Legal
Privacy policy
What data CharmMap processes, why, for how long — and how you get rid of it.
Last updated: 2026-08-31
The short version
CharmMap is free and ad-free. We do not sell data, we run no advertising, and we embed no third-party ad networks, social plugins or tracking services. Analytics run cookie-free on our own infrastructure. That is why there is no cookie banner here: there is nothing to consent to.
Does a profile concern you that you did not create yourself? Then you do not need to read this text. Go straight here: Request profile removal. No account, no proof, no reason required.
1. Controller and contact
The controller within the meaning of Art. 4(7) GDPR is the operator of the website charmmap.com.
All privacy matters reach us at [email protected]. This is the binding contact channel — including for access, erasure and objection. We respond within one month as required by Art. 12(3) GDPR. Requests are handled even if you do not give a legal name.
A postal address for service is made available to authorities, courts and rights holders on request via the same address. It is deliberately not published on the site: the operator side of a directory for sex work is itself a target.
2. When you only read CharmMap
Server logs
Every request leaves a technical entry on the server: truncated IP address, timestamp, requested address, status code, bytes transferred, referrer and browser identifier.
- Purpose: delivering the page, troubleshooting, defending against attacks and automated abuse.
- Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure, uninterrupted operation.
- Retention: 14 days, then automatic deletion.
Analytics
We measure with Matomo, self-hosted, with cookies disabled (disableCookies). No cookie is set, no cross-device identifier is formed, and nothing is transmitted to third parties. Recorded are: page viewed, referrer, coarse region, device type and loading times (Core Web Vitals). The IP address is processed truncated only.
- Legal basis: Art. 6(1)(f) GDPR. Because no cookie is set and no information is accessed on your device, § 25(1) TDDDG does not apply — consent is therefore not required.
- Objection: enable "Do Not Track" in your browser. Matomo is configured to respect it.
Cookies and local storage
We set strictly necessary cookies only. None of them serve advertising or profiling:
age_ok— remembers that you confirmed the age notice. Content: a1. Lifetime: 12 months.projecte.session_token— only after signing in. Links your browser to your session. Lifetime: 30 days, ends when you sign out.- Your browser's
localStorageholds display preferences such as light/dark mode. These values never leave your device.
Legal basis: § 25(2)(2) TDDDG — strictly necessary for a service you explicitly requested; additionally Art. 6(1)(f) GDPR.
3. Profiles in the directory
This is the part that matters. CharmMap contains two kinds of profile, and they are treated differently.
a) Profiles from publicly accessible sources
Some entries originate from publicly accessible directories and listing sites. Processed are: display name, city, services offered, languages, price information, description text and the address of the source page. Photos are not copied and not stored on our servers — only the source image address is recorded and passed through on request.
- Legal basis: Art. 6(1)(f) GDPR — interest in a complete, findable directory and in informing users.
- Data minimisation: only information the data subject has themselves published publicly to advertise their service is taken over. No home addresses, no identity documents, no health data.
- Not indexed by search engines: as long as a profile has not been claimed by the person concerned, it carries
noindex. It does not appear in Google, Bing or comparable services. This is not a detail but the central safeguard: reach stays confined to CharmMap until the person concerned decides otherwise. - Objection under Art. 21 GDPR: at any time, informally and without giving reasons, via Request profile removal or by email to [email protected]. We act on every objection without exception.
b) Profiles created or claimed by the person themselves
Anyone who lists a profile or claims an existing one processes the following data: email address, phone number for the confirmation code, display name, plus everything they voluntarily add.
- Legal basis: Art. 6(1)(b) GDPR — performance of the user agreement.
- Special categories (Art. 9 GDPR): information about sexual preferences or sexual orientation is specially protected data. If you put such information in your profile, you are manifestly making it public yourself within the meaning of Art. 9(2)(e) GDPR. Do not write anything there that should not be public.
- Confirmation code: the phone number is transmitted to our SMS provider solely to deliver the code. The code itself is stored only as a hash.
4. Account, favourites, saved searches
An account is not needed to read the directory. If you create one, we store: email address, display name, password (as a hash only, never in clear text), language, role, plus the IP address and browser identifier of each active session — the latter so that you can spot and end unfamiliar sign-ins.
Favourites and saved searches belong to your account and are visible to no one else.
- Legal basis: Art. 6(1)(b) GDPR.
- Retention: until the account is deleted. All associated data is then removed; sessions expire after 30 days of inactivity at the latest.
5. Reviews and reports
Reviews are possible only on claimed profiles and require an account. Stored are text, rating, timestamp and account ID. The legal basis is Art. 6(1)(f) GDPR.
You can report problematic content without an account. Stored are the reason, free text and timestamp. Reports indicating minors or coercion go into a separate queue and are reviewed with priority — the entry concerned is hidden in the meantime.
6. Erasure and the blocklist — the paragraph that matters most
When a profile is removed on request, a technical problem arises: once the data is deleted, the same entry could simply be picked up again on the next automated run. An erasure that undoes itself is not an erasure.
We therefore store, for a removed profile, only irreversible checksums (HMAC) of its identifiers — phone number, source address, image addresses. A checksum cannot be reversed into the original value. It permits exactly one operation: recognising a newly found entry and not taking it in again.
- Legal basis: Art. 6(1)(c) and (f) GDPR — enforcing the right to erasure under Art. 17 GDPR. Without this list the erasure would not be effective.
- Retention: indefinite. The block is meant to last, and it no longer contains readable personal data.
- We also store a hash of your email address with your request so we can confirm receipt without retaining the address itself.
7. Recipients and processors
We pass on no data for advertising purposes and sell nothing. In use are:
- Hosting and data centre inside the EU — running the application, database and object storage.
- Content delivery network — delivery and attack mitigation. This necessarily involves processing the IP address of the request.
- SMS provider — solely to deliver the confirmation code when a profile is claimed.
- Email delivery service — solely for confirmation and password emails.
Data processing agreements under Art. 28 GDPR are in place with all providers. Where processing takes place outside the EU, it is based on the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR.
8. Search index
For filtered search we run our own search index (Meilisearch) on the same infrastructure. It holds a copy of already published profile information and no account or contact data. A profile that is removed disappears there too.
9. Images from external sources
External images are never copied to our servers. They are delivered through a dedicated image endpoint that signs the target address, checks it against an allowlist and forwards the request to the origin server. In doing so the origin server does not learn who is viewing the image: your IP address never reaches it, our server fetches the image. That is the reason for this design.
10. Your rights
You have the right to:
- Access the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to any processing based on legitimate interest (Art. 21 GDPR) — which includes every profile from public sources
- Withdraw consent with effect for the future (Art. 7(3) GDPR)
A word on how seriously we take this: objecting to a scraped profile is not an exception here that you would have to justify. It is the intended normal route, it takes a minute, and it is acted on without follow-up questions.
Exercise all rights at [email protected] or via Request profile removal.
Independently of this, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular the authority of your habitual residence.
11. Automated decisions
There is no automated decision-making in individual cases and no profiling within the meaning of Art. 22 GDPR. The order of search results is a sort order, not a decision about people. Safety-relevant classifications are reviewed by humans before any publication.
12. Security
The connection is TLS-encrypted throughout. Passwords are stored as hashes only. One-time codes are stored hashed and compared in constant time. Administrative areas are not publicly reachable and are blocked for search engines.
13. Minors
CharmMap is intended for adults only. We knowingly process no data of persons under 18. Any indication of an age below 18 halts publication immediately and is reviewed separately. See Youth protection.
14. Changes
We adapt this text when the processing changes. The version published here at the time applies.