Legal

Privacy Policy

Last updated: February 28, 2026 · GDPR Compliant

1. Who We Are

FanShield provides automated DMCA takedown services for content creators. We comply with GDPR, CCPA, and all applicable data protection laws.

2. Data We Collect

Account data: name, email, model name, platform usernames, subscription plan. Reference photos: up to 10 photos, encrypted, used exclusively for AI leak detection, never shared. Whitelist: your authorized domains. Usage data: IP address, browser, pages visited (anonymized). Payment: processed by Stripe - we never store card numbers.

3. How We Use Your Data

Service delivery (scanning, DMCA filing, reporting), facial recognition for leak detection (consent-based), communications and notifications, service improvement, and legal compliance.

4. Legal Basis (GDPR)

Contract performance, explicit consent for facial recognition, legitimate interest for security, legal obligation for DMCA compliance.

5. Security Measures

256-bit SSL/TLS encryption in transit, AES-256 encryption at rest, regular security audits, role-based access controls, encrypted backups.

6. Data Retention

Account data: active period + 30 days. Reference photos: deleted within 7 days of account closure or on request. DMCA records: 2 years. Payment records: 7 years (tax).

7. Your Rights

You have the right to: access, rectification, erasure ("right to be forgotten"), data portability, restriction, objection, and withdrawal of consent. Contact: privacy@fanshield.com. Response within 30 days.

8. Data Sharing

We never sell personal data. Shared only with: encrypted hosting providers, Stripe for payments, anonymized analytics. Never shared: photos, scan results, personal content.

9. Cookies

Essential cookies only by default. Analytics with consent. Manage in browser settings.

10. International Transfers

EU/US servers. Standard Contractual Clauses for transfers outside EU/EEA.

11. Children's Privacy

18+ only. Any data from minors discovered will be immediately deleted.

12. Breach Notification

Within 72 hours per GDPR Article 33.

13. Contact DPO

privacy@fanshield.com. You may also lodge a complaint with your local supervisory authority.