NoctiFlow AI engagement · Fanvue

Privacy Policy

Last updated: 7 June 2026

1. Roles

For your account data (e.g. your email), NoctiFlow is the data controller. For data about your fans that we process to run conversations on your behalf, you (the creator/agency) are the controller and NoctiFlow acts as your processor under your instructions.

2. Data we process

Account data: your email and a hashed password. Integration data: Fanvue OAuth access/refresh tokens and your persona/configuration. Fan data: Fanvue user IDs, display names, message content, purchase/tip amounts and lifetime value, and AI-generated conversation summaries.

3. Special-category data

Fan messages may reveal data concerning sexual preferences, which is a special category under GDPR Art. 9. As the controller for this data you are responsible for the lawful basis (e.g. explicit consent obtained on the platform). We process it only to provide the service.

4. How we use data

To generate and send replies, price and attribute PPV content, maintain conversation memory, show your dashboard analytics, secure the service and meet legal obligations.

5. Sub-processors

We share the minimum data needed with: OpenAI (fan message text is sent to OpenAI's API to generate replies), our hosting provider [provider/region], and Cloudflare (edge security). We do not sell data or use it for advertising.

6. International transfers

Some sub-processors (e.g. OpenAI) are outside the EEA; such transfers rely on Standard Contractual Clauses or equivalent safeguards.

7. Retention

We keep data while your account is active. You can delete a creator's data or your whole account at any time from the dashboard; deletion is carried out promptly.

8. Your rights

Under GDPR you have rights of access, rectification, erasure, restriction, portability and objection. Use the in-app deletion tools or contact [email]. You can lodge a complaint with the Polish DPA (UODO).

9. Security

Access is restricted, traffic is served over HTTPS, and credentials are hashed. Fanvue tokens are stored with restricted access [and encrypted at rest — once implemented].

10. Deleting your data

Delete a creator's data from its settings page, or your entire account from the dashboard. This removes all data we hold (fans, messages, summaries, revenue records, persona and stored tokens). It does not delete anything on Fanvue — to revoke access, also remove the app at fanvue.com → Settings → Third-party apps.

11. Contact

[Legal entity], [address]. Privacy contact / security reports: [email].