Privacy Policy

Last updated May 28, 2026

1. Who We Are

Camfanatics (https://camfanatics.com) is a creator-discovery directory that helps fans find and follow adult content creators across major platforms. The service is operated by Camfanatics — Custodian of Records. This Privacy Policy explains what personal data we collect, why we collect it, and how we protect it.

2. Information We Collect

We collect the following categories of data:

  • Account data — email address, hashed password, and account role (creator or fan) when you register.
  • Profile data — display name, bio, avatar, and platform links that you provide on your profile.
  • Content you post — creator posts, gallery items, and other material you voluntarily upload or publish.
  • OAuth connected-account data — when you connect a third-party platform via OAuth, we store the provider name and provider user ID. Access tokens and refresh tokens are stored encrypted in the connected_accounts table and are never shared with third parties.
  • Contact-form submissions — name, email address, optional subject, and message body. We also store a SHA-256 hash of your IP address and a truncated user-agent string in the contact_messages table for abuse-prevention purposes.
  • Usage data — page views and click events collected via Umami Analytics. Umami is cookieless and does not send personally identifiable information to our analytics server.

3. Cookies

We set only essential cookies: the Laravel session cookie and a CSRF token. These are required for the secure operation of the site and cannot be opted out of while using the service. We use Umami for analytics — it is cookieless and does not fingerprint you. We do not set advertising, tracking, or third-party cookies. No cookie-consent banner is required.

4. How We Use Your Information

  • Provide, personalise, and improve the Camfanatics service.
  • Process profile claims and identity verifications.
  • Send transactional email via Mailgun (account notifications, claim-status updates).
  • Respond to contact-form enquiries.
  • Detect, investigate, and prevent fraudulent or abusive activity.
  • Comply with applicable legal obligations.

5. Legal Bases (GDPR)

Where the GDPR applies, we rely on the following legal bases:

  • Contract — processing necessary to provide the service you signed up for (e.g. account management, transactional email).
  • Legitimate Interest — fraud prevention, security monitoring, and service improvement, balanced against your privacy rights.
  • Consent — where you have explicitly provided it, such as connecting a third-party OAuth account.

6. Sharing & Sub-Processors

We do not sell personal data. We share data only with the following sub-processors, each bound by a data-processing agreement:

  • Mailgun — transactional email delivery.
  • Wasabi / Cloudflare R2 — file and media storage.
  • Cloudflare — CDN, DDoS protection, and Turnstile bot-verification widget.
  • OpenRouter — AI content generation for Camdeep creator tools. Prompts and results are processed by OpenRouter; we do not include personally identifiable information in prompts.

7. Data Retention

  • Account data — retained for the lifetime of the account and for 90 days after a deletion request is fulfilled.
  • Contact submissions — retained for 12 months, then deleted.
  • Usage analytics — retained per Umami's own policy; no personally identifiable information is stored.

8. Your Rights

Depending on where you are located, you may have the following rights:

  • GDPR — right of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and the right to object.
  • CCPA — right to know what personal data we hold, right to delete, and the right to opt out of the sale of personal data (we do not sell personal data).

To exercise any of these rights, please email [email protected] or use our contact form. We will respond within 30 days.

9. Imported & Unclaimed Creator Profiles

We source publicly available profile data from adult platforms to build a creator-discovery directory. Imported profiles are clearly labeled "unclaimed" and do not imply any endorsement by or relationship with Camfanatics. Creators may remove their profile at any time by submitting an opt-out / removal request. Removal requests are processed promptly.

10. Children

Camfanatics is strictly an adults-only service for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has submitted data to us, please contact us immediately at [email protected] and we will delete the data without delay.

11. Security

We protect your data using industry-standard safeguards: TLS encryption in transit; encrypted storage for OAuth tokens; bcrypt-hashed passwords; and secrets managed exclusively via environment variables — never stored in source code.

12. International Transfers

Your data may be processed outside the country in which you reside by the sub-processors listed in Section 6. All transfers are covered by standard contractual clauses, adequacy decisions, or equivalent safeguards as required by applicable data-protection law.

13. Contact

For privacy-related questions or to exercise your rights, please use our contact form or email us at [email protected].