Last updated 8 October 2026
Privacy
cclarity is a tool creators and agencies use to run their own OnlyFans or Fanvue account, and the Telegram beside it. Most of what passes through it is their data about their fans, not ours — so this explains what we hold, why we hold it, and how to take it back.
Who is responsible
For your account with us — your email, your workspace, your plan, your team — cclarity is the controller.
For everything we read out of OnlyFans, Fanvue or Telegram on your behalf — conversations, fans, earnings, media — you are the controller and cclarity is your processor. We act on your instructions and hold that data to run the features you switched on. If your fans ask you what happens to their messages, this page is the answer, and you can point them at it.
How we get in
Fanvue hands over through its own consent page (OAuth). We hold the token it gives us, encrypted at rest, and never see your Fanvue password.
OnlyFanshas no public API, so the account signs in on onlyfans.com itself, in a browser window opened by the cclarity connector — a small Chrome extension you install once. The window is routed through a residential proxy we assign to that account, and the extension clears any other OnlyFans login in that browser first. The password, captcha and two-factor code are typed on OnlyFans; the extension never reads them. What it reads once the login succeeds is the session OnlyFans issues — its cookies, a session header and the browser’s user-agent string — and hands that to our own backend, which from then on reads and sends as you through the same proxy. Disconnecting the account discards it.
Telegramis the model’s own account, signed in by scanning a code on her phone. We hold that session, encrypted at rest, and read and answer only the conversations on it.
What we store
| What | Why | Kept |
|---|---|---|
| Your email and sign-in | Authentication, optionally with two-factor. Handled by Clerk; we store the identifier and your email. | Until you delete your account |
| Workspace, plan, team | Access control and billing. Members' emails and roles, which accounts each can see, and what chatters are paid. | Until you delete your account |
| Fanvue OAuth tokens | So the app can read and send on your behalf. Encrypted at rest. | Until you disconnect |
| OnlyFans session | The cookies and session header OnlyFans issued at sign-in, plus the proxy assigned to the account. Used to read and send as you. | Until you disconnect, or OnlyFans ends the session |
| Telegram session | The model's own account, so her Telegram conversations appear beside her page. Encrypted at rest. | Until you disconnect |
| Conversations, fans, transactions | Mirrored so screens load instantly and segments can be counted, and read by the AI when you ask it to write. On Telegram this includes the OnlyFans name a man gives. | Until you disconnect or delete |
| Vault media and what the AI sees in it | Media you upload is stored for posting and PPV; media already on the platform is read in place. The AI writes a caption and tags for each file so it can pick the right one. | Until you delete the file or the account |
| Persona, scripts, notes, fan profiles | You wrote the persona and scripts; the AI fills in what it learns about a fan — job, timezone, limits — so replies stay consistent and every chatter works from the same card. | Until you delete them |
| AI drafts and engine logs | So you can review and approve each reply, and audit why the AI said what it said and what it cost. | Drafts 24h; logs up to 12 months |
| Shift presence and messages sent | When each team member was on shift and what went out while they were — the basis of the Team report and chatter pay. | Until you delete your account |
| Invoicing details | Company details and bank accounts you enter so the agency can invoice models and chatters; the invoices themselves. | As long as tax law requires |
| Payment records | Legal obligation to keep invoices for your subscription. | As long as tax law requires |
Who else sees it
Only what a feature needs, and only to run it. We do not sell data and we do not use your conversations to train anybody’s model.
- OnlyFans, Fanvue, Telegram — the sources. We call them as you, with the session or token described above.
- A residential proxy provider — only the OnlyFans traffic for a connected account passes through it. The connection is encrypted end to end; the provider sees that a connection was made, not what was in it.
- Clerk — sign-in, two-factor and team management.
- Neon — the database, hosted in the EU.
- Vercel — hosting, logs, and the storage behind media you upload to the vault.
- Fly.io (Frankfurt) — our own servers: the one that holds OnlyFans sessions and talks to OnlyFans, and the one that runs Telegram and the night-shift automation.
- xAI — the models that write replies, read a thread when you ask about it, translate, tag vault media and transcribe voice notes. Message history and the media in question go with the request. Not used for training.
- ElevenLabs — only if you set a cloned voice; the words of a voice note go there to be spoken.
- Resend — the emails we send you, such as a daily digest or a failed-payment notice, if you switch them on.
- Lemon Squeezy — payments. They are the merchant of record; card details never reach us.
Some of these process data outside the EEA under Standard Contractual Clauses.
The connector extension
The extension runs only on cclarity.space and, during a sign-in, on onlyfans.com and the captcha pages it uses. It changes your browser’s proxy only for those addresses and only while connecting, answers the proxy’s own login itself, and sends nothing anywhere except the session described above, to cclarity. It has no analytics and reads no other site.
Cookies
Only the ones the product cannot work without: your Clerk session, the creator account you last selected, your light/dark preference, and a short-lived pair during the Fanvue connection flow. No advertising cookies, no third-party analytics, no tracking pixels — which is why the banner only tells you this, and asks for nothing.
If that ever changes, you will be asked first, and refusing will keep the product working.
Your rights
Under the GDPR you can see your data, correct it, take it elsewhere, restrict what we do with it, object, and have it erased. Two of those are buttons rather than emails:
- Download everything — a JSON file of your workspace, in Settings → Privacy.
- Delete your account — same page. It removes the workspace, its members, connected accounts, sessions and tokens, mirrored conversations, notes and engine history, and signs you out. It is not reversible.
For anything else, write to privacy@cclarity.space. We answer within 30 days. You can also complain to your national data protection authority.
Automated replies
Auto-chat writes messages in your voice and, when you switch that on, sends them without showing you first. It reads recent messages, the persona and scripts you authored, the notes you and it have kept on a fan, and the vault. It is a drafting tool working for you — it makes no decision about any person that has a legal or similarly significant effect on them. Every reply waits for review until you decide otherwise; a human can cap how often it writes, hold any single conversation back, exclude a fan entirely, or stop every account with one switch, at any time.
Security
Fanvue tokens and Telegram sessions are encrypted at rest. OnlyFans sessions live on our own servers and are never returned to the browser. Access is scoped to your workspace and to the accounts each member has been given, and checked on every request. Transport is TLS throughout. If we ever suffer a breach affecting your data, we notify the supervisory authority within 72 hours and you without undue delay.
Changes
If this notice changes materially we will say so in the app before the change takes effect, not only by editing this date.
This notice describes what the software actually does. It is not legal advice and has not been reviewed by counsel.