Last Update: 25.07.2026
Welcome to FansyMe's privacy policy.
FansyMe respects your privacy and is committed to protecting your personal data. This privacy policy will inform you as to how we look after your personal data when you visit our website (regardless of where you visit it from) and tell you about your privacy rights and how the law protects you.
This Privacy Policy has been set out in the manner provided herein below:
Purpose of this Privacy Policy. This privacy policy aims to give you information on how FansyMe collects and processes your personal data through your use of this website, including any data you may provide through this website when you sign up to our website.
This website is not intended for children and we do not knowingly collect data relating to children.
It is important that you read this privacy policy together with any other privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and privacy policies and is not intended to override them.
Controller. The controller responsible for your personal data within the meaning of the GDPR is the operator of this website as identified in our Impressum (collectively referred to as "FansyMe," "we," "us," or "our" in this privacy policy). If you have any questions about this privacy policy, including any requests to exercise your GDPR legal rights, please contact us at [email protected].
Third-Party Links. This website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
When using our website for informational purposes only, meaning you do not register or provide us with any information, we collect data that is transmitted by your browser to our server, commonly known as "server log files." Whenever you visit our website, we gather the following data that is essential for us to display the website to you:
The processing of this data is performed in accordance with Article 6 (1) f of the GDPR, based on our legitimate interest in enhancing the stability and functionality of our website.
The data will not be shared or used for any other purposes. However, we reserve the right to review the server log files if there are any indications of illegal use.
This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries). You can recognize an encrypted connection by the string https:// and the lock symbol in the browser line.
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
According to Art. 6 (1) point b GDPR, personal data will be collected and processed when opening a customer account with us. The data required for opening an account with us can be found in the input forms during the registration and/or verification process.
Where applicable, this may also include data relating to Partner or Studio Accounts connected to one or more Creator accounts, processed in accordance with this Privacy Policy.
We may collect, use, and store different kinds of personal data about you, grouped together as follows:
Public Profile Data Sharing. If enabled in your Security & Privacy settings, we may share the following publicly available profile information via API calls to third-party websites to help increase your visibility and promote your reach: avatar and cover image, username and display name, bio and interests, ethnicity and country, and shop items.
Public profile data sharing is entirely optional and will only occur if you explicitly enable this feature in your Security & Privacy settings. You can disable this option at any time through your settings, and once disabled, no further public profile data will be shared via API. No additional private data will be shared beyond what is listed above.
If You Fail to Provide Personal Data. Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you. In this case, we may have to cancel a service you have with us, but we will notify you if this is the case at the time.
Account Deletion. You can delete your account at any time by navigating to your profile settings and selecting the "Delete Account" option, or by contacting us at [email protected]. All your data will be deleted, provided that all outstanding contracts and subscriptions have been fully processed.
Security Measures. For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string https:// and the lock symbol in the browser line.
We collect and retain personal data only to the extent necessary for the purposes described in this Privacy Policy and in accordance with applicable data protection laws.
We use different methods to collect data from and about you, including through:
Direct interactions. You may give us your Identity, Contact, and Financial Data by filling in forms or by corresponding with us by post, email, or otherwise. This includes personal data you provide when you apply for our products or services, create an account on our website, create a profile on our website, or subscribe to or purchase services.
Automated technologies or interactions. As you interact with our website, we will automatically collect Technical and Usage Data about your equipment, browsing actions, and patterns. We collect this personal data by using cookies, server logs, and other similar technologies.
User Contributions. You also may provide Content Data for us to publish or display ("post") on public website areas or transmit to other website users or third parties. You submit Content Data for posting and transmission to others at your own risk. Although you may set certain privacy settings for Content Data by logging into your account profile, please be aware that no security measures are perfect or impenetrable. Additionally, we cannot control the actions of any website users with whom you choose to share your Content Data. Therefore, we cannot and do not guarantee that unauthorized persons will not view your Content Data.
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data where we need to perform the contract we are about to enter into or have entered into with you, where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests, or where we need to comply with a legal obligation.
Marketing. We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.
Promotional Use of Public Profile Data. We may use your Identity, Contact, Technical, Usage, and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services, and offers may be relevant for you (we call this marketing).
You will receive marketing communications from us if you have requested information from us or purchased services from us or if you provided us with your details when you entered a competition or registered for a promotion and, in each case, you have not opted out of receiving that marketing.
By sharing content publicly on FansyMe, you agree that such content (including your display name, username, profile image, bio, and publicly available posts) may be used by us to promote your profile and FansyMe on our official social media channels, unless you opt out via your privacy settings or by contacting support.
Third-Party Marketing. We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
Opting Out. You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing messages sent to you or by contacting us at any time. Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a service purchase or registration, service experience, or other transactions.
Cookies. For more information about how we use cookies in accordance with the GDPR and DSGVO, please refer to our Cookie Policy.
Commentary Function. When you use the commentary function on our website, we collect and store your comment, the time it was written, and the username and ID you used when signing up. We also log and store your IP address for security purposes, in case any illegal content is posted or someone violates the rights of third parties. We may use your email address to contact you in case a third party raises concerns about the legality of your content. The legal basis for processing your data is Article 6(1)(b) and (f) of the GDPR. Please note that we reserve the right to delete comments that are deemed unlawful by third parties.
Public Profile Data via API. To help boost your reach and visibility, we offer an option to display your public profile data on third-party websites and applications through our API. This data includes information you have explicitly set as public, such as your avatar, cover photo, username, display name, number of followers, number of likes, media count, livestream count, shop items (name, description, and price), profile link, shop link, video and voice call links, interests, and ethnicity.
Your private information remains secure and will never be shared via the API. The use of this feature is entirely optional, and you can manage it in your privacy settings.
Change of Purpose. We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Retention for Evidence in Case of Abuse or Legal Violations. In cases of documented abuse, threats, defamatory statements, or violations of our Terms of Service, we reserve the right to retain relevant personal data (such as IP addresses, messages, comments, or support communications) for the purpose of legal evidence. The legal basis for this is our legitimate interest under Article 6(1)(f) of the GDPR to protect our rights and defend against unlawful conduct.
We may share your personal data with external third parties, specific third parties, and third parties to whom we may sell, transfer, or merge parts of our business or assets, or with whom we may acquire other businesses or merge.
We may also disclose your personal data to law enforcement authorities, courts, or government agencies where necessary to comply with a legal obligation, a court order, a lawful subpoena, or a lawful request from a competent authority, or where necessary to establish, exercise, or defend legal claims, or to protect the vital interests, rights, property, or safety of FansyMe, our Users, or the general public, including for fraud prevention purposes. The legal basis for such disclosures is Article 6(1)(c) GDPR (compliance with a legal obligation) or, where no specific legal obligation applies, Article 6(1)(f) GDPR (legitimate interest in cooperating with lawful requests and protecting our platform and users). Where FansyMe becomes aware of information giving rise to a suspicion of a criminal offence involving a threat to the life or safety of a person, we will proactively notify the competent authority in accordance with Article 18 DSA and the German Digitale-Dienste-Gesetz (DDG), as further described in our Terms of Service.
We require all third parties to respect the security of your personal data and to process it lawfully. We do not allow our third-party service providers to use your personal data for their own purposes, and we only permit them to process your personal data for specific purposes and in accordance with our instructions. If we transfer your personal data to a third party outside the European Economic Area (EEA), we will ensure that adequate safeguards are in place to protect your personal data, in accordance with the GDPR.
Where we engage third-party technical service providers to develop and maintain our platform, such providers may access personal data in the course of performing their services. All such providers are bound by Data Processing Agreements in accordance with Article 28 GDPR and are contractually prohibited from processing personal data for any purpose other than providing services to us.
We may process, store, and transfer personal data we collect, in and to a country outside your own, with different privacy laws that may or may not be as comprehensive as your own. Where we do so, and where we are required to under local law, we will put in place appropriate mechanisms to ensure that your personal data receives an adequate level of protection where it is processed.
If you reside in the European Economic Area (EEA) or Germany, your personal data may be processed outside of the EEA or Germany, so processing of your personal data will involve a transfer of data outside the EEA or Germany.
Whenever we transfer your personal data out of the EEA or Germany, we ensure a similar degree of protection is afforded to it by ensuring that the recipient third party agrees to contractual clauses.
7.1 CCBill. When paying with Credit Card or SEPA, the payment is processed by the payment provider, CCBill, 2353 W. University Dr., Tempe, AZ 85281-7223, USA, to whom we will pass on your information provided during the order process together with the information about your order. This includes name, address, possibly credit card and bank account number, invoice amount, currency and transaction number, and is necessary for the performance of the contract between you and us in accordance with Article 6(1)(b) of the GDPR. Your data will be passed on exclusively for the purpose and only to the extent necessary for this purpose to the payment provider CCBill.
CCBill is committed to protecting the privacy of its users and has implemented a comprehensive set of privacy policies and data protection measures in compliance with the GDPR. For more information, please see CCBill's privacy policy.
7.2 CoinPayments.com. When you select CoinPayments as your payment method, CoinPayments, 85 Piccadilly, London, England W1J 7NB, GB will process your payment. The processing of the payment will require personal data such as your name, email address, and the amount of the purchase. This data is collected and processed exclusively by CoinPayments and is subject to their privacy policy, which is available on their website.
The processing of your personal data by CoinPayments is based on Art. 6 (1) point b GDPR (performance of a contract) and is necessary for the processing of your payment. We do not have access to your payment data and do not store any payment-related information on our website. We only receive a confirmation from CoinPayments that the payment has been made.
You have the right to request access to and rectification or erasure of your personal data, as well as the right to restrict processing and to object to processing. You also have the right to data portability and the right to lodge a complaint with a supervisory authority. For more information, please see CoinPayments' privacy policy.
7.3 Epoch.com. Our website uses Epoch.com, a secure payment processing service, to handle your transactions. When you select Epoch.com at checkout, you'll be transferred to their secure platform to complete your payment.
During this process, Epoch.com may collect personal information such as your name, email address, billing address, and details related to your chosen payment method (credit card number, bank account information, etc.). This data is gathered and processed solely by Epoch.com, in accordance with their privacy policy which can be found on their website.
We, as the merchant, do not have access to your sensitive payment details and do not store any such information on our servers. We only receive confirmation from Epoch.com once your payment is successful.
For a more comprehensive understanding of Epoch.com's data practices, please refer to their privacy policy.
7.4 UAB Alternative Payments. Our website uses UAB Alternative Payments for secure transactions. When you choose this option at checkout, you'll be redirected to their secure platform. UAB Alternative Payments handles all personal and payment information according to their privacy policy, available on their website. We do not access or store your payment details. We only receive confirmation once your payment is successful.
For more details, refer to their privacy policy.
7.5 Yoti (Age Verification). For fan age verification, we use Yoti Ltd, 5th Floor, 10 East Road, London, N1 6AD, United Kingdom. Age verification for fans is processed exclusively by Yoti. FansyMe does not receive, store, or process the identity documents or biometric data submitted during this process. We receive only a verification outcome (pass or fail) from Yoti. The legal basis for this data transfer is the performance of our legal obligations regarding age verification pursuant to Article 6(1)(c) GDPR. For information on how Yoti processes your personal data, please refer to Yoti's privacy policy.
7.6 Tantum AG (Age Verification and Payment Services). For fan age verification and payments, we use Tantum AG, Landstrasse 114, FL-9495 Triesen, Liechtenstein. Tantum AG is a regulated e-money institution licensed and supervised by the Financial Market Authority Liechtenstein (FMA).
Tantum AG handles two separate functions for fans on FansyMe. Age verification: Tantum verifies your identity and age before you can access certain content. This process involves the submission of identity documents and a facial scan. FansyMe receives only a verification outcome. The legal basis for this processing is our legal age verification obligations pursuant to Article 6(1)(c) GDPR and your explicit consent for biometric processing pursuant to Article 9(2)(a) GDPR.
Payments: Fans pay on FansyMe by scanning a QR code using the Tantum app. All payment processing, including how fans load and hold funds, is handled exclusively by Tantum AG. FansyMe does not have access to fans' payment details, funding sources, or wallet information. We receive only confirmation that a payment has been successfully completed. The legal basis for this processing is the performance of a contract pursuant to Article 6(1)(b) GDPR.
For further information, please refer to Tantum AG's privacy policy.
7.7 Veriff (Creator Identity Verification). For Creator onboarding, we use Veriff OÜ, Rävala pst 8, 10143 Tallinn, Estonia, to verify Creator identity. Verification is carried out automatically: Veriff extracts data from your submitted ID document and compares it against a live selfie using facial biometric matching. Data processed includes the ID document data, the selfie/video capture, and facial biometric data derived from it. Veriff processes this data as our processor under a Data Processing Agreement pursuant to Article 28 GDPR. The legal basis for this processing is the performance of our contract and legal obligations under Article 6(1)(b) and (c) GDPR, and your explicit consent to the processing of biometric data under Article 9(2)(a) GDPR. Biometric data is retained in accordance with Veriff's data retention policy. For more information, please see Veriff's privacy notice.
PEP and Sanctions Screening. As part of Creator onboarding, Veriff also screens your submitted identity data against politically exposed persons (PEP) lists and applicable sanctions lists (including EU and OFAC lists), to help ensure FansyMe does not enter into a payout relationship with a sanctioned or prohibited individual. The legal basis for this processing is our legal obligation to comply with applicable sanctions law pursuant to Article 6(1)(c) GDPR. We receive the screening outcome as part of the overall verification result, and it is taken into account in our onboarding decision.
We take the security of your personal data seriously and have implemented appropriate technical and organizational measures to protect your personal data from unauthorized access, use, alteration or disclosure. These measures include implementing industry-standard encryption technologies to protect sensitive information, limiting access to personal data to only those who have a legitimate business need to access it, and ensuring that our employees, agents, and third-party service providers are bound by strict confidentiality obligations.
We also have procedures in place to detect, report and investigate any suspected data breaches. In the event of a data breach, we will notify you and the relevant supervisory authority without undue delay, unless the breach is unlikely to result in a risk to your rights and freedoms.
Please note that while we take reasonable steps to protect your personal data, no security measures can guarantee absolute security. You should always take care when transmitting personal data over the internet or storing it on your devices.
FansyMe is an adult content platform. Data generated through your use of the platform, including content you view, purchase, subscribe to, interact with, or communicate about, may allow conclusions to be drawn about your sex life or sexual orientation. This constitutes special categories of personal data within the meaning of Article 9(1) GDPR.
Legal basis. The legal basis for processing this data is your explicit consent pursuant to Article 9(2)(a) GDPR. You provide this consent by registering an account and using the platform. Where you are a Creator, this consent is also provided through the act of uploading adult content and accepting the Creator Agreement.
How we use this data. We process this data solely to operate the platform and provide the services you have requested, as described in this Privacy Policy. We do not share data revealing your sexual behaviour or preferences with third parties for their own marketing, advertising, or profiling purposes.
Withdrawing your consent. You may withdraw your consent at any time with future effect by deleting your account or by contacting us at [email protected]. Withdrawal of consent does not affect the lawfulness of any processing carried out before withdrawal. Where withdrawal would prevent us from fulfilling our contractual obligations to you, we will inform you of this at the time of your request.
Biometric Data for Identity Verification. Separately, when you undergo Creator identity verification via Veriff (see Section 7.7), biometric data derived from your ID document and selfie is processed to uniquely verify your identity. This constitutes special category data within the meaning of Article 9(1) GDPR. The legal basis for this processing is your explicit consent pursuant to Article 9(2)(a) GDPR, collected separately at the point of verification, in addition to being necessary for our legal age and identity verification obligations under Article 6(1)(c) GDPR. Where automatic verification is unsuccessful, your documents are instead reviewed manually as a fallback, without further biometric processing.
10.1 Overview. We use third-party services, such as Sightengine, to analyse and moderate user-uploaded content on our platform. This is to ensure compliance with our community guidelines and to provide a safe environment for all users.
10.2 Data Handling. We submit only the URLs of user-uploaded content to these services. The actual content data (such as images, videos, or text) is not uploaded or shared directly with the third-party service. The third-party service does not store or retain any data submitted through URLs. All processing is done in real-time, and no data is retained beyond the completion of the content analysis. The data processed by the third-party service is not used for training or improving their AI models.
10.3 GDPR Compliance. Sightengine complies with the General Data Protection Regulation (GDPR). This compliance is detailed in their Terms of Use and Data Processing Addendum.
10.4 Purpose of Data Processing. The primary purpose of using these services is to automate content moderation, ensuring compliance with our community standards and enhancing the user experience on our platform.
10.5 Legal Basis. The legal basis for processing this data under the GDPR is our legitimate interest pursuant to Article 6(1)(f) GDPR in maintaining a safe and compliant online environment. Additionally, this processing is necessary for the performance of a contract with our users pursuant to Article 6(1)(b) GDPR regarding the use of our platform.
10.6 Your Rights. Users have the right to access, rectify, erase, and restrict the processing of their personal data. Users can also object to the processing of their data and have the right to data portability. To exercise these rights or for any privacy-related inquiries, please contact us at [email protected].
10.7 Data Security. We implement appropriate technical and organisational measures to ensure the security of the data processed through these services. We select third-party service providers that adhere to high standards of data protection and security.
10.8 Automated Features. Creators may have access to optional automated tools to support their activity on the platform. When a Creator activates such a tool, a strictly limited and anonymised subset of platform data is transmitted to third-party processors solely to perform the requested function and return a result to the Creator.
10.9 Data Involved. Only a strictly limited excerpt of interaction data is transmitted, not full conversation histories. The data transmitted is anonymised prior to processing, meaning it cannot reasonably be linked or traced back to any individual user. No usernames, identifiers, payment data, verification documents, or unrelated account information is included in the transmission.
10.10 No Storage or Retention. Third-party processors involved in automated features operate a zero data retention policy for request and response content. All processing occurs in real time solely for the purpose of fulfilling the requested function. Data transmitted is not used for third-party AI model training.
10.11 EU Data Residency. All data transmitted through automated features is processed and stored exclusively within the European Union. No data is transferred outside the EU or EEA at any point during processing. This ensures full compliance with GDPR data residency requirements.
10.12 Sub-Processors. Automated features are fulfilled via EURouter (Netherlands, EU), a GDPR-compliant AI gateway. All of EURouter's own sub-processors are based within the European Union. Data is processed solely on FansyMe's instructions and is governed by appropriate data protection obligations.
10.13 Legal Basis and Compliance. The legal basis for this processing is our legitimate interest under Article 6(1)(f) GDPR in providing Creators with tools to operate effectively on the platform. Given the anonymised and limited nature of the data transmitted, and the fact that all processing remains within the EU, this processing presents minimal risk to the rights and freedoms of data subjects. FansyMe ensures that a Data Processing Agreement (DPA) is in place with EURouter in accordance with Article 28 GDPR. Users are informed of this processing through this Privacy Policy.
Under applicable data protection law (GDPR and DSGVO), you have certain rights as a data subject with respect to the processing of your personal data by the data controller. These rights include:
11.1 Right to Object. If we process your personal data based on our legitimate interests, you have the right to object to this processing at any time for reasons related to your particular situation.
If you exercise your right to object, we will stop processing your data, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing is necessary for the establishment, exercise, or defense of legal claims.
If we process your personal data for direct marketing purposes, you have the right to object to the processing of your personal data for such purposes at any time. If you exercise your right to object, we will stop processing your data for direct marketing purposes.
The duration of storage of personal data is an important consideration when processing personal data. In determining the duration of storage, we take into account several factors, including the legal basis of the processing, the purpose of processing, and any relevant legal retention periods.
If personal data is processed based on explicit consent as per Article 6(1)(a) GDPR, the data will be stored until the data subject revokes their consent.
For data processed within the scope of legal or similar obligations as per Article 6(1)(b) GDPR, the data will be routinely deleted after expiry of the storage periods if it is no longer necessary for the fulfillment of the contract or the initiation of the contract and/or if we no longer have a justified interest in further storage.
When processing personal data based on Article 6(1)(f) GDPR, this data will be stored until the data subject exercises their right to object under Article 21(1) GDPR. However, we may still retain the data if we can provide compelling grounds for processing that are worthy of protection and outweigh the interests, rights, and freedoms of the data subject or if the processing serves to assert, exercise or defend legal claims.
If personal data is processed for the purpose of direct marketing as per Article 6(1)(f) GDPR, this data will be stored until the data subject exercises their right to object under Article 21(2) GDPR.
In cases where specific processing situations are not covered by the information contained in this declaration, stored personal data will be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.
Personal data retained for the purpose of evidence in legal disputes may be stored for the duration of the dispute or until the matter is fully resolved, provided it remains necessary.
Creator identity verification documents, including government-issued identification and selfie images collected during the KYC process, are retained for a period of 90 days following successful verification, after which the source documents are deleted. Where automatic verification is used, biometric data processed by Veriff is retained by Veriff in accordance with its own data retention policy, under our Data Processing Agreement with Veriff. A record confirming that verification was completed and the date on which it took place is retained for the duration of the Creator's account and for a period of 3 years following account closure. The same collection, review, and retention rules apply to identity verification documents and signed consent forms collected from third-party participants depicted in Co-Authored Content. Bank account and payout details are retained for the duration of the Creator relationship and for 10 years thereafter in accordance with German commercial and tax retention obligations (§257 HGB, §147 AO).
Do Not Track ("DNT") is a privacy preference that you can set in your browser. DNT is a way for you to inform websites and services that you do not want certain information about your webpage visits collected over time and across websites or online services. We are committed to providing you with meaningful choices about the information we collect and that is why we provide you the ability to opt out. But we do not recognize or respond to any DNT signals as the Internet industry works toward defining exactly what DNT means, what it means to comply with DNT, and a common approach to responding to DNT.
14.1 Google Analytics. We use Google Analytics, a web analytics service provided by Google Inc. ("Google"), on our website. Google Analytics uses "cookies", which are text files stored on your computer that enable an analysis of your use of the website. The information generated by the cookie about your use of this website (including your IP address) is usually transmitted to a Google server in the USA and stored there.
We have enabled IP anonymization on this website, so your IP address will be truncated by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area before being transmitted. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.
On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.
You can prevent the storage of cookies by setting your browser software accordingly. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available here.
For more information on how Google uses data, please see Google's privacy policy.
15.1 Google Sign-In. If you have a Google profile, you can use the "Google Sign In" social plug-in provided by Google Limited, Gordon House, 4 Barrow St, Dublin, D04 ESW5, Ireland ("Google"), a social network operated by Google Ireland, to create a customer account or to register using the single sign-on method.
When you visit a page utilizing the Google Sign-In plugin, your browser establishes a direct connection with Google servers, even if you do not have a Google profile and are currently not logged in. This information, including your IP address, may be sent to Google LLC in the USA based on Google's legitimate interest in the insertion of personalized advertising on the basis of surfing behavior.
By using our "Sign in with Google" button, you can login or register using your Google user data on our website. We will only receive the general and publicly accessible information stored in your profile if you provide your express consent as required by Art. 6 (1) point a of the GDPR, and only if your personal data protection settings at Google permit it. This information includes your user ID, name, profile picture, age, and gender.
You can withdraw your consent at any time by sending a message to the controller specified at the start of this declaration. For more information, please consult Google's Privacy Policy and the terms of use for Google Sign-In.
To prevent Google from linking the data collected through our website with your Google profile, make sure to log out of Google before visiting our site or install browser add-ons such as Adblock Plus to block Google plugins.
15.2 Twitter Sign-In. We use Twitter Login, a social login service provided by Twitter Inc. ("Twitter"), on our website. When you log in to our website using your Twitter account, Twitter may collect personal data such as your name, email address, profile picture, and a unique identifier for your account. This data is collected and processed exclusively by Twitter and is subject to Twitter's privacy policy, which is available on their website.
We do not have access to your Twitter login data and do not store any login-related information on our website. We only receive a confirmation from Twitter that you have successfully logged in. For more information, please see Twitter's privacy policy.
15.3 FontAwesome. We use web icons from "FontAwesome," a service provided by Fonticons, Inc. located at 710 Blackhorn Dr, Carl Junction, 64834, MO, USA ("FontAwesome"), to display icons uniformly on our website. When you access a page, your browser caches the necessary icons to display them correctly. As a result, your browser connects to FontAwesome's servers in the USA, transmitting your IP address. The use of FontAwesome's icons is based on our legitimate interest, as outlined in Article 6(1)(f) of the GDPR.
We have no control over the data collected and processed by FontAwesome, and we encourage you to review their privacy policy.
15.4 Google reCAPTCHA. We use reCAPTCHA by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google") to prevent automated spam and abuse on our website. The use of reCAPTCHA is based on our legitimate interest in protecting our website from bots and ensuring the security of our users' personal data, as provided for by Art. 6(1)(f) GDPR.
To provide this service, Google LLC collects your IP address and other personal data, such as hardware and software information, which is then transferred to the USA. By using reCAPTCHA, you consent to this data processing by Google. For more information, please consult Google's privacy policy.
15.5 Mailgun (Email Service). We use Mailgun, an email delivery service provided by Mailgun Technologies, Inc., 112 E Pecan St, Suite 1135, San Antonio, TX 78205, USA, to send transactional and marketing emails to users and creators of our platform. This includes account confirmations, password resets, platform notifications, and promotional communications.
When sending emails, Mailgun processes personal data including your email address, name where applicable, and technical metadata such as delivery status, open rates, and click data collected via tracking technologies embedded in emails. This tracking allows us to measure the effectiveness of our communications and improve our email content. If you do not wish to be tracked, you may disable image loading in your email client, which will prevent open tracking.
We use Mailgun's EU infrastructure exclusively. All data is processed and stored on servers located within the European Union. No personal data is transferred outside the EEA in connection with this service.
The legal basis for transactional email processing is the performance of a contract pursuant to Article 6(1)(b) GDPR. The legal basis for marketing emails and tracking is your consent pursuant to Article 6(1)(a) GDPR, which you may withdraw at any time by clicking the unsubscribe link in any marketing email or by contacting us at [email protected].
For further information, please refer to Mailgun's privacy policy.
If you reside in the EEA or Germany, under certain circumstances, you have rights under data protection laws in relation to your personal data, including the right to request access to your personal data, request correction of your personal data, request erasure of your personal data, object to processing of your personal data, request restriction of processing your personal data, request transfer of your personal data, and the right to withdraw consent.
Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Object to processing of your personal data where we are relying on a legitimate interest and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which overrides your rights and freedoms.
Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in certain scenarios, such as where you want us to establish the data's accuracy, where our use of the data is unlawful but you do not want us to erase it, where you need us to hold the data to establish, exercise, or defend legal claims, or where you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
Creators on FansyMe can generate personal tracking links (in the format fansyme.com/username/c1, /c2 and so on) to measure where their audience comes from. If you reach FansyMe through such a link, we record a visit so the Creator can understand the performance of the channel on which they shared it.
What we record for a visit. An irreversible cryptographic hash (SHA-256) of your IP address. We do not store your IP address itself for this purpose. The hash is used solely to recognise repeat visits so a single visitor is not counted multiple times. Your browser user agent, and the browser, operating system, and device type (desktop, mobile, or tablet) derived from it. The referring website address from which you arrived, where your browser transmits one. Your country, derived at country level only. The date and time of the visit.
Attribution on registration. If you register an account during the validity period of a tracking link visit (see Section 18), that visit is linked to your new user account. This allows the Creator to see how many registrations, subscriptions, and purchases resulted from a given link. Attribution occurs only once, at the moment of registration, and applies to registrations through our registration form as well as through Google or Twitter sign-in.
What Creators can see. Creators are shown aggregated statistics for each of their links only: the number of visits, the number of registrations, the number of subscribers, and the total value of subscription and pay-per-view purchases attributed to that link. Creators are never shown your IP address or IP hash, your user agent, your device details, or the identity of individual users attributed to a link.
Legal basis and retention. The legal basis for this processing is our legitimate interest and the legitimate interest of the Creator pursuant to Article 6(1)(f) GDPR in measuring the effectiveness of their own promotional activity. Visit records are retained for as long as the associated tracking link exists. Where a Creator deletes a tracking link, the link and its visit records are retained in order to ensure that a previously shared link address is never reassigned to a different link. You may object to this processing at any time in accordance with Section 11.1 by contacting us at [email protected].
In addition to cookies, which are described in our Cookie Policy, we use your browser's local storage and session storage. These are storage areas within your own browser. Data stored there remains on your device and is transmitted to us only where described below.
Attribution and referral data. Creator tracking links (fansyme_target_link): stores an encrypted, non-readable reference to a tracking link visit as described in Section 17, so that a subsequent registration can be attributed to the correct Creator link. Stored for a maximum of 7 days, and deleted automatically upon registration, upon expiry, or when you are logged in.
Referral and affiliate data (fansyme_affiliate): where you arrive through a Creator referral or affiliate link, we store the referral token, the referring Creator, the website you arrived from, and a timestamp, so that a subsequent registration can be credited to the correct referrer. Stored by default for 48 hours, and deleted automatically upon registration or upon expiry.
Advertising click identifiers (gclid_fansyme): where you arrive through an advertisement, we store the click identifier supplied in the address (gclid, gbraid, or wbraid) in order to measure advertising performance. This is set only where you have consented to analytics cookies.
Analytics configuration (gtag_analytics_key): stores the analytics configuration applicable to your session, used together with the analytics services described in Section 14.
Security and fraud prevention. Device identifier (fp): we generate a device identifier using FingerprintJS, a service of FingerprintJS, Inc., and store it in your browser. It is transmitted to us with your requests and is used to detect fraudulent activity, payment abuse, and duplicate or prohibited accounts. This identifier is derived from technical characteristics of your browser and device and does not contain your name, email address, or other directly identifying information. The legal basis is our legitimate interest pursuant to Article 6(1)(f) GDPR in protecting the platform, our Creators, and our users from fraud and abuse.
Consent and preference data. Cookie consent (cookie_consent_fansyme): stores the cookie choices you have made so that we do not ask you again on every visit and so that your choices are respected. Age confirmation (age_banner_accepted): stores that you have confirmed you are of legal age, so the notice is not shown repeatedly.
Display and interface settings. We store purely functional interface preferences, such as whether the sidebar is collapsed (sidebarCollapsed), whether the notes panel is shown (showNotesSidebar), and whether you have dismissed a notice (hideBanner). This data remains in your browser and does not identify you.
Session storage. We use session storage, which is cleared automatically when you close the browser tab, for temporary operational purposes only. This includes carrying a prepared message into the message composer, retaining your position in search results when navigating back to them, and temporarily holding media you have selected for a story until it is uploaded.
Legal basis and your control. Storage that is strictly necessary for the operation of the website, for security and fraud prevention, and for recording your consent choices is based on our legitimate interest pursuant to Article 6(1)(f) GDPR and, where applicable, on Section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Storage for analytics and advertising purposes is based on your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG, which you may withdraw at any time through the cookie settings on our website.
You can delete data stored in your browser at any time through your browser settings. Please note that deleting this data may reset your preferences and consent choices, and may prevent a registration from being credited to the Creator who referred you.
This Privacy Policy constitutes the complete agreement and understanding between the parties regarding the subject matter described herein, and overrides any prior or current agreements, understandings, inducements, or conditions, either expressed or implied, whether oral or written, regarding the subject matter described herein.