Privacy Policy
Last updated: 2026-06-27
This Privacy Policy explains how bemyfriends, Inc., a corporation organized under the laws of the United States ("bemyfriends," "we," "us"), collects, uses, and shares information when you use Fansim at fansim.ai (the "Service"). By using the Service, you agree to this Policy. The Service is operated from the United States.
1. Information We Collect
We collect the following categories of information:
- Account information — name, email address, and a salted hash of your password (we never store your plain-text password).
- Workspace content — fandom descriptions, audience segments, channels, knowledge-base documents and files you upload, images, prompts, and other content you submit to operate the Service ("Customer Content").
- Billing information — your plan, token balance, and transaction history. Payments are processed by Stripe; we receive limited billing details (such as last-4 of card, transaction amounts) but never store full card numbers.
- Usage and device data — log data, IP address, browser/user-agent, pages and features used, and token consumption, used for security, rate limiting, metering, and product improvement.
- Communications — emails you send us, support requests, and your marketing preferences.
- Cookies — we use first-party, primarily httpOnly cookies for sign-in sessions, security (2FA device trust, access gate), and workspace selection. We do not use third-party advertising cookies.
2. How We Use Information
- Provide, operate, secure, and improve the Service, including generating AI Outputs you request.
- Process subscriptions and token purchases, prevent fraud, and maintain transaction records.
- Send transactional email (account verification, sign-in codes, password reset, billing and service notices) — these are necessary to the Service and cannot be opted out of while you hold an account.
- Send product updates and marketing email only in accordance with your preferences — every marketing email contains a one-click unsubscribe link, honored immediately (CAN-SPAM).
- Monitor for abuse, enforce our Terms, and comply with legal obligations.
3. AI Processing & Service Providers
To fulfill your requests, relevant Customer Content is processed by third-party AI model providers — currently Anthropic (Claude), Google (Gemini), OpenAI (GPT), and MiniMax — and, when web research is enabled, the Exa search API. We send only what is needed to perform the requested analysis. We do not permit these providers to use your content to train their generally available models, where such controls are offered.
Other service providers (processors) include: Stripe (payments), Resend (email delivery), Vercel (hosting/CDN), and Supabase on AWS (database and file storage). Each provider processes data on our instructions under their respective data-protection terms.
4. How We Share Information
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are defined in the California Consumer Privacy Act as amended by the CPRA). We disclose information only: (a) to the service providers above; (b) within your workspace, to its members; (c) to comply with law, legal process, or enforceable government requests; (d) to protect the rights, safety, and security of the Service, our users, or the public; or (e) in connection with a merger, acquisition, financing, or sale of assets, in which case this Policy will continue to apply to previously collected data.
5. Data Retention
We retain personal information for as long as your account is active and as needed to provide the Service. When you delete content or your account, associated personal data is deleted or de-identified within a commercially reasonable period, except where retention is required for legal, billing/tax, security, or dispute-resolution purposes. Transaction records are retained as required by law.
6. Security
We use commercially reasonable safeguards: encryption in transit (TLS) and at rest, salted password hashing (bcrypt), hash-only storage of security tokens, role-based workspace access control, row-level security on the database, rate limiting, two-factor authentication on new devices, and restricted access to production systems. No method of transmission or storage is 100% secure; we cannot guarantee absolute security. If we learn of a breach affecting your personal information, we will notify you and applicable regulators as required by law.
7. Your Rights & Choices
Depending on your state or country of residence, you may have rights to access, correct, delete, or receive a copy of your personal information, and to opt out of certain processing. California residents have rights under the CCPA/CPRA, including the rights to know, delete, correct, and non-discrimination for exercising rights. As stated above, we do not sell or share personal information as defined by the CPRA.
You can exercise these rights by contacting us via the contact page or managing your account settings directly. We will verify your request (typically via your account email) and respond within the time required by applicable law. Authorized agents may submit requests with proof of authorization.
Marketing email: opt out anytime via the unsubscribe link in any marketing email or your account settings. Transactional/security email continues while your account exists.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (COPPA). If you believe a child has provided us personal information, contact us and we will delete it.
9. International Users & Data Transfers
We are based in the United States and process data on servers located in the United States and other jurisdictions where our providers operate. If you use the Service from outside the U.S., you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those of your jurisdiction. For users in jurisdictions with transfer requirements, we rely on appropriate safeguards offered by our providers, including standard contractual clauses where applicable.
10. Do Not Track & Analytics
We do not operate third-party behavioral-advertising trackers. Product analytics, where used, are configured for first-party, aggregate product improvement.
11. Synthetic Data Notice
Fansim's "fan agents" and related Outputs are synthetic, statistically generated personas. They are not real people, are not derived from identified individuals' personal records, and are not intended to identify or profile any real person. Customer Content you upload about real audiences should be aggregated or anonymized; you are responsible for ensuring your uploads comply with applicable privacy law.
12. YouTube API Services
Some Fansim features use YouTube API Services. By using those features, you also agree to be bound by the YouTube Terms of Service. Data obtained through YouTube API Services is additionally handled in accordance with the Google Privacy Policy (linked below).
What we access: Fansim accesses only PUBLIC YouTube data through the YouTube Data API — public channel and video metadata and statistics, and publicly visible comments. We use a server-side API key and do NOT use YouTube/Google account authorization (OAuth). We never access your private YouTube account, watch history, subscriptions, or any non-public data, and we do not collect personal information through YouTube API Services.
How we use it: this public data is used only to produce aggregated fandom analytics and insights about the relevant channel within the Service, with YouTube shown as the source.
Storage and deletion: YouTube API data we cache is kept only as long as needed to provide these analytics and is automatically refreshed or deleted within 30 days, consistent with the YouTube API Services Developer Policies. You may request deletion of stored YouTube-derived data for a specific channel at any time through our contact page, and we will delete it promptly.
Managing access: because we do not use YouTube/Google OAuth, no account permissions are granted to Fansim and there is nothing to revoke on your Google account. You can review third-party access to your Google account, and Google’s data practices, using the links below.
13. Changes & Contact
We may update this Policy from time to time. Material changes will be announced via the Service or email before they take effect; the current version is always at fansim.ai/privacy.
Questions or privacy requests: contact bemyfriends, Inc. via the contact page.