Privacy Policy
Last updated: September 11, 2026
1. Who we are
Velvetly (“we”, “us”, “our”) is an AI-powered creator management platform for adult content creators. Our service is available at velvetly.io. This platform is intended exclusively for users who are 18 years of age or older.
2. What data we collect
- Account data: name, email address, hashed password (via AWS Cognito).
- Profile data: bio, niche, target audience, content pillars, and profile URL that you voluntarily provide.
- Voice profile data: sample messages you paste, plus messages you previously sent on your own OnlyFans/Fansly account, used only to train your personal writing style for draft generation.
- Fan data synced from your creator account: when the Velvetly extension is installed, your fan list (usernames, display names, avatars, subscription dates) and aggregate earnings totals are synced from your own OnlyFans/Fansly account to your Velvetly dashboard. No other creator sees this data.
- Fan conversation content: a short recent-history window of your chats (your messages and the fan’s) is kept inside your Velvetly account so the AI can draft replies that fit the conversation and so coaching suggestions have context. Older messages drop out of that window over time. Message content is not sold, shared, or used to train any AI beyond your personal voice profile.
- Photos you upload for Retouch: the original you choose, its retouched result, and a per-run record (timing, outcome, which of the two fixed editing instructions ran, image size). Camera metadata, including location data, is removed before the photo is stored. Section 7 describes this in full.
- Vault preview copies: when the extension syncs your vault, the preview images your platform already serves for your items are copied into a private Velvetly bucket so the AI can see what an item shows and describe it. Full-size originals are copied only if you have given us written permission for a specific comparison; that is off for everyone by default, capped at 20 photos, and those copies expire after 90 days.
- Usage data: draft history, content calendar entries, and fan-tier classifications — all isolated per creator account.
- Technical data: IP address, browser type, and session cookies for authentication.
3. How we use your data
- To provide and improve the Velvetly service.
- To generate AI-powered draft messages in your writing style.
- To retouch a photo you upload, on your request, one photo at a time.
- To describe your vault items (a name, tags, a suggested price) from their preview images.
- To authenticate your account and protect against fraud.
- To send transactional emails (verification codes, account notices).
We do not sell your data to third parties. We do not use your data to train AI models beyond your own account.
4. Data isolation
All creator data — including fan data, messages, and voice profiles — is strictly isolated per creator account. No data is shared between creators on the platform.
5. Third-party services
- AWS (Amazon Web Services): hosting, database, authentication, and email.
- xAI (Grok): the AI model provider for draft generation, voice analysis and vault descriptions. We route to xAI only while its zero-data-retention setting is verified on its responses; under that setting xAI does not store the content or use it for training. If that check fails, requests go to Anthropic instead.
- Anthropic (Claude): the fallback AI model provider for the same tasks. Content sent to the Claude API is not used for model training per Anthropic's API terms.
- Replicate: the model host for Retouch. For each retouch it fetches your photo through a private link that expires after 15 minutes, runs the pinned model, and returns the result to us. We send the photo link and the editing instruction. The link and the file's storage metadata carry your internal account id; your name, email, fan data and profile never travel with the photo. What Replicate retains is governed by Replicate's own terms.
- Stripe: payment processing. We do not store payment card details.
6. Chrome extension
The Velvetly Chrome extension requests permissions on onlyfans.com, fansly.com, and velvetly.io to operate on your behalf, against your own creator account. We are transparent about what that involves:
On click — when you press the Velvetly reply button
- The current fan’s chat message and a short snippet of conversation history are read from the page and sent over HTTPS to velvetly.io, which forwards them to Anthropic’s Claude API to generate draft replies in your voice.
- The conversation snippet is kept inside your own Velvetly account so the AI has context for the next draft and so coaching suggestions stay relevant; older messages roll out of that window over time. Anthropic does not retain or train on the content per their API terms.
In the background — while you’re signed in
- Your fan list (usernames, display names, avatars, subscription dates), aggregate earnings totals, and post dates are synced from your own OnlyFans/Fansly account to your Velvetly dashboard, at most a few times per hour.
- Your own previously-sent messages are sampled from your OnlyFans/Fansly account to build and refresh your personal voice profile for draft generation.
- When your vault syncs, the preview images the platform already serves for your items are copied into a private, encrypted Velvetly bucket (kept for up to 365 days) so the AI can describe them. Full-size originals are copied only with your written permission for a specific comparison (off by default, at most 20 photos), and those copies expire after 90 days.
- The extension reads your existing OnlyFans/Fansly session cookies via the browser’s
chrome.cookiesAPI to authenticate these requests against your own account. Those cookies stay on your device and are never transmitted to Velvetly or any third party.
What the extension does not do
- It does not inject ads, track your browsing activity on other sites, or read pages outside of OnlyFans, Fansly, and velvetly.io.
- It does not share data with any party other than those listed in section 5.
- It does not contain remote code. All logic and behavior-determining configuration is bundled inside the extension package.
7. Retouch (photo processing)
Retouch edits a photo you upload. This is what happens to that photo, step by step:
- On upload the file lands in a holding area of the same private bucket, is normalised at once, and all camera metadata is removed, including GPS location, the device model and the capture time. The raw copy is deleted in that same step; a lifecycle rule clears anything left in the holding area after one day, as a backstop.
- Storage is a private Velvetly bucket that blocks all public access and encrypts every object at rest (AES-256). Links to your photos are short-lived: an upload link is valid for 10 minutes, a viewing link for 15 minutes.
- Processing happens at Replicate (section 5), which receives the photo through such a 15-minute link together with one of two fixed editing instructions. There is no free-text prompt, so nothing you type travels with the photo.
- Retention: your originals and results are kept until you delete them in the Retouch studio. Nothing deletes them automatically. Deleting your account removes them together with the rest of your data.
- Who can see them: you, and the primary Velvetly administrator, who can open your before-and-after images for support and quality review. No other creator, and nobody else at Velvetly; the model host sees the photo only as described above.
- What we record per run: timing, outcome, which instruction ran and the image size, so we can watch quality and cost. Not the image content.
The result is yours to download and post where you choose; Velvetly never publishes anything on your behalf.
8. Data retention
We retain your account data for as long as your account is active. Specific retention periods, each cut short by account deletion: Retouch photos and results, until you delete them; vault preview copies, up to 365 days; full-size vault originals (only with your written permission), up to 90 days.
Deleting your account (Settings, or by email) removes your account data, fan data, voice profile, drafts, Retouch photos and results, and every vault copy, except the invoicing records the law requires us to keep for seven years (see the Terms). You may also request deletion by emailing privacy@velvetly.io.
9. Your rights (GDPR)
If you are in the European Economic Area, you have the right to access, correct, or delete your personal data, and to object to or restrict processing. Contact us at privacy@velvetly.io.
10. Cookies
On velvetly.io we set a single authentication cookie (velvetly-access-token) to keep you logged in. We do not use advertising or tracking cookies on our site.
The Velvetly Chrome extension additionally reads your existing OnlyFans and Fansly session cookies via the browser’s chrome.cookies API. These cookies are set by OnlyFans/Fansly themselves when you log in to their sites; the extension uses them locally to authenticate API calls against your own creator account. They are never transmitted to Velvetly or any third party.
11. Contact
Questions about this policy? Email us at privacy@velvetly.io.