Sealed RoseSealed Rose
BrowseFor CreatorsSign in
Legal

Privacy Policy

1. Who we are & scope

Kinetic Helix LLC, a Florida limited liability company, operates Sealed Rose (“Sealed Rose,” “we,” “us,” “our”) — a paid, one-to-one messaging platform connecting verified adult creators with verified adult buyers. This Privacy Policy explains what personal information we collect, why, how we use and share it, and the choices and rights available to you. Sealed Rose is a United States-only service; we do not knowingly offer it outside the U.S. and geofence access accordingly. This Policy does not apply to third-party services we link to or that process data on our behalf under their own terms (payment processors, identity-verification vendors) — see Section 6.

2. Information we collect

  • Account information. Name or display handle, email, password (hashed, never stored in plaintext), date of birth, preferences, and support communications.
  • Payment information. We do not store full card numbers. Card data is collected and processed directly by our payment processor (Epoch), subject to PCI-DSS. We retain only transaction metadata for the credits ledger (amount, timestamp, processor reference ID, approximate card type/last four) — never the full card number, CVV, or track data.
  • Identity and age verification. Creators complete government-ID and liveness verification through our verification partner (Persona); buyers complete a lighter-weight facial age-estimation check, also through Persona. Sealed Rose’s own systems do not retain a copy of your government-issued identity document — see Section 4.
  • Biometric information. A facial-geometry template derived from Creator verification, used solely for ban-evasion matching — see Section 5.
  • Device and network information. IP address, approximate IP-derived geolocation (for U.S.-only geofencing and fraud/VPN detection), device identifiers, browser, and OS — collected automatically for fraud prevention, abuse detection, security, and service operation.
  • Messages and media. The content and metadata of messages, images, video, and audio you send or receive. Embedded metadata (EXIF/GPS/device data) is stripped from uploaded media before storage.
  • Usage information. Pages viewed, features used, session duration, and referral source, via first-party analytics.
  • Information from others. If another user reports, blocks, or transacts with you, we may receive information in that context (a report, a chargeback dispute).

Cookies & similar technologies. We use only first-party cookies — never third-party advertising or tracking cookies. They are: a session cookie that keeps you signed in; sr_vid, a random anonymous visitor identifier (12 months) used for the first-party analytics described above; sr_attr, which records how you first found the site — referring site, campaign tags, and landing page (30 days); and sr_survey_done, which remembers that you answered our one-question discovery survey (12 months). None of these contain your name, email, or browsing history on other sites, and we do not use them for cross-site advertising.

We do not request or accept government ID copies, face templates, or voice samples from buyers beyond the zero-retention age-estimation check in Section 4.

3. How we use it

To create and administer your account and authenticate you; verify that creators and buyers are 18+ and are who they claim to be; detect and prevent banned-user re-registration, fraud, chargeback abuse, account takeover, and geofence evasion; process payments, operate the credits ledger, calculate payouts, and process refunds; deliver, moderate, and protect messages and media, including automated screening for child sexual abuse material (“CSAM”) and other prohibited content before content is stored or made viewable; provide support and respond to reports, disputes, and legal process; understand how visitors find and use the public site, via first-party analytics (acquisition source, pages viewed) so we can improve it; and comply with legal obligations (2257A recordkeeping, NCMEC reporting, tax reporting, law-enforcement requests). We do not use your information for cross-context behavioral advertising, and we do not sell your personal information or biometric information.

4. Age & identity verification

Sealed Rose verifies that every creator and buyer is at least 18, and that every creator is who they claim to be, before either can transact. Creators complete a government-ID capture and liveness check through Persona; buyers complete a lower-friction facial age-estimation check through Persona designed to confirm the buyer appears to be an adult without retaining a copy of any government ID.

How we store (and don’t store) your identity document. Sealed Rose’s own systems and databases do not retain a copy of your government-issued identity document. Our verification partner retains a copy in its own secure, compliance-grade vault, because federal recordkeeping law (28 C.F.R. Part 75, implementing 18 U.S.C. §2257A) requires that a copy of each creator’s government ID be retained for at least seven (7) years. Sealed Rose itself stores only the verification result (pass/fail and tier), a vendor reference ID, and the minimal index fields (name, verified date of birth, content references) the law requires our Custodian of Records to locate on request. We never display your ID to buyers or other creators. Our named Custodian of Records is published on the §2257 statement.

5. Biometric information

Because Sealed Rose enrolls a facial-geometry template from every creator to prevent banned individuals from re-registering, we provide these disclosures consistent with biometric-privacy laws such as the Illinois Biometric Information Privacy Act (“BIPA”) and the sensitive-data provisions of state privacy laws — for all users, regardless of residence.

  • What we collect and why. During creator verification, our partner generates a mathematical face template from the ID and liveness capture. It is used exclusively for ban-evasion detection — comparing a new sign-up against templates from previously banned accounts. It is never used for advertising, shared with buyers, or used to identify you to any other user.
  • Consent. Before capture, you are asked to separately and explicitly consent to the collection, storage, and use of your face template for ban-evasion matching, on a standalone consent screen (not bundled into account creation). Withdrawing consent may require closing your creator account, since ban-evasion matching is a condition of creator platform integrity.
  • Retention and destruction. Face templates are retained for the life of your creator account and up to two (2) years after closure, then permanently destroyed within ninety (90) days after that period expires, or sooner on a valid deletion request that does not conflict with our legal retention obligations.
  • No sale. We do not sell, lease, trade, or profit from your face template or any biometric identifier, and disclose it only to our verification vendor (under contract), as required by law, or with your separate written consent.
  • Voice — not persistently stored. A re-verification check may include a brief live voice challenge to confirm you are a live human at that moment. That sample is processed in real time for that single check and discarded afterward — we do not enroll or store a persistent voiceprint. If that ever changes, we will update this Policy and obtain any additional consent required by law first.

6. How we share information

We do not sell your personal or biometric information to anyone, for any purpose. We share only with: service providers under contract (payment processor Epoch; verification vendor Persona; CSAM-scanning vendor Microsoft PhotoDNA; cloud infrastructure, support, email/notification, and analytics providers), restricted to providing services to us; content-safety reporting to the National Center for Missing & Exploited Children (NCMEC) where content is identified as apparent CSAM, as required by 18 U.S.C. §2258A and the REPORT Act, with preservation of the material for at least one year; and law enforcement under the federal Stored Communications Act (18 U.S.C. §§2701–2712) — message content only on a search warrant, non-content records on a subpoena or §2703(d) order, and voluntary disclosure only under the emergency exception for danger of death or serious physical injury. Government requests for your identity documents go to our verification partner, which holds those records, not to Sealed Rose. Information may also transfer in a merger or asset sale under an equivalent policy, or where you direct us to share it. We do not share personal or biometric information with data brokers or advertisers.

7. Data retention

  • 2257A records (verification result and index fields; the underlying ID copy held by our partner) — seven (7) years from the date of the relevant content, plus an additional five (5) years if Sealed Rose ceases operations, per 28 C.F.R. Part 75.
  • CSAM-related material and reports — preserved in a secured, access-restricted quarantine store for at least one (1) year, per 18 U.S.C. §2258A and the REPORT Act, never returned to the servable path.
  • Biometric face templates — per the schedule in Section 5.
  • Voice liveness samples — not retained; discarded after each check.
  • General account data (profile, messages, media, usage) — retained for the life of your account and ninety (90) days after closure, except where a longer period is required by the obligations above or an active dispute, chargeback, or investigation.
  • Payment/ledger metadata — retained seven (7) years consistent with tax and financial recordkeeping requirements.

8. Security

We maintain administrative, technical, and physical safeguards: encryption in transit and, for the narrow set of sensitive fields in our own systems, at rest; minimization of identity data in our infrastructure (raw ID documents, selfies, and voice recordings are never retained in our own databases); role-based, hardware-key-gated access controls on administrative systems; a pre-storage content-safety gate for uploaded media; and incident-response procedures. No system is perfectly secure; see Section 10.

9. Your rights

Depending on your state, you may have rights under the CCPA/CPRA and comparable laws (Virginia, Colorado, Connecticut, Texas TDPSA, and others): to know/access, delete (subject to the legal-retention exceptions in Section 7 — we cannot delete 2257A-mandated records or active CSAM-preservation records early), correct, limit use of sensitive personal information, opt out of “sale”/“sharing” (we do neither), non-discrimination, and appeal. Because Sealed Rose’s core data relates to sexual content, we treat biometric information and information that reveals sexual orientation or sex-life-adjacent information as sensitive personal information and extend heightened protections to all users, not only residents of states where those protections are independently triggered. To exercise your rights, contact [email protected]; we will verify your identity using account-held information before acting.

10. Breach notification

If we experience a security incident involving unauthorized access to your personal information, we will notify affected users and required regulators consistent with applicable state breach-notification law. Given the sensitive nature of our data, we treat any confirmed unauthorized access to identity-verification results, biometric data, or messaging/content data as presumptively notification-triggering, and will not decline to notify solely because card data or a Social Security number was not involved.

11. Children

Sealed Rose is strictly an 18-and-over platform. We do not knowingly allow anyone under 18 to create an account, and both creators and buyers must pass age/identity verification before transacting. We have zero tolerance for CSAM. All uploaded media is screened before it can be stored or viewed, and any apparent CSAM is removed from the servable path, preserved in a secured quarantine, and reported to NCMEC. If you believe a minor has accessed or is depicted on the Service, contact us immediately at [email protected].

12. Changes & contact

We may update this Policy; material changes will be noticed before they take effect. Questions or requests: Kinetic Helix LLC (d/b/a Sealed Rose), 3256 SW 23rd St, Miami, FL 33145 — [email protected].