Last updated: October 5, 2026
Privacy is core to HerFans. This policy explains what data we collect, why we collect it, how long we keep it, and the choices you have. It applies to everyone who uses the Platform, creators and fans alike.
Who is responsible for your data. The controller of your personal data is the company that operates HerFans, , with its registered address at , Poland. Its registration number and tax identification are in our Legal Notice.
Account data: email address, username, password hash, and profile details you choose to add. Age confirmation: the fact and the time that you confirmed you are 18 or over. Verification data: for creators, a government-issued identity document, date of birth, a liveness check, the stage names you publish under, and the participant consent records for anyone else appearing in your content. Payment data: handled by our payment processor; see section 2. Content and activity: posts, messages, subscriptions and interactions on the Platform. Technical data: IP address, device and browser information, and cookies needed to keep you signed in and keep the Platform secure. We also record account activity and device data (sign-ins, purchases, what was opened, IP address and a device identifier) to prevent fraud and to answer payment disputes, on the basis of our legitimate interest, and we keep it for up to 24 months. After that it is deleted. The one exception is an account with a payment dispute still open: its records stay until the dispute is closed, because they are the evidence the dispute is answered with.
We never see or store your full card number, and we never will. Today payments are processed by the cryptocurrency payment processor NOWPayments, named in section 7, and card payments will be added. No card data reaches us or anybody else today. When card payments are added, a card payment is processed by a specialist third-party payment processor under its own PCI DSS certification: you enter your card details on that processor's systems, the processor stores them, and it is an independent controller of that data under its own privacy policy. It is named in section 7 before the first card payment is taken.
Who is responsible for your payment data. We, the company that operates HerFans, are the seller of everything bought on the Platform, so we are the controller of the data about your purchases and payments: what you bought, when, for how much, and the payment record below. We process it to perform the contract of sale with you, to meet our tax and accounting obligations as the seller, and to prevent fraud and answer disputes. A creator whose content you buy is not a party to your payment and does not receive your payment data; what she sees is your username and what was bought on her page.
What reaches us is the record of the payment: amount, currency, date, result, card brand and the last four digits. That is enough to answer a question about a charge, settle a dispute and meet our accounting and anti-fraud obligations, and not enough to make a charge. We use it for nothing else, and we do not sell or rent it.
Payments in cryptocurrency. For a payment made through NOWPayments, what we hold is the transaction record and the amount, as reported by that provider, which is named in section 7. We never hold your private keys and cannot move funds in a wallet of your own. When we refund a cryptocurrency payment, or return a difference, we send it by hand to a wallet address you give us, and we keep that address with the record of the refund.
We use your data to operate the Platform, process payments and payouts, verify age and identity, meet our record-keeping obligations, prevent fraud and abuse, investigate complaints, provide support, and improve the product. We do not sell your personal data. We send transactional emails, and marketing emails only with your consent, which you can withdraw at any time.
Identity documents, dates of birth, alias lists and participant consent records are the most sensitive things we hold, and they are treated that way.
They are stored encrypted, separately from public profile data: every document image and every frame of the camera check is encrypted on our server's disk with a key kept apart from the rest of the application, and is decrypted only for the check itself and for the person who reviews it. Access is restricted to the small number of people who need it for verification, compliance and legal response, and every access is logged. They are never shown to other users, never attached to a public profile, never used for marketing, and never used to train anything of ours.
We share them only with the verification provider acting on our instructions, which is named in section 7 together with the country it works in, with a payment provider or card network when it is entitled to demand them, and with an authority where the law requires it.
How long we keep them, stated plainly. We keep them for as long as your account exists, and after it closes. There is no automatic deletion and we are not going to pretend otherwise: the age record has to outlive the content it covers, our 18 U.S.C. 2257 statement explains why, and the card networks require the same. Closing your account does not start a countdown on them, and it does not shorten a retention period the law sets.
You can still ask us to erase them. Write to support@herfans.com and a person goes through it by hand: we delete what we are free to delete, we tell you what we must keep, and we say which rule makes us keep it. If the content you were verified for has been taken down and no complaint or investigation is open, there is usually less to keep than people expect. We answer within 5 business days.
Section 4 is written about a creator. This section is about a visitor who is asked to prove her age before adult material is shown to her.
Who is asked. Only somebody signing in from a territory whose law requires more than a tick box before adult material is shown. The list is published, and kept current, in section 4 of our age verification policy. Nobody else is asked, and nobody at all is asked twice.
What is asked for. Photographs of both sides of a government issued identity document, a short live camera check on her own phone, and four typed details the check compares against the document: the name printed on it, the date of birth, the kind of document and the country that issued it. Nothing else. We do not ask for an address and we do not ask what the document number is.
What the account shows afterwards. That the age was confirmed, the date it was confirmed, and that it was confirmed with a document and a camera check.
Where it goes. To this server's own disk, never to cloud storage, never anywhere with a public or a shareable address. It is read by the same automatic check described in section 7 and, if that cannot settle it, by the person who decides. It is never shown to other users, and every time a person opens it that is logged.
Today payments are processed by the cryptocurrency payment processor NOWPayments, and card payments will be added. A cryptocurrency payment does not appear on a card statement. For card payments, the processor assigns the text that appears on a statement when a merchant account is approved, and we publish the exact wording at herfans.com/billing before the first card payment is taken rather than guessing at it here. What we can say now is that no creator is ever named on a statement line by us. Emails from us use neutral subject lines where possible.
We share data only with service providers who help us run the Platform (payment processing, identity verification, hosting, email), with card networks and acquirers where they are entitled to it in connection with a payment or a dispute, with authorities when the law requires it, and in connection with protecting our users and enforcing our Terms of Service. Our service providers may only use your data to provide their services to us.
We are established in the European Union, and several of the companies that help us run the Platform are not. Rather than write that data "may be transferred to our partners", here is the whole list, with what each company gets, where it is, and what makes the transfer lawful.
The two facts worth knowing before the list: the server that holds your account and the verification documents, and the storage that holds the photos and videos posted to the Platform, are both in the United States today, and the model that reads verification documents runs in the United States as well.
DigitalOcean, LLC. Rents us the server the Platform runs on, and the same server sends our email whenever the email service below is unavailable.
What it receives: Your account, your posts and messages as text, your payment records, and the verification documents creators and visitors upload, which sit on a private part of that server and nowhere else.
Where it processes it: A United States company. The server stands in its data centre in New York, in the United States, so that is where the database and the verification documents physically are.
Basis for the transfer: Standard contractual clauses approved by the European Commission, which are part of its data processing agreement.
BunnyWay d.o.o., trading as Bunny.net. Stores the photos, videos and audio posted to the Platform, avatars and covers included, and delivers them to the people allowed to see them.
What it receives: The files themselves, and the IP address and technical details of each request for one. Paid files sit in a private storage zone with no public address and are released only through a short lived link we issue after checking that you may see them. Verification documents never go there.
Where it processes it: A Slovenian company, inside the European Union. The files are stored in its New York region, with a copy in Los Angeles, in the United States, and delivered from the point of its network nearest to you.
Basis for the transfer: Standard contractual clauses approved by the European Commission, because the files are stored in the United States.
Google LLC. Provides the Gemini models that check verification documents, rate images for the safe-for-work part of the site, and help with message drafts and search.
What it receives: For verification: photographs of the identity document, front and back, the selfie and the frames of the short camera check, and the name and date of birth typed into the form. Separately: images posted to the Platform, avatars and covers, for the safe-for-work rating, and the text of messages when we look for an attempt to move a payment off the Platform or when the assistant drafts a reply.
Where it processes it: United States.
Basis for the transfer: The EU-US Data Privacy Framework, which Google LLC is certified under, and standard contractual clauses in addition to it.
Cloudflare, Inc.. Carries every request to the site, protects it from attacks, and runs our DNS.
What it receives: Your IP address and the technical details of each request, and whatever passes between you and us on the way. It stores none of our files.
Where it processes it: A United States company with servers in many countries, so a request is handled at the point of its network nearest to you, which can be outside the European Union.
Basis for the transfer: The EU-US Data Privacy Framework, which Cloudflare, Inc. is certified under, and standard contractual clauses in addition to it.
OpenAI. Stands in for the Google model when it gives no answer. It is a fallback, and nothing goes to it while the first model works.
What it receives: The same images rated for the safe-for-work surface, and the same message text. Never a verification document: that path uses one provider only.
Where it processes it: United States.
Basis for the transfer: Standard contractual clauses.
FD Transfers LLC, trading as NOWPayments. Processes the payments fans make on the Platform in cryptocurrency. It is the payment processor in use today; card payments will be added.
What it receives: The amount, the currency and our own reference number for the payment. Not your name and not your email address. Anything you type on their own pages you give to them directly, and they answer for it under their own policy.
Where it processes it: Saint Vincent and the Grenadines.
Basis for the transfer: No European adequacy decision covers that country, so we keep what we send down to the three items above and the transfer rests on standard contractual clauses.
Mailgun Technologies, Inc.. Sends the email we write to you: sign-in codes, receipts, notifications and replies from support.
What it receives: The messages we send you, the address they go to, and whether they were delivered.
Where it processes it: A United States company. We use its European region, so the messages are processed and stored on its servers inside the European Union.
Basis for the transfer: Standard contractual clauses approved by the European Commission, because the company is American even though the messages stay in its European region.
OVH Sp. z o.o.. Rents us the machine that holds our own mailboxes, so it receives what you write to our addresses and our internal notifications.
What it receives: The messages you send us and our replies to them, with the addresses on them.
Where it processes it: Warsaw, Poland, inside the European Union.
Basis for the transfer: Inside the European Union, so no transfer to a third country takes place.
BunnyWay d.o.o.. Delivers the two typefaces the pages are set in, through Bunny Fonts.
What it receives: Your IP address, which is all that sending you a file requires. No cookie is set for it and nothing about your account is passed.
Where it processes it: A Slovenian company, serving the file from the point of its network nearest to you, which can be outside the European Union.
Basis for the transfer: Standard contractual clauses where the file is served from outside the European Union.
Card payments. We have not appointed a card processor yet, so no card data goes anywhere at all today. When one is appointed it is added to this list, with the same three lines as everyone above, before the first card payment is taken.
What makes a transfer outside the European Union lawful. For each company above we rely on one of two things. The first is the standard contractual clauses approved by the European Commission, which are contract terms that bind the company to European standards of protection wherever it processes the data, and give you rights you can enforce against it. The second is the EU-US Data Privacy Framework, a European Commission adequacy decision covering companies in the United States that certify to it and appear on the official list: Google and Cloudflare each do. Where a country has neither, which is the case for the cryptocurrency provider, we cut down what is sent instead, and the clauses carry the rest.
Verification documents and face images, said outright. When a creator verifies her identity, the photographs of her identity document, the selfie and the frames of the short camera check are sent to Google's Gemini models in the United States, together with the name and date of birth she typed in. The models answer four questions: is this a real document rather than a photograph of a screen, do the name and date of birth match, is a living person in front of the camera, and is she the person in the document photograph. Reading a face to answer that last question is processing of biometric data. We do it because we have to know that an adult is who she says she is before she can publish or be paid, we ask for her explicit consent to it before the check starts, and the check is the only reason it happens. A submission the models confirm on all four points is approved on that check; anything left unconfirmed is never approved by software and waits for a person, and the record always names which of the two decided it. On our side this material is used for the check and for nothing else: it is never posted, never shown to another user, never used for marketing, never used to train anything of ours, and never sent to the fallback provider.
The same four questions, the same models and the same country apply to a visitor's age check under section 4a.
The support chat. The chat window in the corner of the page is provided by InChat (inchat.ai). It receives what you type into it, the technical data any web request carries, and, while you are signed in, the email address of your account, so that a person can answer you by mail. It receives nothing else: not your content, not what you bought, and never a verification document. The three lines above are being completed for it and will be published here in the same form as for every company in the list.
Images and messages. Photographs posted to the Platform, along with avatars and covers, are rated by the same provider so that nothing explicit reaches the public pages. Message text is read by a model in two narrow cases: when we check whether somebody is arranging to pay or be paid outside the Platform, and when a creator asks the assistant to draft a reply for her. Both leave the European Union in the same way and on the same basis as everything else in the list.
We keep account data for as long as your account is active. You can close your account yourself in Settings. The moment it is closed, your profile, your posts and your messages stop being shown to anyone. For 30 days after that you can change your mind: sign in, or use the link we email you, and the account comes back as it was.
When those 30 days are over we remove your personal data: your name, email address, username, password, profile text, profile photo and cover, sign-up details, notification settings, payout details and the record of the devices and addresses you visited from. The account stays only as an anonymous entry named "Closed account". Messages you sent stay in the inbox of the person you sent them to, under that name.
We keep what we are required to keep, for as long as that obligation lasts: age and identity verification records, consent records for content that was published and the content they cover, transaction records for accounting and anti-fraud purposes, records relating to an open complaint, investigation or payment dispute, and what we need to show a regulator, a card network or a payment partner that the checks our obligations require were carried out. The activity log described in section 1 is not removed at closure; it runs out on its own, 24 months after each entry. Three things can move the date. If the account still holds money, we wait until it has been paid out, because we need your address to pay you. If a payment dispute or a payout is still open, we wait until it is settled. If we closed the account for breaking our rules, we wait for the six months in which the decision can be appealed, and we then keep a one way fingerprint of the email address, from which the address cannot be read back, so the same address cannot open a new account. Content you delete is removed from the Platform; backups purge on a rolling schedule.
Reports and complaints are kept as a record of what was raised and what we did about it. That record outlives the account that filed it, because the alternative is that closing an account erases the evidence of a complaint against it.
We protect data with encryption in transit for everything, encryption at rest for identity documents and camera checks, access controls, logging and monitoring.
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. You can exercise these rights through your account settings or by writing to support@herfans.com, and we answer within 5 business days. In Settings, the Download my data button emails you a link to a copy of your data as JSON files in one ZIP, once a day, and the Close your account section closes your account at any time; section 8 says what happens after that. If you prefer, write to that same address and a person does either for you.
In the European Union these rights have names, so here they are in the order of the law: access to your data and a copy of it, correction, erasure, restriction of processing, portability in a machine-readable form, and objection to processing we base on our legitimate interests. Where we process something because you consented to it, the verification check included, you can withdraw that consent at any time, and withdrawing it does not make what we did beforehand unlawful. You can also ask us for the copy of the standard contractual clauses that cover a transfer described in section 7.
If you think we have handled your data badly, tell us first and we will try to put it right. You also have the right to complain to a data protection authority without asking us at all: the one in the country where you live or work, or the one that supervises us, which is the authority of the country of registration given in our Legal Notice.
If you appear in content on the Platform and did not consent to it, you do not need an account to have it removed. Use the complaints form: intimate material published without consent comes down within 48 hours of a valid notice, and in practice the same day.
We use essential cookies to keep you signed in, to remember that you confirmed you are 18 or over, and to keep the Platform secure, and that is all. We do not use analytics cookies or third party advertising cookies, and no analytics service runs on the Platform.
If we make material changes to this policy we will notify you on the Platform or by email before they take effect.
The data controller is , , Poland. Its registration number and tax identification are in our Legal Notice.
Questions or requests? Write to support@herfans.com or use the contact page.