Privacy Policy

Last Updated: 7/19/2026

1. Introduction and Roles (GDPR)

Welcome to Monster Chatter. For the purposes of the General Data Protection Regulation (GDPR), if you are an agency or creator using our platform to manage Fanvue accounts, you are the Data Controller of the personal data of your fans. Monster Chatter acts solely as a Data Processor, processing this data strictly on your behalf and according to your configurations to generate automated AI responses.

2. Age Limitation Reinforcement

We do not knowingly collect or process personal data from anyone under the age of 18. If we become aware that we are processing data from a minor, we will immediately delete it and terminate the associated account.

3. Information We Collect and Process

As a Data Processor, we collect and process the following on behalf of the Data Controller:

  • OAuth Data: We collect and securely store authentication tokens provided by Fanvue to act on your behalf.
  • Creator Data: Your Fanvue profile information, custom prompts, and settings used to train your AI persona.
  • Fan Messages and Memories (PII): We process direct messages from your fans on Fanvue. The AI may extract specific contextual facts or "memories" (which may contain Personally Identifiable Information) to improve future conversations. As the Data Controller, you are responsible for ensuring you have a legal basis (e.g., legitimate interest or explicit consent) to process your fans' data in this manner.

4. How We Process Your Data (Third Parties)

To provide our core AI features, we utilize trusted third-party sub-processors:

  • OpenRouter: Used to generate text-based replies. Fan messages and your system prompts are sent securely. We explicitly opt out of allowing OpenRouter to use your data for training their underlying models.
  • ElevenLabs: If enabled, text is sent to ElevenLabs to generate voice notes.
  • Supabase: Our secure database provider where your settings and tokens are encrypted and stored.

5. Data Retention

Fan Messages: Original fan messages are processed and subsequently deleted immediately after the AI response is generated. We do not permanently store full chat histories. We only securely store the specific "memories" extracted by the AI. You have full control over these saved memories and can review, edit, or delete them at any time via your dashboard.

OAuth Tokens: Stored securely until you disconnect your account or request account deletion.

6. Cookies and Tracking Technologies

We respect your privacy and employ a strict minimalist tracking policy:

  • Essential Cookies Only: We solely use essential, secure session cookies required to authenticate your login state.
  • No Third-Party Analytics: We do not use Google Analytics, Meta Pixels, PostHog, or any other intrusive tracking software on our application.
  • No Payment Tracking: All subscription payments are handled directly inside the Fanvue App Store. We do not use tracking pixels like Stripe to monitor your payment behavior.

7. Data Security and Breach Notification

We implement industry-standard security measures, including Row Level Security (RLS) on our databases and encryption for sensitive API keys. We never expose your Fanvue OAuth tokens to the public web.

Data Breach Notification: In the highly unlikely event of a data breach compromising our systems, as your Data Processor, we commit to notifying you (the Data Controller) without undue delay, and in any event within 48 hours of discovering the breach, so you can fulfill your own compliance obligations.

8. International Data Transfers

Our primary servers and databases are located in Europe. However, some of our third-party sub-processors (such as OpenRouter or ElevenLabs) may process data on servers located in the United States. Any transfer of personal data outside the European Economic Area (EEA) is safeguarded by Standard Contractual Clauses (SCCs) or other legally approved transfer mechanisms to ensure your data receives an adequate level of protection.

9. US Privacy Laws (CCPA)

For residents of California or other applicable US states, we act strictly as a "Service Provider." We do not "sell" or "share" personal information as defined by the California Consumer Privacy Act (CCPA) or similar state laws. We process data solely to provide the automated chatting service as directed by our creators/agencies.

10. Your Regional Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have specific rights under the General Data Protection Regulation (GDPR) regarding your personal data:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can request correction of inaccurate data.
  • Right to Erasure ("Right to be Forgotten"): You can request the deletion of your account and all associated data (tokens, prompts, memories).
  • Right to Data Portability: You can request to receive your data in a structured, commonly used format.

11. Contact Us

To exercise any of your data rights, request account deletion, or ask questions about this policy, please contact our Data Protection Officer at: monsterchatter.support@gmail.com