No Pressure. Only Pleasure.
A Lovense community toolkit created for gooners by gooners.
Privacy Notice
Last updated 12 August 2026. This is a living document and may be updated. This service is for adults (18+) only.
The Cúm Cult (“we”, “us”) runs a community safety platform: it lets people check whether a username has a recorded safety note, lets community members submit safety concerns for review, and lets verified members hold an account. The Cúm Cult is the data controller responsible for the information described here. You can contact us about anything in this notice — including any request about your data — at [email protected].
The short version
We collect as little as we can. We don't ask for your real name, your email, or anything we don't need. Evidence people submit is stored privately and seen only by the small number of people reviewing it. Our public search result never shows accusations, details, or reasons — only that a note exists. (The one exception: a scam/fraud or bot listing shows that category label, since it names no person and protects no victim.) We keep records because they protect real people from real harm.
What we collect, and why
- When you search — the username searched, a timestamp, your role, your IP address, your browser user-agent, and automated safety flags (e.g. rapid searching). Logged for community safety. Searching requires a signed-in member account, so each search is linked to your account.
- When you submit a nomination — the username you're reporting, the platform, your description, any categories or dates you add, and any screenshots or links you upload as evidence. If you tick “willing to be contacted”, the single Lovense or Discord handle you provide. You don't have to provide one.
- When you hold a member account — your community username/handle; a password stored only as a one-way bcrypt hash (never in plain text); your verification status; any previous usernames, kept as aliases if you rename; and an internal community identity ID that links your handles so a serious safety record can't be dodged by changing username.
- When you're named in a nomination or on the list — the username, the category of concern, the status (e.g. caution or blocklist), and the private evidence and context behind it. This usually reaches us from the community member who reported it, rather than from you directly. Our public result reveals none of this — only that a recorded note exists (a scam/fraud or bot listing additionally shows that category label).
We do not collect real names, email addresses, or payment information. There are no email-based flows — verification and recovery run through a Bond post, not email.
Our lawful basis
General basis (Article 6). For the safety tool we rely on our legitimate interests — and, for the public safety list, the public interest — in protecting our community from harm. For running member accounts, we rely on our legitimate interest in operating the service you've asked to use.
Sensitive information (Article 9). Some of what we handle concerns allegations relating to consent, harassment, or predatory behaviour. We process this on the basis of substantial public interest (Article 9(2)(g)), as provided for under the Irish Data Protection Act 2018, and, where relevant, for the establishment, exercise or defence of legal claims (Article 9(2)(f)). We apply these carefully: not every nomination is listed, evidence is required, and thin or unsupported reports are shelved or dismissed.
Where your data is processed
We use a small number of trusted providers, who process data only on our instructions and not for their own purposes:
- Hosting and application — Railway (EU, Amsterdam)
- Database and stored evidence — Supabase (EU, Ireland)
- Network and traffic security — Cloudflare (global)
Your account data, the safety records, and uploaded evidence are stored and processed in the EU. Our network provider (Cloudflare) operates globally; to the limited extent any data is processed outside the EU/EEA, we rely on the safeguards permitted under data protection law (such as the European Commission's Standard Contractual Clauses).
How evidence is stored
Uploaded evidence is stored privately (Supabase Storage, behind signed URLs) and is accessible only to the owner and the small number of reviewers granted temporary access for a specific review. Reviewer access is granted by need and removed when it is no longer required. Several engineers from outside the build have gone through the site looking for weak points and exploitable endpoints.
Who can see what
- The public sees only that a username has, or does not have, a recorded safety note — plus, for scam/fraud or bot listings, that category label.
- Approved reviewers may see additional context during an active review, for as long as they hold that role.
- Victims and reporters remain anonymous in anything shown to the community.
- We do not sell, rent, or share your data with advertisers or third parties, and we do not share evidence outside the review process.
Cookies
We set two strictly-necessary cookies — a signed session cookie and a CSRF token — both HttpOnly and (in production) Secure. No third-party advertising or tracking cookies are used.
Decisions are made by people
Whether a nomination is listed, and at what status, is decided by people reviewing the evidence. We do not make these decisions by automated means alone.
How long we keep things
We keep safety records for as long as they remain relevant to community safety. Member account data is kept for as long as you hold an account, plus a short period afterwards. Search logs and analytics are kept only as long as needed to understand and protect the service. If a record is no longer justified, we remove it.
Your rights
Under the GDPR you have the right to:
- Access the information we hold about you.
- Correct information that is inaccurate.
- Request erasure of your information — some limits apply where a serious safety concern is documented.
- Object to or restrict how we process your information.
- Complain to the Irish Data Protection Commission (dataprotection.ie) if you believe we've handled your data unlawfully.
(The right to data portability generally does not apply here, because we don't process your data on the basis of consent or a contract in a way that would trigger it.) To exercise any of these, email [email protected]. Our process for erasure requests is on the Data & Erasure Requests page.