Security
Security
Found a vulnerability? Write to [email protected] with "Security" in the subject. Tell us what you found and how to reproduce it; please don't access other people's data or disrupt the service while testing. We'll acknowledge it promptly and keep you posted until it's fixed.
How we protect data
- All traffic is encrypted in transit (HTTPS).
- Connections to other services — Fanvue, Patreon, Stripe keys and others — are stored encrypted, and we ask only for the access each feature needs.
- Sign-in sessions are HTTP-only cookies; links that sign you in are single-use and expire in minutes.
- Webhooks from payment and membership services are verified by signature before we act on them.
- Only the people who run and support the service can reach creator data, and only to do that.
See also our privacy policy and terms.