Skip to content
AdministrationAccount Safety and Compliance

Account Safety and Compliance

Your creator accounts are your business. This page covers how to operate Sufflera in a way that protects them, keeps your data secure, and keeps your agency on the right side of the platforms you work on.


Sufflera works alongside OnlyFans, Fansly and Fanvue. It is not affiliated with, endorsed by, or operated in partnership with any of them.

Each platform sets its own rules about automation and account access, and those rules apply to you. They change from time to time, and they differ between platforms. Some platforms restrict automated messaging entirely; others restrict particular forms of it.

Before enabling automated sending on a creator account, confirm what that platform’s current terms permit. This is your decision to make as the operator of the account, and the responsibility for it sits with you, not with us. Our Terms of Service §6 sets this out in full.

Practical guidance:

  • Work manually (L1) or with automatic drafting only (L2) unless you have confirmed that automated sending is acceptable for that platform and that account.
  • Keep automation paced as configured. The platform’s default pacing exists for a reason — do not treat it as an obstacle.
  • Keep a person reviewing the automation log daily.
  • Follow each platform’s rules on account sharing and team access.

The platform gives you tools that carry real weight. A few principles that keep agencies out of trouble:

People, not volume. Every message goes to a real person who believes they are talking to your creator. Everything in this platform is designed to make that conversation better, not to make it fake.

Never automate distress. Distress detection is enabled by default on every creator. Leave it on. A person in crisis needs a human, and no commercial consideration outweighs that.

Never automate complaints or disputes. They escalate when handled automatically. The platform holds them for a person; keep it that way.

Do not misrepresent what is being sold. The draft review already prevents promising content that is not attached, or inventing a purchase — but your pricing, your delivery times and your content descriptions are yours to keep honest.

Respect stated boundaries. If a fan says no to something, the conversation record carries that forward. Do not override it.

You own what goes out under your accounts. Every draft is reviewed before it reaches you, and every automated send passes the safety checks described in Autonomy Levels. The final responsibility for what is sent from your creator accounts still sits with you as the operator — which is why review, autonomy policy and the automation log all exist.


You are responsible for the content you upload, the accounts you operate and the conversations you hold. In particular:

  • Every person appearing in content you upload must have consented to it and be of legal age, and you must be able to evidence that.
  • You must be authorised to operate every creator account you connect.
  • Your team must comply with applicable law wherever they work.

Our Acceptable Use Policy (§9) sets out what is prohibited. Breaching it can result in suspension.


Access control

  • Give each team member their own login. Shared logins destroy accountability and are the most common cause of an incident nobody can explain afterwards.
  • Keep chatters on assigned creator scope, so adding a creator never exposes it to everyone by default.
  • Disable leavers on their last day. Disabling takes effect immediately, everywhere, including the extension, and preserves the record of their work.
  • Restrict billing permissions to the people who genuinely need them.

Passwords

  • Use unique passwords, ideally from a password manager.
  • Verify email addresses on every account so password recovery works.

Reviewing activity

  • On a paid subscription, review the activity log monthly: deletions, billing changes, subscription changes and automation escalations.
  • Review the Autopilot log daily during any period when automation is running.

Isolation. Your account’s data belongs to your account. Creators, fans, conversations and media are never visible to another customer, and access inside your own account is limited by role and creator scope.

We never train on your data. Your conversations, CRM records and personas are not used to train, fine-tune or evaluate any machine-learning model of ours. We contract with our AI provider on terms that exclude the use of submitted content for model training. Our own quality testing runs against a separate database of fictional test data, never against customer data.

Self-hosted AI option. For agencies with stricter requirements, the platform can be pointed at a self-hosted model server, in which case no conversation content reaches any third-party AI provider at all. Write to support@sufflera.com to arrange this.

Retention. Conversation history has no automatic expiry — it is kept until you delete it, because it is the assistant’s working memory.

The text of AI drafts is different: it is erased automatically after 180 days. The fan message that prompted the draft, the draft itself and its translation go; the measurements stay, so your quality statistics and ratings are unaffected. Nothing is asked of you and nothing can be switched off — if you need the wording of an old draft for a dispute, export it before the six months are up.

Export.

WhatHow
Your whole account, as JSONSettings → Account → Export
Your billing ledgerSettings → Billing
A single fan’s record — messages, purchases, reminders, media, draftsRequest it from us

The account export is a complete machine-readable copy of everything in your account, and it is the one to use for portability, migration or your own records.

Request a single fan’s record when an individual asks you to hand over what you hold about them — it is scoped to that one person, so you can answer the request without disclosing anything about anyone else.

Deletion. Deleting a fan record removes that person’s messages, purchases, reminders, media and drafts.

Deleting your account permanently purges your operational data — CRM records, fan data, personas and generated drafts.

Two things are kept, for legal reasons and for those reasons only:

  • Financial records — invoices, payment receipts and billing history — for up to seven years, because tax and accounting law requires it.
  • Proof of acceptance — which version of our terms was accepted and when. The IP address and browser details recorded at the time are discarded.

Backups are overwritten on their normal cycle, typically within fourteen days. Export anything you need to keep before deleting.

Exercising data rights. Several rights are exercisable directly in the product — access and portability through the exports above, rectification by editing any field, erasure by deleting a record or the account, and restriction of automation by setting autonomy to manual or leaving Autopilot off. For anything else, write to privacy@sufflera.com; we respond within 30 days.

Security. Passwords are hashed with Argon2id and never stored in plain text; sessions use short-lived tokens with server-side revocation; access is enforced on the server rather than by hiding controls in the interface; data is encrypted in transit; and financial operations run under transaction guarantees that prevent double-charging. Where a data breach is likely to present a risk, we notify the relevant supervisory authority within 72 hours and affected customers without undue delay.

Full detail is in our Privacy Policy.


For the conversations and fan records inside your account, you are the data controller and we act as your processor. Practically, that means:

  • You decide what is collected and how long it is kept.
  • You are responsible for having a lawful basis for holding it.
  • You are responsible for responding to requests from the individuals concerned.
  • We process it on your instructions, and we tell you exactly what we do with it.

Our Privacy Policy §3 covers the split in detail, and §7 covers precisely what is sent for AI processing and what is retained.


If something looks wrong — unexpected messages, a conversation that went badly, an account you did not recognise:

  1. Press pause. The creator-level pause switch stops automated sending instantly, from the dashboard or the extension popup.
  2. Stop Autopilot in any tab where it is running — the button is in the top row of the Autopilot tab.
  3. Read the Autopilot log to see exactly what was sent, to whom, and when.
  4. Check the activity log for account changes you did not expect.
  5. Disable any user account you are unsure about.
  6. Contact support with the timestamps.

Pausing costs nothing and is instantly reversible. Use it early.