Legal

Privacy Policy

What Roesas collects, why it holds it, and how long it keeps it.

This policy explains what information Roesas Operations LLC, a Florida limited liability company (“Roesas”) collects when you use roesas.com, trans.roesas.com, massage.roesas.com and related services, why it holds it, who else sees it, and how long it is kept.

It describes what the platform actually does, rather than what a privacy policy usually says. Where Roesas does not do something (including things people reasonably expect a website to do), this policy says so instead of staying quiet.

What Roesas collects

Account information

Email address, display name, and a hashed password

To create and secure your account, sign you in, and send you service messages.

Whether your email address has been confirmed

To reduce fraudulent registrations and to know whether we can reach you.

Account role and account dates

To decide what you can see and do, and to operate the service.

Advertisement and profile information

Everything you put in an advertisement: text, category, prices, availability, the city and region you advertise in, and your own external links

This is the advertisement. It is published.

Photographs and video, including Stories and Highlights

To publish, and to review before publishing.

A phone number and contact details where you provide them

Held privately for the account. These are never rendered on a public advertisement.

Identity and legal intake

The legal first and last name you type at intake

To match against verification and to identify the signer of an advertiser agreement. It is held privately and is never shown on a profile or an advertisement.

Your recorded confirmation that you are at least 18, that the content you submit is yours or authorised, and that you agree to the terms, with the date, the policy versions in force, and a cryptographic fingerprint of the exact wording you were shown

So that what you agreed to, and when, is a record rather than a recollection. The fingerprint makes a later edit to the wording detectable.

An opaque reference from the verification provider, the verification status, and the times it changed

To know whether identity and age have been established, without holding the underlying documents.

Technical information

A session record: a session token, its expiry, and the browser user-agent string

To keep you signed in and to let you and Roesas see where an account is signed in.

Your IP address, used in memory and not stored against your session

For rate limiting and abuse prevention. Roesas deliberately writes an empty value into the session record rather than keeping the address.

Server logs and operational diagnostics

To run, secure and debug the service.

Communications, moderation and payments

Support conversations between you and Roesas, and the queued email copies of them

To answer you and to keep a record of what was said.

Moderation and enforcement records: what was decided about an advertisement or a photograph, the reason, who decided it, and when

To operate review consistently, to handle disputes, and to enforce the rules.

Orders, entitlements, payment records, transaction references and, for cryptocurrency, the on-chain transfer details relevant to your payment

To take payment, to publish what you paid for, and to keep financial records.

Safety reports from the public

A report submitted through a public safety reporting form: which advertisement it concerns, the concern selected, the description written, any evidence link, and the date

To review the concern, to keep a record that the report was made and what was done about it, and to enforce the rules. Visible only to Roesas staff.

The reporter's email address, only where they choose to give one

So Roesas can contact them about the report if it needs to. It is optional, it is not verified, and a report can be made anonymously.

A public safety report creates no account for the person who made it, and Roesas does not store the reporter’s IP address or browser details. A report is an unverified allegation by a member of the public. It is a record of what somebody said, not a finding by Roesas.

Roesas does not collect a date of birth. Age is established through the verification provider rather than by storing a birth date. Roesas also does not collect government identifiers, bank account numbers or tax identifiers from advertisers.

Identity verification: what goes where

This is the part people most often assume wrongly, so it is set out precisely.

Identity and age checks are carried out by an independent verification provider. When you start a check, Roesas asks the provider for a short-lived token and hands that token to the provider’s own software running in your browser.

Your identity documents and your selfie go from your browser to the verification provider. They do not pass through Roesas, and Roesas does not request, receive or store them. Roesas does not call any provider endpoint that would return them.

What Roesas receives back, and keeps, is:

  • an opaque reference identifying your check with the provider
  • the outcome: not started, in progress, approved, or rejected
  • whether the provider holds a submission, and whether a resubmission is required
  • the times at which those changed

Roesas does not receive or store document images, extracted document fields, the provider’s internal comments or labels, or its raw event payloads. The legal name Roesas holds is the one you typed at intake, not one returned by the provider.

The verification provider processes the information submitted through its verification service under its own applicable privacy terms and data-processing arrangements.

The purposes for which Roesas uses the result are age and identity verification, fraud prevention, safety, and meeting legal obligations.

Signed advertiser agreements

Roesas has built the capability to require a signed agreement for each individual advertisement. No such agreement is currently in force, and no signatures have been collected. This section describes what would be recorded if and when one is brought into force, so that it is not a surprise.

An execution record would contain:

  • the advertisement it covers, and that advertisement's number and address at the time
  • the account that signed, where that account still exists
  • the verified legal name held at the moment of signing, and the name typed as the signature, kept separately because a mismatch is itself meaningful
  • the version of the agreement, and the full text as it was displayed
  • which acknowledgements were presented and accepted
  • the date and time of signing
  • the IP address and browser user-agent at the moment of signing
  • a reference to the identity verification the signature was made under, and its status at that moment
  • a cryptographic fingerprint over all of the above

The IP address is recorded because an electronic signature with no circumstance behind it is only a typed string. It is never shown on any public page. The fingerprint exists so that a later alteration to the record is detectable rather than silent.

This information would be held as evidence of a contract, and used for compliance, fraud prevention, handling disputes and chargebacks, enforcement, and meeting legal obligations.

Photographs, video and how they are handled

Media you upload is stored with a specialist object-storage provider rather than on the website itself, and is delivered from there.

When you upload, media may be:

  • received and staged before it is published
  • resized, re-encoded or transcoded so it can be delivered efficiently
  • watermarked
  • reviewed by a person before it becomes public
  • stored, and delivered to people viewing your advertisement

A newly uploaded or replacement photograph waits outside the published gallery until it has been approved. Original uploads are held in storage that is not publicly readable; what is published is the processed version.

Payment information

Payment is processed by third-party providers under their own terms.

Roesas does not store full payment card numbers. For card payments, the card details are handled by the payment provider and Roesas keeps the order, the amount, the currency, the status, and the provider’s transaction reference.

For cryptocurrency payments, Roesas records the transfer details it needs to match a payment to an order, including the relevant blockchain transaction and address information. Blockchain records are public and permanent by their nature, and are outside Roesas’s control.

Why Roesas uses this information

  • to create and operate your account
  • to review and publish advertisements
  • to verify identity and age
  • to communicate with you about your account, your advertisements and your support requests
  • to take payment and keep financial records
  • to secure the service, limit abuse and prevent fraud
  • to moderate content and enforce the Terms and the policies
  • to keep evidence of agreements and consents
  • to provide support
  • to operate, monitor and debug the service
  • to meet legal obligations and to respond to lawful requests
  • to establish, exercise or defend legal claims

Roesas does not use your information for advertising or marketing, and does not sell it. There is no advertising network on the site, no marketing email, and no sharing of information for anybody else’s marketing.

Where the law that applies to you requires a legal basis for processing, Roesas relies on one or more of the following, depending on the purpose: performing its contract with you, its legitimate interests in operating and protecting the Service, your consent, and compliance with a legal obligation. Which of these applies to a given purpose depends on the law of the place you are in.

Who else sees it

Roesas shares information with the following categories of recipient:

Hosting, database and object-storage providers

They run the infrastructure the service depends on, and necessarily process what is stored on it.

The identity-verification provider

It carries out the identity and age check and returns the result.

Payment providers

They take and confirm payment.

An email delivery provider

It sends the service email Roesas owes you.

Professional advisers, such as lawyers, accountants and auditors

Where Roesas needs advice or is required to be audited.

Law enforcement, regulators and other lawful authorities

Where Roesas is required or permitted by law to disclose, and where it is necessary to protect a person from harm.

A buyer or successor

If Roesas is involved in a merger, acquisition or sale of assets, information may transfer as part of it.

Roesas does not sell personal information and does not share it for anybody’s marketing. Service providers necessarily receive information in order to do their job, and saying “we never share” would be untrue.

Anything you put in your advertisement is published, and can be seen by anybody. Your phone number and email address are not published.

How long it is kept

Different information is kept for different lengths of time, because it is held for different reasons.

Account and advertisement information

Kept while the account exists. Deleting an account permanently removes the account, its advertisements and its media.

Story media

Stories expire by design. Expired Story media is removed from storage automatically after a short grace period.

Photographs you remove or replace

Removed from publication immediately, and the stored object is cleaned up afterwards by a background process.

The consents you gave at intake, and your acknowledgement of an advertisement you asked to delete

Kept as evidence while your account exists, and kept after the advertisement itself is gone. Evidence stored beside an advertisement would be destroyed by the very act it is evidence of. Deleting your account deletes these with it.

A signed advertiser agreement and the record of its execution

Kept as evidence of a contract, and this one outlives the account: if the account is deleted the record remains, with the link to you removed so it is no longer attributed to a person. Deleting an advertisement never removes it.

Moderation, enforcement and audit records

Kept so decisions can be reviewed and disputes answered. When an account is deleted the record of WHAT was done survives; only the attribution to that person is removed.

Financial and payment records

Kept for as long as accounting, tax and anti-fraud obligations require, which outlasts the account.

Public safety reports

Kept while the concern may still need to be reviewed or accounted for, and kept after the advertisement they concern is gone. A report destroyed by the removal of what it reports is no evidence at all. Deleting an advertiser's account does not delete a report made about them; it is a record of what somebody else said.

Backups

Information deleted from the live service may persist in backups for a limited period before those backups are cycled out.

An advertisement expiring or being deleted does not delete the compliance and financial evidence connected to it. Those records exist precisely so that they are still there when somebody asks what happened. Deleting your ACCOUNT is different and goes further: it removes your consents and acknowledgements outright, and, where it is appropriate and practicable, removes the link between your account and the records that must remain. Some of those records necessarily keep identifying information: a signed agreement retains the name held at signing and the signature given, because a record of a signature by nobody is evidence of nothing.

Roesas does not publish fixed retention periods for evidence and financial records. Each is kept for as long as the purpose it is held for requires, and for as long as the accounting, tax, anti-fraud and other obligations that apply in the relevant place require, whichever is longer.

Your rights

Depending on where you live, you may have rights over the information Roesas holds about you. These may include the right to ask for access to it, to have it corrected, to have it deleted, to restrict or object to how it is used, to receive a copy in a portable form, and to withdraw consent where processing relies on consent.

These rights are subject to the law that applies to you and to its exceptions. In particular, Roesas may need to keep evidence, financial records, and moderation records even after a deletion request, where the law requires or permits it, and will tell you if that is why a request cannot be met in full.

There is no self-service export or download tool. Requests are handled by a person.

Anyone can make a privacy request, with or without an account. Use the privacy request form. It asks for your name, your email address, what you are asking for and any detail that helps Roesas find the information. No account, and no sign-in, is needed.

If you do have an account, you may instead raise it in your message centre under the Account category. See the contact page. Either route reaches a person; the form is simply the one that works when you have no account to sign in to.

Roesas may need to confirm who you are before it acts. Releasing, changing or deleting personal information on the strength of an unverified email address would let one person act on another’s data, so where it is reasonably necessary Roesas will ask you to confirm your identity first, and will tell you how.

Do not send identity documents through the request form. It does not ask for them and they should not be submitted through it. Where identity has to be confirmed, that is arranged separately.

Cookies and sessions

Roesas uses cookies to keep you signed in. When you sign in, a session cookie is set; it identifies your session to the server and is necessary for the site to know who you are. Signing out clears it.

Short-lived cookies may also be used for security purposes such as protecting sign-in and form submissions.

Roesas is an adult platform, and the first time you open the public site you are asked to confirm your age and accept the Terms of Service before browsing advertisements. When you confirm, one further essential cookie is set so that you are not asked again on every page.

That cookie holds a short version marker and nothing else: no date of birth, no name, no identifier, no network address and no record of what you look at. It is set for the roesas.com family of sites so that one confirmation covers roesas.com, trans.roesas.com and massage.roesas.com, it expires after a year, and it is not shared with anybody. If the wording you confirmed changes materially, the marker changes with it and you are asked again.

This confirmation is an acknowledgment. It is not identity or age verification: Roesas does not ask a visitor for a date of birth or a document in order to browse, and does not check one.

Roesas does not use advertising cookies, tracking pixels, or third-party analytics. There is no analytics package on the site and no third-party tracking script in its pages. Because the only cookies used are necessary ones, there is no consent banner to dismiss.

Children

The Roesas service is for adults. It is not intended for, and must not be used by, anybody under 18, or under a higher age where the law that applies to them sets one.

Roesas does not knowingly collect information from anybody under that age. If Roesas becomes aware that it holds such information, it will delete it and terminate the account.

Security

Roesas uses technical and organisational measures appropriate to the service to protect information against loss, misuse and unauthorised access. Passwords are stored hashed rather than in readable form, and access to production data is restricted.

No service can promise absolute security, and Roesas does not. Keep your password to yourself, do not reuse it elsewhere, and tell us if you think your account has been accessed without your authorisation.

Where information is processed

Roesas relies on infrastructure, verification, payment and email providers that may process information in countries other than the one you are in. Where that happens, the information is subject to the laws of the place it is processed in.

Roesas does not claim to have put any specific legal transfer mechanism in place. Where the law that applies to you requires one for information to leave your country, Roesas does not represent that such a mechanism is currently in place, rather than naming one that is not.

Changes to this policy

Roesas may revise this policy. The current version is always the one published on this page, with the date it was last updated at the foot of it. Where a revision is material, Roesas will take reasonable steps to bring it to the attention of account holders.

Contacting Roesas about privacy

Anyone may use the privacy request form, with or without an account. Account holders may also use their message centre. See the contact page.

The Service is operated by Roesas Operations LLC, a Florida limited liability company. Roesas has not appointed a data protection officer and does not represent that it is required to.

Where a privacy matter needs to reach Roesas in writing rather than through the form, Roesas Operations LLC can be reached at roesas.ad.services@gmail.com. The form above remains the route for a privacy request, because it records the request rather than relying on an inbox.

Depending on where you live, you may also have the right to complain to a data protection authority.

These terms may be updated from time to time. The version published here is the current one.

Last updated: 31 August 2026