Privacy policy

What we collect, and what we don't

Last updated 8 September 2026

NEXFAN is software you install on your own server. That shapes this entire document: for the overwhelming majority of what happens inside your business, we are not a party to it and could not be if we wanted to be.

The short version.

  • The sales page does not load advertising or analytics tags. Fonts are self-hosted. Starting payment loads Stripe's payment services, which may use cookies and other browser storage.
  • Browsing costs you nothing but a line in a web server log. We only learn who you are if you buy or get in touch.
  • When you buy, we hold your name, email, and the record of your purchase — because we have to issue a licence key and keep a tax record.
  • Card details are entered into Stripe-controlled payment fields, either embedded on this site or on Stripe's hosted checkout. Our application does not receive your full card number or security code.
  • We never see your members, your messages, your media or your earnings. They live in your database, on your server.

01Who is responsible for your data

The data controller for the information described here is:

NEXFAN

Email:

Referred to below as "we", "us" and "our". If you are in the UK or the European Economic Area, this policy is written to meet the UK GDPR and the EU General Data Protection Regulation. If you are elsewhere, the rights described in section 09 may differ, but what we collect and why does not.

02Visiting this website

You can read every page of this site without telling us anything. Our web server keeps standard access logs, as essentially every web server does: your IP address, the page requested, the time, the response code, and the browser's user-agent string. These are used to keep the site running, to diagnose faults and to detect abuse such as automated scraping or denial-of-service attempts. They are not used to build a profile of you, and they are not combined with anything else.

03Cookies and tracking

The sales page does not load advertising or analytics tags. The typeface is self-hosted. When you continue to payment, Stripe's JavaScript and secure payment fields may load on this site, or you may be redirected to Stripe's hosted checkout. Stripe may use cookies, browser storage and technical information to provide payment and fraud-prevention services.

Stripe processes payment information under its own privacy policy, including when its payment fields are embedded here. The contact buttons open Telegram, Instagram or your email client, each of which is its own service with its own terms.

04Buying a licence

Before you are sent to payment, we ask for a small amount of information and store it against your order:

WhatWhy we need it
Your nameTo identify the licence holder and to issue an invoice or receipt.
Your email addressTo deliver the licence key, and to reach you about your purchase. We ask for it twice because a typo here means the key lands somewhere you cannot read it.
Domain, if supplied with an earlier orderEarlier checkout forms allowed an optional domain to prepare an install command. The current form does not ask for it; you enter your domain during installation.
Your acceptance of the terms, and which version you acceptedRecorded at the moment of purchase so that both of us can tell, later, exactly what was agreed. This is a legal record and cannot be deleted on request while the purchase stands.
Your licence key and its statusTo let your installation verify that it is licensed, and to deliver updates for as long as they are included.

We do not ask for a postal address, a phone number, a date of birth or anything about your business. If a field is not in the table above, we do not have it.

05Payment data

Payment is handled by Stripe through Stripe-controlled fields embedded on this site or through Stripe's hosted checkout. Your full card number and security code are sent directly to Stripe, not to our application server. Our server creates the checkout session and receives payment status and purchase information.

What comes back to us is the outcome: that a payment succeeded, which tier it was for, an amount, a currency, and Stripe's own reference for the transaction. Stripe acts as an independent controller for the payment data it collects, under its own privacy policy.

06Getting in touch

If you message us on Telegram or WhatsApp, or send an email, we hold that conversation and whatever you chose to put in it. Those messages sit inside the service you used — we do not copy them into a CRM or a mailing list. If you send feedback or a feature request through this site or by message, we keep the message and, if you gave one, the email address to reply to.

We do not send marketing email. Buying a licence does not subscribe you to anything. The only unprompted email you should ever get from us is about your own purchase or a security matter affecting your installation.

07What your installation sends us

Once NEXFAN is running on your server, two features contact us. We would rather state this here than let you find it in a firewall log. This mirrors section 16 of the terms of sale.

7.1 Automatic error reports

When a server error occurs on your installation, a scrubbed report is sent to us so we can see what is breaking across installs. Each report contains:

Before sending, the message and stack trace are scrubbed of email addresses, IP addresses, tokens, database identifiers, file paths and query strings. Your members are not identifiable in these reports. Our server additionally records the IP address the report came from, which is used for rate limiting.

You can switch this off entirely by setting ERROR_REPORTING_ENABLED=false in your installation's environment configuration. It is on by default in production. Turning it off has no effect on your licence or on any other feature.

7.2 Update checks

When checking for available updates, your installation asks our server for the current version number. That tells us an install checked in, and from which IP address. It carries nothing about your content, your members or your business.

08Why we are allowed to hold it

Under the UK and EU GDPR, every use of personal data needs a lawful basis. Ours are:

WhatLawful basis
Name, email, order and licence keyPerformance of a contract — we cannot sell you a licence and deliver a key without them.
Invoice and payment recordsLegal obligation — tax and accounting law requires us to keep them.
Record of terms acceptanceLegal obligation and legitimate interests — establishing what was agreed, for both sides.
Server logs, error reports, update checks, rate limitingLegitimate interests — keeping the software and the service working and secure. Balanced against your privacy by scrubbing the reports and by letting you switch error reporting off.
Messages you send usLegitimate interests — answering you.

09Your rights

If you are in the UK or the EEA you have the right to:

Email the address in section 01 and we will answer within one month. There is no charge. We may ask you to confirm the email address on the order before we send data to it — not to obstruct you, but because handing someone else's purchase history to whoever asks would be the greater failure.

10Who else processes it

We keep the list of companies touching your data as short as the job allows:

WhoWhat they do
StripeProcesses payment through embedded payment fields or its hosted checkout. See Stripe's privacy policy for its processing of payment data.
DigitalOceanHosts the licence server, which stores the order record and issues keys.
[name your email delivery provider]Delivers the licence key email.

We do not sell your data, we do not share it for anyone else's marketing, and we do not pass it to data brokers. The only other circumstance in which we would disclose it is a valid legal demand — a court order or equivalent — and we will tell you if that happens unless we are legally prevented from doing so.

11Transfers outside the UK and EEA

Stripe is headquartered in the United States and may process payment data there. Where data leaves the UK or EEA it is protected by the safeguards those providers have in place — typically the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses. You can ask us which safeguard applies to a given provider.

12How long we keep it

WhatKept for
Invoices, payment records, terms acceptanceAs long as applicable tax and accounting law requires — commonly six years from the end of the relevant financial year.
Licence key and order recordFor the life of the licence. A licence does not expire, so this is kept until you ask us to close the account and no legal retention period applies.
Web server access logsShort-term, for security and diagnostics — typically no more than 90 days.
Error reportsUntil the fault is resolved and the release containing the fix has shipped; typically no more than 12 months.
Support messagesAs long as needed to answer you and to understand the history of your installation, then deleted on request.

13Security

Data in transit is encrypted with HTTPS across this site, the licence server and every request your installation makes to us. Access to the licence server is restricted to the operator of the business named in section 01. Licence keys are stored in a form that lets us verify them without the error-reporting pipeline ever handling the key itself.

No system is perfectly secure, and anyone claiming otherwise is selling something. If a breach occurs that is likely to affect your rights, we will notify the relevant supervisory authority within 72 hours and tell you directly without undue delay.

14Your own members' data

This is the part most people are really asking about. Your fans, subscribers, messages, photos, videos, payouts and analytics live in your database on your server. We have no access to your installation, no login to it, and no ability to read any of it. Nothing in NEXFAN sends your members' personal data to us.

The consequence is that you are the data controller for everyone who uses your site. Publishing your own privacy notice, answering your members' data requests, keeping their data secure and meeting the law where you and your creators live are your responsibilities, not ours. NEXFAN ships tooling to help — consent pages, data export, moderation — but tooling is not compliance.

15Children

This site sells business software and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a minor has given us personal data, email us and it will be deleted.

16Automated decisions

We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. Licence validation is an automated check of whether a key is valid — it makes no judgement about you.

17Changes to this policy

If this policy changes, the date at the top changes with it. Material changes affecting people who have already bought will be sent to the email address on the order rather than quietly published. Older versions are available on request.

18Complaints and contact

For anything in this policy — a request, a correction, or a complaint — email . Please raise it with us first; most of these are misunderstandings that a reply can settle.

You also have the right to complain to a data protection supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk). In the EEA it is the authority in the country where you live or work. Complaining to us does not remove that right.

End of Privacy Policy

Back to pricing Terms of sale