Privacy Policy — Charm•e
Last updated: 2026-06-10
Charm•e ("we", "the extension") is a Chrome extension that helps OnlyFans creators
generate AI-powered chat replies. This policy describes what data we collect, why,
and how it is handled.
1. Data we collect
-
Account data. When you sign in, we collect and store your email
address and a hashed password on our backend server. After login, an
authentication token (JWT) is stored locally in your browser via
chrome.storage.local so you remain signed in.
-
Persona data. Any personas you create (name, traits, lore, etc.)
are stored on our backend so the extension can use them to generate replies.
-
Chat content. When you ask the extension to generate a reply, it
reads the visible messages of the currently open OnlyFans chat thread and sends
them to our backend as context for the AI model. We do not read chats you do not
actively generate replies for, and we do not read any data from websites other
than
onlyfans.com.
-
Usage signals. The extension sends a heartbeat (every 30 seconds
while active) so your dashboard can show whether the extension is currently
running. The heartbeat contains only the extension version — no chat content,
no browsing activity.
2. What we do NOT collect
- We do not collect GPS or precise location.
- We do not track which websites you visit or your browsing history.
- We do not record clicks, scrolls, keystrokes, or any other passive user activity.
- We do not collect health information.
-
We do not collect payment card details inside the extension. Any payments are
handled by our web dashboard, not by the extension.
3. How data is used
-
Authentication data is used solely to sign you in and authorize
API requests.
-
Persona and chat data is used solely to generate AI replies that
you have explicitly requested. Chat content is sent to a third-party
large-language-model provider via our backend strictly for the purpose of
producing a reply for you.
- We do not sell user data to any third party.
-
We do not use data for advertising, profiling, creditworthiness,
lending, or any purpose unrelated to the extension's stated function.
4. Data retention and deletion
-
Authentication tokens stored in
chrome.storage.local are cleared
whenever you sign out.
-
To delete your account and all associated server-side data (personas, transaction
history, etc.), contact us at the email below. Account deletion is permanent.
5. Security
Data in transit is encrypted via HTTPS. Authentication tokens are signed JWTs with
a 30-day expiry. Passwords are hashed before storage on our backend.
6. Changes to this policy
If we materially change what data we collect or how we use it, we will update this
page and update the "Last updated" date above.
7. Contact
Questions, deletion requests, or concerns:
vladyslav.vydryhan@fintexinc.com