Privacy Policy
This site deals with unusually sensitive information: the simple fact that you have an account here says something private about you. That single idea drives every decision below. We collect as little as we can, we keep it as briefly as we can, and we do not let advertising technology anywhere near the part of the site you log into.
1. The principle this policy is built on
Membership of a site like this one is sensitive personal information in its own right — more sensitive, arguably, than most of the individual fields we hold. Several US state privacy laws treat inferences about a person's sex life as a protected category, and we think that is the correct way to look at it.
So the question we ask of every feature is not “are we allowed to collect this?” but “what happens to this person if this data leaks?” That is why there is no advertising technology in the member area, why we never receive your identity document, and why we do not keep a log of which IP address subscribed.
2. Who is responsible for your data
Brielle Fans decides how and why your personal information is handled. Contact us at support@briellefans.com.
This site is offered in the United States only. We do not knowingly serve visitors elsewhere, and access from outside the areas we serve is refused.
3. What we collect, and why
Account. Your email address, a password (stored only as a hash by our authentication provider), and your language preference. Used to sign you in, to run your membership, and to contact you about it.
Your age, at signup. We ask for your date of birth when you create an account, because BrielleFans is for adults 18 and over. We work out whether the date makes you 18 and then discard the date. What we keep is that the check happened, when, and that it was based on what you told us.
This is your own statement of age. We do not check a document, we do not verify your identity, and we do not ask a third party about you. If the date you give us means you are under 18, the account is not created.
Membership and billing. Which tier you are on, your subscription status, period start and end dates, and a record of each transaction — amount, date, currency, and identifiers that link it to your account. Also a billing consent record capturing the exact price and interval you were shown at checkout and the version of each policy in force at that moment. That record exists to protect you as much as us: it is the evidence of what you actually agreed to.
We never receive your card number, expiry date, or security code. Checkout happens on the payment processor's own page. Those details do not pass through this site and are not stored here in any form.
Age assurance. Where verification is required, we store only the outcome: whether it passed, how it was checked, the name of the company that performed the check, a reference number that means nothing outside their systems, and the issue and expiry dates. We do not receive or store identity documents, document numbers, your name, your address, your date of birth, facial images, or biometric templates. The check happens on their systems; we get a yes or no and a reference number.
Likes. Which posts you have liked. That is the only thing you can contribute here — there are no comments, no messages, no uploads, and no posts, so there is no such content for us to collect.
Support, reports, and DMCA notices. What you send us, plus a contact address to reply to. If you submit a report anonymously, we do not require an address and cannot reply.
Technical and security data. Ordinary server logs from our hosting and database providers. For rate limiting we store a hashed identifier that expires within minutes to hours — long enough to stop automated abuse, too short and too coarse to build a history from.
Approximate location. See section 5.
Date of birth, again at checkout. When you subscribe we ask a second time, and this time we do keep the date. The two are different records for different reasons: the one at signup only has to answer “is this person an adult”, while the one at checkout is the specific statement you made at the moment money changed hands, which is what a payment dispute is argued over. Keeping a yes/no there would leave us unable to show what you actually said.
It is never shown on your profile, never shown to anyone else, never sent to the payment processor, and never used to work out anything else about you. If you tell us you are under 18, we refuse the sale and do not store the date at all.
4. What we deliberately do not do
- No third-party analytics in the member area. Not on the feed, not on your account page, not in the creator area. Which posts you open is never transmitted to an analytics vendor. This is enforced by an automated test that watches the network traffic, not by a promise in a document.
- No advertising, no ad pixels, no retargeting, no cross-site tracking.
- We do not sell or share your personal information, as those terms are used in US state privacy law. There is no opt-out to offer you because there is nothing to opt out of.
- No data brokers, no list rental, no enrichment services.
- No long-term IP address history. We do not keep a record of which address subscribed to this site.
- No profiling or automated decision-making that produces legal or similarly significant effects about you.
5. Location, and how little of it we use
Age-verification duties depend on where you are, so we have to know roughly where that is. We use only the coarse country and region that our hosting provider derives from your connection — the same signal that decides which data centre serves you.
- We do not ask for, or use, GPS or precise device location.
- We do not store your location against your account. It is read from the request, used to pick the applicable rule, and discarded.
- The jurisdiction under which a verification was performed is recorded on that verification record, because it is what makes the record meaningful.
This method is approximate by nature. It is a routing signal, not a determination of where you live, and we treat it that way.
6. Cookies
We use a small number of cookies, all of them functional:
- Session — keeps you signed in. Short-lived, marked
httpOnlyandSecure, so it cannot be read by scripts or sent over an unencrypted connection. - Age acknowledgment — records that you confirmed your age on entry. It holds a version marker and a timestamp. No personal data.
- Language preference.
On public marketing and legal pages only, we load Google Analytics with IP anonymisation on and advertising features off. It does not run on the feed, on any post, on your account page, or in the creator area — so it cannot observe anything about your membership or what you view.
We do not use advertising cookies, and there are none to reject.
7. Who else touches your data
We use a small number of service providers. Each gets the minimum it needs to do its job, and none is permitted to use your information for its own purposes.
- Hosting and database provider — stores account, membership, engagement, and content data, and runs the site.
- Payment processor — takes your payment on its own page and handles your card details under its own privacy policy, as an independent controller of that data. This is Stripe, Inc. We never receive or store your full card number, expiry date, or security code.
- Age-verification provider, where verification applies — receives what it needs to check your age, directly from you, and returns only a result to us. No such provider is currently engaged, and no age verification of this kind is currently performed. If that changes we will name the provider here before it begins, and we will still never receive your identity document, your facial image, or your date of birth.
- Transactional email provider — delivers account, billing, and security emails. It receives your email address and the message.
- Rate-limiting store — receives hashed, short-lived counters. No identifiers.
Our operational alerts are scrubbed before they leave. When something goes wrong we notify ourselves through a messaging tool, and account identifiers, email addresses, and file paths are removed from those messages first. An alert channel is a far less controlled place than a database and should never carry “payment failed for [your email]”.
We may also disclose information where we are legally required to, or where it is necessary to investigate fraud, protect someone from harm, or defend a legal claim. If the business is ever sold, your information may transfer with it, and this policy continues to apply until you are told otherwise.
8. Email we send you
We send only transactional email: confirming a sign-up, confirming a subscription, confirming a cancellation, telling you a payment failed, confirming a refund, replying to your support message, and warning you of something important about your account's security.
These are discreet by design. Subject lines and message bodies are written so that someone glancing at your inbox learns nothing about what this site is, and we never send content or explicit imagery by email.
We do not send marketing email and there is no mailing list. You cannot unsubscribe from transactional messages while you hold an account, because they are how we tell you about your own money.
9. How long we keep things
- Account — while your account exists, then deleted within 30 days of closure.
- Subscriptions and transactions — 7 years, for tax and accounting. These survive account deletion, in a form no longer attached to a live account. We are required to keep them and we would rather say so plainly than delete them quietly and be unable to answer a tax question.
- Billing consent records — 3 years, or one year after the membership ends, whichever is longer. This is a statutory minimum under California's automatic-renewal law.
- Age-assurance outcomes — until expiry plus 30 days, then deleted. Deleted immediately on account closure.
- Likes — while your account exists, and deleted with it. You can remove a like at any time by unliking the post.
- Support requests and content reports — 2 years.
- DMCA notices and counter-notices — 3 years.
- Rate-limit counters — minutes to hours. They expire themselves.
- Server logs — per our hosting providers' own short retention. We do not aggregate or analyse them.
10. Your rights
We honour the following for every member, regardless of which state you live in and regardless of whether a statute happens to apply to a business of our size:
- Know and access — ask what we hold about you and get a copy.
- Correct — fix anything inaccurate. Your display name you can change yourself.
- Delete — have your account, engagement, and age-verification records erased. Transaction records are kept for the tax period described above; we will tell you exactly what was retained and why.
- Take your data elsewhere — receive it in a portable format.
- Opt out of sale, sharing, or targeted advertising — already true for everyone. We do none of these.
- Limit the use of sensitive personal information — we use it only to provide the service you asked for, never to infer anything about you.
- No retaliation. Exercising any of these will never affect your price, your access, or how we treat you.
To exercise any of them, email support@briellefans.com from your account address. We reply within 10 business days and complete the request within 45 days. We may need to confirm it is really you first — for a request to delete an account like this one, verifying the requester is protection for you, not an obstacle.
Authorised agents. You may use an agent to make a request on your behalf. We will ask for written permission signed by you, and we may still ask you to confirm the request directly — for an account of this kind, letting a stranger extract or delete your data on your say-so is the risk, not the safeguard.
If we say no, you can appeal. Reply to our decision and a different person will review it. We answer an appeal within 45 days and explain our reasoning in writing. If we still decline, we will tell you how to complain to your state Attorney General, and you may do so whether or not you appeal to us first.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising — as those terms are defined by the California Consumer Privacy Act and the comparable statutes in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and every other state with a consumer privacy law. We have not done so in the preceding twelve months, and there is no mechanism in this site by which it could happen: there are no advertising trackers, no data brokers, no affiliate pixels, and no third party receives member data except the operational providers named in section 7, each of which is contractually limited to processing it on our instructions.
No automated decision-making. Nothing here profiles you, scores you, or makes a decision about you by algorithm. Access is decided by one fact — whether your membership is paid and current — and any decision to suspend or end an account is made by a person.
11. Children
This site is for adults. It is not directed to anyone under 18 and we do not knowingly collect information from anyone under 18.
If we learn that an account belongs to a minor we close it immediately, delete the data, and refund the unused period. If you believe a minor has created an account here, or is depicted in any content here, tell us at once at /report — that report is treated as urgent and goes to the front of the queue.
12. Security
Every access decision is made on the server. The database enforces row-level security so that one member cannot read another's subscription, billing records, or verification status even if the interface were bypassed — and that is checked by an automated suite that runs against a real database.
- The site is served over HTTPS only.
- Content files are stored privately and delivered only through links that expire in minutes. There is no permanent public URL for any protected media.
- The creator account requires a second authentication factor in addition to a password.
- Card data never reaches our systems at all, so it cannot be breached here.
- Media published by Brielle is stripped of embedded metadata, such as GPS coordinates and device identifiers, before it is stored. Members cannot upload anything.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities as required by law, without unreasonable delay, and tell you what happened and what to do.
13. Changes to this policy
If we change this policy we will update the version and date at the top of this page. For a change that materially affects how we handle your information, we will email you at least 30 days before it takes effect. The version in force when you subscribed is recorded with your billing consent.
14. Contact
Data controller: Brielle Fans,
For any privacy question, request, or complaint — including anything in section 10 — email support@briellefans.com. A real person reads it. There is no privacy request too small to send to Brielle's support address.
Questions about this page? Get in touch.