Last updated: 1 August 2026
Draft for legal review. This document was prepared from the platform's source code to describe the personal data we actually process. It is not legal advice and makes no claim of legal completeness or certification. A qualified data-protection lawyer must review, complete the placeholders, and close the gaps flagged in the "Known gaps" section before this policy is published or relied upon.
1. Who we are (Controller)
ruletka.sex is an adults-only (18+) random video-chat and dating platform. The data controller responsible for your personal data is:
- Controller: Ruletka
- Data Protection Officer / privacy contact: —
- Contact e-mail for all privacy matters: admin@ruletka.sex
If you have any question about this policy or want to exercise your rights, write to admin@ruletka.sex.
Which law applies
Our audience is primarily in Europe and Africa. For users in the European Economic Area (EEA), the EU General Data Protection Regulation (GDPR) governs. For users in Africa, national data-protection laws may also apply — for example Nigeria's NDPR and South Africa's POPIA. Where those laws grant you rights beyond this policy, we honour the stronger protection.
2. Scope and the nature of this service
This is an adult platform. By its nature you may share intimate images, sexual preferences, and other sensitive information through video calls, chat, your profile bio, and interests. Some of this can constitute special-category data under Art. 9 GDPR (e.g. data revealing your sex life or sexual orientation). We ask you not to share more than you are comfortable with, and we do not require any such data to use the core service. Where you choose to disclose it, we rely on your explicit consent given by voluntarily posting or transmitting it.
3. What personal data we collect
The list below reflects what the application actually stores. Categories map to database records in our system.
3.1 Account and identity
- E-mail address (required, unique to your account).
- Password — stored only as an argon2id hash, never in plaintext. If you sign in through Google or Telegram, we store no password.
- Sign-in provider and provider ID (LOCAL, GOOGLE, or TELEGRAM).
- Gender (recorded as MALE or FEMALE — the system currently offers only these two values).
- Date of birth — we store your full date of birth, from which your age is derived. See Section 11 on age.
- Telegram linkage — your Telegram ID and username, and whether you have started our bot, if you connect Telegram.
- E-mail verification status, referral code, VIP status and expiry, online/last-seen status, and your matching preferences (preferred country, preferred language).
3.2 Profile (self-authored)
- Display name, avatar image, country, city, languages, free-text bio (up to 500 characters), and interests. This is content you write yourself; it may contain any personal detail you choose to include.
3.3 Technical and session data
- For each active login session we store a hashed refresh token, the IP address and browser user-agent captured at sign-in, and the session's revocation/expiry state. This is the only place we store your IP address and user-agent. The IP is taken from the first
X-Forwarded-Forhop (or the direct connection) and the user-agent from your request headers.
3.4 Communications and calls
- Chat messages — the text you send (up to 4,000 characters per message), attachments, edits, reactions, and replies. Note: when you delete a message, we currently perform a soft delete — the UI shows "message deleted" but the underlying text remains stored in our database (see Known gaps). A short preview of the last message is also cached on each conversation.
- Call sessions — who called whom, room ID, start/end time, duration, minutes billed, diamonds spent, and how the call ended (including whether it ended because it was reported). This is social-graph and behavioural data.
- Support/finance bot chats — messages you send to our in-app support and billing assistants.
3.5 Payments, wallet, and creator earnings
- Wallet — your virtual "diamond" balance and lifetime earned/spent totals, and (for creators) coin earnings.
- Transaction ledger — every credit and debit, with type, amount, running balance, description, and metadata.
- Payments — real-money top-ups processed by our crypto payment provider: amount, currency, diamonds purchased, status, the provider's external payment ID, the hosted payment URL, and timestamps.
- Creator economy — gift events (sender, recipient, price), earning entries, and payouts. A payout record stores the amount and the destination you provide (crypto wallet address, card, or account handle). Important: when a payout is processed, our server transmits the full destination wallet address, your login, your public ID, and the amount to an internal Telegram group (see Section 5).
3.6 Social, safety, and behavioural data
- Contacts — private notes, custom nicknames, tags, and 1–5 ratings you keep about other users (VIP feature), plus favourite/pin/mute/block flags.
- Favourites, profile views ("who viewed my page" — viewer, target, and time), referrals, gifts, achievements, daily-bonus claims, promo redemptions, and notifications.
- Reports — if you report another user, we store your ID, the reported user's ID, the reason (which can include a nudity/minor category), and your free-text comment. If you are reported, that data is stored about you.
- Bans — user ID, who issued it, type, reason, and expiry.
- Settings — notification preferences, auto-translate, invisible mode, hide-balance, and a "history cleared" marker.
- Surprise Room / live streams — participation, ratings, and viewer counts.
3.7 Face verification data (performers) — biometric
If you register as a creator/performer or otherwise offer paid video, we ask you to complete a face check using your device camera. From the frames we compute a facial template (biometric embedding) and a gender/liveness assessment, and we store the template and the check result (scores, timestamps) to (a) decide eligibility and (b) periodically re-verify that it is still you. This is biometric data used to uniquely identify you — a special category under Art. 9 GDPR — and we process it only with your explicit consent (Art. 9(2)(a)), given when you start the check. Raw camera frames are processed transiently and are not retained; the facial template is deleted when your account is deleted or when you withdraw consent (after which you can no longer perform). If you do not consent, you can still use the Service as a viewer.
4. Why we process your data and our legal basis
| Purpose | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Create and run your account; authenticate you | E-mail, password hash, provider IDs, refresh-token session data | Contract (Art. 6(1)(b)) |
| Matchmaking, video calls, chat, gifts, profiles | Profile, call sessions, messages, gender, preferences | Contract (Art. 6(1)(b)) |
| Process top-ups and creator payouts | Payments, wallet, transactions, payout destination | Contract (Art. 6(1)(b)); payment records also retained under legal obligation (Art. 6(1)(c)) |
| Safety, moderation, anti-fraud, and abuse handling | Reports, bans, block flags, call/report metadata, session IP & user-agent | Legitimate interests (Art. 6(1)(f)) — keeping the platform and its users safe |
| Session security and abuse prevention | IP address and user-agent stored with your login sessions | Legitimate interests (Art. 6(1)(f)) |
| Analytics and session-replay (Yandex.Metrika, incl. Webvisor) | Usage events, session recordings, _ym_* identifiers | Consent (Art. 6(1)(a)) — off unless you opt in |
| Special-category content you choose to share (adult context) | Anything intimate you post or transmit | Explicit consent (Art. 9(2)(a)) |
| Performer face verification (gender + liveness + re-check) | Facial template (biometric embedding), check scores and timestamps | Explicit consent (Art. 9(2)(a)) — biometric data to uniquely identify you |
You can withdraw consent at any time (Section 9); withdrawal does not affect processing already carried out.
5. Who we share your data with (recipients and processors)
We do not sell your personal data. We share it with the following categories of recipients, each of which actually receives data in our system:
5.1 Yandex.Metrika (analytics + session replay) — consent-gated
We use Yandex.Metrika (counter 110772171) for analytics. This includes Webvisor, a session-replay feature that records how you interact with pages, including parts of the page content (the DOM). This is our most significant disclosure, so please read this carefully:
- It is off by default. The Metrika script does not load until you click "accept" in our cookie banner. Until then, no analytics data or
_ym_*cookies are set. You can decline and keep using the service. - We mask the most sensitive fields even after you opt in. Your chat conversation area and message input are marked so Webvisor does not record their content or keystrokes, and the payout wallet-address field is likewise masked from recording. Other parts of the page (profiles, navigation, wallet amounts) are recorded once you consent.
- Yandex.Metrika is operated by Yandex and the script is served from Russia. See Section 6 on international transfers.
5.2 Telegram
- Client-side widget/Mini-App SDK: the Telegram SDK loads in the web app, so Telegram may see the IP address, browser, and referrer of visitors.
- Server-to-Telegram notifications and payouts: our server sends account notifications through Telegram bots, and — for creator payouts — posts payout details (your login, public ID, network, the full destination wallet address, and amounts) to an internal Telegram group used by our finance team. These server-to-Telegram calls are routed through an HTTP proxy operator (our server cannot reach Telegram directly), which is an additional recipient in an unknown jurisdiction.
5.3 Crypto payment gateway (Apione)
Real-money top-ups are handled by Apione (apione.app). When you buy diamonds, our server sends the transaction details (amount, coin, callback URL) to Apione, and you complete payment on an Apione-hosted page, so Apione processes your payment interaction directly. Apione is a keyless address-forwarding gateway; its jurisdiction is —.
5.4 WebRTC connectivity (STUN/TURN)
Video calls use WebRTC. To connect two participants, a STUN server is used — by default Google's public STUN server (stun.l.google.com, in the USA), unless we configure our own. The STUN/TURN operator, and — in a direct peer-to-peer call without a relay — the other participant, can see your public IP address. This is inherent to how real-time video works.
5.5 Conditional: DeepSeek (AI support)
Our in-app support assistant can be configured to answer free-text questions using DeepSeek (an AI provider based in China). This feature is currently dormant and disabled. If we enable it, messages you send in support/finance chats would be transmitted to DeepSeek, and we will update this policy and treat it as an international transfer before doing so.
5.6 Infrastructure
Our hosting, database, and file storage providers process data on our behalf under processor agreements.
6. International data transfers (Art. 44–49 GDPR)
Some recipients are outside the EEA, and adequate safeguards still need to be put in place (see Known gaps):
- Yandex.Metrika / Webvisor → Russia. Russia has no EU adequacy decision. When you opt in, usage data and session recordings are transferred to Russia. This requires appropriate safeguards (e.g. Standard Contractual Clauses) or reliance on your explicit, informed consent.
- Google STUN → USA. Your public IP may be exposed to Google's US infrastructure during calls (unless we self-host STUN/TURN).
- Telegram + proxy operator → outside the EEA / unknown jurisdiction. Payout wallet addresses and user identifiers transit both.
- Apione crypto gateway → —. Payment interaction data.
- DeepSeek → China — only if/when the AI support feature is enabled.
Where a transfer relies on Standard Contractual Clauses or other safeguards, you can request a copy by writing to admin@ruletka.sex.
7. How long we keep your data (Retention)
We must be honest with you: the platform currently has no defined retention limits for personal data, and no self-service way to delete your account.
- The only automated deletion in the system removes expired and revoked login-session tokens (daily), which also purges the IP address and user-agent stored with those old sessions.
- All other data — your account, profile, messages (including soft-deleted ones), call history, payments, reports, and bans — is retained indefinitely until we implement a storage-limitation policy.
This does not meet the GDPR storage-limitation principle (Art. 5(1)(e)) and is flagged as a gap for our team to fix. In the meantime, you can ask us to erase your data manually by writing to admin@ruletka.sex (Section 9).
8. How we protect your data (Security)
Security measures actually implemented include:
- Passwords hashed with argon2id (never stored in plaintext).
- HttpOnly, rotated refresh-token cookies with
SecureandSameSiteprotections in production; the token value is random and only its hash is stored server-side. - TLS/HTTPS in transit.
- Rate-limiting on authentication (sign-in and registration) endpoints.
A caveat we want to be candid about: our crypto payment callbacks are currently authenticated only by a secret in the callback URL (the gateway does not use signed webhooks). Hardening this is on our list (see Known gaps). No system is perfectly secure, but we work to protect your data against unauthorised access, loss, and misuse.
9. Your rights
Under the GDPR (and, where applicable, NDPR/POPIA), you have the right to:
- Access — get a copy of the personal data we hold about you (Art. 15).
- Rectification — correct inaccurate or incomplete data (Art. 16). You can edit much of your profile and settings directly in the app.
- Erasure ("right to be forgotten") — ask us to delete your data (Art. 17). Note: there is currently no automated account-deletion feature, so we handle erasure requests manually — write to admin@ruletka.sex.
- Restriction — ask us to limit processing in certain cases (Art. 18).
- Data portability — receive your data in a structured, machine-readable format (Art. 20).
- Objection — object to processing based on legitimate interests, including for safety analytics (Art. 21).
- Withdraw consent — for analytics, decline or clear consent via the cookie banner at any time; this disables Yandex.Metrika. Withdrawal does not affect prior processing (Art. 7(3)).
- Not to be subject to solely automated decisions with legal or similarly significant effects (Art. 22). Note that some bans can be issued automatically by our safety systems; you can contact us to have a human review any such decision.
To exercise any right, e-mail admin@ruletka.sex. We will respond within the time limits set by law. You will not have to pay a fee unless your request is manifestly unfounded or excessive.
Right to complain. If you believe we have mishandled your data, you may lodge a complaint with your local supervisory authority (in the EEA, your national data-protection authority; in Nigeria, the NDPC; in South Africa, the Information Regulator). We would appreciate the chance to address your concern first via admin@ruletka.sex.
10. Cookies and similar technologies
We use a strictly necessary authentication cookie (rt, HttpOnly, ~30-day lifetime) that keeps you signed in, and — only after you opt in — Yandex.Metrika's _ym_* analytics cookies. Your consent choice itself is stored in your browser's local storage. For full details, categories, names, and lifetimes, see our Cookie Policy.
11. Age and children (18+)
This platform is strictly for adults aged 18 or over. Age is self-declared at registration (via your date of birth, or an age value from Telegram sign-in) — we do not verify identity documents. We do not knowingly allow anyone under 18. If we learn that a minor has registered, we will act to remove their access to the platform (for example, by banning and disabling the account). The child-consent provisions of Art. 8 GDPR are relevant here, and because no document verification exists, age assurance is a known limitation. If you believe a minor is using the service, report it in-app or contact admin@ruletka.sex immediately.
12. Changes to this policy
We may update this policy as the product and its legal obligations evolve. We will change the "Last updated" date above and, for material changes (such as enabling AI support or adding new recipients), take reasonable steps to notify you.
13. Contact
For any privacy question or to exercise your rights, contact — at admin@ruletka.sex, or write to Ruletka, —.