Privacy policy

What we collect, and what we don't

Last updated 6 August 2026

NEXFAN is software you install on your own server. That shapes this entire document: for the overwhelming majority of what happens inside your business, we are not a party to it and could not be if we wanted to be.

The short version.

  • This website sets no cookies and runs no analytics, no advertising pixels and no third-party scripts. The font is served from this server, not a CDN.
  • Browsing costs you nothing but a line in a web server log. We only learn who you are if you buy or get in touch.
  • When you buy, we hold your name, email, and the record of your purchase — because we have to issue a licence key and keep a tax record.
  • Card details never touch this site or our servers. Stripe handles payment on its own domain.
  • We never see your members, your messages, your media or your earnings. They live in your database, on your server.

01Who is responsible for your data

The data controller for the information described here is:

,

Address:

Email:

Referred to below as "we", "us" and "our". If you are in the UK or the European Economic Area, this policy is written to meet the UK GDPR and the EU General Data Protection Regulation. If you are elsewhere, the rights described in section 09 may differ, but what we collect and why does not.

02Visiting this website

You can read every page of this site without telling us anything. Our web server keeps standard access logs, as essentially every web server does: your IP address, the page requested, the time, the response code, and the browser's user-agent string. These are used to keep the site running, to diagnose faults and to detect abuse such as automated scraping or denial-of-service attempts. They are not used to build a profile of you, and they are not combined with anything else.

03Cookies and tracking

This website sets no cookies at all. There is no analytics package, no advertising or conversion pixel, no session storage and no third-party script of any kind. The typeface is self-hosted, so even the font does not tell another company that you were here. That is why you were not shown a cookie banner: there is nothing to consent to.

Two exceptions are worth naming plainly, because both leave this site. If you start a purchase you are sent to Stripe, which sets its own cookies under its own policy — that is Stripe's page, not ours. And the contact buttons open Telegram, WhatsApp or your email client, each of which is its own service with its own terms.

04Buying a licence

Before you are sent to payment, we ask for a small amount of information and store it against your order:

WhatWhy we need it
Your nameTo identify the licence holder and to issue an invoice or receipt.
Your email addressTo deliver the licence key, and to reach you about your purchase. We ask for it twice because a typo here means the key lands somewhere you cannot read it.
Your domain (optional)Only so your install command can be written out ready to paste. Leave it blank and nothing is lost.
Your acceptance of the terms, and which version you acceptedRecorded at the moment of purchase so that both of us can tell, later, exactly what was agreed. This is a legal record and cannot be deleted on request while the purchase stands.
Your licence key and its statusTo let your installation verify that it is licensed, and to deliver updates for as long as they are included.

We do not ask for a postal address, a phone number, a date of birth or anything about your business. If a field is not in the table above, we do not have it.

05Payment data

Payment is handled by Stripe on Stripe's own hosted checkout page. Your card number, expiry date and security code are entered on Stripe's domain and are never sent to this website or to our servers — we could not store them if we wanted to, because we never receive them.

What comes back to us is the outcome: that a payment succeeded, which tier it was for, an amount, a currency, and Stripe's own reference for the transaction. Stripe acts as an independent controller for the payment data it collects, under its own privacy policy.

06Getting in touch

If you message us on Telegram or WhatsApp, or send an email, we hold that conversation and whatever you chose to put in it. Those messages sit inside the service you used — we do not copy them into a CRM or a mailing list. If you send feedback or a feature request through this site or by message, we keep the message and, if you gave one, the email address to reply to.

We do not send marketing email. Buying a licence does not subscribe you to anything. The only unprompted email you should ever get from us is about your own purchase or a security matter affecting your installation.

07What your installation sends us

Once NEXFAN is running on your server, two features contact us. We would rather state this here than let you find it in a firewall log. This mirrors section 16 of the terms of sale.

7.1 Automatic error reports

When a server error occurs on your installation, a scrubbed report is sent to us so we can see what is breaking across installs. Each report contains:

Before sending, the message and stack trace are scrubbed of email addresses, IP addresses, tokens, database identifiers, file paths and query strings. Your members are not identifiable in these reports. Our server additionally records the IP address the report came from, which is used for rate limiting.

You can switch this off entirely by setting ERROR_REPORTING_ENABLED=false in your installation's environment configuration. It is on by default in production. Turning it off has no effect on your licence or on any other feature.

7.2 Update checks

When checking for available updates, your installation asks our server for the current version number. That tells us an install checked in, and from which IP address. It carries nothing about your content, your members or your business.

08Why we are allowed to hold it

Under the UK and EU GDPR, every use of personal data needs a lawful basis. Ours are:

WhatLawful basis
Name, email, order and licence keyPerformance of a contract — we cannot sell you a licence and deliver a key without them.
Invoice and payment recordsLegal obligation — tax and accounting law requires us to keep them.
Record of terms acceptanceLegal obligation and legitimate interests — establishing what was agreed, for both sides.
Server logs, error reports, update checks, rate limitingLegitimate interests — keeping the software and the service working and secure. Balanced against your privacy by scrubbing the reports and by letting you switch error reporting off.
Messages you send usLegitimate interests — answering you.

09Your rights

If you are in the UK or the EEA you have the right to:

Email the address in section 01 and we will answer within one month. There is no charge. We may ask you to confirm the email address on the order before we send data to it — not to obstruct you, but because handing someone else's purchase history to whoever asks would be the greater failure.

10Who else processes it

We keep the list of companies touching your data as short as the job allows:

WhoWhat they do
StripeTakes the payment, on its own hosted page. Independent controller for card data.
DigitalOceanHosts the licence server, which stores the order record and issues keys.
[name your email delivery provider]Delivers the licence key email.

We do not sell your data, we do not share it for anyone else's marketing, and we do not pass it to data brokers. The only other circumstance in which we would disclose it is a valid legal demand — a court order or equivalent — and we will tell you if that happens unless we are legally prevented from doing so.

11Transfers outside the UK and EEA

Stripe is headquartered in the United States and may process payment data there. Where data leaves the UK or EEA it is protected by the safeguards those providers have in place — typically the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses. You can ask us which safeguard applies to a given provider.

12How long we keep it

WhatKept for
Invoices, payment records, terms acceptanceAs long as tax and accounting law in requires — commonly six years from the end of the relevant financial year.
Licence key and order recordFor the life of the licence. A licence does not expire, so this is kept until you ask us to close the account and no legal retention period applies.
Web server access logsShort-term, for security and diagnostics — typically no more than 90 days.
Error reportsUntil the fault is resolved and the release containing the fix has shipped; typically no more than 12 months.
Support messagesAs long as needed to answer you and to understand the history of your installation, then deleted on request.

13Security

Data in transit is encrypted with HTTPS across this site, the licence server and every request your installation makes to us. Access to the licence server is restricted to the operator of the business named in section 01. Licence keys are stored in a form that lets us verify them without the error-reporting pipeline ever handling the key itself.

No system is perfectly secure, and anyone claiming otherwise is selling something. If a breach occurs that is likely to affect your rights, we will notify the relevant supervisory authority within 72 hours and tell you directly without undue delay.

14Your own members' data

This is the part most people are really asking about. Your fans, subscribers, messages, photos, videos, payouts and analytics live in your database on your server. We have no access to your installation, no login to it, and no ability to read any of it. Nothing in NEXFAN sends your members' personal data to us.

The consequence is that you are the data controller for everyone who uses your site. Publishing your own privacy notice, answering your members' data requests, keeping their data secure and meeting the law where you and your creators live are your responsibilities, not ours. NEXFAN ships tooling to help — consent pages, data export, moderation — but tooling is not compliance.

15Children

This site sells business software and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a minor has given us personal data, email us and it will be deleted.

16Automated decisions

We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. Licence validation is an automated check of whether a key is valid — it makes no judgement about you.

17Changes to this policy

If this policy changes, the date at the top changes with it. Material changes affecting people who have already bought will be sent to the email address on the order rather than quietly published. Older versions are available on request.

18Complaints and contact

For anything in this policy — a request, a correction, or a complaint — email . Please raise it with us first; most of these are misunderstandings that a reply can settle.

You also have the right to complain to a data protection supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk). In the EEA it is the authority in the country where you live or work. Complaining to us does not remove that right.

End of Privacy Policy

Back to pricing Terms of sale