We collect what we need, nothing more. This page explains what data we gather, why we gather it, and what we do with it. No legal fluff. Just the truth.
01
What We Collect
When you use Gatekept, we collect a few types of information:
- Account info — your email address, username, and profile details (like your bio or avatar)
- Payment info — handled by Stripe or PayPal, depending on the creator you're paying. We never see or store your card number; the processor sends us just enough to show your purchase history.
- Content you upload — the files, images, descriptions, and anything else you post as a creator
- Usage data — things like which pages you visit, what you click, and how long you stay. This helps us understand what's working and what's not.
- Where you came from — when you arrive, we record referral context: the referring site, UTM campaign tags, and ad-click identifiers (like gclid or fbclid) if they're in the link, plus the page you landed on. We keep this per visit so creators' analytics and our own can say “this signup came from Instagram” — it powers stats, not ads. Signups and purchases store a snapshot of this context.
- Device & session info — browser, operating system, and approximate location (country/city, derived from your IP) for the sessions list in Settings, so you can spot a login that isn't you. Security-sensitive actions (logins, purchases, tips — including guest tips) are also recorded in an audit log with IP address and browser info.
- Identity verification — only if you opt into features that require it (like age-restricted content), verification is handled by a specialist provider (Didit). We store the outcome, not your documents.
02
How We Use It
We use your data to make Gatekept work. That's it. Here's what that means:
- To create and manage your account
- To process purchases and send payouts to creators
- To show your profile and products to other people on the platform
- To send you important updates (like order confirmations or policy changes)
- To fix bugs and improve the platform
- To keep Gatekept safe and prevent abuse
We use Supabase for authentication and our database, and Stripe and PayPal for payment processing.
03
What We Share
We do not sell your data. Not now, not ever. We will never sell your personal information to advertisers, data brokers, or anyone else.
We share data with the services that run the platform, each getting only what its job needs:
- Stripe and PayPal — to process payments and payouts
- Supabase — our database, authentication, and file storage
- Resend — to send you email (receipts, notifications, verification)
- Sentry — error reporting when something crashes, so we can fix it
- hCaptcha — bot checks on guest actions like tipping without an account
- Cloudmersive — uploaded files are scanned for malware before buyers can download them
- Didit — identity/age verification, only when you opt into features that require it
- Law enforcement & NCMEC — when we are legally required to (see Messages & Safety below)
Your public profile, username, and uploaded products are visible to other users. That's how a marketplace works. Everything else stays private.
04
Cookies
All of our cookies are first-party — no advertising cookies, and nothing from ad networks following you around the internet. What we actually set:
- Sign-in cookies — keep you logged in, including across our sister domains (gatekept.to, .art, .work, .agency), so moving between a creator's page and the app doesn't log you out
- A security cookie — protects forms against cross-site request forgery
- A session identifier — lets the “Sessions” list in Settings show your devices, and lets you sign one out remotely
We also use your browser's session storage (not cookies) to remember referral context — like the UTM tag on the link that brought you here — for the analytics described in “What We Collect”. It clears when you close the tab. If you clear cookies, you'll just need to sign in again.
05
Your Choices
You're in control. Here's what you can do:
- Update your info — edit your profile, email, or username anytime in Settings
- Download your data — you can request a copy of everything we have on you
- Delete your account — you can delete your account at any time. Your profile is anonymized (your name, bio, and avatar are removed and your username is released) and your content comes down. Transaction records are kept for legal and financial reasons, and anonymized analytics rows (no longer tied to you by name) are retained. Buyers keep access to things they bought.
If you want to do any of this, head to your Settings page or reach out to us directly.
06
Messages & Safety
Direct messages on Gatekept are private from other users — not from Gatekept. Messages are encrypted in transit and at rest, but they are not end-to-end encrypted, which means our systems can access them. Here's exactly how that access works:
- Automated scanning — every message is checked by automated systems at send time for scams, phishing, threats, and content that endangers minors. Machines scan broadly; humans look narrowly.
- Human review — moderators see message content only when something triggers it: an automated flag, a report from a participant in the conversation, or a valid legal request. Nobody at Gatekept browses inboxes, and moderator access is permission-gated and logged.
- Legal obligations — we report child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC) as required by law, and we respond to valid legal process (subpoenas, warrants).
If you need conversations that no service operator can read, use an end-to-end encrypted messenger — that is a different design than the one Gatekept uses, and we'd rather tell you that plainly than imply otherwise.
07
Data Security
We take security seriously. Your data is stored securely through Supabase with encryption. Passwords are hashed, not stored in plain text. Payment data lives on Stripe's servers, not ours.
No system is perfect. We can't guarantee that a breach will never happen, but we do everything reasonable to protect your information. If something does go wrong, we'll tell you.
08
Children's Privacy
You must be at least 16 to use Gatekept (see the Terms of Service), and at least 18 to sell. We do not knowingly collect data from anyone under 16. If we find out someone under that age has created an account, we will delete it and its data.
If you're a parent and you believe your child is using Gatekept, please contact us and we'll take care of it right away.
09
Changes to This Policy
We might update this policy from time to time. When we do, we'll change the “last updated” date at the top. If we make a big change, we'll let you know through the platform or by email.
We won't quietly change the rules on you. That's not how we operate.
10
Contact
If you have questions about this policy, your data, or anything else, reach out to us at privacy@gateke.pt.
We'll get back to you. For real.