Privacy Policy

Last updated: October 1, 2026

1. Introduction

Anlora is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our platform at meetanlora.com. This policy is designed to align with the General Data Protection Regulation (GDPR) and applicable Czech and EU data protection laws.

2. Data Controller & Processor

The data controller for your account data (name, email, billing) is: Anlora (operations based in Prague, Czech Republic) Data Protection Contact: privacy@meetanlora.com When you use the Service to manage OnlyFans creator accounts on behalf of content creators, you (the agency/organization) act as the Data Controller for fan and subscriber data, and Anlora acts as the Data Processor. We process this data solely on your instructions and for the purpose of providing the Service. For data processing agreements (DPA), contact privacy@meetanlora.com.

3. Data We Collect

We collect the following categories of personal data: Account Information: Name, email address, and organization details provided during registration. (Legal basis: contract performance) OnlyFans Credentials: The email address and password of each creator account you connect, and the session tokens issued once it logs in. All are encrypted at rest. The password is kept for as long as the account stays connected, because OnlyFans sessions expire every few weeks and the stored password is what lets us reconnect without asking the creator to log in by hand each time. A password that OnlyFans rejects is never stored. (Legal basis: contract performance) Usage Data: Dashboard activity, API request logs, IP addresses, and browser information. (Legal basis: legitimate interest: service improvement and security) Financial Data: Invoices, the revenue figures they are calculated from, and the cryptocurrency transaction identifiers and wallet addresses used to settle them. We charge a share of revenue, invoiced in arrears and paid in cryptocurrency: we do not take card payments, so there is no card number to store and no card details are collected. (Legal basis: contract performance) Content Data: Messages, subscriber lists, analytics data, and other content accessed through the Service. Retained while your account is active and erased 30 days after you delete it. (Legal basis: contract performance)

4. How We Use Your Data

We process your data for the following purposes: - Providing the Service: Authenticating with OnlyFans, proxying API requests, powering AI messaging, and displaying analytics (Legal basis: contract performance, Art. 6(1)(b) GDPR) - Account management: Managing your subscription and support requests (Legal basis: contract performance, Art. 6(1)(b) GDPR) - Security: Detecting and preventing fraud and unauthorized access (Legal basis: legitimate interest, Art. 6(1)(f) GDPR) - Improvement: Analyzing usage patterns to improve the Service (Legal basis: legitimate interest, Art. 6(1)(f) GDPR) - Legal compliance: Retaining billing records as required by tax law (Legal basis: legal obligation, Art. 6(1)(c) GDPR) - Product email: Sending news about Anlora, ONLY if you ticked the box when creating your account (Legal basis: consent, Art. 6(1)(a) GDPR). The box is never pre-ticked, every such email carries an unsubscribe link, and withdrawing is as easy as giving it: we record the moment consent was given so we can show when and how. Service email is separate and not covered by this: invoices, payment confirmations, security notices and messages about your chatbots being paused are part of running your account, and are sent whether or not you opted in. We do not sell your personal data. We do not use your data for advertising, and we do not share your address with advertisers or data brokers.

5. Credential Storage & Encryption

Your OnlyFans credentials receive a high level of protection: - Password handling: Your OnlyFans password is encrypted at rest with a key held outside the database, and is decrypted only at the moment a login or a session renewal needs it. It is kept while the creator account is connected, because OnlyFans sessions expire and without it every expiry would need the creator to log in again by hand. Disconnecting the account stops it being used, and deleting your Anlora account erases it immediately, before anything else is deleted. You can also ask us to erase it at any time at privacy@meetanlora.com. - Day to day requests do not use it: once logged in, ordinary requests are made with an encrypted session token. The password is used only to obtain a new session. - Validation before storage: a password OnlyFans rejects is never written to your account record. - Encryption at rest: Session tokens and sensitive data are encrypted at rest. - Encryption in transit: All data transmission uses TLS 1.2 or higher. - Access control: Encrypted data is only decrypted at the moment of API request execution and is not intentionally logged. - Plaintext storage: We are designed not to store credentials in plaintext, and we employ measures intended to keep sensitive data out of our database, logs, and caches. - Key management: Encryption keys are stored separately from the database.

6. Data Sharing & Sub-Processors

We share data only with the following sub-processors: - OnlyFans (onlyfans.com): Session tokens transmitted to perform API requests on your behalf - Hetzner Online GmbH (Nuremberg, Germany, EU): Server hosting and infrastructure - Our AI conversation provider (servers in Germany, EU): receives fan messages, the creator profile and content descriptions in order to generate the replies the Service sends, and returns them to us. This is the core of the Service and it processes message content. The models it calls may be operated by providers outside the EU/EEA; where that is the case, transfers rely on Standard Contractual Clauses - Bright Data Ltd (Israel, subject to an EU adequacy decision): the static ISP proxy network that carries our connections to OnlyFans so each creator account keeps a stable IP address. It routes the encrypted connection and sees the destination and the timing, not message content or credentials - CapSolver: solves the anti bot challenge OnlyFans presents during login. It receives the challenge parameters and the address of the page, never a password, a session token or message content - Resend (US): delivery of our email, which is invoices, payment confirmations, security notices, messages about your chatbots being paused, and the product news you opted into. Receives your email address and the content of those messages; relies, where applicable, on Standard Contractual Clauses - Telegram (Telegram FZ LLC, UAE): receives our internal operational alerts, for example a failed login or an overdue invoice. These can name a team and a connected creator handle. No fan message content and no credentials are sent - Cloudflare, Inc. (EU/US): CDN, DDoS protection, and WAF: relies, where applicable, on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs) - Sentry (US): Application error monitoring: receives only technical error data (no personal content), relies, where applicable, on Standard Contractual Clauses (SCCs) - Google Ireland Ltd (EU) / Google LLC (US): Google Analytics, loaded only after you consent via the cookie banner: receives usage data (pages viewed, referral source, browser and device information); relies, where applicable, on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs) - Microsoft Ireland Operations Ltd (EU) / Microsoft Corporation (US): Microsoft Clarity, loaded on our public marketing pages only after you consent via the cookie banner: receives anonymized interaction data for session replays and heatmaps (typed text is masked by default; the logged-in dashboard is excluded); relies, where applicable, on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs) - Public blockchain explorers (TronGrid, mempool.space, Etherscan, Solana RPC): queried to confirm that an invoice has been paid. They receive a wallet address or a transaction identifier, never your name or email Where a sub-processor processes personal data on our behalf we put a data processing agreement in place, relying on the provider's standard DPA where it publishes one. We maintain an up-to-date list of sub-processors and will notify you of changes with 14 days' notice. The current list is the one in this section.

7. Data Retention

We retain your data for the following periods: - Account data: Retained while your account is active. When you delete your account we erase it 30 days later. The 30 days are deliberate: they make a mistaken or unauthorised deletion recoverable, and logging in during that window lets you restore everything except the erased OnlyFans credentials - OnlyFans passwords: Encrypted and kept while the creator account is connected, so an expired session can be renewed. Erased immediately when you delete your account, without waiting for the 30 days, and on request at any time. The separate copy held on a single login attempt record is erased as soon as that attempt finishes, pass or fail - OnlyFans session tokens: Kept with the connected account, invalidated when it is disconnected, and erased immediately when you delete your account - Content data (messages, subscriber lists, fan history, vault): Retained while your account is active, and erased 30 days after you delete it - API request logs: Retained for 30 days, then automatically purged - Analytics data: Retained for 12 months in aggregate form - Billing records: Retained for 7 years as required by Czech tax law - Backups: Our encrypted database backups let us recover from a disaster to any point in the previous 30 days, and each backup file is deleted 32 days after it is written. Data erased from the live system can therefore remain in a backup for up to 32 more days before it ages out. We do not restore it into the live system except to recover from a disaster, and if we ever did, we would erase it again You may request earlier deletion at any time (see Your Rights below).

8. Your Rights Under GDPR

As a data subject, you have the following rights: - Right of Access: Request a copy of all personal data we hold about you - Right to Rectification: Request correction of inaccurate personal data - Right to Erasure: Request deletion of your personal data - Right to Restriction: Request that we limit processing of your data - Right to Data Portability: Request your data in a structured, machine-readable format - Right to Object: Object to processing based on legitimate interest - Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time To exercise any of these rights, email privacy@meetanlora.com. We will respond within one month as required by GDPR Art. 12(3).

9. Security Measures

We implement the following technical and organizational measures: - Strong encryption for sensitive credentials - TLS 1.2+ for all data in transit - Field-level encryption at rest for credentials, session tokens and other sensitive data - Role-based access control with team-level isolation - Automated log rotation and data purging - Containerized infrastructure with network isolation - Cloudflare WAF and DDoS protection - Host firewall restricting access to Cloudflare IPs only - Automated encrypted backups with separate encryption key Access by our own staff: a small number of Anlora personnel can reach customer and fan data where it is needed to operate, repair, or secure the Service, or to answer a support request you raise. Access is limited to the people who need it for that purpose, they are bound by confidentiality obligations, and the data is not used for anything else. We work from logs and configuration wherever an issue can be resolved that way, rather than from a live creator account. As the controller for fan data, you may restrict this in your data processing agreement: contact privacy@meetanlora.com.

10. Cookies

We use two categories of cookies. Essential cookies (always active, no consent required): the session cookie (anlora_session) that keeps you signed in, a CSRF token that blocks cross-site request forgery, the consent cookie (anlora_consent) that stores your cookie choice for 180 days, Cloudflare's bot-detection cookie (__cf_bm), and, only if you arrived through a partner's referral link, the referral cookie (anlora_ref) that credits that partner for 30 days. None of these are used for advertising or cross-site tracking. Analytics cookies (optional, loaded only with your consent): Google Analytics (_ga, _ga_*) and, on our public marketing pages only, Microsoft Clarity (_clck, _clsk) for anonymised session replays and heatmaps. Text you type into forms is masked by default and Clarity never runs inside the logged-in dashboard. (Legal basis: consent, Art. 6(1)(a) GDPR.) If you decline, or simply ignore the banner, none of these cookies are set and no data is sent to Google or Microsoft. You can change or withdraw your choice at any time via "Cookie settings" in the page footer. Withdrawing consent removes the analytics cookies and stops all further analytics collection. We do not use advertising or cross-site tracking cookies. Our Cookie Policy at meetanlora.com/cookies lists every cookie individually, with what it does and when it expires.

11. Affiliate Partners & Referral Links

Partners. If you join our affiliate program we process: your name, email and password (stored hashed), what you told us about how you will promote Anlora, your legal name, country and USDT wallet (legal name and wallet encrypted at rest), a keyed hash of your IP address at signup and login, and the clicks on your referral link (time, a keyed hash of the visitor's IP address, and the referring website). We use it to run the program, pay you, keep tax and payout records, check sanctions and prevent fraud such as self-referral. Legal basis: contract (Art. 6(1)(b)), legal obligation for tax and accounting records (Art. 6(1)(c)), and legitimate interest in preventing fraud (Art. 6(1)(f)). Payout records are kept as long as accounting law requires; the IP hashes on link clicks are erased after 12 months. Agencies that arrive through a partner. When your agency signs up through a partner's link or code, that partner sees a masked form of your agency name (its first two letters), how far your setup has got, and the commission they earned from your agency (a share of what you pay us). They never see your creators, fans, chats or revenue details. Legal basis: our legitimate interest in running the referral program (Art. 6(1)(f)). You can object at privacy@meetanlora.com. The referral cookie (anlora_ref) is listed in our Cookie Policy.

12. International Data Transfers

Your data is processed and stored on servers located in Germany (Hetzner Online GmbH, Nuremberg) within the European Union. Some sub-processors listed above are outside the EU/EEA, or may transfer data outside it: Sentry, Cloudflare, Google, Microsoft and Resend in the United States, Telegram in the United Arab Emirates, Bright Data in Israel (which holds an EU adequacy decision), and the model providers our AI conversation provider calls. Where a transfer leaves the EU/EEA without an adequacy decision, it relies on Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

13. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from minors. If we discover that we have collected data from a person under 18, we will delete it immediately.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

15. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Czech Office for Personal Data Protection (UOOU) at www.uoou.cz, or the supervisory authority in your country of residence.

16. Contact

For privacy-related questions or to exercise your rights: Anlora (operations based in Prague, Czech Republic) Data Protection Contact: privacy@meetanlora.com General inquiries: hello@meetanlora.com