it; and, once a transfer is made, its public transaction hash, the network it was on, the block it landed in, and the sending and receiving addresses. We do not store wallet balances, what else is in a wallet, any other transaction history, or a link between a wallet and an IP address, and we never look at a wallet's history for any other purpose. If a transfer is signed or recorded from a device, that browser also keeps the transaction hash and the payment's identifiers in its own storage until the payment is confirmed or finally fails — it is not a cookie, and clearing your browser storage removes it.
  • Being someone's, in public — you and a Domme can agree that you are hers. It is a title and nothing else: it moves no money, changes no score, and gives neither of you any power over the other that you did not already have. Nothing is published unless all three of these are true — you both agreed to it, she chose to show it on her page, and you chose how you appear. Your choice is yours alone and has three settings: named, which puts “Owned by” and her @handle on your own profile page and counts you on hers; anonymous, which counts you on her page without naming you anywhere; and hidden, which publishes nothing at all, not even the count. Be aware that a small count can still point at you: if she has only one or two subs marked as hers, somebody who knows her stable may be able to work out who. Anonymous hides your name, not the arithmetic — if that matters to you, choose hidden. If you have joined the DebtKeeper Discord server, a public ownership shows there too: whether you chose named or anonymous, you wear an ⛓️ Owned role — it says you are owned, never by whom. Only if you chose named does a one-time card in the #ownership channel say who owns you, and you can stop that card on its own with /dk public. The role follows your display choice, not that switch: choosing hidden takes the role off, and both the role and any card come down the moment the ownership ends or she stops showing it. What is published is the title, her @handle, and a number on her page. Never any figure — not what you have sent, not what you owe, not your reputation, not your history, not how long it has lasted. Either of you can end it at any time, instantly, for free, without the other's agreement and without giving a reason, and ending it takes the display down. It also ends on its own if either of you blocks the other, if you mute her, if the tracker between you is settled or archived, or if either account is deleted, suspended or put on an age-review hold — and the display goes with it in every one of those cases. We cannot recall a screenshot somebody already took, and we do not pretend otherwise.
  • Notes you write about other people — private notes about someone you have a contract with, and, if you record income received outside DebtKeeper, the names and notes you attach to it. Those names may refer to people who do not have a DebtKeeper account. They are visible only to you — never on a share card, a notification, or the other person's copy of anything — with one exception you control: on your own public page, an amount you recorded as received outside DebtKeeper is listed as added manually, and you may choose, one person at a time, to show the name you gave it beside that amount. Showing a name is off by default; until you turn it on for that person, the entry appears without any name. All of it appears in your own data export, and is erased when you delete your account. If you believe you are named in someone's private notes, contact us — see “Your rights” below. “Only to you” describes the app. It does not remove anyone's legal rights over personal data about them: a request about your notes is assessed individually, weighing the rights and safety of everyone involved, and may be answered with a redacted copy.

Where it comes from. Most of this comes from you or from your use of DebtKeeper. Some comes from the other person in an arrangement with you — what she records about a payment, a task or a game is a record about you too. Names attached to income received outside DebtKeeper can refer to people who have no account here. If that is you, write to [email protected].

Cookies

We use two strictly necessary cookies, both first-party: one to keep you signed in, and one that remembers you’ve seen the 18+ notice on our public pages so you aren’t asked again on that browser. If you choose to connect X or Discord, each connection sets one more for ten minutes — a security token that stops someone else hijacking the connection. It is scoped to that one address, so it is never sent on any other page, it is never set unless you start the connection yourself, and it expires on its own whether or not you finish. None of them is used for tracking or advertising — and the 18+ one is only a record that the notice was shown, never proof of anyone’s age. We use no advertising or tracking cookies and build no advertising profiles, so no cookie-consent banner is required. We do not run third-party usage analytics. The scores described below are worked out from records inside DebtKeeper and are a different thing from tracking; they have their own section.

Why we use it (legal basis)

We process account and contract data to provide the service you sign up for (performance of a contract), and technical data to keep the service secure (legitimate interest). We send transactional emails — verification and password reset — because they are necessary to operate your account. If you use the USDC option, we process the payment request and check the public transfer because that is the service you asked for (performance of a contract). We keep the transaction's identifier and the addresses involved so that the same transfer can never be counted twice, so that a payment under review can be resolved, and so that a shared record the other person relies on stays accurate (legitimate interest — we have written down why that interest is justified and how little it takes).

We work out the scores described below, keep records of suspensions, age-safety holds and reports, and rate-limit abusive behaviour, because a service where money is claimed has to be honest and safe for the people using it (legitimate interest — ours and theirs). We have written down how we weighed that interest against yours; you can object to it by writing to [email protected]. Everything published about you to other people — a public page, a leaderboard, the Discord server, being someone’s in public — rests on a choice you make in its own control, described in this policy.

Sensitive information

Using DebtKeeper says something about your sex life: the arrangements it records belong to a kink, and some features go further — a sub's profile can list kinks and limits, and keyholding records a chastity arrangement. Under the GDPR that is a special category of personal data, and we process it on your explicit consent. We ask for it separately when you create your account — its own box, unticked, in plain words — and existing accounts are asked once, on sign-in, when a version of this consent is in force. We keep a record of when you gave it and the exact words you agreed to.

Consent to run your account is not consent to publish anything. What other people can see about you is governed by the controls described elsewhere in this policy, each in its own place. One person's consent never covers another: what a Domme records about you follows the same rules, and what can appear about you in the DebtKeeper Discord server — including the one case where a game you played can be posted without your name if you have never answered — is set out exactly under “Your games, in the DebtKeeper server” above.

You can withdraw consent at any time by deleting your account, which erases your personal data as described below. Because the service cannot run without this information there is no half-way setting, and withdrawing does not undo processing that happened while your consent stood. We keep the record of the consent itself — when it was given and the words it was given to — as the evidence of what you agreed to and later withdrew.

Scores, and what they change

DebtKeeper works out a few scores from what is recorded in it. A sub’s reputation is platform-wide and built only from money honesty: confirmed payments, rejected payment claims, obligations he took on and left unpaid, and Dommes ending relationships with him. Inside each tracker there are also a trust score, a danger score and obedience points, built from payments, lateness, tasks and the tracker’s own terms. What the other person records affects them. They summarise DebtKeeper records: they are not a credit rating and say nothing about anyone’s finances or conduct outside the service.

Reputation has automatic consequences here. A low tier caps how many unconfirmed payment claims an account can have open at once, can add a waiting period between claims, and can require a confirmed tribute to a Domme before playing her games; the lowest tier cannot play at all. Some of those limits are platform-wide; a Domme can waive the ones inside her own relationships. Nothing here stops anyone paying what they owe.

You can see your own reputation and every factor behind it in Profile → Reputation. A Domme sees a sub’s reputation only when they share a tracker or a pending request. We never publish a score outside the app. If you think a score rests on a wrong record, or a limit is wrong, write to [email protected]: a person will look at it and tell you the outcome.

Who we share it with

We do not sell your data. Some providers process it only on our instructions — our hosts, our backup storage, our email provider, Cloudflare, the Base data provider and Didit. Others are services you choose to connect and that run under their own terms — Telegram, Discord, X, your wallet and the public Base network — and for those we send only what your connection needs.

  • EU infrastructure providers — application and database hosting in Amsterdam (MojoHost for the primary, Hostwinds for the streaming replica). Encrypted backups are stored off-site with Backblaze in two places, a European Union bucket and a United States bucket; every backup is encrypted on our own servers before it is uploaded, so Backblaze holds only ciphertext it cannot read.
  • Resend — the current delivery provider for verification, password-reset and other service emails. A replacement email provider would receive only the information needed to deliver those messages.
  • Didit (didit.me) — only if you choose to verify your age. They process your selfie (and, depending on the check, an ID document) to confirm you're 18+; we receive only the result.
  • Apple / Google / Mozilla push services — only if you enable notifications, to deliver them to your device.
  • Telegram — only if you connect Telegram, to deliver your alerts to your Telegram chat.
  • Discord — only if you connect Discord, to deliver your alerts there.
  • Cloudflare — every request to debtkeeper.app passes through Cloudflare's network, which protects the site and delivers it to you. Your connection is encrypted to Cloudflare and again from Cloudflare to our servers; in between, Cloudflare's systems handle each request, including a USDC payment request or the transaction hash you send us. Cloudflare processes this on our behalf under its data-processing terms.
  • A Base network data provider — only if you use the USDC option. To check that a transfer happened, our server asks Alchemy Insights, Inc. (United States) about the transaction hash and addresses involved. The provider sees our server's request, not your browser or IP address, and holds its logs under its own terms, which we have reviewed.
  • The public Base network — a USDC transfer is written to a public ledger by your wallet, not by us. The transaction, amount and both addresses are visible to anyone, permanently, and neither we nor you can remove them. A link on a verified payment opens the public record on Basescan, a site that is not ours.

Where it is processed. The application and the database run in the European Union. A few things reach the United States: our encrypted backups with Backblaze, our service email through Resend, Cloudflare in front of the site, and the Base data provider, Alchemy Insights, Inc. Their published privacy and data-processing terms describe the safeguards they use for international transfers, including the EU–US Data Privacy Framework and the standard contractual clauses where applicable. Services you connect yourself — Telegram, Discord, X and your wallet — run under their own terms, and Telegram is not covered by an EU adequacy decision. Ask us at [email protected] and we will send you what we hold on this.

The other participant in any contract you take part in can see that contract's shared details and your display name and avatar.

Age verification

Browsing DebtKeeper doesn’t require verification, but the actions at its heart — creating or signing a contract, keyholding, playing games, sending tributes, paying with USDC, being publicly listed — require a one-time 18+ check (fully in force from 1 September 2026). Our verification partner Diditoffers two pathways: an ID document check, or facial age estimation from a selfie. Facial age estimation is biometric processing performed by Didit, not by us. A selfie check may still ask for a document if Didit can’t tell your age confidently.

What DebtKeeper stores is limited to the result, how it was reached (ID document, selfie check, or a manual grant by us), the current status of a check in progress, and the check’s risk-code labels — short provider labels such as “date of birth not detected”. We never store images, never store a document, and never store an estimated age.

The images needed for the check are held by Didit under their own privacy policy and deleted after 30 days. You can ask us, or Didit, to delete them sooner. If a check fails wrongly, you can retry or contact us at [email protected] — a mistaken result is never permanent.

Safety holds: if a check indicates someone may be under 18, we place a hold on the account. The record of that hold and its reason is retained after account deletion, on the same legitimate-interest basis as a suspension, because deleting it would let the same person return immediately.

One exception: in rare cases we confirm someone’s age ourselves — for example a creator we already know and have verified directly — and grant the badge without sending them to Didit. When that happens no selfie or document is collected at all, by us or anyone else; we record only who granted it, when, and why. You can ask us at [email protected] which route applied to your account.

Protecting minors

DebtKeeper is an adult service and is built to keep minors out of everything that matters: consequential actions require the 18+ check above for both people involved; accounts that fail verification lose adult-facing features; public page imagery and writings must stay non-explicit (see the Terms), we review and remove what crosses the line, and profile images on public pages are excluded from image search. We keep a written assessment of how children could encounter the service and review it when the service changes. To report content or a user, email [email protected].

Private messages

Your Inbox conversations are yours. Nobody at DebtKeeper reads your private messages — staff can’t browse conversations, and nothing in the product is built to. Conversations are kept so that you and the person you’re talking to can read them — for about twelve months after each message, after which they’re deleted automatically. If either of you chooses to keep a conversation, it stays for as long as it’s kept. Voice notes are kept on the same twelve-month clock. Photos are too — unless you chose to send one that disappears, which stops being viewable about ten minutes after it’s first opened, with the file itself deleted within about a day.

The one exception is moderation, and it only ever starts with one of you. If a participant reports a message or a conversation, a moderator can see the reported content and, by default, a few messages either side of it, so the report makes sense — and nothing in any conversation that hasn’t been reported. A moderator can deliberately widen that window when a report needs it, and every widening is recorded against the report. So that a report can be acted on and its outcome stood behind, a copy of the reported text and its surrounding context is kept for up to two years, even if an account is later deleted; it notes that a photo or voice note was attached but doesn’t include the file, which stays on its normal clock. The report itself and the record of how it was handled are kept as part of our moderation history — it keeps the report’s reason, references, dates and the recorded grounds for any action taken, but not another copy of the conversation.

Answers you submit to a Domme’s application form stay while the application is pending or accepted. If it’s declined, withdrawn or expires, or its required fee is refused or disappears, the answers are scheduled for deletion after ninety days. Deleting either account removes the live application answers immediately. If an application was reported, its report exhibit keeps the questions and any answers the reporter was allowed to see on the two-year moderation clock above, including after account deletion.

Feedback and reports can include a private, text-only conversation between the submitter and the team. The person reported cannot read it or receive its notifications. Your data export includes your own submissions and replies, not private moderation notes or report exhibits. Deleting the submitter account removes these follow-up messages and their in-app notifications, including copies sent to the team. Deleting a team member account removes their attribution from replies on other people’s submissions. Deleting the reported account does not remove the reporter’s support conversation. Previously delivered external notifications cannot be recalled. These rules do not change the report and evidence retention described above.

How long we keep it

We keep your data while your account is active. If you delete your account, your personal data — name, email, avatar, login, profile, your signature and any details you provided on an agreement, and content you authored (writings, testimonials) — is erased, and you show to others as a closed account. Where you are a party to a tracker that the other person relies on as a record, that tracker stays with them: the amounts, the dates and the notes both of you wrote remain, with your name and every account identifier removed. We do not call that anonymous — the other person may well still know who it was from what it contains — and it stays for as long as their account exists.

Three things are kept on purpose after deletion: a record that an account was suspended or placed on an age-safety hold, so the same person cannot simply return; reports and their moderation records, as described under “Private messages”; and a Discord account id until a pending removal from the 18+ server has finished. Encrypted backups exist for disaster recovery only. We never restore one to bring an account back, and if we ever had to restore one after a failure, we would re-apply every deletion made since it was taken.

If you use the USDC option: your wallet settings and verification records are removed when you delete your account; a payment request that was never used becomes eligible for deletion 30 days after it was created, once our clean-up runs, and is removed when either of you deletes an account. A payment request that became a transfer, and the record of that transfer, are kept with the ledger they belong to — the other person relies on them, and they are how the same transfer can never be counted twice. When you delete your account your wallet address on those records is replaced by an irreversible code; the transaction hash, the amounts and the dates stay. What is written on the public ledger is outside our control and cannot be deleted by us or by you, and it still links that transaction to the address you used.

Your rights

Under the GDPR you can ask us for a copy of your personal data, to correct it, to erase it, to restrict or object to how we use it, and to receive the data you gave us in a portable form; where we rely on your consent you can withdraw it at any time. In the app you can:

  • Edit your name and avatar at any time from your profile.
  • Delete your account from your profile, which erases your personal data as described above.
  • Export your data from your profile; if you used the USDC option the export includes the wallet addresses you verified and, for each payment, the network, the asset, its status, the amounts, the transaction hash and its dates. It does not include the other person's wallet address or the exchange-rate details used for the quote.

Erasure removes what we hold; it cannot reach the public ledger, and a record that also belongs to the other person in a ledger stays with that ledger in the reduced form described above. If you have a USDC payment request from the last 72 hours that is still being checked, your deletion is recorded at once and completes on its own once that request is resolved, or 72 hours after it was created, whichever comes first — usually within the hour after that, and no later than two hours after, unless we tell you otherwise. You won't get a separate message when it completes; if you can still sign in, it hasn't completed yet.

For anything else, email [email protected]. You do not need an account to ask, and if we need to check it is really you we ask only for what that takes. Requests are free. We answer within a month; if a request is unusually complex we may take up to two months more, and we tell you within the first month. You can also complain to a data-protection authority — the one where you live or work, or where the problem happened.

Security

Passwords are hashed with bcrypt, all traffic is encrypted over HTTPS, sessions use httpOnly cookies, and access to your data requires authentication. No system is perfectly secure, but we take reasonable measures to protect it.

Contact

For any privacy question or request, email [email protected]. It is read by the person who builds DebtKeeper, not a queue, and you will get an answer from a human. Who that is, and how DebtKeeper is run, is on the About page.

DebtKeeper is provided as-is. We update this policy when our processing changes; material changes are announced in the app and by email, and where a new use needs your consent we ask for it separately.

Privacy Policy · DebtKeeper