Privacy Policy
This Privacy Policy explains how RedSearch (redsearch.top) collects, uses, discloses, and retains personal information when you use our website and related services (the Service). RedSearch is an adult, embed-only index: we list embeds hosted by third-party KYC partner platforms. We do not host video files.
This Policy is designed to meet transparency requirements under the EU/UK General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and California privacy laws including the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and similar U.S. state privacy laws where applicable. It is not legal advice.
1. Who we are (controller)
For GDPR purposes, the controller of personal data processed through the Service is the operator of RedSearch at redsearch.top.
Privacy contact
Email: [email protected]
Copyright / DMCA notices: [email protected] (see DMCA Policy). Electronic mail is preferred.
You may also open Cookie settings at any time to change non-essential preferences.
2. Scope and audience
- The Service is for adults only (minimum age 18). We do not knowingly collect personal information from anyone under 18.
- If you believe a minor has provided information or that content depicts a minor, use the on-site Report flow (reason: underage) and contact us immediately at [email protected].
- Partner embed players, ad networks, and analytics vendors process data under their own policies when your browser connects to them.
3. Personal information we collect
Depending on how you use the Service, we may process the categories below.
3.1 Information you provide
- Account data: email address, username, password (stored as a one-way hash), date of birth, role (performer / studio / promoter), and optional profile content (name, bio, aliases, body/profile fields, links, avatar, gallery images, comments, playlists, follows).
- Verification materials (optional): government ID image/PDF uploads and/or social-proof URLs, plus a site-issued verification key, status, and admin review notes.
- Payout destinations: PayPal email, 2Checkout email, Bitcoin address, Focus.xyz / Creator Coin username, and free-text bank details when you enable a payout method.
- Content submissions: embed codes/URLs, titles, descriptions, categories, keywords, performer/studio associations.
- Reports and support: report reason, notes, and related identifiers for listed videos.
- Password reset: email used to request a reset (tokens are hashed; reset links are issued through our mail outbox process).
3.2 Information collected automatically
- Device and usage: IP address, user agent, referrer, requested URLs, timestamps, approximate country (from CDN country headers when available, otherwise a short-lived lookup via a geo IP API), and security/rate-limit signals.
- Cookies and similar tech: session and preference cookies described in Section 8 (age gate, consent, referral, visitor id, ad-script proof, login session).
- Age-assurance session: a first-party session token, method used (e.g. date-of-birth declaration, on-device age estimate, facial age inference where configured, or third-party certificate paste), country/region code, optional estimated age band, expiry (default 60 days). We do not keep the declared date of birth on the age-session record after a successful gate pass.
- View and fraud signals: hashed visitor / IP / user-agent identifiers, watch duration signals, adblock / ad-script beacon status, share events, and related anti-fraud metrics used for payable view counting.
- Operational logs (when logging is enabled by administrators): request metadata, redacted POST snapshots, channel messages, and sometimes plaintext IP in log stores. Default file/DB log retention is approximately 30 days when purge jobs run.
3.3 Information from third parties
- CDN or hosting edge country headers.
- Cloudflare Turnstile bot-check results when enabled.
- Partner platforms (metadata/thumbnails fetched for listing display; playback occurs on the partner).
- Referral codes supplied by other users via
?ref=links.
3.4 Sensitive / special-category data
Adult-content browsing preferences and account DOB can reveal sensitive aspects of private life. Optional age-assurance methods may involve biometric-related processing (on-device camera age estimation, or a face image sent to a configured inference endpoint). Verification ID documents are identity data. We process these only as needed to operate an 18+ Service, prevent underage access, verify optional claims, and meet legal duties. Where GDPR requires explicit consent for biometric or special-category processing, we rely on that consent for the relevant method; you may choose another available age method where offered.
4. Why we use personal information (purposes)
- Provide, secure, and improve the Service (browse, watch embeds, submit, claim profiles, earn, payouts).
- Create and administer accounts; authenticate users and admins.
- Enforce 18+ access controls and age-assurance requirements by region.
- Attribute referrals and calculate uploader / referral earnings.
- Process payout requests using destinations you supply.
- Moderate reports (including CSAM / non-consensual / copyright escalation paths) and respond to legal notices.
- Prevent fraud, abuse, spam, and artificial view inflation.
- Show display advertising and site-listing badges that fund the Service.
- Measure traffic with analytics tools only after you accept Analytics in the consent banner.
- Comply with law, enforce Terms, and protect rights, safety, and integrity of users and the public.
5. Legal bases (GDPR / UK GDPR)
Where the GDPR applies, we rely on one or more of the following:
- Contract (Art. 6(1)(b)): account registration, login, profile features, submissions, earnings ledgers, and payouts you request.
- Legitimate interests (Art. 6(1)(f)): security, fraud prevention, rate limiting, referral attribution, product analytics that are strictly necessary, service improvement, and defending legal claims. You may object where applicable (Section 11).
- Consent (Art. 6(1)(a)): non-essential analytics cookies/scripts; certain age-assurance methods that involve biometric processing; any optional marketing we may offer in the future. Withdraw consent anytime via Cookie settings or by contacting us (withdrawal does not affect prior lawful processing).
- Legal obligation (Art. 6(1)(c)): responding to lawful requests, retaining records required for tax/disputes where applicable, and handling child-safety / illegal-content reports.
- Vital interests (Art. 6(1)(d)): rare cases involving imminent harm or CSAM response.
Where we process special-category data, we additionally rely on Art. 9 grounds as applicable (e.g. explicit consent, or substantial public interest / legal claims where available under local law).
6. How we disclose information
We may disclose personal information to:
- Service providers / processors that host infrastructure, send mail, provide bot protection, geo lookup, age tools, or payment rails, under instructions and appropriate contracts where required.
- Advertising and listing partners whose tags or creatives load in your browser (see Section 9). Your browser sends standard request data (IP, user agent, referrer, page URL) to those parties.
- Analytics vendors (Google Analytics, StatCounter) only after Analytics consent.
- Partner tube platforms when you play an embed or follow a report/outbound link (their policies apply).
- Other users for public profile, directory, comment, and listing content you choose to publish.
- Professional advisers and authorities when required by law, court order, or to protect rights, safety, and the Service (including CSAM reporting channels).
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality.
We do not sell personal information for money in the ordinary sense. Under California law, “sale” and “sharing” can include certain disclosures for cross-context behavioral advertising. See Section 12 for California-specific disclosures and opt-out rights.
7. International transfers
We may process and store information in the United States and other countries where we or our providers operate. Those countries may not provide the same level of data protection as your home jurisdiction. Where GDPR requires safeguards for transfers (e.g. Standard Contractual Clauses, adequacy decisions, or another lawful mechanism), we implement them with relevant vendors as applicable. Contact [email protected] for transfer details relevant to your request.
8. Cookies and similar technologies
We use first-party cookies and similar storage. You can manage non-essential categories via Cookie settings. Necessary cookies run for the Service to function.
8.1 Necessary / functional (always)
rs_age- age-assurance session (HttpOnly; default 60 days).rs_cc- cookie consent choices (up to 365 days).rs_ref- referral attribution code (HttpOnly; about 90 days).rs_vid- anonymous visitor id for view/fraud hashing (HttpOnly; up to about 400 days).rs_adok- short-lived ad-script integrity proof (HttpOnly; about 1 day).- PHP session cookie - login / admin session.
8.2 Local / session storage (browser)
- Continue-watching history, watch-float dismissals, and client view-session ids used for beacons.
8.3 Analytics (only with consent)
- Google Analytics (property id configured in the Service) and StatCounter load only if you accept Analytics.
8.4 Display ads and Rommie
Display ad creatives (e.g. JuicyAds, A-Ads, Adclicks when enabled) and the Rommie site-listing / track script are treated as part of how the Service is funded and listed. In our consent UI they are presented as always on for display advertising / listing. Those third parties may receive standard browser request data when their resources load. See their policies for any cookies they set.
9. Third-party services (examples)
- Google Analytics; StatCounter (after Analytics consent).
- Rommie listing / track scripts.
- JuicyAds, A-Ads, Adclicks (or other admin-configured creatives).
- Cloudflare Turnstile (bot protection when enabled).
- Geo country lookup API when CDN country headers are unavailable.
- Universal Verify age estimator (runs in your browser; we receive an estimated age result).
- Optional self-hosted facial age inference endpoint (face image processed for age estimate when that method is enabled).
- Optional third-party age certificates you paste (e.g. CertiBee-style tokens).
- Partner embed hosts and outbound report destinations.
- Payout networks you choose (PayPal, banks, Bitcoin networks, Focus.xyz, etc.) when we pay you.
10. Retention
- Account and profile data: for the life of the account, then deleted or anonymized within a reasonable period after closure, unless we must retain longer for legal, security, or dispute reasons.
- Payout and earnings records: retained as needed for accounting, fraud prevention, and legal obligations.
- Age sessions: until cookie/session expiry (default 60 days) or earlier invalidation.
- Reports, moderation, and security events: retained as needed to investigate and meet legal duties.
- Verification ID files: retained while a review is pending and thereafter as reasonably necessary for compliance, abuse prevention, and dispute handling; contact us if you want us to review deletion after a final decision.
- Operational logs: when enabled, typically purged on a rolling window of about 30 days (admin-configurable).
- Cached thumbs / site art derivatives: retained while useful for display; may be regenerated or deleted during cleanup.
11. Your rights under GDPR / UK GDPR
If you are in the EEA, UK, or another jurisdiction with similar rights, you may have the right to:
- Access your personal data and obtain a copy.
- Rectify inaccurate or incomplete data.
- Erase data (“right to be forgotten”) in certain cases.
- Restrict or object to certain processing (including processing based on legitimate interests).
- Data portability for data you provided where processing is based on consent or contract and is automated.
- Withdraw consent where processing is consent-based.
- Lodge a complaint with your local supervisory authority (for example, your EU member-state DPA or the UK ICO).
To exercise these rights, email [email protected] from the address on your account when possible, and describe the request. We may need to verify your identity before acting. We will respond within the timeframes required by law (generally one month under GDPR, extendable when complex).
Some rights are limited (e.g. we may retain data needed for legal claims, security, or child-safety obligations). Deleting an account does not remove public content already published in a way that must remain for integrity of the index, or data we must keep by law, until those bases end.
12. California privacy notice (CCPA / CPRA)
This section applies to California residents. “Personal information” and “sensitive personal information” have the meanings in the CCPA/CPRA. We describe practices above; this section maps them to California categories.
12.1 Categories collected (last 12 months)
- Identifiers (email, username, IP, cookie IDs, account IDs).
- Customer records / commercial information (payout destinations, earnings, transactions).
- Internet or other electronic network activity (browsing on our Service, beacons, logs).
- Geolocation data (coarse country/region derived from IP or CDN headers).
- Audio/visual information (avatar/gallery images; optional ID images; optional face image for age inference when that method is used).
- Professional or employment-related information if you submit studio/performer business profile details.
- Inferences drawn from the above for fraud, payability, and abuse prevention.
- Sensitive personal information as defined by CPRA may include: account log-in + password; precise contents of certain messages you send us; government ID images; account date of birth; and biometric/face processing used solely for age assurance when you choose those methods.
12.2 Sources
Directly from you; automatically from your device/browser; from service providers and security tools; from referral links; and from partner platforms when fetching listing metadata.
12.3 Business / commercial purposes
The purposes in Section 4, including auditing, security, debugging, short-term transient use, performing services, internal research, quality control, and advertising that funds the Service.
12.4 Sale, sharing, and advertising
- We do not sell personal information for monetary consideration.
- We may share identifiers and internet activity with advertising / listing partners when their tags load (cross-context advertising under CPRA’s definitions may apply).
- We do not knowingly sell or share personal information of consumers under 16.
Right to opt out of sale/sharing: email [email protected] with the subject “Do Not Sell or Share,” or use Cookie settings to refuse Analytics. Because display ad tags may still load as part of the funded Service, California residents who want a stricter opt-out of advertising-related sharing should contact us; we will honor legally required opt-outs and explain any service limitations.
12.5 Sensitive personal information
We use sensitive personal information to provide the Service, authenticate you, pay you, verify optional claims, enforce 18+ access, and prevent fraud/abuse, not to infer characteristics for unrelated advertising. California residents may request that we limit use of sensitive PI to purposes permitted by CPRA by emailing [email protected] with subject “Limit Sensitive PI.”
12.6 California rights
- Right to know / access categories and specific pieces of PI.
- Right to delete PI (subject to exceptions).
- Right to correct inaccurate PI.
- Right to opt out of sale/sharing.
- Right to limit use/disclosure of sensitive PI.
- Right to non-discrimination for exercising CCPA/CPRA rights.
Submit requests to [email protected]. We will verify identity (e.g. account ownership) and respond within the statutory period. You may use an authorized agent with proof of authority. We will not discriminate against you for exercising these rights.
Shine the Light (Cal. Civ. Code §1798.83): we do not disclose personal information to third parties for their own direct marketing based on a shared customer list in the manner that statute addresses. For requests, use the privacy email above.
13. Other U.S. state privacy laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, and other states with consumer privacy laws may have rights to access, delete, correct, or opt out of targeted advertising / certain profiling. Email [email protected] and specify your state; we will handle the request under the applicable statute.
14. Security
We use administrative, technical, and organizational measures appropriate to the risk, including password hashing, HTTPS, CSRF protections, rate limits, hashed identifiers in several fraud pipelines, restricted access to verification files, and role-based admin access. No method of transmission or storage is 100% secure. Notify us promptly of suspected account compromise.
15. Automated processing
We use automated signals (hashes, beacons, rate limits, payability rules, spam/honeypot checks) to protect the Service and calculate earnings. These do not produce legal effects solely by automated decision-making without human involvement in the sense of GDPR Art. 22 for account-critical outcomes such as verification approval or payout release, which involve human review where configured. Contact us if you want an explanation of a significant automated fraud decision affecting you.
16. Children
The Service is strictly 18+ (or older where required). We do not knowingly collect data from children. We will delete information and take appropriate action if we learn we have collected personal information from anyone under 18, and we escalate suspected underage content reports for human review.
17. Third-party sites and embeds
Embeds, outbound links, partner report pages, and third-party badges are outside our control once you leave our origin or load their resources. Their privacy policies govern that processing.
18. Changes to this Policy
We may update this Policy from time to time. The effective date above will change when we do. Material changes may also be signaled via the Service or email where appropriate. Continued use after an update means you accept the revised Policy where permitted by law.
19. Contact
Privacy requests and questions:
[email protected]
DMCA / copyright:
[email protected] ·
DMCA Policy