Skip to content
Erobino

Legal

Privacy

What we collect, why we have it, who else can see it, and how to get it removed. Written to be read, not to be survived.

Last updated 12 August 2026.

Who is responsible

Erobino (company registration pending) is the data controller for everything described here. Write to [email protected] about anything on this page, including the requests in “Your rights”.

The short version

  • We do not run advertising, and we do not sell anything about you to anyone.
  • There are no analytics trackers on this site. Nobody is following you around the internet from here.
  • Photographs have their location data stripped before they are stored, not before they are shown.
  • We never store identity documents.
  • Messages stay between the two people in them, unless one of them reports something.

Special category data

A profile on Erobino says something about a person's sex life. Under the GDPR that is “special category” data and gets the strictest treatment there is.

We rely on your explicit consent (Article 9(2)(a)) to publish it, given when you create a profile and publish it. You can withdraw that consent at any time by hiding your profile, which removes it from search, city pages and every listing immediately.

What we hold

Your account

Name, email address, password (hashed, never readable), the type of account, and the language you use.

Why: To have an account at all — performance of a contract.

Where you connected from

The IP address and country you signed up from, and when you were last active.

Why: To detect duplicate and fraudulent accounts. Legitimate interest, and one of the few things here you cannot switch off, because it is what keeps fake profiles down.

Your profile

Everything you type into it: name, bio, age, gender, height, languages, services, rates.

Why: Explicit consent. It is published because you asked for it to be.

Where you are and where you are going

Your city, your availability, and the dates of trips you add.

Why: Explicit consent. It is the point of the product, and it is as public as the rest of your profile.

Photographs

The pictures you upload, re-encoded. Location data and camera metadata are removed before anything is written to storage. We also keep a short mathematical fingerprint of each picture.

Why: Explicit consent to publish. The fingerprint is legitimate interest: it is how the same stolen photograph is spotted across several accounts.

Messages

What you write, when it was sent, and when it was read.

Why: Performance of a contract, and legitimate interest in keeping the platform safe.

Blocks and reports

Who you have blocked, and anything you report.

Why: Legitimate interest in keeping people safe from each other.

Verification

That a check happened, who decided, when, and a reference to where the check is recorded.

Why: Legal obligation and legitimate interest. See the next section for what is deliberately absent.

Favourites and trips

What you saved and the trips you planned. Only you can see these.

Why: Performance of a contract.

A record of moderation decisions

What staff did, when, and to what.

Why: Legal obligation. We must be able to answer for our own decisions.

What we do not hold

Identity documents. Verification is checked elsewhere — today in a short video call, later through a specialist provider — and all Erobino keeps is that it happened, who decided, and when. There is no field in our database for a passport, and there is not going to be one. A breach of a system holding those documents would out people who are relying on us not to.

Payment details. We do not take payments yet. When we do, card details will go to the payment provider and never touch our servers.

Your exact location. We store the city you say you are in. We do not track you, and the GPS coordinates in the photographs you upload are removed before the file is stored.

Who else sees it

Only the companies that run the machinery. None of them are allowed to use your data for their own purposes.

Hetzner Online GmbH · Germany
The servers and the database.
Cloudflare · European Union
Sits in front of the site and stores the photographs. Sees the IP address of every visitor.
Google Ireland Limited · Ireland, and the United States
Google Analytics. Counts visits and records which pages are opened. Data may be processed outside the European Union under the EU–US Data Privacy Framework.

Your account, your profile, your messages and your photographs are stored inside the European Union and stay there. Analytics is the one exception, and it never receives your name, your email address or anything you typed.

There is no advertising network and no social media pixel. Nobody else is on this list.

We hand data to the police or a regulator only when the law requires it, and we tell you when we are allowed to.

Cookies

Three are needed for the site to work: one that keeps you signed in, one that stops other websites submitting forms as you, and — before launch — one that remembers you were given a preview link.

We would also like to use Google Analytics to see which pages are used. It sets its own cookies and it tells Google the address of the page you are on, and on this site that address says what you were looking at.

It does not load unless you say yes. Not the script, not a cookie, not a single request — we ask once, and if you decline or ignore the question, nothing is ever sent. There is no advertising and no social media pixel, and we never send Google your name, your email address or anything you typed.

Changed your mind, either way? This clears your answer and asks again.

How long we keep it

  • Your account and profile: until it is erased at your request.
  • Messages: as long as both accounts exist. A conversation belongs to two people, so one of them cannot delete it for the other.
  • Sign-up IP address: two years, then removed.
  • Moderation records: five years. We have to be able to answer for decisions long after we made them.
  • Blocks: until you remove them. A block that expired on its own would be worse than useless.

Your rights

You can ask for a copy of everything we hold about you, ask us to correct it, ask us to erase it, ask us to restrict what we do with it, or object to it. Write to [email protected]. We answer within a month.

Erasure is by request, not by button

You can hide your profile yourself, instantly, and that takes it out of search, city pages and every listing. There is no delete button, and that is deliberate.

Deleting a profile would turn every copy of a link you have handed out into a dead page, and would take half of every conversation with it — and a conversation belongs to two people. An account that has been taken over, or somebody acting in a moment of anger, should not be able to do something nobody can undo.

So we do it on request, after checking it is really you. Ask, and it is done — photographs included.

If you think we have handled your data badly, you can complain to your national data protection authority. In Denmark that is Datatilsynet.

Adults only

Erobino is for people aged 18 and over. We do not knowingly hold data about anyone younger, and an account that turns out to belong to a minor is removed along with everything on it. If you believe we are holding data about a child, write to [email protected] and we will act the same day.

Changes

When this page changes in a way that matters, we will say so on the site rather than quietly updating the date at the top.