Privacy Policy
What this editorial site collects about its readers, why, for how long, and how to exercise your rights under California, other US state, EU, and UK privacy law. Effective and last updated: September 3, 2026.
Summary
Clothoff AI is an independent editorial project run by the Clothoff AI Editorial Team. The site publishes reviews and comparisons of third-party undress-AI tools; it does not operate a generator, does not accept uploads, and does not process or store images. This Privacy Policy explains the small amount of personal information the site does handle when you read it or write to us. It is written in plain language and is not legal advice.
- No accounts, no uploads. There is no registration, login, or profile system, so there is no account to create or delete.
- Five data categories only. Server logs, Google Analytics, a yes/no age-gate flag, emails you send us, and aggregate click counts on affiliate redirects.
- No sale of personal information. We have never sold personal information. Analytics cookies may count as “sharing” under California law, so we provide an opt-out on Do Not Sell or Share My Personal Information.
- Rights for everyone. Access, deletion, correction, portability, and opt-out requests are handled through Privacy Rights Request or privacy@clothoff.ai, for any visitor, in any state or country.
- Cookies in detail. Names, lifetimes, and controls are in the Cookie Policy.
Who We Are and What This Policy Covers
This policy applies to the website this website and its Markdown mirror pages. It does not cover the third-party tools we review. When you leave this site through a review link, the provider’s own privacy policy applies, and we have no access to what you do there. Our editorial independence and the way affiliate commissions are handled are described in the Editorial policy and the Affiliate disclosure.
The site is for adults 18 and older. It reviews adult-oriented tools and asks every visitor to confirm their age before the content is shown. More on state rules for age checks: State age verification. Safety expectations for using any reviewed tool — only your own photos or photos of consenting adults — are set out in Responsible AI.
What We Collect, Why, and for How Long
The table lists every category of personal information the site handles. We collect nothing else: no names, no payment data, no photos, no account credentials, no precise geolocation, and no sensitive personal information as defined in Cal. Civ. Code §1798.140(ae).
| Category | What it contains | Why we use it | Legal basis (EU/UK visitors) | Retention |
|---|---|---|---|---|
| Server and edge logs | IP address, browser and device signature (user agent), requested URL, referring page, date and time, HTTP status | Security, abuse and bot detection, capacity planning, debugging | Legitimate interests, GDPR Art. 6(1)(f) | Up to 30 days, then deleted or reduced to aggregate counts |
| Google Analytics 4 (via Google Tag Manager container GTM-KQW3DB4F, property G-YDLCXGXXQB) | Pseudonymous client ID in the _ga and _ga_G-YDLCXGXXQB cookies, pages viewed, approximate city-level location derived from IP, device and browser type, referral source | Understanding which reviews and guides are read, fixing broken pages, measuring the reach of editorial content | Consent where required (ePrivacy/PECR); otherwise legitimate interests | Cookies: 2 years. Google Analytics event- and user-level data: no longer than 14 months, the maximum for standard properties |
| Age-gate flag | The key clothoffai_age_ok in your browser’s localStorage, storing a single yes value | Remembering your 18+ confirmation, so the age screen is not shown on every page | Strictly necessary for the service you requested | Until you clear site data in your browser; it has no server-side copy |
| Email correspondence | Your email address, the content of your message, and any attachments you choose to send to editorial@, privacy@, legal@, ncii@, dmca@, abuse@, accessibility@, or lawenforcement@clothoff.ai | Answering questions, handling corrections, processing privacy, DMCA, and NCII requests, keeping a record of legal notices | Legitimate interests; legal obligation for DMCA, NCII, and privacy requests | Up to 24 months after the thread is closed; DMCA and NCII records as long as the DMCA and NCII report pages state |
| Affiliate redirect counts | The number of clicks on each /go/ redirect per day, without IP addresses, cookies, or identifiers | Reporting to partners how many readers followed a sponsored link | Legitimate interests | Indefinitely, as anonymous aggregate statistics |
How affiliate redirects work, and why they never influence scores, is explained in the Affiliate disclosure. Retention periods above are maximums; we delete earlier whenever a record is no longer needed.
Who Receives Data
We do not sell personal information and we do not run advertising networks on this site. Data leaves our systems only in the cases below.
- Google (Google Analytics 4 and Google Tag Manager). Google processes analytics data on our behalf and under its own policies. Google states that “Google Analytics does not log or store IP addresses from EU users” and derives only coarse city-level location from the address (Google, EU-focused data and privacy). Google’s general terms: How Google uses information from sites that use its services.
- Hosting and edge network (Cloudflare and our static-hosting provider). These providers deliver the pages and see the same request data as our server logs. They act as processors for us.
- Affiliate partners. When you click a sponsored link, the partner receives an HTTP referrer and the redirect identifier. We do not pass your IP address, email, or any profile to partners.
- Legal requests. We disclose data only when a valid legal process requires it, following the procedure on Law enforcement requests.
Google may process analytics data in the United States. For EU, EEA, and UK readers this is an international transfer covered by Google’s standard contractual clauses and, where applicable, the EU-US Data Privacy Framework, as described in Google’s Privacy Policy.
Cookies and Similar Technologies
The site sets two analytics cookies and one localStorage item. The _ga cookie “enables the service to distinguish one visitor from another and lasts for 2 years,” according to Google’s cookie documentation. The property-specific cookie _ga_G-YDLCXGXXQB has the same 2-year lifetime. Neither cookie contains your name, email, or IP address.
US visitors see no consent banner by default; you can decline analytics at any time by enabling Global Privacy Control, blocking cookies, or installing the Google Analytics opt-out browser add-on. Visitors from the EU, EEA, or UK are asked for consent before analytics runs, because the UK ICO and EU regulators require that “you must also get the user’s consent” for non-essential cookies (ICO, Cookies and similar technologies). Full details: Cookie Policy.
California Privacy Rights (CCPA/CPRA)
The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (Cal. Civ. Code §§1798.100–1798.199.100), applies to businesses that exceed statutory thresholds: annual gross revenue above $26,625,000 (the figure adjusted by the California Privacy Protection Agency effective January 1, 2025), buying, selling, or sharing the personal information of 100,000 or more consumers or households, or deriving 50 percent or more of revenue from selling or sharing personal information (Cal. Civ. Code §1798.140(d); CPPA, Updated Monetary Thresholds). This editorial project is unlikely to meet any threshold, but we honor every CCPA right for all visitors as a matter of policy.
Under the CCPA you have the right to:
- Know what personal information we collect, the sources, purposes, and recipients, covering the 12 months before your request (§1798.130(a)(2)(B)).
- Delete personal information we collected from you, subject to statutory exceptions such as security and legal-compliance records.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information: “A consumer shall have the right, at any time, to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer’s personal information” (§1798.120(a)). Use Do Not Sell or Share My Personal Information.
- Limit the use of sensitive personal information. We collect none, so there is nothing to limit.
- Non-discrimination for exercising any right. The site is free and identical for everyone.
Categories collected in the last 12 months: identifiers (IP address, cookie ID, email address if you write to us) and internet or network activity (pages viewed, referrer, browser type). Sold: none. Shared for cross-context behavioral advertising: possibly identifiers and internet activity through Google Analytics cookies, which is why the opt-out exists. Disclosed for a business purpose: identifiers and internet activity to our analytics and hosting processors.
We honor opt-out preference signals such as Global Privacy Control, as required by §1798.135(c) and CCPA Regulations §7025; receipt of a request is confirmed within 10 business days and answered within 45 calendar days under Regulations §7021, and opt-out requests are completed within 15 business days under §7026 (CPPA, Law and Regulations). We do not have a “Shine the Light” disclosure obligation under Civ. Code §1798.83 because we do not disclose personal information to third parties for their direct marketing. Requests may be submitted through Privacy Rights Request or privacy@clothoff.ai; an authorized agent may act for you with written permission. Official guidance: California Attorney General, CCPA.
Other US State Privacy Laws
As of September 3, 2026, comprehensive consumer privacy laws are in effect in 19 states: California (2020), Virginia (2023), Colorado (2023), Connecticut (2023), Utah (2023), Texas (2024), Oregon (2024), Montana (2024), Delaware, Iowa, Nebraska, New Hampshire, and New Jersey (2025), Tennessee, Minnesota, and Maryland (2025), and Indiana, Kentucky, and Rhode Island (January 1, 2026). Laws in Louisiana and Oklahoma (2027), Alabama (May 2027), and Vermont (2028) have been signed but are not yet effective. Florida’s Digital Bill of Rights applies only to very large companies.
Most of these statutes apply above processing thresholds that a small editorial site does not reach. We nevertheless grant the common core of rights — access, correction, deletion, portability, and opt-out of targeted advertising and sale — to every visitor, and we honor universal opt-out mechanisms such as Global Privacy Control everywhere. If we decline a request you may appeal by replying to our decision; we answer appeals within 45 days and tell you how to contact your state Attorney General if you still disagree.
Visitors From the EU, EEA, and UK
If you read this site from the European Union, the European Economic Area, or the United Kingdom, Regulation (EU) 2016/679 (GDPR) or the UK GDPR applies. The controller is the Clothoff AI Editorial Team, reachable at privacy@clothoff.ai; we have not appointed a representative or a data protection officer because our processing is small-scale and low-risk.
Legal bases: legitimate interests (Art. 6(1)(f)) for server logs, security, and correspondence; consent (Art. 6(1)(a)) for analytics cookies; legal obligation (Art. 6(1)(c)) for records of takedown and rights requests. You may withdraw consent at any time in the Cookie Policy controls without affecting the lawfulness of earlier processing.
Your rights under Articles 15 to 22 include access, rectification, erasure, restriction, portability, and objection. The GDPR requires that a controller “shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request” (GDPR Art. 12(3), EUR-Lex); that period may be extended by two further months for complex requests. The UK ICO confirms the same one-month rule (ICO, A guide to subject access). You also have the right to lodge a complaint with your supervisory authority (Art. 77). Use Privacy Rights Request to exercise any right.
Children and Age Limits
This site is intended for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18, and we do not sell or share the personal information of anyone under 16, in line with Cal. Civ. Code §1798.120(c). The Children’s Online Privacy Protection Act (COPPA), enforced by the Federal Trade Commission, protects children under 13; if we learn that we hold data from a child, we delete it. Parents or guardians may write to privacy@clothoff.ai.
Security, Changes, and Contact
All pages are served over HTTPS. The site is static: there is no database of users, no login system, and no server-side image processing, which removes the most common attack surfaces. Access to mailboxes and analytics is limited to the editorial team and protected with two-factor authentication.
When this policy changes, we update the date at the top and describe material changes in the Transparency report. Continued use of the site after a change means the updated policy applies to data collected from that date onward.
Contact
Privacy questions and requests: privacy@clothoff.ai. Corrections to published content: editorial@clothoff.ai. Non-consensual intimate imagery: Report NCII. Copyright: DMCA. General contact options are listed on Contact. Related policies: Terms, Disclaimer, Acceptable use.
Privacy Policy FAQ
How do I delete a Clothoff account?
There is no account to delete. this website has no registration, login, or profile system, and it never receives or stores images. If a look-alike app asked for an account, that provider, not this site, holds the data; check its own privacy policy or send its name to privacy@clothoff.ai and we will point you to the right contact where we can.
Does this site upload, process, or store photos?
No. The site is an editorial catalog of reviews. It has no upload form, no generator, and no image storage. All hands-on tests run on the reviewed providers’ own websites with the editorial team’s control photos. The only personal data we handle is described above: server logs, analytics identifiers, an age-gate flag, and emails you send us.
What personal data does this website actually collect?
Five categories: (1) server and edge logs with your IP address and browser signature, kept up to 30 days; (2) Google Analytics identifiers in the _ga cookies; (3) a yes/no age-gate flag in your browser’s localStorage; (4) emails you send to our role addresses; (5) aggregate click counts on /go/ affiliate redirects without personal data.
Do you sell or share my personal information?
We do not sell personal information and have never done so. Google Analytics cookies could count as “sharing” for cross-context behavioral advertising under Cal. Civ. Code §1798.140(ah), so we treat them as opt-outable. Turn on Global Privacy Control, block the cookies, or follow the steps on Do Not Sell or Share.
How fast will you answer a privacy request?
We confirm receipt within 10 business days and answer within 45 calendar days; if we need more time, we tell you and take at most 45 additional days (90 in total), as the CCPA regulations allow. Visitors from the EU, EEA, or UK receive an answer within one month. Opt-out signals are processed within 15 business days.
Which US states’ privacy laws do you honor?
All of them, without checking residency. Comprehensive laws are in force in 19 states as of September 3, 2026, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. We extend the same rights to every visitor via Privacy Rights Request.
Where do I complain if I am not satisfied?
First reply to our decision email; we answer appeals within 45 days. California residents may also contact the California Privacy Protection Agency or the Attorney General; residents of other states may contact their state Attorney General. EU or UK residents may lodge a complaint with their supervisory authority under GDPR Article 77, for example the ICO in the UK.