The Cúm Cult
The Cúm Cult

No Pressure. Only Pleasure.

A Lovense community toolkit created for gooners by gooners.

Privacy Notice

Last updated 12 August 2026. This is a living document and may be updated. This service is for adults (18+) only.

The Cúm Cult (“we”, “us”) runs a community safety platform: it lets people check whether a username has a recorded safety note, lets community members submit safety concerns for review, and lets verified members hold an account. The Cúm Cult is the data controller responsible for the information described here. You can contact us about anything in this notice — including any request about your data — at [email protected].

We collect as little as we can. We don't ask for your real name, your email, or anything we don't need. Evidence people submit is stored privately and seen only by the small number of people reviewing it. Our public search result never shows accusations, details, or reasons — only that a note exists. (The one exception: a scam/fraud or bot listing shows that category label, since it names no person and protects no victim.) We keep records because they protect real people from real harm.

We do not collect real names, email addresses, or payment information. There are no email-based flows — verification and recovery run through a Bond post, not email.

General basis (Article 6). For the safety tool we rely on our legitimate interests — and, for the public safety list, the public interest — in protecting our community from harm. For running member accounts, we rely on our legitimate interest in operating the service you've asked to use.

Sensitive information (Article 9). Some of what we handle concerns allegations relating to consent, harassment, or predatory behaviour. We process this on the basis of substantial public interest (Article 9(2)(g)), as provided for under the Irish Data Protection Act 2018, and, where relevant, for the establishment, exercise or defence of legal claims (Article 9(2)(f)). We apply these carefully: not every nomination is listed, evidence is required, and thin or unsupported reports are shelved or dismissed.

We use a small number of trusted providers, who process data only on our instructions and not for their own purposes:

Your account data, the safety records, and uploaded evidence are stored and processed in the EU. Our network provider (Cloudflare) operates globally; to the limited extent any data is processed outside the EU/EEA, we rely on the safeguards permitted under data protection law (such as the European Commission's Standard Contractual Clauses).

Uploaded evidence is stored privately (Supabase Storage, behind signed URLs) and is accessible only to the owner and the small number of reviewers granted temporary access for a specific review. Reviewer access is granted by need and removed when it is no longer required. Several engineers from outside the build have gone through the site looking for weak points and exploitable endpoints.

We set two strictly-necessary cookies — a signed session cookie and a CSRF token — both HttpOnly and (in production) Secure. No third-party advertising or tracking cookies are used.

Whether a nomination is listed, and at what status, is decided by people reviewing the evidence. We do not make these decisions by automated means alone.

We keep safety records for as long as they remain relevant to community safety. Member account data is kept for as long as you hold an account, plus a short period afterwards. Search logs and analytics are kept only as long as needed to understand and protect the service. If a record is no longer justified, we remove it.

Under the GDPR you have the right to:

(The right to data portability generally does not apply here, because we don't process your data on the basis of consent or a contract in a way that would trigger it.) To exercise any of these, email [email protected]. Our process for erasure requests is on the Data & Erasure Requests page.