Who is responsible
NSFWDL is an independent hobby project. For privacy or site-related requests, contact smartulethtb@gmail.com.
The site does not publish additional operator identity or physical-address information.
The sensitive input you provide
When you submit a URL, NSFWDL receives that complete URL in a small POST request. Adult-content URLs can be sensitive: their paths or query strings may name content, performers, accounts, or access tokens, and a person's use of one could permit sensitive inferences. NSFWDL uses the URL to validate the public destination, choose an extraction route, request the source page, and deliver the media you select. It does not treat the URL as evidence of your identity, sex life, sexual orientation, or preferences, and does not build an interest profile from it.
The downloader does not put the submitted URL in an NSFWDL page query string, title, canonical URL, or public result URL. Smart routing temporarily uses browser session storage to move the URL between NSFWDL downloader pages, consumes it on arrival, and rejects records older than about two minutes.
Short-lived extraction state
Extraction necessarily produces a source URL, media/CDN URL, title, format identifiers, request headers, thumbnail reference, and sometimes uploader, tag, category, or similar source metadata. The application keeps the sensitive values in bounded process memory behind random opaque references. The configured default lifetime is 15 minutes, records may be evicted earlier when capacity is reached, and all in-memory state disappears on process restart. A public extraction response can show the title and a same-origin thumbnail, but it does not expose the submitted page URL, upstream media URL, signed tokens, cookies, or extracted tags.
Media delivery and temporary files
A direct media response is streamed through NSFWDL and is not saved as a complete media file. A format that requires preparation, merging, or remuxing is written to a private temporary directory with an opaque name. Prepared files are removed after a successful full transfer, preparation failure or timeout, job expiry, or orderly process shutdown. A partial or ranged transfer may leave the file available for resume until its job expires. The configured job lifetime is one hour; a conservative startup cleanup also removes clearly stale job directories older than the configured stale threshold, currently six hours. Unexpected termination or an operational fault can therefore extend a temporary file's presence beyond the normal one-hour job lifetime. NSFWDL is not a permanent media archive.
Server, network, and security data
A web request inherently exposes network data such as IP address, timestamp, requested NSFWDL path, browser headers, and transfer size to the server and any network, hosting, reverse-proxy, DNS, or security provider involved. The application does not write raw IP addresses to its analytics database or structured application event log, and its Uvicorn access log is disabled. It transiently uses request network identity to derive a keyed daily grouping value for approximate traffic counts. That does not prove that every infrastructure layer keeps no access or security log; provider-level logging and retention are not controlled or proven by the application repository.
Private application logs and the authenticated operational dashboard use fields needed for reliability, abuse investigation, and capacity planning. These can include source family, extraction engine, outcome category, latency, format, byte counts, title, filename, and the submitted source URL. Signed media URLs, cookies, supporter keys, and session tokens are excluded. The analytics store is internal-only, applies short detail retention, and does not create advertising profiles or cross-site identifiers.
Requests to third-party sources
To perform the request, NSFWDL sends the submitted public URL to the original source platform through server-side extraction tools. It may then request media or thumbnails from that source or its delivery hosts. Those third parties receive NSFWDL's server network address and ordinary request headers, and apply their own terms and privacy practices. The separate dl.nsfwdl.com delivery hostname is configured as another entry point to the same application; its opaque download URL does not contain the source URL.
Direct downloads are server-mediated by default, including RedGifs. A disabled-by-default operator fallback exists for compatible direct media: if enabled, the browser receives the source media address and connects to that source host itself, exposing the browser's IP address and ordinary request information to it. The normal public configuration does not use that fallback.
NSFWDL does not ask users to upload account cookies. A source-specific cookie file may be configured privately on the server for permitted public-page compatibility. It is not user-provided or exposed publicly, and it must never be used to bypass subscriptions, private pages, or paywalls.
When a real thumbnail image is unavailable, some results can instead offer an optional inline video preview. The preview never loads automatically and never plays audio or video on page load. If you press play, your browser requests the video directly from the source's own media host, not through NSFWDL's server, so that host receives your IP address and browser information for that request in the same way it would if you visited the source page directly. NSFWDL does not store, cache, or log anything about a preview play.
Supporter data
Free use requires no account. Supporter access uses a random activation key and an HTTP-only session cookie. The SQLite store contains hashes of the key and session token, internal random identifiers, creation/expiry/revocation times, pass duration, optional payment amount/currency/provider fields, refund status, and an optional short operator note. A note may contain the contact handle a supporter supplied for manual key delivery, so it must be treated as personal data. NSFWDL does not store a payment method or a general customer-account profile.
Supporter payments and no-benefit contributions use external Revolut links. Revolut receives information under its own policy when a visitor follows a link or completes a payment. Submitted adult URLs and extracted-media metadata are not placed in those links.
Cookies and browser storage
The secure-by-default, HTTP-only, SameSite=Lax Supporter session cookie is set after a valid key is activated. The smart router uses session storage briefly as described above. A local-storage entry records when the adults-only notice was accepted, and another records an analytics opt-out if the visitor chooses one. After a visitor enters the site and unless analytics has been turned off, Google Analytics 4 sets its own first-party measurement cookies. Clearly labeled sponsored widgets are embedded from StripCash's HandPickedXXX White Label creative host and may use cookies or other browser storage under that provider's policy; they load independently of the Google Analytics choice. See Cookies, Analytics & Advertising for the full current inventory.
Analytics, advertising, and affiliate links
NSFWDL records limited first-party operational usage data independently of Google Analytics to understand reliability, capacity, traffic, and product use. This can include page path, broad device class, normalized referrer host and path without query strings or fragments, coarse visible-page duration, download lifecycle and byte counts, and short-lived keyed request grouping. Raw IP addresses and full User-Agent strings are not stored in the application analytics database. Page timing uses an in-memory page identifier and same-origin requests; it does not use cookies or persistent browser storage. Submitted source URLs can appear in short-retention, authenticated operational records because they are needed to diagnose downloader behavior. These analytics are not public.
Google Analytics 4 is enabled when a visitor presses Enter on the adults-only notice, which states this, and can be turned off at any time with the footer control. Before Enter is pressed and after analytics is turned off, no Google tag is requested and no request reaches Google at all. Advertising consent signals stay denied regardless of the analytics choice, and Google Signals and ad-personalization signals are explicitly disabled. A submitted URL, filename, title, performer, content tag, or extracted-media metadata is never sent to Google. The first-party operational system does not change this GA4 choice or its behavior.
NSFWDL embeds clearly labeled StripCash affiliate widgets served through the HandPickedXXX White Label creative host. The provider may receive ordinary browser, device, IP, impression, and click data and the static affiliate parameters contained in the widget URL under its own policy. NSFWDL does not add the user's submitted URL, filename, title, performer, content tag, extracted-media metadata, or download identifier to that request. Because the widget loads in a cross-origin iframe, ordinary browser referrer behavior can disclose the NSFWDL site origin (for example, https://nsfwdl.com/) to the affiliate/creative host; it does not disclose the full page path, query string, fragment, or any pasted URL, extracted title, filename, or download/job identifier. No separate advertising-network script is integrated.
Purposes and legal bases
- Provide the service you request: validate, extract, prepare, and deliver a public URL; generally necessary to perform the requested service or take steps at your request (GDPR Article 6(1)(b), where applicable).
- Operate and protect the service: coarse logs, rate and resource controls, security checks, and abuse prevention; pursued as legitimate operational and security interests (Article 6(1)(f)), balanced against the unusually sensitive context.
- Meet legal duties and handle claims: process valid privacy, safety, legal, or copyright requests (Article 6(1)(c) where a duty applies, or legitimate interests in establishing and defending legal claims).
- Google Analytics: enabled on entering the site as the adults-only notice states (Article 6(1)(a) and applicable ePrivacy rules); it can be turned off at any time without losing the core downloader.
A submitted adult URL could, in context, reveal special-category information under GDPR Article 9. NSFWDL minimizes and transiently processes such input only on the user's instruction and does not infer or profile it. This policy does not claim that the applicable Article 9 condition has been conclusively resolved; that remains a jurisdiction-specific legal question for the operator.
Retention and minimization
Current analytics defaults keep page-view, timing, event, and logical-download detail for 30 days; exact submitted source URLs for 14 days; daily visitor/session grouping values for 7 days; and daily aggregate totals for up to 365 days. Cleanup removes or clears those fields opportunistically through the application's existing maintenance path. These are application-database defaults, not claims about infrastructure, provider, payment, email, or separately rotated application-log retention. Supporter records and legal correspondence follow their own operational or legal handling.
Security
NSFWDL uses opaque references, private runtime directories, bounded request and process limits, no-store and no-referrer response headers, SSRF protections, restricted media types, hashed supporter secrets, and short-lived state. No internet service can promise absolute security. Report a suspected exposure through the safety contact route.
Your data-protection rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or information about processing, and may object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. Because NSFWDL deliberately avoids accounts and long-term URL history, it may hold too little information to identify a record as yours; the operator may request limited verification and will not collect extra sensitive information merely to create a match.
You may also lodge a complaint with the data-protection supervisory authority where you live, work, or believe an infringement occurred. This site does not name an establishment or lead supervisory authority. Questions can be sent through the public privacy contact above.
International transfers and service providers
Current external services include source platforms and their media hosts, Cloudflare at the site edge, Google Analytics only after consent, Revolut when a visitor follows a payment or contribution link, and the site's hosting and email providers. Some providers may process data outside the EEA under their own terms. The repository does not establish every provider's legal role, processing location, transfer mechanism, safeguard, or retention term, so this policy does not claim that those questions are fully resolved.
Adults only
NSFWDL is intended only for people aged 18 or older who can lawfully use an adult-content service. It is not directed to children and does not knowingly seek their personal data. Any suspected child sexual abuse material or exploitation must be reported through the urgent safety route and may be reported to competent authorities as required by law.
Policy changes
This page will be updated when data flows or providers change. Material changes—especially analytics, advertising, identity, transfers, or retention—must be published before the new processing begins and new consent obtained where required. The version date above identifies this text; it does not invent a launch date.