MODOTO STUDIOS + XO

Privacy Policy

A system-by-system explanation of what Modoto collects, why it is used, who receives it, how long it is kept, and how users exercise privacy rights.

Document: privacy_policyVersion: 2026-08-10Effective: August 10, 2026
This version adds the current Google AdSense advertising configuration and subscription-based ad suppression.

Systems and fields collected

Account and authentication systems collect an account identifier, email, authentication events, display name, username, optional phone number, role, and account status. Store and reservation systems collect product, hold, price, status, timestamps, and pickup coordination. Booking and service systems collect the requested service, scheduling details, equipment or project information, messages, estimates, and status. Academy systems collect enrollment, lesson activity, and results. Event systems collect attendance or registration records. Loyalty and Terminal systems collect Tokens, XP, transactions, device pairing, and account-linked session activity. XO collects adult eligibility, profile settings, contributions, sources, communities, projects, messages, blocks, mutes, reports, moderation, and reputation records. Privacy, safety, copyright, accessibility, and support systems collect the request, evidence, correspondence, status, and resolution needed to handle the matter.

Why information is collected

Fields are collected only for the feature that uses them: identity and security; reservations and transactions; scheduling and service performance; learning progress; event operation; rewards; Terminal pairing; adult XO eligibility; community and messaging; abuse prevention; legal requests; accessibility; accounting; audits; advertising eligibility; and incident response.

Public and private information

Account email, phone, authentication, transactions, private messages, reports, blocks, mutes, eligibility, safety records, and internal moderation notes are private. XO subject pages, public posts, public comments, public projects, public communities, and profile fields deliberately set for public display may be visible to eligible XO users. New XO profiles default to limited visibility, no search discovery, no external indexing, and restricted messaging.

Providers and storage

Supabase provides authentication, PostgreSQL database, storage, and server functions. Cloudflare provides website delivery and security. Google AdSense may provide advertising on eligible public pages when network advertising is enabled. Data is stored or processed in the provider systems configured for Modoto and may be processed where those providers and approved subprocessors operate.

Retention schedule

Profile and preference data is kept while the account is active and then deleted or anonymized under the account-closure workflow. Pending deletion has a 30-day cancellation window. Reservation, payment, tax, and accounting records are retained for the defined business period. Security, fraud, moderation, incident, and dispute evidence is retained while needed for the case and any legal hold. Public XO revision history may be retained with account identity disassociated. Terminal sessions expire operationally and are later deleted under the session rule. Backups age out under the provider backup-retention period. The table-by-table matrix in the compliance register controls deletion review.

Export, correction, and deletion

Authenticated users can view and correct profile information, review accepted policies, change communication preferences, request a server-generated self-only export, and request account deletion through the Privacy & Safety Center. Deletion immediately restricts public activity and begins the cancellation window. Eligible personal information is later deleted or anonymized; required transaction, safety, fraud, audit, dispute, and legal records are retained only under the applicable rule.

Cookies, local storage, and advertising

Essential browser storage may maintain authentication, security, interface preferences, feature state, and service-worker caching. On eligible public pages, Google AdSense may use cookies, device or browser identifiers, IP addresses, and related advertising technologies as permitted by applicable law and the visitor's consent choices. Modoto does not load the AdSense script for signed-in users whose subscription entitlement removes ads, and the owner can disable Google network advertising globally.

Advertising, email, and SMS status

Google AdSense advertising may be enabled on eligible public pages. Manual placements are controlled by Modoto and are suppressed on protected account, administration, transactional, and XO application surfaces. In-app transactional notices are enabled. Necessary account email may be enabled when a provider is connected. Marketing email is disabled. SMS is disabled and requires separate consent and launch approval.

Age restrictions

XO Web is restricted to adults. Ordinary XO access does not require a government ID at launch. An adult affirmation, current policy acceptance, and explicit XO grant are required. Under-18 venue or Academy participation is handled separately through a guardian-controlled process. A minor does not receive an XO profile or XO messaging access.

Security and legal exceptions

Access controls, row-level database policies, restricted server functions, audit logs, rate limits, evidence preservation, and provider security reduce risk. Information may be preserved or disclosed when reasonably necessary for safety, fraud, disputes, accounting, legal process, or compliance with law. No internet service can guarantee absolute security.

Requests and contact

Use the Privacy & Safety Center for access, correction, export, deletion, restriction, objection, or consent withdrawal. Use Contact for other privacy questions. Modoto does not need an IP-address record merely to prove ordinary authenticated policy acceptance.