Privacy Policy
Last updated:
At Lenacore TV, we believe your privacy is sacred. This policy explains what data we collect, why we collect it, and what rights you have. No gatekeeping. No surveillance. No dark patterns.
1. Introduction
Lenacore TV Studios LLC ("we," "our," "us," or "Lenacore TV") operates the website and streaming platform at tv.lenacore.net. This Privacy Policy outlines our commitment to protecting your personal information and your rights under applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CPRA).
We are a San Francisco-based video hosting platform founded in 2022. Our mission is to democratize premium video content without compromising your privacy. This policy is binding on all users of our platform, whether you're a viewer, creator, or partner.
2. Data We Collect
2.1 Personal Information
We collect personal information only when you voluntarily provide it:
- Account registration: Name, email address, password (hashed), optional profile picture, bio, and location when creating a creator account.
- Payment information: When you donate to creators, purchase premium features, or request payouts, we collect billing name, address, and payment method. We never store full credit card numbers—payment processing is handled by PCI-DSS compliant third-party processors.
- Communications: If you contact us via email at admin@tv.lenacore.net, submit a support ticket, or participate in surveys, we collect your message content.
- Creator information: Tax identification numbers (W-9/W-8BEN) for revenue distribution, bank account details for payouts, and optional biographical information.
- Subscriber information: Email address if you opt into our newsletter (completely optional, unsubscribe anytime).
2.2 Technical Information
We collect minimal technical data to operate the platform:
- Device information: Device type, operating system, browser type, and screen resolution—only to optimize video playback and UI rendering.
- Network data: IP address (anonymized after 30 days), connection speed, and bandwidth diagnostics for CDN optimization only. We do not use IP data for behavioral profiling.
- Video playback metrics: Play, pause, seek, and completion events linked to your account. This helps creators understand their audience but never feeds into algorithmic ranking—you control what you discover.
- Platform activity: Timestamp of login, logout, uploads, comments, and watch history duration (not content identification for advertising purposes). Your watch history is private to you unless you choose to share it.
- Error logs: Crash reports and error messages to improve platform stability. These logs are deleted after 90 days.
2.3 Cookies & Local Storage
We use cookies and local storage minimally:
- Session cookies: To keep you logged in. Cookie prefix: lctv_session (expires after 30 days of inactivity).
- Preference cookies: lctv_theme (light/dark mode), lctv_language (your language preference), lctv_quality (video quality preference). These persist for one year.
- Analytics cookies (optional): lctv_analytics_consent: If you explicitly consent, we use a privacy-respecting analytics service (no third-party vendor tracking). You can opt out anytime in settings.
- Local storage: Draft video metadata, unsent comments, and playback position—all stored locally on your device, never synced to our servers without your action.
- No advertising or tracking cookies: We do not use cookies for behavioral targeting, retargeting, or third-party advertising networks.
3. How We Use Your Data
We use the data you provide for the following purposes, each with a clear legal basis:
- Account management & authentication: Creating and maintaining your account, password recovery, and security verification (legal basis: contract/consent).
- Content delivery: Streaming videos at optimal quality, managing uploads, and transcoding to multiple formats (legal basis: contract).
- Creator revenue & payouts: Calculating earnings, processing donations and sponsorships, distributing revenue, and tax compliance (legal basis: contract/legal obligation).
- Platform improvement: Analyzing error logs and usage patterns to fix bugs and improve performance—never for algorithmic content ranking (legal basis: legitimate interest).
- Security & fraud prevention: Detecting unauthorized access, DDoS mitigation, and preventing abuse of creator accounts (legal basis: legitimate interest).
- Customer support: Responding to your inquiries, technical troubleshooting, and dispute resolution (legal basis: contract).
- Legal compliance: Meeting regulatory requirements, responding to lawful government requests with proper warrants, and maintaining records (legal basis: legal obligation).
- Communications (with consent): Sending you newsletter updates, platform announcements, and feature releases—only if you've opted in. You can unsubscribe instantly.
We do not use your data to build behavioral profiles, train machine-learning models for content ranking, or sell to advertisers or data brokers.
4. Sharing & Disclosure of Your Data
We share your data only when necessary and with strict confidentiality agreements:
- Service providers: Payment processors (Stripe, PayPal), email delivery (SendGrid), CDN partners (Cloudflare, Bunny CDN), and hosting providers (AWS). All have signed Data Processing Agreements (DPAs) and are GDPR/CCPA compliant.
- Creators & analytics: Video creators can see anonymized viewer aggregates (total views, watch time, top regions) but never individual viewer names, emails, or watch history unless you publicly comment.
- Public content: Your username, profile picture, and any comments you post on videos are publicly visible. Your watch history is private by default.
- Legal requests: We comply with lawful government requests (subpoenas, warrants, court orders). We will notify you before disclosure unless legally prohibited. We do not comply with requests lacking proper legal authority.
- Business transfers: If Lenacore TV is acquired or merges, your data may be transferred as part of the transaction. You will be notified with at least 30 days' notice and the right to request deletion.
- No third-party marketing: We do not sell, rent, or share your email or viewing history with advertisers, data brokers, or marketing firms.
5. Your Privacy Rights (GDPR & CPRA)
Depending on your location, you have the following rights:
5.1 GDPR Rights (European Users)
- Right to access: Request a copy of all personal data we hold about you.
- Right to rectification: Correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request deletion of your data, with certain legal exceptions (e.g., tax records, legal holds).
- Right to restrict processing: Limit how we use your data while a dispute is being resolved.
- Right to data portability: Receive your data in a machine-readable format (JSON, CSV) to export or transfer to another service.
- Right to object: Opt out of processing for marketing, profiling, or legitimate interest purposes.
- Right to lodge a complaint: Contact your local Data Protection Authority if you believe we've violated your rights.
5.2 CPRA Rights (California Residents)
- Right to know: What personal information we collect, use, and share.
- Right to delete: Request deletion of personal information, with exceptions for legal obligations.
- Right to correct: Correct inaccurate information.
- Right to opt-out: Opt out of "sales" or "sharing" of personal information (we don't do this, but you have the right).
- Right to limit use: Restrict use of sensitive personal information (SSN, health data, etc.).
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
5.3 How to Exercise Your Rights
To submit a privacy request, email admin@tv.lenacore.net with the subject "PRIVACY REQUEST" and specify which right you're exercising. Include your account email and any supporting details. We will respond within 30 days (45 days for complex requests). Verification of identity may be required to prevent unauthorized access to your data.
6. Data Retention
We retain your data only as long as necessary:
- Account data: Retained for the life of your account. Upon deletion, deactivated for 30 days (recovery window), then permanently deleted.
- Payment records: Retained for 7 years for tax and compliance purposes (as required by US law).
- Video metadata & analytics: Aggregated (anonymized) viewership data is retained indefinitely for historical reporting. Individual viewer identifiers are deleted after 12 months.
- Cookies & session data: Automatically expire as noted above (30 days for sessions, 1 year for preferences).
- Error logs & diagnostics: Deleted after 90 days unless a security investigation requires longer retention.
- Support tickets & communications: Retained for 2 years unless you request deletion sooner.
- Archived content: If you delete a video, we retain a backup in our archive for 30 days for recovery purposes. Historically significant content may be preserved with the Internet Archive; you can opt out.
7. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit: All data is transmitted via HTTPS/TLS 1.3. API requests are signed and timestamped.
- Encryption at rest: Sensitive data (passwords, payment info, tax IDs) is encrypted with AES-256. Encryption keys are rotated quarterly.
- Password security: Passwords are hashed using bcrypt with a cost factor of 12, never stored in plaintext.
- Access controls: Only authorized personnel with a legitimate business need can access personal data. All access is logged and audited.
- Network security: Firewalls, intrusion detection, and DDoS protection via Cloudflare. Regular security audits and penetration testing.
- Data minimization: We collect and retain only the minimum data necessary. Non-essential personal data is pseudonymized or deleted.
- Incident response: In the event of a data breach, we will notify affected users and relevant authorities within 72 hours (as required by GDPR). A breach investigation and remediation plan will be published.
While we strive for the highest security, no system is 100% secure. You are responsible for maintaining the confidentiality of your password and account.
8. Children's Privacy (COPPA Compliance)
Lenacore TV does not knowingly collect personal information from children under 13 years old. Our platform is intended for ages 13+. If you are under 13, please do not create an account or submit personal information.
If we become aware that we have collected information from a child under 13, we will delete it immediately and notify the parent/guardian. Please contact admin@tv.lenacore.net if you believe a child has created an account.
For users aged 13–18, we provide enhanced privacy protections: watch history is fully private by default, no cookies beyond session management, and parental consent options available upon request.
9. International Data Transfers
Lenacore TV is based in San Francisco, California. Your data is primarily stored in US data centers operated by AWS. If you are in the EU or elsewhere, your data is transferred internationally.
We ensure these transfers comply with GDPR and other regulations via:
- Standard Contractual Clauses (SCCs): Our service providers are bound by SCCs approved by the European Commission.
- Privacy Shield / Adequacy decisions: We monitor legal adequacy determinations and adjust practices accordingly.
- Your consent: By using Lenacore TV, you consent to the transfer of your data to the United States, subject to the protections outlined in this policy.
You have the right to request that your data be stored in an alternative jurisdiction (e.g., EU data center). Contact us at admin@tv.lenacore.net for options.
10. Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Posting the updated policy on this page with a new "Last updated" date.
- Sending an email notification if the change significantly affects your rights (you can opt out of these notifications, but we recommend staying informed).
- Requiring explicit consent if the change expands our data collection or sharing in new ways.
Your continued use of Lenacore TV after an update constitutes acceptance of the new policy. For significant changes, you will have at least 30 days to review and accept before the change takes effect.
11. Contact Us
If you have questions, concerns, or wish to exercise your privacy rights, please contact us:
Lenacore TV Studios LLC
575 Market St Suite 400
San Francisco, California 94105
United States
Email: admin@tv.lenacore.net
Phone: +1 (442) 412-1779
Data Protection Officer (DPO): Privacy requests are routed to our legal and compliance team for response within 30 days.
If you are unsatisfied with our response or believe we've violated your privacy rights, you have the right to lodge a complaint with your local data protection authority:
- EU/EEA: Your national Data Protection Authority (e.g., CNIL in France, ICO in UK).
- California: California Attorney General's Office or California Privacy Protection Agency (CPPA).