Skip to content
Fan Auto.Sign in ↗

FAN AUTO / LEGAL

Privacy Policy

What Fan Auto processes, why it is used, and the choices available to you.

Effective September 8, 2026

On this page

  1. Who we are and what this covers
  2. Information we process
  3. Where information comes from
  4. How we use information
  5. The screenshot demo
  6. Who receives information
  7. Cookies and browser storage
  8. Retention and deletion
  9. Security and processing locations
  10. Your choices and privacy rights
  11. Adults only
  12. Policy updates
  13. Contact and requests
Terms of UsePrivacy Policy

1. Who we are and what this covers

This policy explains how Fan Auto handles personal information through its website, screenshot demo, application, APIs, and creator-operation services.

For website, account administration, security, and our own business communications, we determine how information is used. For connected creator-page data, we generally process information on behalf of the creator or agency that connected the page, under its instructions and applicable agreement. That customer is responsible for its own privacy notices and lawful handling of fan information. Where we determine a separate purpose, such as our own evaluation activities, we are responsible for that processing.

This policy does not replace a creator’s, agency’s, or connected platform’s privacy notice or any required data processing agreement.

2. Information we process

  • Account and organization information: names, email addresses, password hashes, memberships, roles, permissions, session records, API-key records, and credentials or tokens for authorized provider connections.
  • Connected page information: creator profiles, account and fan identifiers, usernames, conversation text and timestamps, media and media references, content inventories, offers, prices, purchases, tips, subscriptions, spending totals, and message or delivery status available from the provider.
  • Derived information: fan memories and profiles, preferences, conversation summaries, interaction classifications, AI decisions and outputs, evaluation records, feedback, and action audit logs. These inferences can be wrong.
  • Information you submit: demo screenshots, configuration, training examples, annotations, and communications with us.
  • Technical and security information: IP addresses, browser and device information, login times, approximate location derived from an IP address when enabled, error reports, diagnostic context, and usage or request records.

Conversations and media may contain sensitive information, including intimate communications or information about sex life, sexual orientation, or health. We process such information when it is included in authorized inputs; do not submit unnecessary sensitive information. Purchase records obtained from connected platforms are different from complete payment-card details.

3. Where information comes from

Information comes from you, your organization and its authorized users, creator pages and service providers you connect, platform events and imported histories, your browser or device, and the Service’s own processing. Fan information can therefore reach Fan Auto through a creator or agency even when that fan has never visited this website.

4. How we use information

We use information to provide and secure accounts; enforce organization and page permissions; connect services; maintain conversation history and fan context; operate authorized messages, content offers, and follow-ups; handle escalations; troubleshoot failures; record decisions and deliveries; respond to requests; and comply with legal obligations.

AI processing may use conversation history, inferred preferences, and spending patterns to personalize replies, choose offers, or decide when to wait or involve a person. Enabled pages can act on those decisions automatically. The creator or agency controls whether page automation is enabled and is the first contact for questions about its interactions with a fan.

Internal training and evaluation features also process submitted examples, histories, feedback, and simulated-fan material to evaluate and improve Decision Brain behavior. This is distinct from a third-party AI provider training its own models. The public demo does not save screenshots into Fan Auto’s learning stores. Customer information remains subject to its applicable agreement and permissions.

5. The screenshot demo

When you select an image, the browser displays a local preview. Running the demo uploads the image for AI analysis. The server normalizes the image and removes embedded metadata before AI processing; this does not remove names or other details visible in the image. Crop or redact those yourself and share only chats you have permission to provide.

Fan Auto processes the screenshot and extracted conversation for the request and does not save them to application chat history or learning stores. The result remains visible in your current browser session until cleared or the page is reloaded. A hashed IP address and a browser-device cookie are used for abuse limits. Hosting and AI providers may separately retain operational or request data under their applicable terms and settings; this is not a promise of zero retention by every provider.

6. Who receives information

  • Your organization and authorized personnel: users with the relevant permissions can access information in their organization. Platform administrators can enter customer organizations through an audited administrative access flow for operation and support.
  • Connected services: platform and integration providers receive the requests and content needed to retrieve data and execute authorized actions.
  • AI providers: relevant text, context, and, where needed, images are sent to configured AI services. Integrations include OpenRouter and its upstream providers, OpenAI, and Mistral; the provider used depends on the feature and configuration. Provider retention and processing depend on the applicable service terms and settings.
  • Infrastructure and security providers: hosting and database services, including Fly.io, process stored data and requests. Sentry receives error and diagnostic information when enabled, which can include signed-in account identifiers and email. IPinfo receives login IP addresses for approximate-location lookup when configured.
  • Legal and business recipients: information may be disclosed where reasonably necessary to comply with law, protect rights and safety, resolve disputes, or support a merger, acquisition, or transfer of the business, subject to applicable protections.

Fan Auto’s current application does not include a feature for selling personal information or sharing it with advertising networks for cross-context behavioral advertising. Connected platforms have their own independent practices. We do not promise that changing or disabling a connection deletes records already held by another provider.

7. Cookies and browser storage

Authentication cookies maintain sign-in sessions, and a demo device cookie helps enforce abuse limits. Browser storage also remembers preferences such as the selected creator page. Technical requests and error monitoring help operate and protect the Service. The current application does not use advertising pixels or session-replay recording.

You can clear cookies and site storage in your browser. Blocking authentication cookies can prevent sign-in, and clearing storage can reset preferences. Clearing your browser does not delete server-side account or conversation records.

8. Retention and deletion

Retention depends on the information’s purpose, the customer relationship, applicable agreements, security and audit needs, and legal obligations. Connected conversation history and fan memory currently have no automatic expiry. Pausing automation, signing out, or disconnecting a page does not automatically remove those records.

Account, decision, delivery, and audit records may remain after active use ends to support service history, investigate incidents, resolve disputes, or meet legal requirements. Deletion requests require review of the relevant records and obligations. Backup copies and records held independently by connected providers may have different lifecycles. The public demo’s handling is described separately above.

Contact us or the responsible creator or agency to request deletion or information about retention for a particular account. We will explain any applicable limitations rather than treat a pause or account closure as a completed deletion request.

9. Security and processing locations

The Service uses measures including hashed passwords, authenticated sessions, organization and page access controls, and audit records. No storage or transmission system is completely secure. Keep account credentials private and report suspected unauthorized access promptly.

Our hosting, AI, and other providers may process information in countries other than yours, including the United States. Applicable agreements and law determine any required transfer safeguards. Contact us for information about the providers, locations, and safeguards relevant to your service arrangement.

10. Your choices and privacy rights

Depending on your location and applicable law, you may have rights to access or obtain a copy of personal information, correct inaccuracies, request deletion or portability, restrict or object to processing, withdraw consent where processing relies on it, or complain to a privacy regulator. California residents may also have rights to know categories of information and disclosures, opt out of qualifying sale or sharing, limit certain uses of sensitive information, and exercise rights without unlawful discrimination. These rights have conditions and exceptions.

Where European or UK data protection law applies to processing we control, the relevant legal basis may be providing a requested contract, legitimate interests in operating and securing the Service, compliance with law, or consent where required. Sensitive information requires an additional permitted condition; this notice does not itself supply consent or authorize otherwise unlawful processing. For processing on a customer’s behalf, the customer is responsible for identifying the applicable legal basis.

For fan information held on behalf of a creator or agency, contact that creator or agency first. You may also contact us so we can identify the responsible customer and assist as appropriate. For your Fan Auto account or website information, use our contact below. We may need proportionate information to verify your identity and authority before responding. Authorized agents may submit requests where allowed by law. If a request is denied, you can ask us to reconsider or appeal where that right applies.

11. Adults only

Fan Auto is intended for adults aged 18 or over, and is not directed to children. Do not submit content involving minors. If you believe information about a minor has been provided to the Service, contact us so we can investigate and take appropriate action.

12. Policy updates

We will update the effective date when this policy changes and provide additional notice of material changes where required. A policy update does not by itself authorize a new use requiring consent or another legal basis.

13. Contact and requests

For account questions or privacy requests, contact your organization administrator or use your existing Fan Auto business contact. Identify the account or creator page your request concerns. Do not send passwords, access tokens, or unnecessary conversation content.

For information processed on behalf of a creator or agency, contact the creator or agency responsible for that page.

← Back to Fan Auto
Terms of UsePrivacy Policy