Privacy policy
Last updated: September 2026.
At DomBound, privacy is a design principle, not an add-on. This policy explains what data we process, for what purpose and what rights you have, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish data protection law.
1. Data controller
Owner: Víctor Manuel Aldeguer Juárez · NIF: 73996803F · Address: Calle La Calera, 33 - 2º F - 03182 Torrevieja (Alicante) - España · Contact: hola@dombound.com.
2. What data we process
- Account and access: email address and password (managed by the authentication system).
- Profile: alias, role, photographs and any data you choose to show. We do not ask for your real name.
- Profile photos: before being published they go through an automated nudity-detection filter run on our servers. We only keep the result (approved, under review or +18). See section 4.
- Location: city and, if you enable it, GPS position, used only to sort by proximity on the server. Exact coordinates are never shared with or shown to other users.
- Private messages and media: end-to-end encrypted; DomBound cannot read them on its own. They are only decrypted with your explicit consent, through actions you trigger: (a) if you authorise your Owner to supervise a conversation, and (b) if, when reporting a user, you authorise the moderation team to review the messages from the period you specify. Outside those cases, only the participants can read them.
- Dynamic activity: tasks, challenges, chastity, reputation and the like, in order to provide the service.
- Personal details: height, weight, build, position, orientation, situation and experience, plus the identities or communities you identify with (leather, bear…). All of it is optional and you can delete it whenever you want. Your date of birth is stored separately, in a private table only you can read: other people are only ever shown your age.
- Presence: the timestamp of your last activity, so other users can see who is online. You can turn it off in Settings.
- How you found us: if you answer the optional question at sign-up, the channel you pick (and a short free text if you choose “other”). We only use it in aggregate, to know where people come from.
- Declaration of legal age: the fact and date of your confirmation that you are over 18.
- Payments: payment data is handled entirely by the payment provider; DomBound does not store your card.
3. Purposes and legal basis
Special category data (art. 9 GDPR). By the very nature of the platform, we process data revealing your sexual orientation and sex life (D/s role, practices, chastity dynamics, limits and associated media). The legal basis for this processing is your explicit consent (art. 9.2.a GDPR), given separately and informed when you register, which you can withdraw at any time by deleting your account.
Public profile. By default your profile is only visible inside the app, to registered users. If you turn on the “Public profile” switch, your alias’s page becomes reachable from the open internet, with no account, showing your main photo, alias, role, city, age, personal details, identities, practices and limits and, if you have made them public, your chastity records. Much of that is special category data, so turning that switch on means making it public by your own decision (arts. 9(2)(a) and 9(2)(e) GDPR). Think it over first: once published, a page may be copied or indexed by third parties even if you turn it off later. You can turn it off at any time and the page stops being served immediately.
- Provide the service and the features you request — performance of the contract.
- Verify legal age and comply with legal obligations — legal obligation.
- Sort by proximity and display your profile — consent, revocable at any time.
- Aggregate usage analytics, without cookies or profiling — legitimate interest, with a right to object.
- Security, abuse prevention and content moderation — legitimate interest and legal obligation (protection of minors and Regulation (EU) 2022/2065 on Digital Services). Where moderation involves images that may reveal special category data, it is additionally based on your explicit consent.
- Showing your profile outside the app, if you turn on the public profile — explicit consent, revocable.
- Knowing which channel you arrived through, if you answer the sign-up question — consent, optional.
4. Processors and third parties
For specific features we also rely on: OpenStreetMap (nearby-place lookup for location check-ins, queried from our servers), CARTO (check-in maps) and Apple and Google push notification services (delivering alerts to your device). Some operate in the US, with appropriate safeguards.
To operate we use providers that process data on our behalf, with the appropriate safeguards: Supabase (database, storage and authentication), Vercel (web hosting), Dinahosting (domain and email), Resend (delivery of service emails) and, once payment is enabled, Stripe (payment processing). Some may host data outside the European Economic Area, in which case adequate safeguards apply (standard contractual clauses or equivalent).
Image moderation. Profile photos are analysed automatically by Sightengine (Sightengine SAS, France), a provider specialised in detecting explicit sexual content. The image is sent from our servers, never from your browser: the provider does not receive your IP address and does not know who you are. We only keep the outcome of that analysis (approved, under review or +18). Your images are not used to train artificial intelligence models, ours or anyone else’s; this is set out in the data processing agreement signed with the provider, which must also delete them within a maximum of 90 days. Its infrastructure includes sub-processors outside the European Economic Area, so the analysis may take place outside the EU under standard contractual clauses.
Usage analytics. We measure visits with Vercel Web Analytics, the tool provided by our own hosting provider. It uses no cookies and no persistent identifier, it does not track your activity across other websites and it does not build a profile of you: it only aggregates page views and general technical data (country, device type, referring page). We cannot identify you from that data, nor link it to your account if you have one. The legal basis is our legitimate interest in knowing whether the site works and which content is useful; you may object by writing to hola@dombound.com.
5. Retention
We keep your data for as long as your account is active. When you close your account, it is hidden and you have 30 days to recover it; after that period your profile, photos, conversations and activity are deleted. We may retain, for as long as legally required, the minimum data necessary to meet legal obligations or requests from the authorities.
6. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability, as well as withdraw your consent, by writing to hola@dombound.com. You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es).
7. Minors
The service is exclusively for people over 18. We do not knowingly process minors' data. See Age verification.
8. Changes
We may update this policy. We will publish the current version on this page with its update date.