Trust
Security.
What actually protects a delivery, and what it doesn't. We'd rather tell you the limits here than have you discover them from a failed match.
1. The mark
Every delivery carries two things: a visible signature the buyer can see, and a separate forensic layer they can't. Both are unique to that one delivery: not to the creator, not to a batch, to that single sale.
What it's built to survive
The mark is designed to hold through the ways a buyer would normally save or re-share a file: a screen recording, a platform re-encode, a resize.
What can defeat it
Aggressive cropping, heavy blurring, or re-rendering a copy from scratch can degrade or remove the signal, and we haven't published a resistance guarantee against those because we don't have one to stand behind yet. If a match can't be made, we'll tell you that plainly rather than imply a confidence we don't have.
2. Content in storage and in transit
Content is encrypted in transit between your device and our servers. Your original upload is never the file that gets delivered: every delivery is a separately generated, marked copy, and only marked copies leave our systems.
Identity documents and biometric verification data (creator identity checks, buyer age checks) are encrypted field by field before they touch disk. This isn't opt-in: the service is built to refuse to start in production if its encryption keys aren't configured, so there's no path where that data silently falls back to being stored in the clear.
Storage itself lives on a dedicated, persistent volume, not on a container's local disk. That matters in practice: a redeploy or container restart doesn't wipe or orphan what's already been uploaded.
3. Where this runs
sixx.me runs on a dedicated server in the Netherlands, inside the EU. We chose that rather than a shared multi-region hosting platform where we couldn't tell you which jurisdiction your data actually sits in.
4. Backups
We take a database backup immediately before every production release, and content storage is separate from the database, on its own persistent volume. Backups are kept on a rotation, not indefinitely, so retention stays consistent with deletion requests rather than working against them.
5. Payments
We never see or store full card numbers. Payment is handled by our adult-friendly payment processor, who is responsible for card-data security under their own compliance obligations. What we hold is a payment identity and transaction reference tied to each delivery, not raw payment details.
6. Access controls
Access to creator content and delivery records is limited to what's needed to operate the platform: screening uploads, generating deliveries, and investigating reported leaks. We log access to sensitive records for accountability.
7. If something surfaces
Report it through our report form. If a match is found, you get an incident package: the match itself, the delivery it traces to, and when and to whom it was sold. See Terms §6 for what we do and don't do with that.
8. Reporting a vulnerability
Found a security issue in sixx.me itself, not a content leak, an actual platform vulnerability? Email support@sixx.me with details and we'll respond directly rather than through the general support queue.