FeaturesPricingFAQ
Sign inStart free
LEGAL

Privacy Policy

What we collect, why, and the controls you keep. Written to be read, not skimmed past.

Effective July 29, 2026 · version 1.0
CONTENTS
Who we areThe two hats we wearWhat we collectWhy, and on what legal basisSensitive dataAI processingWho we share withInternational transfersHow long we keep dataSecurityYour rightsCookiesAgeChanges and contact
01

Who we are

Fandash ("we") runs an operations platform for agencies that manage creators on Fanvue. This policy covers the Fandash website and the Fandash application, and explains what we do with personal data in both.

Questions, requests, and complaints all reach us at privacy@fandash.io. We answer within one month, and we tell you if a request will take longer than that and why.

02

The two hats we wear

For your account, your team's data, and this website, we decide how data is used, so we are the controller and this policy is our notice to you.

For the creator and fan data an agency brings into Fandash, the agency decides and we act on its instructions, so we are the processor and our Data Processing Agreement governs it, not this policy.

If you are a fan or a creator and want to exercise rights over conversation or purchase data, the agency or creator you deal with is the controller and is the right first contact. Write to us anyway if that is easier: we will forward your request to them without delay, help them answer it, and tell you we have done so.

03

What we collect

As controller, for your account and your team:

  • Account data. Name, email address, avatar, role and permissions, and sign-in records for each person on your team.
  • Agency configuration. Teams, roles, shifts, revenue splits, schedules, templates, and the settings you create.
  • Audit records. Who did what and when for significant actions, so you can investigate and so we can keep the service secure.
  • Usage and device data. Pages viewed, actions taken, browser and IP address, and error diagnostics, kept for security and reliability.
  • Support messages. Whatever you send us when you ask for help.

As processor, on your instructions, once a creator authorizes the connection:

  • Creator data. Profile and account details from Fanvue, connection tokens, performance statistics, and where the feature is used, reference audio and a derived voice model.
  • Fan data. Handle, display name, avatar, subscription status, purchase and spending history, retention signals, and any notes or list membership your team adds.
  • Conversations. Message content, attachments, read state, reactions, and translations, mirrored from Fanvue so the inbox is fast.
  • Money records. Sales, refunds and disputes, earnings, attribution to the chatter who closed a sale, and payout calculations.
  • Generated content. Captions, voice notes, translations, and fan sentiment snapshots, plus the inputs used to produce them.
04

Why, and on what legal basis

Where we act as controller, these are our purposes and the legal bases we rely on:

  • To run the service you signed up for, including creating accounts, syncing data, and providing support: performance of a contract.
  • To keep it safe: abuse detection, rate limiting, audit logging, and incident investigation, under our legitimate interest in a secure product. We have balanced this against your interests and consider the impact minimal.
  • To improve it: aggregated, de-identified usage analysis under legitimate interest, and optional analytics only where you consent.
  • To talk to you: service and security emails as part of the contract; product news only with your consent, with a working unsubscribe in every message.
  • To comply with law: tax, accounting, and responding to lawful requests.
  • To establish or defend legal claims: under legitimate interest.

Providing account data is necessary to have an account; without it we cannot provide the service. Where we rely on legitimate interest you can object at any time, and you can withdraw consent at any time without affecting processing that already happened.

05

Sensitive data

Fandash is used on an adult content platform, so conversations mirrored into it can contain information about a person's sex life or sexual orientation. Voice cloning produces a biometric identifier of a creator. Both are special category data under Article 9 of the GDPR, and both deserve saying out loud rather than burying.

We do not seek out this data and we do not use it to profile anyone for our own purposes. It reaches us because it is part of the conversation history an agency instructs us to mirror. For that data the agency is the controller: it is responsible for holding explicit consent or another Article 9 condition, and it warrants to us that it does. We process it only on the agency's documented instructions, apply the same protections described below, and restrict internal access to staff who need it.

If you are a fan or creator and you are not comfortable with an agency processing your conversations this way, raise it with that agency or creator, and tell us at privacy@fandash.io if you want us to pass it on. An agency that cannot evidence its lawful basis is in breach of our terms and we will act on that.

06

AI processing

Fandash sends content to third-party AI providers for four features. Captions are drafted by Anthropic, OpenAI, or Replicate. Messages are translated by DeepL. Voice notes are produced by SexyVoice.ai. Fan sentiment snapshots are produced by Anthropic from a transcript of the recent conversation.

Providers act as our subprocessors, process the content only to return the result, and are contractually barred from using it to train their models. We send the minimum the feature needs and we do not send your billing details or your team's credentials. Results are stored in your agency's own data.

A voice clone is created only where the creator's consent is recorded in Fandash, along with who obtained it and how. She can withdraw it at any time, and withdrawal deletes the clone and stops further generation.

Sentiment scores, health scores, and whale flags are working signals for the agency's team. They are not automated decisions that produce a legal effect or similarly significant effect on anyone within the meaning of Article 22, a human decides what to do with them, and they are never used to decide anything about your team's employment.

07

Who we share with

We share personal data only with the providers that help us run Fandash. Each is bound by a written data processing agreement, may act only on our instructions, and is listed here rather than left to a request:

ProviderWhat they doWhere
SupabaseDatabase, authentication, and file storage. Holds the mirrored platform data.European Union
VercelApplication hosting and content delivery, plus page-view and performance analytics when you consent to those.European Union (Frankfurt), vendor established in the United States
InngestRuns background sync jobs and scheduled work.United States
ResendSends transactional email such as invites and sync notices.United States
AnthropicGenerates captions and produces fan sentiment snapshots from conversation transcripts.United States
OpenAIGenerates captions.United States
ReplicateHosts models used for caption and media generation.United States
DeepLTranslates messages between languages.European Union (Germany)
SexyVoice.aiCreates and runs creator voice clones, using reference audio supplied with the creator's documented consent.Outside the European Economic Area

This list was last updated on July 29, 2026. We give notice to account owners before a new provider starts processing personal data, so that an agency can object.

We do not sell personal data, we do not share it with ad networks or data brokers, and we do not use it for advertising. Otherwise data leaves us only where the law requires it, where we need it to establish or defend a legal claim, or where you ask us to move it. If we are ever part of a merger or acquisition, we will tell you before your data becomes subject to a different privacy policy.

08

International transfers

Production data is stored in the European Union: our database, authentication, and file storage run in an EU region, and the application runs in Frankfurt.

Some providers in the table above process data outside the European Economic Area, mainly in the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses, together with supplementary measures including encryption in transit, access controls, and sending the minimum data the feature needs. Where an adequacy decision applies we rely on that instead. You can ask us for a copy of the safeguards for a specific provider at privacy@fandash.io.

09

How long we keep data

We keep your agency's data for as long as your account is open, because the product's job is to hold the mirror. When the account closes you have 30 days to ask for an export, then we delete your agency's data from our production systems, and backups containing it roll off within a further 35 days.

Some things outlive that. Accounting and tax records are kept for as long as the law requires. Audit and security logs are kept for up to 24 months. Consent records, including creator voice consent, are kept for as long as we may need to evidence that consent was given. Aggregated, de-identified statistics are not personal data and may be kept indefinitely.

Where we act as processor, deletion of creator and fan data happens on the agency's instruction and on the timetable in the DPA. If you want data erased sooner than the schedule above, ask us at privacy@fandash.io and we will do it unless the law requires us to keep it.

10

Security

Data is encrypted in transit and at rest. Each agency's data is isolated in the database itself, by row-level security tied to the signed-in identity, rather than by application code remembering to filter, so a bug in a query cannot return another agency's rows. Creator connection tokens are encrypted with AES-256-GCM before they are stored, and they are never written to logs.

Creators connect through Fanvue's official authorization flow and never share a password with us, and access can be revoked in one click. Access by our own staff is least-privilege and limited to people who need it to operate or support the service. Significant actions are recorded in an audit trail. We keep dependencies patched and review changes before they ship.

No system is perfectly secure. If a breach affects your personal data we will notify the competent supervisory authority within 72 hours where the GDPR requires it, and tell you without undue delay where the risk to you is high. Where we act as processor we notify the agency instead, without undue delay, so it can meet its own deadline.

11

Your rights

Under the GDPR you can ask for access to your data, correction of it, deletion of it, restriction of processing, and a portable copy. You can object to processing based on legitimate interest, including profiling. Where processing rests on consent you can withdraw it at any time without affecting what happened before. You will never be treated worse for exercising a right.

Write to privacy@fandash.io. We may need to verify your identity first, and we will not use what you send for verification for anything else. We answer within one month and can extend by two further months for complex requests, telling you if we do. Requests are free unless they are manifestly unfounded or excessive.

You can also complain to the supervisory authority in the country where you live or work, or where you think the problem happened. We would rather you told us first so we can fix it.

12

Cookies

Strictly necessary storage is always on: it carries sign in, security, your workspace choices, and the record of your cookie choice itself. Analytics and campaign measurement are set only after you opt in, and rejecting them changes nothing about what you can use. There is no cookie wall and no pre-ticked box.

Your choice is stored in this browser for six months, then we ask again. The settings panel lists every item we store, what it does, and how long it lasts.

Review or change your choice anytime: open Cookie settings.

13

Age

Fandash is a business tool for adults. You must be 18 or older to use it, and we do not knowingly process data about anyone younger. Content involving minors is forbidden by our terms, ends the account immediately, and is reported to the competent authorities. If you believe we hold data about a child, tell us at privacy@fandash.io and we will delete it.

14

Changes and contact

When this policy changes we update the date at the top of the page. If the change is material we email account owners before it takes effect, and where the change needs your consent we ask for it rather than assuming it. The current version always lives at this address, and we keep previous versions available on request. Anything unclear, ask: privacy@fandash.io.

The AI back office for Fanvue agencies. Fandash is an independent product and is not affiliated with, endorsed by, or sponsored by Fanvue.
ProductAI & automationsAttributionPricingFAQ
AccountStart freeSign in
LegalPrivacyTermsData processingCookie settings
© 2026 Fandash · all figures NET
Cookies at Fandash

Strictly necessary cookies keep sign in and security working; they are always on. Everything else stays off until you say so: preferences, analytics, and campaign measurement. You can change your choice anytime under Cookie settings in the footer. More in our Privacy Policy.