PEEPER
Last updated: 2026-08-18 · Court-harden C10 · Controller identity from live host only · Not legal advice.
Controller: · Not yet published on this host (formation data pending). Contact: support@peeper.live.
peeper.session.v1 (account session),
peeper.legal.v1 (TOS version accepted),
peeper.age (session only, age affirm), wallet/progress/shop
meta, content preferences, settings, optional save-login and share codes.
No third-party ad cookies are set by the core app shell itself; embed
networks (e.g. JuicyAds) may set their own when ads run.
Payments unlock access to a large pool of premade tokens (on the order of 1072+ units reserved for play). Your balance is a meter of that access, not bank money and not a refundable deposit. See Terms for no-refund rules.
Categories you toggle (realism, furry, gay, bi, etc.) are stored so we can exclude scenes you did not enable. Preferences stay on your device (and only mirror if you later enable cloud sync features).
The default open project does not sell profile lists. A commercial operator must disclose any future analytics or processors here.
If you choose “watch ad” for ✦, a third-party network (e.g. JuicyAds) may set cookies, load scripts, and process device/IP data under their privacy policy. Ads are optional; pack purchase is an alternative. First ad watch requires an in-app acknowledgment of this third-party processing.
Local data remains until you clear site storage or use in-app reset. Account records on a host remain until deletion is requested or the operator’s retention schedule ends.
Passwords are hashed on the server implementation; no system is perfect. Use a unique password. Do not store production secrets in the frontend.
During play, a moving on-screen watermark may display a non-secret label derived from your username or session so leaked captures can be attributed. This is a deterrent, not encryption. Browser/PWA capture guards are best-effort only; OS screenshots and external recorders may still work. See Terms §7 (Capture limits).
Depending on your region (e.g. GDPR/UK GDPR, CCPA/CPRA) you may request access or deletion of account data held on the operator’s server. Contact: support@peeper.live · security: security@peeper.live. Account self-serve: in-app delete where offered.
PEEPER is not directed at anyone under 18. We do not knowingly collect data from minors.
To comply with sanctions, adult-content laws, and commercial age-assurance
statutes, we process coarse location from your CDN or host
(typically country, and for the United States a region/state code such as
Cloudflare CF-IPCountry / CF-Region-Code or
equivalent). We use that signal to decide whether the service is offered at
all. We do not currently collect government ID, liveness
selfies, or third-party age-verification payloads, because we
hard-block jurisdictions that require a certified AV vendor
rather than running an optional Settings toggle.
Blocked visitors can still read public legal pages. Purchase, play, and account APIs return HTTP 451 with a region-unavailable notice. We do not sell geo data. Logs may retain country/state codes briefly for abuse prevention and audit. See Global compliance for the current U.S. state and country lists.
Depending on your region you may have rights under GDPR/UK GDPR, CCPA/CPRA, or similar laws to request access or deletion of account data. Geo headers themselves are typically processed as a security/legal-obligation interest rather than marketing profiling.
Servers and processors may be located outside your country. By using the service you acknowledge transfers necessary to provide token access, accounts, and payments.
← Back to PEEPER · Terms · Compliance · 2257 · Support · Report