Legal

Privacy Policy

Effective date: 30 August 2026

This Privacy Policy explains how OFM UI ("we", "us", "our"), the operator of OFM UI (the "Service", at https://ofmui.com), collects, uses, shares, and protects personal data. OFM UI is a tool that connects to a Fanvue creator's account through Fanvue's official API and, on the creator's instruction, drafts and sends chat messages to that creator's fans and helps manage paid content.

"OFM UI" is the trading name under which the Service is operated; the provider's identification details are set out in Section 19 of our Terms of Service. If you have any questions, contact us at [email protected].


1. Who this policy is for, and our two roles

The Service is used by creators — people with a Fanvue creator account who sign up to automate their fan chats. Creators' fans never install or log in to the Service; however, the Service processes fans' messages and profile identifiers on the creator's behalf.

Our role under data-protection law depends on whose data it is:

  • Creator account data (your login, your settings, your billing and referral relationship with us): here we are the data controller.
  • Fan data (your fans' messages, identifiers, purchase, tip and read events, and everything the Service derives from them): here we act as a data processor acting only on your documented instructions as the creator. You, the creator, are the controller of your fans' personal data. You are responsible for having a lawful basis to process it and for your own privacy notice to your fans. A Data Processing Agreement (DPA) is available on request and forms part of our Terms of Service.
Note on Fanvue API data. Once you authorise the Service against your Fanvue account, we — not Fanvue — control how the authorised data is used, stored, and shared. This policy is that disclosure.

2. The data we collect and process

2.1 Creator account & configuration data

  • Your email address (used to sign in, verify your account, and send service emails) and a salted password hash (we never store your password in plaintext). Optional two-factor authentication secrets where you enable 2FA.
  • App settings you configure (pricing, persona/character description, pacing, media-tier folder mappings, etc.).
  • Your Fanvue OAuth tokens (access and refresh tokens) obtained when you connect your account, used solely to call the Fanvue API on your behalf.

2.2 Billing and referral data

  • Subscription data: which plan you are on, its status and renewal dates, and your Stripe customer identifier. Payments are processed by Stripe; your payment card details are collected by Stripe directly on Stripe-hosted pages and never touch our servers. We receive billing events (e.g. "subscription started", "invoice paid") from Stripe to activate and manage your plan.
  • Referral data (if you use the referral program): your referral code, who signed up with it, the commission accrued and paid out, and — if you set up payouts — your Stripe Connect account identifier and its onboarding/payout status. Identity and bank details required for payouts are collected by Stripe directly under Stripe's own terms and privacy policy; we do not see or store your bank details.

2.3 Fan data (processed on your behalf)

Pulled from Fanvue via the API, or received through Fanvue webhooks:

  • Fan identifiers (Fanvue user UUID, and display name/first name where available).
  • Message content you and your fans exchange, and message timestamps and message UUIDs.
  • Media metadata (which content items exist, their descriptions, prices, tiers, and whether an item was sent or purchased).
  • Events: purchases, tips, subscriptions, and message-read receipts.
  • Earnings/insights data synced from Fanvue's insights API (aggregate revenue figures and top-spender summaries).

2.4 Data the Service derives

  • Conversation memory and summaries used to keep replies consistent.
  • Vector embeddings of message text, used for long-term recall and for detecting purchase intent ("buying signals").
  • Generation and quality logs (the drafts the Service produced, quality scores, and — in approve mode — a record of edits an operator made to a draft).

2.5 Technical data

  • A login cookie to keep you signed in to the dashboard. If you tick "Remember me" when you sign in, this cookie lasts up to 7 days and survives closing your browser; if you don't, it is a session cookie that your browser clears as soon as you close it. We use this — and a small number of other strictly functional first-party cookies (for example, remembering whether you collapsed the sidebar, and briefly holding a referral code from a sign-up link) — only to operate the Service. We do not use any advertising or third-party tracking cookies, so no cookie-consent banner is required.
  • IP address, used transiently to rate-limit dashboard logins and protect against brute-force attacks.
  • Server logs needed to operate and debug the service.

2.6 Special-category data — please read

Fanvue is an adult-content platform. Fan messages processed by the Service will frequently reveal information about a person's sex life or sexual orientation, which is a special category of personal data under Article 9 UK/EU GDPR. The Service processes this content because it is the very content of the conversations you have instructed it to handle.

Processing special-category data requires an Article 9 condition (such as the data subject's explicit consent) in addition to an ordinary lawful basis. As the controller of your fans' data, you are responsible for ensuring an appropriate Article 9 condition is in place for the conversations the Service processes on your behalf. We process this data only as your processor and only to provide the Service's functionality.


3. Why we process data (purposes) and our lawful bases

PurposeData usedLawful basis
Provide the core service (draft & send replies, manage content, sync revenue)2.1, 2.3–2.5Performance of our contract with you (creator); for fan data, your instructions as controller
Billing: subscriptions, invoicing, plan limits2.1, 2.2Performance of our contract; legal obligation (tax/accounting)
Referral program: attribution, commission, payouts2.2Performance of our contract
Account emails (verification, password reset, service notices)2.1Performance of our contract; legitimate interests
Keep your account secure2.1, 2.5Legitimate interests (security), legal obligation
Maintain and debug the service2.4, 2.5Legitimate interests (running a reliable service)
Comply with law and platform obligationsas neededLegal obligation; legitimate interests

Where we rely on legitimate interests, we have balanced them against your and your fans' rights. You may object — see Section 8.


4. How AI is used, and what that means for the data

To draft replies and understand conversations, the Service sends message content and related context to third-party AI providers (see Section 6). This means fan message content — including the special-category content described in Section 2.6 — leaves our systems and is processed by those providers under their own terms and security. We use providers that offer business/API terms; however, you should assume message content is transmitted to and processed by these providers for the purpose of generating output. If you are not comfortable with this, do not use the Service.


5. Retention

  • Conversation content is retained per your configuration. By default the Service keeps the most recent 25 messages per conversation (the "Messages kept in memory" setting); older messages are compressed into summaries or discarded.
  • Derived data (memory, embeddings, logs) is kept while your account is active and the underlying conversation is retained.
  • On deletion or disconnection (Section 8), we erase your creator data root — conversations, memory, embeddings, media metadata, revenue cache, logs — and forget your Fanvue tokens.
  • Billing and referral records (invoices, subscription history, commission and payout records) are retained after account deletion for as long as tax, accounting, and anti-fraud law requires.
  • Otherwise we keep only what we still need for the purposes above, or as required by law.

6. Who we share data with (sub-processors & recipients)

We do not sell personal data. We share it only with the service providers needed to run the Service:

RecipientWhat they receiveWhy
FanvueAPI calls carrying your tokens and the messages/content you sendThe platform you operate on
StripeYour email; payment card and bank/identity details you enter on Stripe-hosted pages; subscription and payout eventsSubscription billing; referral payouts (Stripe Connect)
ResendYour email address and the content of account emails (verification, password reset)Transactional email delivery
xAI (Grok)Message content and contextGenerating chat replies
Google (Gemini)Message textGenerating embeddings for memory & buying-signal detection
OpenRouter (only if you enable it)Message content and contextAlternative reply/judge model routing
Our hosting / infrastructure providersData at rest and in transit on our serversOperating the service

Several of these providers are located outside your country, including in the United States. Where personal data is transferred internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. Details are available on request.

We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety, or property of any person.


7. Security

We maintain technical and organisational measures appropriate to the risk, including: encryption in transit (HTTPS/TLS); storage of API secrets and tokens in server-side secrets management rather than in client code; salted PBKDF2 password hashing with optional two-factor authentication for dashboard accounts; login rate-limiting; payment-card handling delegated entirely to Stripe (PCI-DSS Level 1); and restricting staff access to personal data to what is necessary. No system is perfectly secure, and we cannot guarantee absolute security.

Breach notification. If we become aware of a personal-data breach affecting your data, we will notify you without undue delay and, where the breach involves data accessed through the Fanvue API, we will also notify Fanvue, consistent with Fanvue's API policy. We will report to the relevant supervisory authority where legally required.


8. Your rights, and how to delete your data

Depending on your location, you have rights to access, rectify, erase, restrict, object to, and port your personal data, and to withdraw consent. To exercise these rights over creator account data, contact [email protected]. Because fans do not have accounts with us, fans should direct requests to the creator they were talking to (the controller); we will support creators in fulfilling such requests.

You can delete your data in these ways:

  1. In-app: disconnecting a creator from the dashboard permanently erases that creator's data root (conversations, memory, media metadata, revenue, logs) and revokes its Fanvue tokens.
  2. Cancelling your subscription (Account page) stops the service; you may then request full account deletion.
  3. By request: email [email protected]; we will action deletion within 30 days, except for billing records we must keep by law (Section 5).

We also treat disconnecting the Service in Fanvue (Settings → Third-Party Apps) as a signal to stop processing and delete the associated data.

You may lodge a complaint with the data-protection supervisory authority in your country of residence or work, or where you believe an infringement occurred (Article 77 GDPR). Contact details for EU authorities are published by the European Data Protection Board at https://edpb.europa.eu.


9. Children

The Service is for use only by adults (18+) operating a Fanvue creator account, in connection with fans who are themselves adults. The Service is not directed to children and we do not knowingly process children's data.


10. Changes to this policy

We may update this policy from time to time. Material changes will be notified through the Service or by email, and the "Effective date" above will change. Continued use after an update constitutes acceptance of the revised policy.


11. Contact

This policy is governed by the laws of the Republic of Lithuania (the same law as Section 17.1 of our Terms of Service).