Privacy policy.
How Creator Chat handles personal data. This policy corresponds to our Terms of Service.
Creator Chat Limited has its registered seat in Gibraltar and is not directly subject to European Union data-protection law. Nevertheless, we voluntarily align our handling of personal data with the principles of the EU General Data Protection Regulation (GDPR) and apply them as far as reasonably possible and as far as legally required, in order to offer our users and their contacts a high and consistent standard of protection.
Contents
1. Who we are & how to reach us
The controller responsible for the processing described here is Creator Chat Limited, with registered seat in Gibraltar, as identified in our Imprint. You can reach us regarding data protection at info@creator-chat.com.
2. Our two roles: controller and processor
Creator Chat plays two distinct roles, and this matters for your rights:
- As a controller — for the personal data of our users (account holders, agency admins and agents): your account, login, billing and usage data. We decide how this data is processed, as described in this policy.
- As a processor — for the personal data of your fans and contacts that flows through the connected Telegram and Fangate accounts (messages, usernames, contact and purchase data). Here you are the controller and we process this data on your behalf and on your instructions, under a Data Processing Agreement (DPA) in accordance with Art. 28 GDPR (see also Section 11 of our Terms).
3. What data we process
a) Account & registration data (controller)
- Name, work email address, agency name
- Password (stored only as a salted hash) and two-factor authentication settings
- Role and team membership (admin / agent), and the accounts assigned to you
b) Connected-account credentials (controller, on your instruction)
- For a connected Telegram account: the login session (stored encrypted) and, for user accounts, the phone number used to connect
- For a connected Fangate account: the API token (stored encrypted) and the associated Fangate login email
c) Usage, log & device data (controller)
- IP address, browser/device information, and timestamps
- Technical logs needed to operate, secure and debug the Service
d) Fan & contact data (processor — you are the controller)
- Telegram message content, attachments, usernames, user IDs, display names and avatars of the people who chat with your connected accounts
- Group/channel data where connected
- Sales and purchase data received from Fangate (e.g. transaction id, buyer email, product and amount) to attribute and display sales
e) AI-feature data
- Where you use AI-assisted reply suggestions, relevant conversation content is transmitted to our AI sub-processor to generate a suggestion. AI suggestions are not stored by us as training data.
4. Purposes & legal bases
- Providing the Service (account, connecting Telegram/Fangate, sending/receiving messages, sales tracking) — performance of a contract, Art. 6 (1)(b) GDPR.
- Processing fan/contact data on your behalf — on your instructions as our customer; you are responsible for the legal basis vis-à-vis your fans (Art. 28 GDPR; see the DPA).
- Security, abuse prevention, debugging, backups — our legitimate interest in a safe, reliable service, Art. 6 (1)(f) GDPR.
- Onboarding phone-number checks (e.g. blocking virtual/VoIP numbers to reduce account-ban risk) — legitimate interest, Art. 6 (1)(f) GDPR.
- Legal compliance (e.g. responding to lawful requests, statutory retention) — Art. 6 (1)(c) GDPR.
5. Recipients, sub-processors & international transfers
We use carefully selected service providers to operate the Service. Each acts under a data-processing agreement and only on our instructions.
Our infrastructure and hosting are located in the European Union. Some supporting services (for example transactional email delivery and AI-assisted reply suggestions) may process data in the United States. Where data is transferred to the United States, the transfer is based on an appropriate legal safeguard — such as an adequacy decision (e.g. the EU–US Data Privacy Framework, where the recipient is certified) and/or the European Commission's Standard Contractual Clauses (SCCs) — together with appropriate supplementary measures.
In addition, by connecting them you direct data to your own integrations, which act under their own terms and privacy policies:
- Telegram — the messaging platform your chats run on. Message data is processed by Telegram under Telegram's privacy policy.
- Fangate — the PPV platform whose vault, sales and webhook data we fetch on your behalf, under Fangate's privacy policy.
We do not sell your personal data and do not use it for third-party advertising.
6. Retention & deletion
- Account data: kept while your account is active and deleted within 30 days of account deletion, unless mandatory retention periods (e.g. tax or accounting obligations) require otherwise.
- Connected-account credentials: deleted promptly when you disconnect the account or delete your account.
- Fan/contact data: retained according to your instructions as controller and the DPA; removed when you delete the conversation, the connected account, or your account.
- Logs: kept for up to 30 days for security and debugging.
- Backups: overwritten on a rolling basis within 30 days.
7. Data security
We use technical and organisational measures appropriate to the risk, including TLS encryption in transit, encryption at rest for sensitive credentials (Telegram sessions, Fangate tokens), access controls and role-based permissions, EU-based hosting, and regular backups. No system is perfectly secure, but we work to protect your data against unauthorised access, loss and misuse.
8. Your rights
Under the GDPR you have the right to:
- Access your personal data (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure / "right to be forgotten" (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw any consent at any time, without affecting prior processing
To exercise these rights, contact info@creator-chat.com. If you are a fan/contact rather than a user, please direct your request to the creator/agency you interacted with (the controller of that data); we will support them in responding.
Where applicable data-protection law grants you the right to lodge a complaint with a competent supervisory authority, you may do so. We will assist you in identifying the appropriate point of contact upon request.
9. Cookies & the website
The Creator Chat application uses strictly necessary cookies only — for example to keep you signed in and to secure your session. These are required for the Service to function and do not require consent.
Our public website loads web fonts from Google Fonts, which transmits your IP address to Google when the page loads. We do not use third-party advertising or cross-site tracking cookies.
10. Children
The Service is intended exclusively for adults (18+). It is not directed at children, and we do not knowingly process the personal data of minors as users.
11. Changes to this policy
We may update this policy to reflect changes in the Service, our sub-processors, or the law. Material changes will be announced to active users by email. The "last updated" date below always reflects the current version.
Last updated: January 2026 · Version 1.0 · Data-protection contact: info@creator-chat.com