perso.social · Juridisch
Earlier versions
Superseded versions of the perso legal documents, kept available to read.
Van kracht sinds 2026-09-23 · Taal: NL
Deze pagina wordt in het Engels weergegeven.
About this page
- This page keeps earlier versions of the perso legal documents available to read. Each entry below reproduces a superseded version in full, exactly as it was served, with the version number and the date it took effect.
- A superseded version is published here for reference only. The current documents are the ones that apply: the Privacy Policy and the Terms of Service linked from the footer of this site.
- Each entry records the commit that served it, so the text on this page can be checked against the repository that published it.
Privacy Policy, version 2.6
- Effective 3 July 2026. Superseded by version 2.7 on 23 September 2026.
- Served from commit 6d5b0bb6fbc0a2ab5d392f9c934fdad17ae3b3fd, file packages/web/src/content/legal/privacy.ts, sha256 7025e2e5a09372dce9fd60b00bdf58a67813aea1f7070fbe3f14d725b1022906.
- The full text as it was served follows.
Privacy Policy 2.6: Data Controller & Points of Contact (GDPR Art. 13(1)(a); DSA Arts. 11-12)
- - perso.social is operated by ACGG Rent, S.L., a Spanish sociedad limitada and the sole data controller, with registered office (domicilio social) at Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain; CIF B-56240385; registered with the Registro Mercantil de Madrid, Tomo 45565, Folio 30, Hoja M-801410; represented by Etienne Gillard. ACGG Rent, S.L. is established in Spain.
- - perso is not directed to residents of the United Kingdom, the Channel Islands, the Isle of Man, or Gibraltar, and does not offer services to, or monitor the behaviour of, individuals located in those jurisdictions; account creation from a declared residence in any of them is refused. perso has therefore not designated a representative under Article 27 of the UK GDPR.
- - For data-protection enquiries: dpo@perso.social
- - DSA Single Point of Contact: dsa@perso.social
- - General Legal Enquiries: legal@perso.social
- - You have the right to lodge a complaint with the supervisory authority in your country of residence within the European Economic Area.
Privacy Policy 2.6: Identity Verification
- When you choose to verify your identity, you complete the verification process directly with our verification provider. The provider checks your identity documents and performs liveness and fraud-prevention checks. We do not receive or store copies of your identity documents or biometric templates. From the verification outcome, we receive and store only a limited set of attributes linked to your account, such as: whether your verification was successful and which method was used; your verified legal name; a one-way identifier derived from your document number, which we use to prevent the same document from being used to open more than one account, to support account recovery, and to refuse recovery of an account that has been banned; whether your verification relied on certain trusted sources (for example, notified electronic identities) and an audit reference; confirmation that you are at least 18 years old; and your country of residence. Our verification provider sends us a technical payload that can include IP-based location and network metadata (for example, country and city derived from IP, and security signals). We do not read, use, or retain this information; it is not used for profiling, eligibility, or any other purpose, and no precise location data (such as GPS coordinates or IP-derived latitude/longitude) is stored. We use these attributes to confirm that each account is held by a real person, to prevent the same document from being used to open more than one account, to determine eligibility for certain features, and to comply with our legal, safety and platform-integrity obligations. They are stored separately from your public content at the application level and are accessible only to authorised personnel and services that need them for account integrity, safety, support or compliance purposes. We protect them using technical and organisational measures appropriate to their sensitivity, including encryption in transit, encryption at rest provided by our hosting provider, restricted access rights, key management for our de-duplication mechanism, and logging of administrative access. We keep your identity-verification attributes for as long as your account is active. If you delete your account, we delete or irreversibly anonymise these attributes, including the de-duplication identifier, as part of the account-deletion process. We do not retain identity-verification attributes after account deletion, except a limited accountability record of the verification decision and its reason, held for up to 12 months for security and audit purposes, with the email address redacted. In the future, we may retain a non-reversible technical identifier for a limited period solely to prevent abuse (for example, to prevent the same document from being used to open more than one account), and we will update this section before any such mechanism is enabled.
Privacy Policy 2.6: Press Verification
- If you apply for a "verified journalist" badge, we ask you to provide your work email address, the name of your media organisation, and an optional link to a portfolio or recent work. At this stage, we do not collect or store images of press cards or other professional credentials as part of this process. We use this information only to assess your eligibility for a "verified journalist" badge and to prevent misuse of that status. Your work email address is stored in encrypted form and is accessible only to authorised personnel and services involved in verification and audit. These data are stored separately from your public content at the application level. In the future, we may offer you the option to upload a press card or similar professional credential as part of the verification process. If we introduce this feature, we will update this notice before we begin processing these images to explain what we collect, how long we keep it, and how we protect it, including the security measures that apply to any images you choose to upload.
Privacy Policy 2.6: Organisation verification information
- - If you apply for organisation verification, we process the organisation's registration information, the authorised representative's details, and the business email address provided for that application. We use this information to assess and administer organisation verification and retain it only for the periods described in this Privacy Policy.
Privacy Policy 2.6: Account contact details
- - We do not collect a personal email address or phone number when you create a perso account. You can create and use a free perso account without providing either contact detail.
- - We collect an email address in limited circumstances. You may choose to provide one for a press-credential application, organisation-verification application, website contact form, or partner form. We use and retain that information only for the relevant process described in this Privacy Policy. If you purchase paid membership, we also require a billing contact email to administer your membership. See Billing contact email below for how we use, share, and retain that address.
Privacy Policy 2.6: Billing contact email
- When you purchase paid membership, we collect your email address to administer your membership and communicate with you about verification outcomes, subscription status, cancellation, refunds or other remedies, and paid-member support. We process this information because it is necessary to perform our contract with you and meet related legal obligations. We do not use your billing contact email for marketing unless you separately choose to receive marketing communications.
- We use an email-delivery provider to send these communications. The provider processes the billing contact email and the message information needed to deliver and secure the message on our behalf.
- If you do not become eligible for paid participation and your refund or remedy case is completed, we delete your billing contact email 90 days after the case reaches a terminal state, unless we need to keep it longer for an open dispute, legal claim, fraud/security investigation, or a legal accounting or tax obligation.
Privacy Policy 2.6: App updates
- - We may make software updates available to improve security, reliability, and functionality. Where an update service processes personal data on our behalf, we will identify the relevant provider and applicable safeguards in this Privacy Policy before that service is used for the production app.
Privacy Policy 2.6: Security and Technical Logs
- For security, abuse-prevention and operational purposes, we create and retain logs about how our services are used. These logs can include information such as your IP address, your browser or device type and settings, the date and time of your requests, and how you interact with certain features (for example, account recovery and administrative tools). We use these logs to detect and prevent malicious or abusive activity, to investigate incidents, and to maintain the stability and security of the service. We keep this information for as long as necessary for these purposes and then delete it or irreversibly anonymise it.
Privacy Policy 2.6: Infrastructure and Hosting
- perso's own application and database infrastructure is hosted on servers located in the European Union. In particular: application servers are located in France and operated by an EU infrastructure provider (OVHcloud); the primary database is a managed PostgreSQL database from Scaleway (an EU provider) in the Paris region (fr-par), where all connections between the application and the database use Transport Layer Security (TLS) with certificate verification and the database is encrypted at rest by the cloud provider at the storage-volume level (this provider-level encryption is distinct from application-level field encryption, which perso does not apply to identity attributes); the search index is Meilisearch, self-hosted by perso on its EU-based application infrastructure; email delivery uses an EU-based email service provider (IONOS); and key management uses a managed key service provided by Scaleway, used to generate and protect the key for the humanity-deduplication mechanism. perso does not currently use a separate caching layer (such as Redis) or a content delivery network. If perso later introduces such services, this section will be updated before they are used to process users' personal data. Third-party processors, including any processing outside the EU or EEA (such as identity verification, media-scanning, and any future analytics services), are addressed in the sub-processors section below and in perso's subprocessors and international-transfers documentation.
Privacy Policy 2.6: Media You Upload
- Media you upload. When you post images or other media, we store them on European object storage operated by Scaleway in the Paris region, with encryption at rest. We use Microsoft PhotoDNA to screen submitted images and sampled video frames for matches to databases of known child sexual abuse material. This check is designed to help prevent the sharing of known material and protect the safety of our community. When an image is submitted for screening, or when video frames are screened, perso creates and sends only the non-reversible PhotoDNA hash needed for that safety check. Microsoft PhotoDNA returns a screening result, which we use to apply our safety rules and comply with applicable legal obligations. Your media is also automatically screened by a nudity-detection classifier. Media is not displayed until these checks complete. Every video you upload is then withheld from display until an authorized reviewer has reviewed it and approved it, whether or not an automated check flags it, because automated screening of video frames is limited to matches with known material and cannot by itself identify all harmful or unlawful material. For images, the automated checks gate display, and an image is withheld for human review only if the classifier flags it. We do not notify you when a video is approved, and we do not promise a fixed review completion time. If media held for review has not been reviewed within 36 hours of upload, we delete it instead of holding it any longer, and we tell you so that you can upload it again. This is not a decision about you or your content.
Privacy Policy 2.6: Direct messages
- If you use direct messages, we process the message text, conversation information, delivery and request status, read status, and the account relationships needed to provide the feature.
- Messages from people you do not follow may appear as message requests. You can choose who may send you messages: everyone, people you follow, or nobody. You can block another member, which prevents further direct messages between you and that member.
- We retain message content for up to 24 months after the last relevant activity in the conversation. Reading a message, receiving a notification, or background syncing does not extend that period. You may remove a conversation from your own view earlier.
- If you erase your account, we remove your message content from ordinary conversation views. Other participants may retain their own messages and limited thread information, but not a readable copy of your removed message content.
- You may report an individual direct message. A trained authorised reviewer may review the reported message and limited surrounding context needed to assess it.
Privacy Policy 2.6: Data Retention
- perso keeps personal data only for as long as necessary. Account data is retained while your account is active and deleted within 30 days of account deletion via a cascading purge. Identity-verification attributes are retained while your account is active and are deleted or irreversibly anonymised, including the de-duplication identifier, as part of the account-deletion process; perso does not retain identity-verification attributes after account deletion, except a limited accountability record of the verification decision and its reason, held for up to 12 months for security and audit purposes, with the email address redacted. In the future, we may retain a non-reversible technical identifier for a limited period solely to prevent abuse (for example, to prevent the same document from being used to open more than one account), and we will update this section before any such mechanism is enabled. A verification-decision audit record is retained for 12 months from the decision, including past account deletion, for security and accountability purposes, with account-identifying fields redacted. Content data is retained while posted and deleted within 30 days of removal or of account deletion. Moderation audit logs are retained for as long as necessary for accountability under the Digital Services Act. Records of moderation decisions and appeals are retained without a deletion timeline, for the life of that accountability obligation, as the durable record supporting platform-safety and appeal decisions; other moderation audit logs are deleted or irreversibly anonymised once no longer necessary. Security and technical logs are retained for as long as necessary for security, abuse-prevention and operational purposes, then deleted or irreversibly anonymised. Contact-form and partnership-inquiry data is retained for up to 12 months: network identifiers are removed after 90 days and the records are deleted after 12 months. Where an organisation verification application is declined, the personal data of the authorised representative from that application is retained for 365 days from the decline and then deleted. Network identifiers (IP address and browser information) captured with an account-recovery attempt are removed after 30 days; the recovery-attempt record is retained without them as a security-audit record. CSAM evidence: where we detect or are notified of suspected child sexual abuse material (CSAM), we immediately remove or disable access to that content on our service but may retain associated hashes, metadata and a minimal evidentiary copy in a segregated evidence store for as long as necessary to comply with our legal obligations, cooperate with competent authorities and protect victims, and then delete it securely. Analytics data is pseudonymised and aggregated and retained no longer than necessary for the purposes described in this policy.
Privacy Policy 2.6: Lawful Basis for Processing
- - Performance of a contract (GDPR Art. 6(1)(b)), together with the substantial-public-interest condition (GDPR Art. 9(2)(g)) for the special-category biometric data, for identity verification.
- - Consent (GDPR Art. 6(1)(a)) for analytics and marketing cookies.
- - Contract performance (GDPR Art. 6(1)(b)) for account operation and feature delivery.
- - Legal obligation (GDPR Art. 6(1)(c)) for fraud prevention and law-enforcement requests.
- - Legitimate interest (GDPR Art. 6(1)(f)) for service security and abuse prevention.
Privacy Policy 2.6: Your Rights
- Under GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. Erasure ("Right to be Forgotten", Art. 17) and portability (Art. 20) are exposed in-app under Settings → Your Data Rights.
Privacy Policy 2.6: Automated Decision-Making (GDPR Art. 22)
- Most processing at perso does not involve solely automated decisions with legal or similarly significant effects. There is one exception, disclosed here with the safeguards that apply to it. To prevent the same document from being used to open more than one account, the outcome of your identity verification is automatically checked against a non-reversible de-duplication identifier derived from your identity document number. If it matches an already-verified account, your verification is automatically declined and a second account is not created. Because this is a solely automated decision that can significantly affect you (it can prevent you from opening an account), the GDPR Article 22(3) safeguards apply: you have the right to contest the decision, to obtain human review, and to express your point of view. To exercise these rights, email dpo@perso.social from the email address linked to your attempt, stating that you believe the duplicate decision is wrong and why (for example, that you are a different person who was matched in error). A human reviewer will re-examine your case, and if the decline was incorrect we will let you re-verify. Account matching decision. When you verify your identity, whether to recover an account or as part of opening a new one, the one-way identifier derived from your document number is automatically compared against existing accounts. If it does not match an account we can return to you, verification does not proceed. That is the case when no account exists for that identity, when the account was deleted, and when the account is one we have permanently closed. We do not tell you which of these applies, because the reason could reveal the status of an account that is not yours. Because this comparison is automated and can significantly affect you, the Article 22(3) safeguards apply: you can contest the outcome, obtain human review, and express your point of view. Write to dpo@perso.social. A person will review whether the match is correct. If your document was matched to an account that is not yours, we will clear the match so that you can verify and open your own account. We will not give you access to the matched account, and this review does not reconsider any decision we made about that account. Age determination. perso is only for adults. Before an approved verification is accepted, an automated check confirms that its age evidence positively establishes that you are 18 or older. If it does not, whether because the evidence shows you are under 18 or because it could not be read, your verification is automatically declined and no account is created. This check is deliberately strict: absent or unreadable age evidence is treated as not passing rather than guessed. We do not retain your date of birth. The one exception is narrow and temporary: if you contest an age decline and then verify again while that contest is open, we keep the date of birth read from that retry, together with the birthdate you tell us, solely so a person can compare them and judge whether the automated check misread your document. We keep those two dates only while your contest is open, and we delete them the moment it is resolved, whichever way it is resolved; what remains afterward is only the record that a decision was made and its reason. If your verification succeeds, we keep only the fact that the over-18 check passed; if it is declined and not contested, we keep only the decline and its reason category. Because this is a solely automated decision that can significantly affect you, the Article 22(3) safeguards apply: you can contest the outcome, obtain human review, and express your point of view. Write to dpo@perso.social and a person will review your case. If a person reviews your case and confirms from the evidence that you are over 18, we apply that confirmation so your next verification is accepted on the strength of it, and a correct outcome takes effect on your account rather than the same automated misreading repeating. If you are under 18, you are welcome to join once you meet the age requirement. Today, content moderation on perso is primarily human: we may review posts and accounts and restrict or remove them in accordance with our rules and the Digital Services Act (DSA). Where a moderation decision is based on an automated check (for example, to detect duplicate accounts), you have the safeguards required by Article 22(3) GDPR: you will be informed when an automated decision is made, you can contest it and express your point of view, and you can ask for a human to review the decision. Automated media-safety screening. We use automated media-safety screening to help detect and prevent the sharing of known child sexual abuse material. When an image is submitted for screening, or when video frames are screened, perso generates a non-reversible PhotoDNA hash from the image or video frame and compares it against reference hashes of known illegal material. We use a match result to take safety action under our rules, including restricting, removing, or escalating the relevant content for review where appropriate. If an automated decision has a legal or similarly significant effect on you, you may contact us to request human review, express your point of view, and challenge the decision. Automated screening of uploaded media. Media you upload is automatically evaluated by a nudity-detection classifier before it can be shown to others. If the classifier flags your content, the content is withheld from display until we have reviewed it. Separately, and regardless of what any automated check returns, every video is withheld until an authorized reviewer has reviewed it and approved it. This automated step does not by itself suspend your account or impose penalties; it gates visibility pending human review. You can contest a resulting moderation decision through our complaint and appeal process.
Privacy Policy 2.6: Sub-Processors
- - Didit: identity verification. Acts as our data processor, on our documented instructions, for identity verification and de-duplication. We never receive your identity-document images, biometric templates, or document nationality; Didit processes biometric data only transiently during the verification session, and we configure the session for immediate deletion at the vendor once the verification outcome is returned. The verification payload may also contain technical and security signals, including IP-based location metadata. perso does not read, use, or retain these signals.
- - OVHcloud (France): application server hosting.
- - Scaleway (France, Paris region): managed PostgreSQL database, key management, and future object storage.
- - IONOS (EU): email delivery.
- - Microsoft (PhotoDNA Cloud Service): detection of known child sexual abuse material via perceptual-hash matching. Data: a non-reversible perceptual hash of uploaded media plus operational request metadata; no image content or account identifiers in the routine path. Location: Microsoft EU instance (processed within the EEA). Safeguard: processed within the EEA; for any incidental access from outside the EEA, perso relies on Microsoft's EU-U.S. Data Privacy Framework certification and, as a fallback, the 2021 Standard Contractual Clauses in Microsoft's DPA.
Privacy Policy 2.6: App stores and platform providers
- Apple and Google provide app-distribution services. Where you use an app-store feature, the relevant platform provider processes information under its own privacy terms. If perso later enables paid membership or in-app purchases, we will update this Privacy Policy and the relevant payment information before those features become available.
Privacy Policy 2.6: International transfers
- Some of our service providers may process personal data outside the United Kingdom, European Economic Area, or another jurisdiction in which you live. Where this occurs, we use the safeguards required by applicable data-protection law. These may include an adequacy decision, approved contractual protections, or another lawful transfer mechanism.
- For child-safety screening, perso sends non-reversible PhotoDNA hashes generated from submitted images and sampled frames from submitted video to Microsoft's European PhotoDNA endpoint. We do not send the original image or video, a link to the media, or the uploader's account identifier for this check.
- You can contact us to request further information about the safeguards that apply to a particular international transfer. Where we receive a request for personal data from a public authority outside the United Kingdom or European Economic Area, we assess the request and applicable legal requirements before responding and, where permitted, challenge or narrow requests that appear unlawful, disproportionate, or overbroad.
Privacy Policy 2.6: Data Protection Contact
- For data-protection enquiries: dpo@perso.social.
Privacy Policy 2.6: Supervisory Authority
- Users in the European Economic Area have the right to lodge a complaint with their local supervisory authority.
Privacy Policy 2.6: United Kingdom, Crown Dependencies & Gibraltar: No Article 27 Representative
- perso is not directed to residents of the United Kingdom, the Channel Islands, the Isle of Man, or Gibraltar, and does not offer services to, or monitor the behaviour of, individuals located in those jurisdictions; account creation from a declared residence in any of them is refused. perso has therefore not designated a representative under Article 27 of the UK GDPR.
Privacy Policy 2.6: Contact
- - Privacy questions: dpo@perso.social.
- - Data Controller: perso.social is operated by ACGG Rent, S.L., a Spanish sociedad limitada, with registered office (domicilio social) at Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain; CIF B-56240385; registered with the Registro Mercantil de Madrid, Tomo 45565, Folio 30, Hoja M-801410. Represented by Etienne Gillard. ACGG Rent, S.L. is the sole data controller, established in Spain.
Privacy Policy, version 2.7
- Effective 23 September 2026. Superseded by version 2.8 on 26 September 2026.
- Served from commit 32940b25cdbd32e276bd8ec352b51967aa2c89dc, file packages/web/src/content/legal/privacy.ts, sha256 e45b06eb24f3e0609cae637846d2e7cb5d335a458db3c9b45011377e39b5d54a.
- The full text as it was served follows.
Privacy Policy 2.7: Data Controller & Points of Contact (GDPR Art. 13(1)(a); DSA Arts. 11-12)
- - perso.social is operated by ACGG Rent, S.L., a Spanish sociedad limitada and the sole data controller, with registered office (domicilio social) at Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain; CIF B-56240385; registered with the Registro Mercantil de Madrid, Tomo 45565, Folio 30, Hoja M-801410; represented by Etienne Gillard. ACGG Rent, S.L. is established in Spain.
- - perso is not directed to residents of the United Kingdom, the Channel Islands, the Isle of Man, or Gibraltar, and does not offer services to, or monitor the behaviour of, individuals located in those jurisdictions; account creation from a declared residence in any of them is refused. perso has therefore not designated a representative under Article 27 of the UK GDPR.
- - For data-protection enquiries: dpo@perso.social
- - DSA Single Point of Contact: dsa@perso.social
- - General Legal Enquiries: legal@perso.social
- - You have the right to lodge a complaint with the supervisory authority in your country of residence within the European Economic Area.
Privacy Policy 2.7: Identity Verification
- When you choose to verify your identity, you complete the verification process directly with our verification provider. The provider checks your identity documents and performs liveness and fraud-prevention checks. We do not receive or store copies of your identity documents or biometric templates. From the verification outcome, we receive and store only a limited set of attributes linked to your account, such as: whether your verification was successful and which method was used; your verified legal name; a one-way identifier derived from your document number, which we use to prevent the same document from being used to open more than one account, to support account recovery, and to refuse recovery of an account that has been banned; whether your verification relied on certain trusted sources (for example, notified electronic identities) and an audit reference; confirmation that you are at least 18 years old; and your country of residence. Our verification provider sends us a technical payload that can include IP-based location and network metadata (for example, country and city derived from IP, and security signals). We do not read, use, or retain this information; it is not used for profiling, eligibility, or any other purpose, and no precise location data (such as GPS coordinates or IP-derived latitude/longitude) is stored. We use these attributes to confirm that each account is held by a real person, to prevent the same document from being used to open more than one account, to determine eligibility for certain features, and to comply with our legal, safety and platform-integrity obligations. They are stored separately from your public content at the application level and are accessible only to authorised personnel and services that need them for account integrity, safety, support or compliance purposes. We protect them using technical and organisational measures appropriate to their sensitivity, including encryption in transit, encryption at rest provided by our hosting provider, restricted access rights, key management for our de-duplication mechanism, and logging of administrative access. We keep your identity-verification attributes for as long as your account is active. If you delete your account, we delete or irreversibly anonymise these attributes, including the de-duplication identifier, as part of the account-deletion process. We do not retain identity-verification attributes after account deletion, except a limited accountability record of the verification decision and its reason, held for up to 12 months for security and audit purposes, with the email address redacted. In the future, we may retain a non-reversible technical identifier for a limited period solely to prevent abuse (for example, to prevent the same document from being used to open more than one account), and we will update this section before any such mechanism is enabled.
Privacy Policy 2.7: Press Verification
- If you apply for a "verified journalist" badge, we ask you to provide your work email address, the name of your media organisation, and an optional link to a portfolio or recent work. At this stage, we do not collect or store images of press cards or other professional credentials as part of this process. We use this information only to assess your eligibility for a "verified journalist" badge and to prevent misuse of that status. Your work email address is stored in encrypted form and is accessible only to authorised personnel and services involved in verification and audit. These data are stored separately from your public content at the application level. In the future, we may offer you the option to upload a press card or similar professional credential as part of the verification process. If we introduce this feature, we will update this notice before we begin processing these images to explain what we collect, how long we keep it, and how we protect it, including the security measures that apply to any images you choose to upload.
Privacy Policy 2.7: Organisation verification information
- - If you apply for organisation verification, we process the organisation's registration information, the authorised representative's details, and the business email address provided for that application. We use this information to assess and administer organisation verification and retain it only for the periods described in this Privacy Policy.
Privacy Policy 2.7: Account contact details
- - We do not collect a personal email address or phone number when you create a perso account. You can create and use a free perso account without providing either contact detail.
- - We collect an email address in limited circumstances. You may choose to provide one for a press-credential application, organisation-verification application, website contact form, or partner form. We use and retain that information only for the relevant process described in this Privacy Policy. If you purchase paid membership, we also require a billing contact email to administer your membership. See Billing contact email below for how we use, share, and retain that address.
Privacy Policy 2.7: Billing contact email
- When you purchase paid membership, we collect your email address to administer your membership and communicate with you about verification outcomes, subscription status, cancellation, refunds or other remedies, and paid-member support. We process this information because it is necessary to perform our contract with you and meet related legal obligations. We do not use your billing contact email for marketing unless you separately choose to receive marketing communications.
- We use an email-delivery provider to send these communications. The provider processes the billing contact email and the message information needed to deliver and secure the message on our behalf.
- If you do not become eligible for paid participation and your refund or remedy case is completed, we delete your billing contact email 90 days after the case reaches a terminal state, unless we need to keep it longer for an open dispute, legal claim, fraud/security investigation, or a legal accounting or tax obligation.
Privacy Policy 2.7: App updates
- - We may make software updates available to improve security, reliability, and functionality. Where an update service processes personal data on our behalf, we will identify the relevant provider and applicable safeguards in this Privacy Policy before that service is used for the production app.
Privacy Policy 2.7: Security and Technical Logs
- For security, abuse-prevention and operational purposes, we create and retain logs about how our services are used. These logs can include information such as your IP address, your browser or device type and settings, the date and time of your requests, and how you interact with certain features (for example, account recovery and administrative tools). We use these logs to detect and prevent malicious or abusive activity, to investigate incidents, and to maintain the stability and security of the service. We keep this information for as long as necessary for these purposes and then delete it or irreversibly anonymise it.
Privacy Policy 2.7: Infrastructure and Hosting
- perso's own application and database infrastructure is hosted on servers located in the European Union. In particular: application servers are located in France and operated by an EU infrastructure provider (OVHcloud); the primary database is a managed PostgreSQL database from Scaleway (an EU provider) in the Paris region (fr-par), where all connections between the application and the database use Transport Layer Security (TLS) with certificate verification and the database is encrypted at rest by the cloud provider at the storage-volume level (this provider-level encryption is distinct from application-level field encryption, which perso does not apply to identity attributes); the search index is Meilisearch, self-hosted by perso on its EU-based application infrastructure; email delivery uses an EU-based email service provider (IONOS); and key management uses a managed key service provided by Scaleway, used to generate and protect the key for the humanity-deduplication mechanism. perso does not currently use a separate caching layer (such as Redis) or a content delivery network. If perso later introduces such services, this section will be updated before they are used to process users' personal data. Third-party processors, including any processing outside the EU or EEA (such as identity verification, media-scanning, and any future analytics services), are addressed in the sub-processors section below and in perso's subprocessors and international-transfers documentation.
Privacy Policy 2.7: Media You Upload
- Media you upload. When you post images or other media, we store them on European object storage operated by Scaleway in the Paris region, with encryption at rest. We use Microsoft PhotoDNA to screen submitted images and sampled video frames for matches to databases of known child sexual abuse material. This check is designed to help prevent the sharing of known material and protect the safety of our community. When an image is submitted for screening, or when video frames are screened, perso creates and sends only the non-reversible PhotoDNA hash needed for that safety check. Microsoft PhotoDNA returns a screening result, which we use to apply our safety rules and comply with applicable legal obligations. Your media is also automatically screened by a nudity-detection classifier. Media is not displayed until these checks complete. Every video you upload is then withheld from display until an authorized reviewer has reviewed it and approved it, whether or not an automated check flags it, because automated screening of video frames is limited to matches with known material and cannot by itself identify all harmful or unlawful material. For images, the automated checks gate display, and an image is withheld for human review only if the classifier flags it. We do not notify you when a video is approved, and we do not promise a fixed review completion time. If media held for review has not been reviewed within 36 hours of upload, we delete it instead of holding it any longer, and we tell you so that you can upload it again. This is not a decision about you or your content.
Privacy Policy 2.7: Direct messages
- If you use direct messages, we process the message text, conversation information, delivery and request status, read status, and the account relationships needed to provide the feature.
- Messages from people you do not follow may appear as message requests. You can choose who may send you messages: everyone, people you follow, or nobody. You can block another member, which prevents further direct messages between you and that member.
- Message content. We retain message content for up to 24 months after the last relevant activity in the conversation. We may retain relevant messages for longer where the review, report, appeal, safety, legal, dispute or hold exception described below applies.
- If you erase your account, we remove your message content from ordinary conversation views. Other participants may retain their own messages and limited thread information, but not a readable copy of your removed message content.
- You may report an individual direct message. A trained authorised reviewer may review the reported message and limited surrounding context needed to assess it.
Privacy Policy 2.7: Data Retention
- perso keeps personal data only for as long as necessary. Account data is retained while your account is active and deleted within 30 days of account deletion via a cascading purge. Identity-verification attributes are retained while your account is active and are deleted or irreversibly anonymised, including the de-duplication identifier, as part of the account-deletion process; perso does not retain identity-verification attributes after account deletion, except a limited accountability record of the verification decision and its reason, held for up to 12 months for security and audit purposes, with the email address redacted. In the future, we may retain a non-reversible technical identifier for a limited period solely to prevent abuse (for example, to prevent the same document from being used to open more than one account), and we will update this section before any such mechanism is enabled. A verification-decision audit record is retained for 12 months from the decision, including past account deletion, for security and accountability purposes, with account-identifying fields redacted. Content data. We retain posts, comments and associated content data while they are available on perso. After removal, we normally delete them within 30 days. We may retain relevant content for longer where the review, report, appeal, safety, legal, dispute or hold exception described below applies. Moderation audit logs are retained for as long as necessary for accountability under the Digital Services Act. Records of moderation decisions and appeals are retained without a deletion timeline, for the life of that accountability obligation, as the durable record supporting platform-safety and appeal decisions; other moderation audit logs are deleted or irreversibly anonymised once no longer necessary. Security and technical logs are retained for as long as necessary for security, abuse-prevention and operational purposes, then deleted or irreversibly anonymised. Contact-form and partnership-inquiry data is retained for up to 12 months: network identifiers are removed after 90 days and the records are deleted after 12 months. Where an organisation verification application is declined, the personal data of the authorised representative from that application is retained for 365 days from the decline and then deleted. Network identifiers (IP address and browser information) captured with an account-recovery attempt are removed after 30 days; the recovery-attempt record is retained without them as a security-audit record. CSAM evidence: where we detect or are notified of suspected child sexual abuse material (CSAM), we immediately remove or disable access to that content on our service but may retain associated hashes, metadata and a minimal evidentiary copy in a segregated evidence store for as long as necessary to comply with our legal obligations, cooperate with competent authorities and protect victims, and then delete it securely. Analytics data is pseudonymised and aggregated and retained no longer than necessary for the purposes described in this policy.
- Reviews, reports, appeals and holds. We may retain content, messages and related account information for longer than the periods above where this is necessary to review or resolve an open report, complaint, appeal, account restriction, dispute, suspected misuse, safety matter, or legal claim. We keep that information only for as long as needed for the relevant review or process. If a legal, regulatory, law-enforcement, court, or preservation obligation applies, we may retain the relevant information for the period required or permitted by that obligation. Once the review, appeal, hold or other applicable process ends, we delete or anonymise the information in accordance with our retention schedule unless another lawful reason to retain it applies.
Privacy Policy 2.7: Lawful Basis for Processing
- - Performance of a contract (GDPR Art. 6(1)(b)), together with the substantial-public-interest condition (GDPR Art. 9(2)(g)) for the special-category biometric data, for identity verification.
- - Consent (GDPR Art. 6(1)(a)) for analytics and marketing cookies.
- - Contract performance (GDPR Art. 6(1)(b)) for account operation and feature delivery.
- - Legal obligation (GDPR Art. 6(1)(c)) for fraud prevention and law-enforcement requests.
- - Legitimate interest (GDPR Art. 6(1)(f)) for service security and abuse prevention.
Privacy Policy 2.7: Your Rights
- Under GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. Erasure ("Right to be Forgotten", Art. 17) and portability (Art. 20) are exposed in-app under Settings → Your Data Rights.
Privacy Policy 2.7: Automated Decision-Making (GDPR Art. 22)
- Most processing at perso does not involve solely automated decisions with legal or similarly significant effects. There is one exception, disclosed here with the safeguards that apply to it. To prevent the same document from being used to open more than one account, the outcome of your identity verification is automatically checked against a non-reversible de-duplication identifier derived from your identity document number. If it matches an already-verified account, your verification is automatically declined and a second account is not created. Because this is a solely automated decision that can significantly affect you (it can prevent you from opening an account), the GDPR Article 22(3) safeguards apply: you have the right to contest the decision, to obtain human review, and to express your point of view. To exercise these rights, email dpo@perso.social from the email address linked to your attempt, stating that you believe the duplicate decision is wrong and why (for example, that you are a different person who was matched in error). A human reviewer will re-examine your case, and if the decline was incorrect we will let you re-verify. Account matching decision. When you verify your identity, whether to recover an account or as part of opening a new one, the one-way identifier derived from your document number is automatically compared against existing accounts. If it does not match an account we can return to you, verification does not proceed. That is the case when no account exists for that identity, when the account was deleted, and when the account is one we have permanently closed. We do not tell you which of these applies, because the reason could reveal the status of an account that is not yours. Because this comparison is automated and can significantly affect you, the Article 22(3) safeguards apply: you can contest the outcome, obtain human review, and express your point of view. Write to dpo@perso.social. A person will review whether the match is correct. If your document was matched to an account that is not yours, we will clear the match so that you can verify and open your own account. We will not give you access to the matched account, and this review does not reconsider any decision we made about that account. Age determination. perso is only for adults. Before an approved verification is accepted, an automated check confirms that its age evidence positively establishes that you are 18 or older. If it does not, whether because the evidence shows you are under 18 or because it could not be read, your verification is automatically declined and no account is created. This check is deliberately strict: absent or unreadable age evidence is treated as not passing rather than guessed. We do not retain your date of birth. The one exception is narrow and temporary: if you contest an age decline and then verify again while that contest is open, we keep the date of birth read from that retry, together with the birthdate you tell us, solely so a person can compare them and judge whether the automated check misread your document. We keep those two dates only while your contest is open, and we delete them the moment it is resolved, whichever way it is resolved; what remains afterward is only the record that a decision was made and its reason. If your verification succeeds, we keep only the fact that the over-18 check passed; if it is declined and not contested, we keep only the decline and its reason category. Because this is a solely automated decision that can significantly affect you, the Article 22(3) safeguards apply: you can contest the outcome, obtain human review, and express your point of view. Write to dpo@perso.social and a person will review your case. If a person reviews your case and confirms from the evidence that you are over 18, we apply that confirmation so your next verification is accepted on the strength of it, and a correct outcome takes effect on your account rather than the same automated misreading repeating. If you are under 18, you are welcome to join once you meet the age requirement. Today, content moderation on perso is primarily human: we may review posts and accounts and restrict or remove them in accordance with our rules and the Digital Services Act (DSA). Where a moderation decision is based on an automated check (for example, to detect duplicate accounts), you have the safeguards required by Article 22(3) GDPR: you will be informed when an automated decision is made, you can contest it and express your point of view, and you can ask for a human to review the decision. Automated media-safety screening. We use automated media-safety screening to help detect and prevent the sharing of known child sexual abuse material. When an image is submitted for screening, or when video frames are screened, perso generates a non-reversible PhotoDNA hash from the image or video frame and compares it against reference hashes of known illegal material. We use a match result to take safety action under our rules, including restricting, removing, or escalating the relevant content for review where appropriate. If an automated decision has a legal or similarly significant effect on you, you may contact us to request human review, express your point of view, and challenge the decision. Automated screening of uploaded media. Media you upload is automatically evaluated by a nudity-detection classifier before it can be shown to others. If the classifier flags your content, the content is withheld from display until we have reviewed it. Separately, and regardless of what any automated check returns, every video is withheld until an authorized reviewer has reviewed it and approved it. This automated step does not by itself suspend your account or impose penalties; it gates visibility pending human review. You can contest a resulting moderation decision through our complaint and appeal process.
Privacy Policy 2.7: Sub-Processors
- - Didit: identity verification. Acts as our data processor, on our documented instructions, for identity verification and de-duplication. We never receive your identity-document images, biometric templates, or document nationality; Didit processes biometric data only transiently during the verification session, and we configure the session for immediate deletion at the vendor once the verification outcome is returned. The verification payload may also contain technical and security signals, including IP-based location metadata. perso does not read, use, or retain these signals.
- - OVHcloud (France): application server hosting.
- - Scaleway (France, Paris region): managed PostgreSQL database, key management, and future object storage.
- - IONOS (EU): email delivery.
- - Microsoft (PhotoDNA Cloud Service): detection of known child sexual abuse material via perceptual-hash matching. Data: a non-reversible perceptual hash of uploaded media plus operational request metadata; no image content or account identifiers in the routine path. Location: Microsoft EU instance (processed within the EEA). Safeguard: processed within the EEA; for any incidental access from outside the EEA, perso relies on Microsoft's EU-U.S. Data Privacy Framework certification and, as a fallback, the 2021 Standard Contractual Clauses in Microsoft's DPA.
Privacy Policy 2.7: App stores and platform providers
- Apple and Google provide app-distribution services. Where you use an app-store feature, the relevant platform provider processes information under its own privacy terms. If perso later enables paid membership or in-app purchases, we will update this Privacy Policy and the relevant payment information before those features become available.
Privacy Policy 2.7: International transfers
- Some of our service providers may process personal data outside the United Kingdom, European Economic Area, or another jurisdiction in which you live. Where this occurs, we use the safeguards required by applicable data-protection law. These may include an adequacy decision, approved contractual protections, or another lawful transfer mechanism.
- For child-safety screening, perso sends non-reversible PhotoDNA hashes generated from submitted images and sampled frames from submitted video to Microsoft's European PhotoDNA endpoint. We do not send the original image or video, a link to the media, or the uploader's account identifier for this check.
- You can contact us to request further information about the safeguards that apply to a particular international transfer. Where we receive a request for personal data from a public authority outside the United Kingdom or European Economic Area, we assess the request and applicable legal requirements before responding and, where permitted, challenge or narrow requests that appear unlawful, disproportionate, or overbroad.
Privacy Policy 2.7: Data Protection Contact
- For data-protection enquiries: dpo@perso.social.
Privacy Policy 2.7: Supervisory Authority
- Users in the European Economic Area have the right to lodge a complaint with their local supervisory authority.
Privacy Policy 2.7: United Kingdom, Crown Dependencies & Gibraltar: No Article 27 Representative
- perso is not directed to residents of the United Kingdom, the Channel Islands, the Isle of Man, or Gibraltar, and does not offer services to, or monitor the behaviour of, individuals located in those jurisdictions; account creation from a declared residence in any of them is refused. perso has therefore not designated a representative under Article 27 of the UK GDPR.
Privacy Policy 2.7: Contact
- - Privacy questions: dpo@perso.social.
- - Data Controller: perso.social is operated by ACGG Rent, S.L., a Spanish sociedad limitada, with registered office (domicilio social) at Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain; CIF B-56240385; registered with the Registro Mercantil de Madrid, Tomo 45565, Folio 30, Hoja M-801410. Represented by Etienne Gillard. ACGG Rent, S.L. is the sole data controller, established in Spain.
Privacy Policy, version 2.8
- Effective 26 September 2026. Superseded by version 2.9 on 1 October 2026.
- Served from commit 04a7f4c11e009817d5d93679d1c91691e4de37be, file packages/web/src/content/legal/privacy.ts, sha256 13a2f0548db2f301bca7f4ec6406652ddeaa1415675b4a718a22d788367fa31a.
- The full text as it was served follows.
Privacy Policy 2.8: Data Controller & Points of Contact (GDPR Art. 13(1)(a); DSA Arts. 11-12)
- - perso.social is operated by ACGG Rent, S.L., a Spanish sociedad limitada and the sole data controller, with registered office (domicilio social) at Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain; NIF B-56240385; registered with the Registro Mercantil de Madrid, Tomo 45565, Folio 30, Hoja M-801410; represented by Etienne Gillard. ACGG Rent, S.L. is established in Spain.
- - perso is not directed to residents of the United Kingdom, the Channel Islands, the Isle of Man, or Gibraltar, and does not offer services to, or monitor the behaviour of, individuals located in those jurisdictions; account creation from a declared residence in any of them is refused. perso has therefore not designated a representative under Article 27 of the UK GDPR.
- - For data-protection enquiries: dpo@perso.social
- - DSA Single Point of Contact: dsa@perso.social
- - General Legal Enquiries: legal@perso.social
- - You have the right to lodge a complaint with the supervisory authority in your country of residence within the European Economic Area.
Privacy Policy 2.8: Identity Verification
- When you choose to verify your identity, you complete the verification process directly with our verification provider. The provider checks your identity documents and performs liveness and fraud-prevention checks. We do not receive or store copies of your identity documents or biometric templates. From the verification outcome, we receive and store only a limited set of attributes linked to your account, such as: whether your verification was successful and which method was used; your verified legal name; a one-way identifier derived from your document number, which we use to prevent the same document from being used to open more than one account, to support account recovery, and to refuse recovery of an account that has been banned; whether your verification relied on certain trusted sources (for example, notified electronic identities) and an audit reference; confirmation that you are at least 18 years old; and your country of residence. Our verification provider sends us a technical payload that can include IP-based location and network metadata (for example, country and city derived from IP, and security signals). We do not read, use, or retain this information; it is not used for profiling, eligibility, or any other purpose, and no precise location data (such as GPS coordinates or IP-derived latitude/longitude) is stored. We use these attributes to confirm that each account is held by a real person, to prevent the same document from being used to open more than one account, to determine eligibility for certain features, and to comply with our legal, safety and platform-integrity obligations. They are stored separately from your public content at the application level and are accessible only to authorised personnel and services that need them for account integrity, safety, support or compliance purposes. We protect them using technical and organisational measures appropriate to their sensitivity, including encryption in transit, encryption at rest provided by our hosting provider, restricted access rights, key management for our de-duplication mechanism, and logging of administrative access. We keep your identity-verification attributes for as long as your account is active. If you delete your account, we delete or irreversibly anonymise these attributes, including the de-duplication identifier, as part of the account-deletion process. We do not retain identity-verification attributes after account deletion, except a limited accountability record of the verification decision and its reason, held for up to 12 months for security and audit purposes, with the email address redacted. In the future, we may retain a non-reversible technical identifier for a limited period solely to prevent abuse (for example, to prevent the same document from being used to open more than one account), and we will update this section before any such mechanism is enabled.
Privacy Policy 2.8: Press Verification
- If you apply for a "verified journalist" badge, we ask you to provide your work email address, the name of your media organisation, and an optional link to a portfolio or recent work. At this stage, we do not collect or store images of press cards or other professional credentials as part of this process. We use this information only to assess your eligibility for a "verified journalist" badge and to prevent misuse of that status. Your work email address is stored in encrypted form and is accessible only to authorised personnel and services involved in verification and audit. These data are stored separately from your public content at the application level. In the future, we may offer you the option to upload a press card or similar professional credential as part of the verification process. If we introduce this feature, we will update this notice before we begin processing these images to explain what we collect, how long we keep it, and how we protect it, including the security measures that apply to any images you choose to upload.
Privacy Policy 2.8: Organisation verification information
- - If you apply for organisation verification, we process the organisation's registration information, the authorised representative's details, and the business email address provided for that application. We use this information to assess and administer organisation verification and retain it only for the periods described in this Privacy Policy.
Privacy Policy 2.8: Account contact details
- - We do not collect a personal email address or phone number when you create a perso account. You can create and use a free perso account without providing either contact detail.
- - We collect an email address in limited circumstances. You may choose to provide one for a press-credential application, organisation-verification application, website contact form, or partner form. We use and retain that information only for the relevant process described in this Privacy Policy. If you purchase paid membership, we also require a billing contact email to administer your membership. See Billing contact email below for how we use, share, and retain that address.
Privacy Policy 2.8: Billing contact email
- When you purchase paid membership, we collect your email address to administer your membership and communicate with you about verification outcomes, subscription status, cancellation, refunds or other remedies, and paid-member support. We process this information because it is necessary to perform our contract with you and meet related legal obligations. We do not use your billing contact email for marketing unless you separately choose to receive marketing communications.
- We use an email-delivery provider to send these communications. The provider processes the billing contact email and the message information needed to deliver and secure the message on our behalf.
- If you do not become eligible for paid participation and your refund or remedy case is completed, we delete your billing contact email 90 days after the case reaches a terminal state, unless we need to keep it longer for an open dispute, legal claim, fraud/security investigation, or a legal accounting or tax obligation.
Privacy Policy 2.8: App updates
- - We may make software updates available to improve security, reliability, and functionality. Where an update service processes personal data on our behalf, we will identify the relevant provider and applicable safeguards in this Privacy Policy before that service is used for the production app.
Privacy Policy 2.8: Security and Technical Logs
- For security, abuse-prevention and operational purposes, we create and retain logs about how our services are used. These logs can include information such as your IP address, your browser or device type and settings, the date and time of your requests, and how you interact with certain features (for example, account recovery and administrative tools). We use these logs to detect and prevent malicious or abusive activity, to investigate incidents, and to maintain the stability and security of the service. We keep this information for as long as necessary for these purposes and then delete it or irreversibly anonymise it.
Privacy Policy 2.8: Infrastructure and Hosting
- perso's own application and database infrastructure is hosted on servers located in the European Union. In particular: application servers are located in France and operated by an EU infrastructure provider (OVHcloud); most member data is held on those servers, and a managed PostgreSQL database from Scaleway (an EU provider) in the Paris region (fr-par) holds a copy of part of it and some records of its own, including the audit log, where all connections between the application and the database use Transport Layer Security (TLS) with certificate verification and the database is encrypted at rest by the cloud provider at the storage-volume level (this provider-level encryption is distinct from application-level field encryption, which perso does not apply to identity attributes); the search index is Meilisearch, self-hosted by perso on its EU-based application infrastructure; email delivery uses an EU-based email service provider (IONOS); and key management uses a managed key service provided by Scaleway, used to generate and protect the key for the humanity-deduplication mechanism. perso does not currently use a separate caching layer (such as Redis) or a content delivery network. If perso later introduces such services, this section will be updated before they are used to process users' personal data. Third-party processors, including any processing outside the EU or EEA (such as identity verification, media-scanning, and any future analytics services), are addressed in the sub-processors section below and in perso's subprocessors and international-transfers documentation.
Privacy Policy 2.8: Media You Upload
- Media you upload. When you post images or other media, we store them on European object storage operated by Scaleway in the Paris region, with encryption at rest. We use Microsoft PhotoDNA to screen submitted images and sampled video frames for matches to databases of known child sexual abuse material. This check is designed to help prevent the sharing of known material and protect the safety of our community. When an image is submitted for screening, or when video frames are screened, perso creates and sends only the non-reversible PhotoDNA hash needed for that safety check. Microsoft PhotoDNA returns a screening result, which we use to apply our safety rules and comply with applicable legal obligations. Your media is also automatically screened by a nudity-detection classifier. Media is not displayed until these checks complete. Every video you upload is then withheld from display until an authorized reviewer has reviewed it and approved it, whether or not an automated check flags it, because automated screening of video frames is limited to matches with known material and cannot by itself identify all harmful or unlawful material. For images, the automated checks gate display, and an image is withheld for human review only if the classifier flags it. We do not notify you when a video is approved, and we do not promise a fixed review completion time. If media held for review has not been reviewed within 36 hours of upload, we delete it instead of holding it any longer, and we tell you so that you can upload it again. This is not a decision about you or your content.
Privacy Policy 2.8: Direct messages
- If you use direct messages, we process the message text, conversation information, delivery and request status, read status, and the account relationships needed to provide the feature.
- Messages from people you do not follow may appear as message requests. You can choose who may send you messages: everyone, people you follow, or nobody. You can block another member, which prevents further direct messages between you and that member.
- Message content. We retain message content for up to 24 months after the last relevant activity in the conversation. We may retain relevant messages for longer where the review, report, appeal, safety, legal, dispute or hold exception described below applies.
- If you erase your account, we remove your message content from ordinary conversation views. Other participants may retain their own messages and limited thread information, but not a readable copy of your removed message content.
- You may report an individual direct message. A trained authorised reviewer may review the reported message and limited surrounding context needed to assess it.
Privacy Policy 2.8: Data Retention
- perso keeps personal data only for as long as necessary. Account data is retained while your account is active and deleted within 30 days of account deletion via a cascading purge. Identity-verification attributes are retained while your account is active and are deleted or irreversibly anonymised, including the de-duplication identifier, as part of the account-deletion process; perso does not retain identity-verification attributes after account deletion, except a limited accountability record of the verification decision and its reason, held for up to 12 months for security and audit purposes, with the email address redacted. In the future, we may retain a non-reversible technical identifier for a limited period solely to prevent abuse (for example, to prevent the same document from being used to open more than one account), and we will update this section before any such mechanism is enabled. A verification-decision audit record is retained for 12 months from the decision, including past account deletion, for security and accountability purposes, with account-identifying fields redacted. Content data. We retain posts, comments and associated content data while they are available on perso. After removal, we normally delete them within 30 days. We may retain relevant content for longer where the review, report, appeal, safety, legal, dispute or hold exception described below applies. Moderation audit logs are retained for as long as necessary for accountability under the Digital Services Act. Records of moderation decisions and appeals are retained without a deletion timeline, for the life of that accountability obligation, as the durable record supporting platform-safety and appeal decisions; other moderation audit logs are deleted or irreversibly anonymised once no longer necessary. Security and technical logs are retained for as long as necessary for security, abuse-prevention and operational purposes, then deleted or irreversibly anonymised. Contact-form and partnership-inquiry data is retained for up to 12 months: network identifiers are removed after 90 days and the records are deleted after 12 months. Where an organisation verification application is declined, the personal data of the authorised representative from that application is retained for 365 days from the decline and then deleted. Network identifiers (IP address and browser information) captured with an account-recovery attempt are removed after 30 days; the recovery-attempt record is retained without them as a security-audit record. CSAM evidence: where we detect or are notified of suspected child sexual abuse material (CSAM), we immediately remove or disable access to that content on our service but may retain associated hashes, metadata and a minimal evidentiary copy in a segregated evidence store for as long as necessary to comply with our legal obligations, cooperate with competent authorities and protect victims, and then delete it securely. Analytics data is pseudonymised and aggregated and retained no longer than necessary for the purposes described in this policy.
- Reviews, reports, appeals and holds. We may retain content, messages and related account information for longer than the periods above where this is necessary to review or resolve an open report, complaint, appeal, account restriction, dispute, suspected misuse, safety matter, or legal claim. We keep that information only for as long as needed for the relevant review or process. If a legal, regulatory, law-enforcement, court, or preservation obligation applies, we may retain the relevant information for the period required or permitted by that obligation. Once the review, appeal, hold or other applicable process ends, we delete or anonymise the information in accordance with our retention schedule unless another lawful reason to retain it applies.
Privacy Policy 2.8: Lawful Basis for Processing
- - Performance of a contract (GDPR Art. 6(1)(b)), together with the substantial-public-interest condition (GDPR Art. 9(2)(g)) for the special-category biometric data, for identity verification.
- - Consent (GDPR Art. 6(1)(a)) for analytics and marketing cookies.
- - Contract performance (GDPR Art. 6(1)(b)) for account operation and feature delivery.
- - Legal obligation (GDPR Art. 6(1)(c)) for fraud prevention and law-enforcement requests.
- - Legitimate interest (GDPR Art. 6(1)(f)) for service security and abuse prevention.
Privacy Policy 2.8: Your Rights
- Under GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. Erasure ("Right to be Forgotten", Art. 17) and portability (Art. 20) are exposed in-app under Settings → Your Data Rights.
Privacy Policy 2.8: Automated Decision-Making (GDPR Art. 22)
- Most processing at perso does not involve solely automated decisions with legal or similarly significant effects. There is one exception, disclosed here with the safeguards that apply to it. To prevent the same document from being used to open more than one account, the outcome of your identity verification is automatically checked against a non-reversible de-duplication identifier derived from your identity document number. If it matches an already-verified account, your verification is automatically declined and a second account is not created. Because this is a solely automated decision that can significantly affect you (it can prevent you from opening an account), the GDPR Article 22(3) safeguards apply: you have the right to contest the decision, to obtain human review, and to express your point of view. To exercise these rights, email dpo@perso.social from the email address linked to your attempt, stating that you believe the duplicate decision is wrong and why (for example, that you are a different person who was matched in error). A human reviewer will re-examine your case, and if the decline was incorrect we will let you re-verify. Account matching decision. When you verify your identity, whether to recover an account or as part of opening a new one, the one-way identifier derived from your document number is automatically compared against existing accounts. If it does not match an account we can return to you, verification does not proceed. That is the case when no account exists for that identity, when the account was deleted, and when the account is one we have permanently closed. We do not tell you which of these applies, because the reason could reveal the status of an account that is not yours. Because this comparison is automated and can significantly affect you, the Article 22(3) safeguards apply: you can contest the outcome, obtain human review, and express your point of view. Write to dpo@perso.social. A person will review whether the match is correct. If your document was matched to an account that is not yours, we will clear the match so that you can verify and open your own account. We will not give you access to the matched account, and this review does not reconsider any decision we made about that account. Age determination. perso is only for adults. Before an approved verification is accepted, an automated check confirms that its age evidence positively establishes that you are 18 or older. If it does not, whether because the evidence shows you are under 18 or because it could not be read, your verification is automatically declined and no account is created. This check is deliberately strict: absent or unreadable age evidence is treated as not passing rather than guessed. We do not retain your date of birth. The one exception is narrow and temporary: if you contest an age decline and then verify again while that contest is open, we keep the date of birth read from that retry, together with the birthdate you tell us, solely so a person can compare them and judge whether the automated check misread your document. We keep those two dates only while your contest is open, and we delete them the moment it is resolved, whichever way it is resolved; what remains afterward is only the record that a decision was made and its reason. If your verification succeeds, we keep only the fact that the over-18 check passed; if it is declined and not contested, we keep only the decline and its reason category. Because this is a solely automated decision that can significantly affect you, the Article 22(3) safeguards apply: you can contest the outcome, obtain human review, and express your point of view. Write to dpo@perso.social and a person will review your case. If a person reviews your case and confirms from the evidence that you are over 18, we apply that confirmation so your next verification is accepted on the strength of it, and a correct outcome takes effect on your account rather than the same automated misreading repeating. If you are under 18, you are welcome to join once you meet the age requirement. Today, content moderation on perso is primarily human: we may review posts and accounts and restrict or remove them in accordance with our rules and the Digital Services Act (DSA). Where a moderation decision is based on an automated check (for example, to detect duplicate accounts), you have the safeguards required by Article 22(3) GDPR: you will be informed when an automated decision is made, you can contest it and express your point of view, and you can ask for a human to review the decision. Automated media-safety screening. We use automated media-safety screening to help detect and prevent the sharing of known child sexual abuse material. When an image is submitted for screening, or when video frames are screened, perso generates a non-reversible PhotoDNA hash from the image or video frame and compares it against reference hashes of known illegal material. We use a match result to take safety action under our rules, including restricting, removing, or escalating the relevant content for review where appropriate. If an automated decision has a legal or similarly significant effect on you, you may contact us to request human review, express your point of view, and challenge the decision. Automated screening of uploaded media. Media you upload is automatically evaluated by a nudity-detection classifier before it can be shown to others. If the classifier flags your content, the content is withheld from display until we have reviewed it. Separately, and regardless of what any automated check returns, every video is withheld until an authorized reviewer has reviewed it and approved it. This automated step does not by itself suspend your account or impose penalties; it gates visibility pending human review. You can contest a resulting moderation decision through our complaint and appeal process.
Privacy Policy 2.8: Sub-Processors
- - Didit: identity verification. Acts as our data processor, on our documented instructions, for identity verification and de-duplication. We never receive your identity-document images, biometric templates, or document nationality; Didit processes biometric data only transiently during the verification session, and we configure the session for immediate deletion at the vendor once the verification outcome is returned. The verification payload may also contain technical and security signals, including IP-based location metadata. perso does not read, use, or retain these signals.
- - OVHcloud (France): application server hosting.
- - Scaleway (France, Paris region): managed PostgreSQL database, key management, object storage for uploaded media, and offsite backups.
- - IONOS (EU): email delivery.
- - Microsoft (PhotoDNA Cloud Service): detection of known child sexual abuse material via perceptual-hash matching. Data: a non-reversible perceptual hash of uploaded media plus operational request metadata; no image content or account identifiers in the routine path. Location: Microsoft EU instance (processed within the EEA). Safeguard: processed within the EEA; for any incidental access from outside the EEA, perso relies on Microsoft's EU-U.S. Data Privacy Framework certification and, as a fallback, the 2021 Standard Contractual Clauses in Microsoft's DPA.
Privacy Policy 2.8: App stores and platform providers
- Apple and Google provide app-distribution services. Where you use an app-store feature, the relevant platform provider processes information under its own privacy terms. If perso later enables paid membership or in-app purchases, we will update this Privacy Policy and the relevant payment information before those features become available.
Privacy Policy 2.8: International transfers
- Some of our service providers may process personal data outside the United Kingdom, European Economic Area, or another jurisdiction in which you live. Where this occurs, we use the safeguards required by applicable data-protection law. These may include an adequacy decision, approved contractual protections, or another lawful transfer mechanism.
- For child-safety screening, perso sends non-reversible PhotoDNA hashes generated from submitted images and sampled frames from submitted video to Microsoft's European PhotoDNA endpoint. We do not send the original image or video, a link to the media, or the uploader's account identifier for this check.
- You can contact us to request further information about the safeguards that apply to a particular international transfer. Where we receive a request for personal data from a public authority outside the United Kingdom or European Economic Area, we assess the request and applicable legal requirements before responding and, where permitted, challenge or narrow requests that appear unlawful, disproportionate, or overbroad.
Privacy Policy 2.8: Data Protection Contact
- For data-protection enquiries: dpo@perso.social.
Privacy Policy 2.8: Supervisory Authority
- Users in the European Economic Area have the right to lodge a complaint with their local supervisory authority.
Privacy Policy 2.8: United Kingdom, Crown Dependencies & Gibraltar: No Article 27 Representative
- perso is not directed to residents of the United Kingdom, the Channel Islands, the Isle of Man, or Gibraltar, and does not offer services to, or monitor the behaviour of, individuals located in those jurisdictions; account creation from a declared residence in any of them is refused. perso has therefore not designated a representative under Article 27 of the UK GDPR.
Privacy Policy 2.8: Contact
- - Privacy questions: dpo@perso.social.
- - Data Controller: perso.social is operated by ACGG Rent, S.L., a Spanish sociedad limitada, with registered office (domicilio social) at Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain; NIF B-56240385; registered with the Registro Mercantil de Madrid, Tomo 45565, Folio 30, Hoja M-801410. Represented by Etienne Gillard. ACGG Rent, S.L. is the sole data controller, established in Spain.
Terms of Service, version 2.6
- Effective 3 July 2026. Superseded by version 2.7 on 1 October 2026.
- Served from commit c389175802a86069181fb581854ea5bad68a5371, file packages/expo/constants/legal/termsSections.ts, sha256 727a99488c29c6bd56e8ab59bfd40847f4e9db6e7d3ee1199346d58a2d6d59df.
- The full text as it was served follows.
Terms of Service 2.6: 1. Apple & Google EULA: Objectionable Content Policy
- This application is distributed through the Apple App Store and Google Play Store. By using perso, you agree to the following additional terms required by these distribution platforms:
- Objectionable Content, Zero Tolerance: perso maintains an absolute zero-tolerance policy for objectionable content, including but not limited to: pornography, graphic violence, threats of harm, hate speech targeting protected characteristics, content that exploits or endangers children, and any content that violates applicable law.
- Immediate Termination: Users who post objectionable content will have their accounts immediately suspended or permanently terminated without prior notice. perso reserves the right to remove any content that violates these standards at its sole discretion.
- Reporting Mechanism: Every post on perso includes a visible Report button. Users can report objectionable content directly from the post. Additionally, a Block User function is accessible from any user profile. Reports are reviewed by a human moderator, promptly and diligently, in compliance with both App Store Review Guideline 1.2 and DSA Article 16.
- Apple Standard EULA: To the extent this app is distributed via the Apple App Store, the Apple Standard End User Licence Agreement (https://www.apple.com/legal/internet-services/itunes/dev/stdeula/) applies. In the event of a conflict between these Terms and the Apple Standard EULA, the Apple Standard EULA shall prevail for Apple App Store users.
- Google Play Terms: To the extent this app is distributed via Google Play, the Google Play Terms of Service apply. perso complies with Google Play's Developer Programme Policy, including requirements for user-generated content moderation and reporting mechanisms.
- Child Safety: perso has zero tolerance for child sexual abuse and exploitation. Content that sexually exploits, sexualises, or endangers a child is prohibited, and so is any use of perso to solicit, groom, or exploit a child. Accounts involved are suspended and, where a case is confirmed, permanently terminated. Confirmed child sexual abuse material is preserved as evidence and reported to the competent Spanish authorities. To report a child-safety concern, use the Report control on any post or account and choose the Illegal content reason. perso's full Child Safety Standards, covering detection, reporting, and enforcement, are published at perso.social/legal/child-safety.
Terms of Service 2.6: 2. Ownership & Governing Law
- perso is operated and published by ACGG Rent, S.L., a Spanish sociedad limitada, with its registered office (domicilio social) at Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain (CIF B-56240385; Registro Mercantil de Madrid, Tomo 45565, Folio 30, Hoja M-801410), represented by Etienne Gillard. ACGG Rent, S.L. is the sole controller for perso and is established in Spain.
- These Terms of Service ("Terms") are governed by the laws of Spain, without regard to conflict-of-laws principles. Disputes shall be resolved in the competent courts of Madrid, Spain.
- If you are a consumer habitually resident in the European Economic Area, nothing in these Terms, including the choice of governing law and forum above, deprives you of the protection afforded by the mandatory provisions of the law of your country of residence, and you may bring or defend proceedings in the courts of that country. These Terms do not affect your statutory consumer rights.
Terms of Service 2.6: 3. Identity Accountability & Pseudonymity
- perso permits the use of pseudonymous display names and handles. However, every account that engages in active participation (posting, commenting, liking, or quoting) must be backed by a verified legal identity through our KYC process.
- The natural person behind the verified account bears full legal responsibility for all content published under their pseudonym. This accountability framework operates under applicable Spanish law, applicable EU law, in particular Regulation (EU) 2022/2065 (the Digital Services Act), notably Articles 14-16 concerning content moderation and notice-and-action mechanisms, and the law of the user's Member State of residence, which together govern public expression, defamation, incitement, and online-intermediary obligations.
- While perso does not publicly disclose the legal identity of pseudonymous users, this information may be disclosed to competent judicial authorities upon a valid court order issued under Spanish or EU law.
Terms of Service 2.6: 4. Eligibility
- You must be at least 18 years old and a natural person to use perso. By creating an account, you confirm you meet this age requirement in accordance with the Spanish Data Protection Act (LOPDGDD, Ley Orgánica 3/2018).
- perso is operated from the European Union by ACGG Rent, S.L. perso is not directed to, offered to, or made available to residents of the United Kingdom, the Channel Islands (Jersey and Guernsey), the Isle of Man, or Gibraltar. By creating an account you confirm that you are not resident in any of those jurisdictions. Account creation from a declared residence in any of them is refused, and we do not knowingly register, serve, or monitor residents of those jurisdictions.
Terms of Service 2.6: 5. Three-Tier Access Model
- perso operates a graduated access system:
- Tier 1, Anonymous (Open Consumption): Any person may browse the public feed and search content without creating an account. Engagement buttons are visible but disabled.
- Tier 2, Signed-Up (Personalised Browsing): Upon creating an account, users may follow others and save browsing preferences.
- Tier 3, ID-Verified (Active Participation): Only users who have completed KYC verification (Didit) may post, like, comment, or quote. This tier establishes the legal accountability link between the pseudonym and the natural person.
Terms of Service 2.6: 6. Rule-of-Law Content Standard
- perso applies the "Legal in a Physical Public Square" standard as its baseline for permitted content. If a statement would be lawful when spoken aloud in a public square in Spain or the user's EU Member State, it is presumptively permitted on perso.
- Content that is unlawful under Spanish law, EU law, or the law of the user's Member State of residence is prohibited. This includes but is not limited to:
- • Incitement to hatred or violence • Defamation and public insult • Cyber-harassment • Glorification or apology of terrorism • Holocaust denial and denial of crimes against humanity • Child sexual abuse material • Violations of intellectual property rights
- perso does not prohibit lawful political speech, satire, or vigorous public debate.
Terms of Service 2.6: 7. DSA Notice-and-Action Mechanism (Article 16)
- In compliance with the Digital Services Act (EU) 2022/2065, any person may submit a notice regarding content they consider illegal through perso's in-app reporting mechanism or by email to dsa@perso.social.
- A valid notice under DSA Article 16 must contain: • The reporter's name and email address • A clear identification of the allegedly illegal content (URL or screenshot) • An explanation of why the content is considered illegal • A statement of good faith that the information is accurate
- Upon receipt of a valid notice, perso will: 1. Acknowledge receipt within 24 hours with a unique reference number 2. Assess the content in a timely, diligent, non-arbitrary, and objective manner 3. Notify the content author of the decision with a Statement of Reasons (DSA Art. 17) 4. Provide both the reporter and the author with information about available remedies, including our internal appeal channel, dispute resolution through a consumer body in their country of residence where available, and judicial redress.
- Repeated submission of manifestly unfounded notices may result in suspension of the reporting function for a reasonable period (DSA Art. 16(3)).
Terms of Service 2.6: 8. Content Moderation & Appeals
- To help keep perso safe, we use automated tools to review content before and after it's posted. This includes a third-party image-classification model that screens uploads for nudity and other sensitive content, and Microsoft's PhotoDNA service, which checks submitted images and sampled video frames against known records of child sexual abuse material using a one-way, non-reversible hash; it never stores or views the original image. PhotoDNA matches known material only and cannot by itself identify all harmful or unlawful material.
- Every video you upload is withheld from display until an authorized reviewer has reviewed it and approved it, whether or not an automated check flags it. An image is withheld for human review only if the classifier flags it. If media held for review has not been reviewed within 36 hours of upload, we delete it instead of holding it any longer, and we tell you so that you can upload it again. That is not a decision about you or your content.
- No fully automated decision leads to content removal or account restriction without human review. Every moderation action is recorded in a structured audit trail.
- You may appeal any moderation decision for six months from the date of the decision, through our internal complaint-handling system: members appeal in the app, from the decision notice itself. Six months is the period the Digital Services Act requires and the period our systems allow. If you are not satisfied with the outcome, you may bring the matter to a certified out-of-court dispute settlement body under Article 21 of the Digital Services Act, or to a consumer dispute resolution body in your country of residence where one is available, and nothing here limits your right to go to a court.
- Anyone, with or without an account, may tell us about content they believe is illegal using the notice form at perso.social/report-illegal-content. This is our notice and action mechanism under Article 16 of the Digital Services Act. We acknowledge every notice that gives us a way to reply, and we tell the notifier what we decide. These Terms and our moderation practice follow Articles 14 to 16 of Regulation (EU) 2022/2065.
Terms of Service 2.6: 9. User Content & Licence
- You retain full ownership of content you post on perso. By posting, you grant ACGG Rent, S.L. a non-exclusive, royalty-free, worldwide licence to display, distribute, and cache your content within the platform for the purpose of providing the service.
- This licence terminates when you delete your content or account, subject to reasonable technical delays and the 30-day cascading purge schedule described in our Privacy Policy.
Terms of Service 2.6: 10. Account Termination
- ACGG Rent, S.L. may suspend or terminate accounts that violate these Terms. Before termination:
- • We provide a Statement of Reasons (DSA Art. 17) • You may appeal for six months from the date of the decision • Data export is offered before deletion
- You may delete your account at any time. Deletion triggers a 30-day cascading purge across both Identity and Content databases, as detailed in our Privacy Policy.
Terms of Service 2.6: 11. Liability
- ACGG Rent, S.L. acts as a hosting service provider within the meaning of Article 6 of the Digital Services Act (Regulation (EU) 2022/2065). ACGG Rent, S.L. is not liable for user-generated content unless it has actual knowledge of manifestly illegal content and fails to act expeditiously to remove or disable access to it.
- Nothing in these Terms excludes or limits liability for death or personal injury caused by negligence, fraud, or any liability that cannot be excluded under mandatory Spanish or EU law.
Terms of Service 2.6: 12. Dispute Resolution
- Disputes shall first be addressed through perso's internal complaint-handling system. If unresolved:
- • You may file a complaint with the Spanish Digital Services Coordinator (the Comisión Nacional de los Mercados y la Competencia, CNMC) • You may bring proceedings before the competent courts of Madrid, Spain
- If we can't resolve a dispute directly, you may be able to bring it to an alternative dispute resolution body in your country of residence, where one is available for this type of service, or to your national consumer protection authority. You always retain the right to bring a claim before the courts.
- Mandatory consumer-protection rules of your Member State of habitual residence remain applicable under Regulation (EU) No 593/2008 (Rome I).
Terms of Service 2.6: 13. Direct Messages
- You may use direct messages only in accordance with these Terms and the Community Guidelines. Do not use direct messages to harass, threaten, deceive, impersonate, distribute unlawful material, evade another member's block or message settings, or send unsolicited commercial communications. We may remove messages, restrict direct-messaging access, block communication between members, or take other proportionate action where permitted by law and these Terms.
Terms of Service 2.6: 14. Creating an account
- To create a perso account, you must confirm your country of residence, accept the Terms of Service and Privacy Policy, and complete the identity-verification process made available through the service.
- perso does not currently offer account creation or sign-in by email and password, Apple Sign In, Google Sign-In, or other social-sign-in providers.
Terms of Service 2.6: 15. Changes to these Terms
- We may update these Terms to reflect changes to perso, applicable law, security, our services, or the way we provide them. We will publish the updated Terms with their effective date and keep earlier versions available.
- Where a change is material, we will take reasonable steps to notify you before it takes effect through an appropriate channel available to us, such as a prominent in-app notice, a notice when you next use perso, or direct communication where appropriate. If a material change requires your acceptance, we will ask you to accept the updated Terms before you continue to use the affected part of the service.
- If you do not agree to updated Terms that require acceptance, you may stop using perso and request deletion of your account, subject to any lawful retention obligations described in our Privacy Policy.
Terms of Service (website text), version web-2026-06-18
- Effective 18 June 2026. Superseded by version 2.7 on 1 October 2026.
- Served from commit c389175802a86069181fb581854ea5bad68a5371, file packages/web/src/content/legal/terms.ts, sha256 d4bb3150c3d2697dcb6376875ab546800771231666b72388b1d57ecee5899b4d.
- The full text as it was served follows.
Terms of Service (website text) web-2026-06-18: Eligibility: 18+ Age Floor
- You must be at least eighteen (18) years old to register or use perso.social. By creating an account you represent that you meet this age requirement.
Terms of Service (website text) web-2026-06-18: Territorial Scope: Not Available in the UK, Crown Dependencies, or Gibraltar
- perso is operated from the European Union by ACGG Rent, S.L. perso is not directed to, offered to, or made available to residents of the United Kingdom, the Channel Islands (Jersey and Guernsey), the Isle of Man, or Gibraltar. By creating an account you confirm that you are not resident in any of those jurisdictions. Account creation from a declared residence in any of them is refused, and we do not knowingly register, serve, or monitor residents of those jurisdictions.
Terms of Service (website text) web-2026-06-18: Identity Verification
- Usage of specific features (posting, commenting) requires successful identity verification through our third-party identity-verification provider, Didit. Verification is an account-level badge and does not constitute an endorsement by perso.social of any user’s content or conduct.
Terms of Service (website text) web-2026-06-18: Content Ownership
- You retain 100% ownership of the content you post. By posting, you grant perso.social a non-exclusive, worldwide, royalty-free license to host, display, and distribute your content solely for the purpose of operating the Service. This license terminates when you delete the content or your account, except to the extent the content has been shared with others who have not deleted it.
Terms of Service (website text) web-2026-06-18: Anti-Scraping
- Automated collection, scraping, or extraction of any perso.social content, user data, or metadata is prohibited absent prior written authorisation. This includes the use of headless browsers, bots, or any system designed to circumvent rate limits or access controls.
Terms of Service (website text) web-2026-06-18: Prohibited Conduct
- - Impersonation of any real individual or organisation.
- - Operation of automated, bot-driven, or coordinated inauthentic accounts.
- - Posting content that violates applicable EU or local law.
- - Circumventing the verification requirement or sharing access to a verified account.
Terms of Service (website text) web-2026-06-18: Child Safety
- perso has zero tolerance for child sexual abuse and exploitation. Content that sexually exploits, sexualises, or endangers a child is prohibited, and so is any use of perso to solicit, groom, or exploit a child. Accounts involved are suspended and, where a case is confirmed, permanently terminated. Confirmed child sexual abuse material is preserved as evidence and reported to the competent Spanish authorities. Our Child Safety Standards set out how detection, reporting, and enforcement work, and how to report a concern.
Terms of Service (website text) web-2026-06-18: Direct Messages
- You may use direct messages only in accordance with these Terms and the Community Guidelines. Do not use direct messages to harass, threaten, deceive, impersonate, distribute unlawful material, evade another member's block or message settings, or send unsolicited commercial communications. We may remove messages, restrict direct-messaging access, block communication between members, or take other proportionate action where permitted by law and these Terms.
Terms of Service (website text) web-2026-06-18: Content Moderation & Automated Tools
- To help keep perso safe, we use automated tools to review content before and after it's posted. This includes a third-party image-classification model that screens uploads for nudity and other sensitive content, and Microsoft's PhotoDNA service, which checks submitted images and sampled video frames against known records of child sexual abuse material using a one-way, non-reversible hash; it never stores or views the original image. PhotoDNA matches known material only and cannot by itself identify all harmful or unlawful material. Every video you upload is withheld from display until an authorized reviewer has reviewed it and approved it, whether or not an automated check flags it. An image is withheld for human review only if the classifier flags it. If media held for review has not been reviewed within 36 hours of upload, we delete it instead of holding it any longer, and we tell you so that you can upload it again. That is not a decision about you or your content. No fully automated decision leads to content removal or account restriction without human review. Every moderation action is recorded in a structured audit trail. You may appeal any moderation decision for six months from the date of the decision, through our internal complaint-handling system: members appeal in the app, from the decision notice itself. Six months is the period the Digital Services Act requires and the period our systems allow. If you are not satisfied with the outcome, you may bring the matter to a certified out-of-court dispute settlement body under Article 21 of the Digital Services Act, or to a consumer dispute resolution body in your country of residence where one is available, and nothing here limits your right to go to a court. Anyone, with or without an account, may tell us about content they believe is illegal using the notice form at perso.social/report-illegal-content. This is our notice and action mechanism under Article 16 of the Digital Services Act. We acknowledge every notice that gives us a way to reply, and we tell the notifier what we decide. These Terms and our moderation practice follow Articles 14 to 16 of Regulation (EU) 2022/2065.
Terms of Service (website text) web-2026-06-18: Suspension & Termination
- perso.social may suspend or terminate accounts that violate these Terms, the Community Guidelines, or applicable law. Termination of an account does not relieve the user of liability for prior conduct.
Terms of Service (website text) web-2026-06-18: Governing Law
- - These Terms are governed by the laws of Spain, without regard to conflict-of-laws principles. Disputes shall be resolved in the competent courts of Madrid, Spain.
- - If you are a consumer habitually resident in the European Economic Area, nothing in these Terms, including the choice of governing law and forum above, deprives you of the protection afforded by the mandatory provisions of the law of your country of residence, and you may bring or defend proceedings in the courts of that country. These Terms do not affect your statutory consumer rights.
Terms of Service (website text) web-2026-06-18: Contact
- - Questions about these Terms: legal@perso.social.
- - Publisher & Operator: perso.social is operated by ACGG Rent, S.L., a Spanish sociedad limitada, with registered office (domicilio social) at Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain; CIF B-56240385; Registro Mercantil de Madrid, Tomo 45565, Folio 30, Hoja M-801410. Represented by Etienne Gillard.
Child Safety Standards, version 1.2
- Effective 19 September 2026. Superseded by version 1.3 on 1 October 2026.
- Served from commit 04a7f4c11e009817d5d93679d1c91691e4de37be, file packages/web/src/content/legal/child-safety.ts, sha256 72a2e84d8023ba2e35ee2408e61f9afb7e1077f9f1ab1d3d0bb7668e7971532c.
- The full text as it was served follows.
Child Safety Standards 1.2: Our Commitment
- perso has zero tolerance for child sexual abuse and exploitation (CSAE) and for child sexual abuse material (CSAM). Content that sexually exploits, sexualises, or endangers a child is prohibited on perso, and so is any use of the service to solicit, groom, or exploit a child. This standard applies to posts, media, profiles, and direct messages. perso is an adults-only service: it is neither designed for nor directed to children, and it does not knowingly permit anyone under 18 to hold an account.
Child Safety Standards 1.2: An Adults-Only, Identity-Verified Service
- - perso has an 18+ age floor, and membership is reached through identity verification that includes an automated check that the person is at least 18 years old.
- - That age check is deliberately strict. Where the age evidence is absent or cannot be read, the verification is declined rather than guessed, and no account is created.
- - Verification is carried out by a third-party verification provider. perso does not receive or store copies of identity documents or biometric templates; it receives a limited set of verification attributes, including confirmation that the person is at least 18.
- - Requiring a verified adult behind each account is itself a child-safety measure. It means an account is not anonymous to perso, and it means enforcement against an offending account is durable rather than trivially evaded.
Child Safety Standards 1.2: Detection
- - Before media is shown to anyone, uploaded images are automatically checked for known child sexual abuse material using Microsoft PhotoDNA through its European hash-matching endpoint. The check sends only a non-reversible mathematical signature of the image. The image itself is never sent to Microsoft.
- - The pipeline is fail-closed. Media is not shown unless that check has completed and cleared it, and if the check cannot complete the media stays unpublished rather than being shown unchecked.
- - Uploaded media is separately screened by an automated classifier for nudity and other sensitive content. Anything the classifier flags is withheld from display until we have reviewed it.
- - We state the limit of automated detection plainly: hash matching finds material that is already known. Material that is not in the reference hash sets is addressed through reports and human review, which is why the reporting route below matters and why we act on reports quickly.
Child Safety Standards 1.2: What Happens When Material Is Found
- - The item is quarantined immediately and is never served to anyone.
- - A minimal evidentiary copy, with the associated hashes and metadata, is preserved in a segregated, encrypted evidence store under legal hold, so that it stays available to the competent authorities and is not destroyed by routine deletion.
- - The account that uploaded it is suspended before any reporting step is taken. Protecting people and preserving evidence come first.
- - Access to that evidence store is restricted to a named Reporting Officer. Ordinary administrators have no access to it.
Child Safety Standards 1.2: Reporting to the Authorities
- perso is established in Spain. A confirmed case is reported to Spanish law enforcement, namely the Policía Nacional Grupo de Delitos Telemáticos and the Guardia Civil cybercrime unit, and to INCIBE, the Spanish hotline that forms part of the INHOPE network. Reports are filed by a named Reporting Officer through the official channels of those authorities, with an internal target of 24 hours from the moment a case is confirmed. Filing is done by a person rather than by machine because those channels accept structured human filings. perso cooperates with law-enforcement and judicial requests made under Spanish or EU law, and assesses each request against EU law.
Child Safety Standards 1.2: How to Report a Child-Safety Concern
- - In the app, every post and every comment carries a Report control, and a direct message can be reported from the conversation. You can also block or mute an account. For a child-safety concern, choose "Illegal content" and add whatever detail you can in the description field.
- - A report of illegal content is assessed in a timely, diligent, non-arbitrary and objective manner, which is the standard Article 16 of the Digital Services Act sets. You receive a reference number. Where you give us contact details, we confirm receipt and, once we have decided, we tell you the decision, the reasons for it, and how to contest it. A report about child sexual abuse material may be sent without contact details, and where you do that there is no way for us to tell you the outcome.
- - You can also write to dsa@perso.social, the single point of contact for illegal content, including child sexual abuse and exploitation. Authorities, hotlines, and researchers can use the same address.
- - If a child is in immediate danger, contact your local emergency services first. Reporting to perso is not a substitute for contacting the authorities.
Child Safety Standards 1.2: Enforcement
- - An account involved in child sexual abuse or exploitation is suspended, and where the case is confirmed it is permanently terminated. No prior warning is required.
- - Suspension does not erase evidence. Material and records the authorities may need are held under legal hold, and a legal hold blocks routine deletion and erasure requests for as long as it stands.
- - Because membership is tied to a verified identity, enforcement reaches the person behind the account rather than only the account.
- - A member can contest a moderation decision through the appeals process, and perso issues a statement of reasons as the Digital Services Act requires.
Child Safety Standards 1.2: The Framework We Work Within
- - Regulation (EU) 2022/2065, the Digital Services Act, including the notice-and-action mechanism of Article 16 and the statement-of-reasons duty of Article 17. The Spanish Digital Services Coordinator is the CNMC.
- - Spanish criminal law, including the duty to report serious offences.
- - The child-safety requirements of the app stores through which perso is distributed.
Child Safety Standards 1.2: Contact
- Child-safety enquiries, including from authorities and hotlines: dsa@perso.social. Data-protection enquiries: dpo@perso.social. ACGG Rent, S.L., Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain.
DSA Transparency Report, version 2.6
- Effective 3 July 2026. Superseded by version 2.7 on 1 October 2026.
- Served from commit 04a7f4c11e009817d5d93679d1c91691e4de37be, file packages/expo/constants/legal/dsaTransparency.ts, sha256 6702616002023e574efe277169cb669841ec8a582a7c3864352ef912335b3c6c.
- The full text as it was served follows.
DSA Transparency Report 2.6: DSA Transparency Report
- Digital Services Act (EU) 2022/2065 · Version 2.6
- ACGG Rent, S.L. operates in full compliance with the European Digital Services Act. This page provides transparency about our content moderation practices, notice-and-action mechanisms, reporting procedures, and dispute resolution in accordance with DSA Articles 14-24.
DSA Transparency Report 2.6: Single Point of Contact (DSA Art. 12)
- For authorities, Digital Services Coordinators, and users: Email: dsa@perso.social
- Legal Entity: ACGG Rent, S.L. Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain
DSA Transparency Report 2.6: Digital Services Coordinator (DSA Art. 49)
- ACGG Rent, S.L. is established outside the European Union and provides perso to users in the EU under the Digital Services Act. You may contact the Digital Services Coordinator of your Member State regarding matters under the DSA.
DSA Transparency Report 2.6: Notice-and-Action (DSA Art. 16)
- Any person may notify perso of content they consider illegal via our in-app reporting tool or by email to dsa@perso.social. A valid notice must include: reporter identification, content URL, explanation of illegality, and a good-faith statement. Reporter identification is not required for notices about child sexual abuse material: those may be sent without giving a name or email, as Article 16(2) of the Digital Services Act provides. You can also use the web form at perso.social/report-illegal-content, which needs no account. perso acknowledges receipt within 24 hours with a unique reference number.
DSA Transparency Report 2.6: Content Moderation
- Content moderation decisions are made by a human reviewer. An automated first-pass check using a third-party image-classification model, which runs on perso's own servers so that no content is sent outside perso for this check, may flag content for priority review, but final decisions are always human-made. No fully automated decision leads to content removal or account restriction.
DSA Transparency Report 2.6: Response Times
- Reports of illegal content and other violations are assessed promptly and diligently. We do not commit to fixed completion times. Appeals: reviewed by a person who was not involved in the original decision wherever that is possible. perso currently has a single administrator, so where it is not possible the decision is examined again against the evidence. We do not commit to a fixed completion time. All timelines are tracked in a structured DSA audit trail.
DSA Transparency Report 2.6: Statement of Reasons (DSA Art. 17)
- Every content moderation action is accompanied by a clear Statement of Reasons, including: the specific rule violated, the legal basis (Spanish law, EU law, or Terms of Service), the facts relied upon, the scope and duration of the restriction, and instructions for appeal. Statements are provided in the user's preferred language where possible.
DSA Transparency Report 2.6: Trusted Flaggers (DSA Art. 22)
- perso recognises trusted flaggers designated by national Digital Services Coordinators. Reports from trusted flaggers receive priority processing. perso maintains records of trusted flagger interactions as required by the DSA.
DSA Transparency Report 2.6: Appeals & Dispute Resolution
- You may appeal any moderation decision for six months from the date of the decision, through our internal complaint-handling system: members appeal in the app, from the decision notice itself. Six months is the period the Digital Services Act requires and the period our systems allow. If unsatisfied with the outcome, you may raise the matter with a consumer dispute resolution body in your country of residence, where available, or seek judicial redress.
DSA Transparency Report 2.6: Transparency Reports (DSA Art. 15/24)
- perso will publish transparency reports covering: • Number of content moderation actions taken • Reports received (by category) and their outcomes • Average processing times for notices and appeals • Number and outcomes of trusted flagger reports • Use of automated detection tools (with accuracy metrics) • Moderation staffing, expressed as full-time equivalents • Orders received from judicial and administrative authorities
- Reports will be published on our website and submitted to the Spanish Digital Services Coordinator (CNMC) once required under the Digital Services Act.
DSA Transparency Report 2.6: DSA Audit Trail Structure
- Every moderation decision is logged with the following structured data:
- • Audit ID (unique identifier) • Content Hash (SHA-256 of the affected content) • Reason Code (structured DSA reason code enum) • AI Model Reference (if AI-assisted flagging was used) • Categories (content violation categories) • Confidence Score (if AI-assisted) • Moderator Decision (allowed / restricted / removed) • Timestamp and duration of processing
- This audit trail is retained for as long as necessary to comply with our obligations under the Digital Services Act and to manage content-moderation disputes, and is then deleted or irreversibly anonymised; it is available to the Spanish Digital Services Coordinator (CNMC) upon lawful request.
DSA Transparency Report 2.6: Rule-of-Law Content Standard
- perso applies the "Legal in a Physical Public Square" standard. Content that would be lawful when spoken in a public square in Spain or the user's EU Member State is presumptively permitted. Content that is unlawful under Spanish law, EU law, or the user's national law is prohibited.
- perso does not prohibit lawful political speech, satire, or vigorous public debate.
DSA Transparency Report 2.6: Legal Entity
- ACGG Rent, S.L. DSA Contact: dsa@perso.social Data protection: dpo@perso.social Legal: legal@perso.social
- Last updated: 3 July 2026
© 2026 perso