privacy policy

effective june 2026 · 18+ platform
the short version: (you)r room is (you)rs. we cannot read (you)r messages — they are encrypted before leaving (you)r device. we do not sell (you)r data, run ad targeting, or build behavioral profiles. thaypley is funded by subscriptions, not surveillance.

what we collect

what we do not collect

E2E messaging

thaypley uses libsodium crypto_box (X25519 + XSalsa20-Poly1305) for all direct messages. (you)r key pair is generated on (you)r device. the public key is shared with recipients so they can encrypt messages to (you). the private key never leaves (you)r device.

what the server stores per message: ciphertext (encrypted blob), nonce (random value), sender ID, recipient ID, and timestamp. nothing readable. a database breach exposes no message content.

content tiers & age verification

thaypley is an 18+ platform. we verify age at signup and store an encrypted birthday + an age-verified flag. creators may label their content general, mature, or explicit. explicit content requires age verification and is never shown to any account without it. thaypley does not censor expression — the tier system is a gate, not a judge.

data sharing

(you)r rights

security

we use HTTPS with HSTS, AES-256-GCM for sensitive fields, and rate limiting on all endpoints. our API enforces strict CORS and origin validation. we do not log message content. security incidents are disclosed within 72 hours to affected users.

contact

questions? privacy@thaypley.com

thaypley is built and maintained by @(u)azit.