Legal
Privacy Policy
Effective: 2026-04-01 · Last updated: 2026-04-01
1. Overview
This Privacy Policy explains what personal data FanStudio ("we", "us", "our") collects when you use our platform ("the Service"), why we collect it, how we use and share it, and the rights you have over it.
This policy applies to all users of the Service. It is read alongside our Terms of Service.
2. What we collect
Identity and account data (via Clerk):
- Email address
- Display name, first/last name (if provided)
- Avatar URL (if provided)
- Authentication identifiers (Clerk user ID, OAuth provider IDs)
- Records of your acceptance of our Terms of Service (version, timestamp, IP address)
Content data:
- Photos, videos, audio, and AI training data you upload
- Photos, videos, captions, and other media you generate via the Service
- Prompts, parameters, and other inputs you provide to generation features
- Collections, folders, favourites, and organisational metadata
Payment data (handled by Stripe / NowPayments):
- Purchase amount, currency, status, timestamps
- Provider transaction IDs (Stripe session ID / NowPayments payment ID)
- We do NOT store full card numbers, CVV, or crypto private keys
Third-party connection data (when you opt in):
- Fanvue user UUID, handle, display name, avatar URL
- Fanvue OAuth access + refresh tokens (encrypted at rest with AES-256-GCM)
- Scopes you granted at connection time
Technical data:
- IP address (used for security, rate limiting, and fraud prevention)
- Device, browser, and operating system (from request headers)
- Sign-in and session records (session identifiers, timestamps, IP address, device and browser)
- Service usage logs (timestamps, endpoints called, success/error)
- Error reports (via Sentry, with sensitive tokens automatically scrubbed)
3. How we use your data
- Provide and operate the Service (account access, generation, library, organisation).
- Process payments and manage your credit balance.
- Communicate transactional messages (welcome, payment receipts, deletion confirmations, security alerts).
- Detect and prevent fraud, abuse, and security incidents.
- Resolve payment disputes — where a payment is disputed, we share relevant transaction, account, session (including IP address), and usage records with our payment processors, the card networks, and the issuing bank.
- Comply with legal obligations (tax records, lawful requests).
- Improve the Service: aggregate, anonymised analytics on feature usage to inform product decisions.
We do not use your content or prompts to train our own AI models without your explicit consent.
4. Legal basis for processing (GDPR)
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to keep the Service secure, prevent abuse, contest fraudulent or erroneous payment disputes, and improve product quality.
- Consent — for optional features like third-party integrations (e.g. Fanvue), which you initiate explicitly.
- Legal obligation — to retain financial records and respond to lawful requests.
5. Third-party processors
We share personal data with the following processors strictly as necessary to deliver the Service:
- Clerk — authentication and user identity
- Stripe — card payments (including submission of dispute evidence to card networks and issuing banks when a payment is disputed)
- NowPayments — cryptocurrency payments
- Amazon Web Services — storage (S3) and infrastructure
- AI model and inference providers — content generation
- Fanvue — optional creator-platform integration (only when you connect it)
- Resend — transactional email delivery
- Sentry — error monitoring (sensitive tokens automatically redacted)
Each processor handles your data under its own privacy policy. We use providers that maintain industry-standard security practices.
7. Data retention
We retain your data only as long as necessary for the purposes described in this policy.
- Account and content data: as long as your account is active.
- After account-deletion request: a 30-day cool-off period during which you can cancel; after that, all content and personal identifiers are permanently and irreversibly removed ("hard-purge"), subject to the exceptions below.
- Credit purchase records: retained in anonymised form indefinitely for accounting and tax compliance.
- Anonymised system and security logs: up to 90 days.
- Dispute, fraud, and legal-claim records: records reasonably necessary to resolve payment disputes, investigate fraud or abuse, or establish, exercise, or defend legal claims — including transaction records, sign-in and session history, IP addresses, usage logs, and related communications — are retained (pseudonymised where practicable) until the matter is closed and applicable card-network dispute windows have expired, and in any case no longer than 18 months, notwithstanding an account-deletion request.
- Backups: up to 30 days, after which data is also removed from backup snapshots.
8. Your rights
Under GDPR and similar regimes, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion of your account and personal data. The self-serve path is in your settings page.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Objection — object to certain processing based on legitimate interests.
- Restriction — ask us to limit processing in specific circumstances.
- Withdraw consent — for processing that depends on consent, withdraw it any time.
- Lodge a complaint — with your local data-protection authority.
To exercise any right, email support@fanstudio.ai. We will respond within 30 days.
9. International transfers
Some of our processors store or process data outside your country of residence (notably the United States). Where personal data is transferred outside the EEA / UK, we rely on Standard Contractual Clauses or equivalent safeguards approved by the relevant authority.
10. Children's privacy
The Service is not intended for, and may not be used by, anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact support@fanstudio.ai and we will delete it promptly.
11. Security
We implement administrative, technical, and physical safeguards to protect your data:
- Encryption in transit (TLS) for every connection to the Service.
- OAuth tokens and similar secrets encrypted at rest using AES-256-GCM with key versioning for rotation.
- Strict access controls on internal databases and storage.
- Automatic redaction of sensitive credentials in logs and error reports.
- Routine vulnerability scanning and dependency updates.
For our responsible-disclosure policy, see our security page.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email and surfaced in-app. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact us
For any privacy-related question, email support@fanstudio.ai.