Fankare Privacy Policy
Aurora Interactive Services LLC, doing business as Aurora Interactive ("Company," "we," "us," or "our"), operates the Fankare social media platform ("Platform"). This Privacy Policy describes how we collect, use, disclose, retain, and protect the Personal Data of individuals who access or use our Platform as subscribers ("Subscribers"), creators ("Creators"), or visitors who express pre-launch interest in our services.
We organize and operate exclusively under the laws of the State of Minnesota. We do not target, market to, or knowingly permit the use of our Platform by any individual residing outside of the United States or any individual who is a legal resident of the State of California.
1. Scope and Strict Geographic Restrictions
1.1 United States Only
We restrict access to the Platform exclusively to legal residents of the United States who are physically located within the United States. We deploy internet protocol (IP) geofencing to detect and block access attempts originating from outside the United States.
1.2 Absolute Exclusion of California Residents
To mitigate regulatory conflicts and legal complexity, we categorically bar legal residents of the State of California from creating accounts, accessing the Platform, transacting on the Platform, or registering interest on our landing pages. We enforce this exclusion through:
- Mandatory Self-Attestation: All Users must explicitly certify during registration or interest collection that they are not legal residents of the State of California.
- IP-Based Geofencing: We block registration and landing page sessions originating from California IP addresses.
- Payment Gateway Address Validation: Our payment processor, Stripe, validates the billing address of all payment methods. If a transaction payload contains a billing state of "CA" or "California," or a billing ZIP code corresponding to California, our API gateway immediately declines the transaction.
2. Age Restrictions and Verification
2.1 18+ Absolute Restriction
The Platform permits the upload of adult and sexually explicit media. Accordingly, we require all Users and visitors to be at least 18 years of age. A mandatory age-gate check must be confirmed prior to entering the site.
2.2 Verification Mechanisms
- Creators: Before a Creator can customize their profile, set subscription rates, or publish content, they must undergo identity verification via Stripe Identity. This process requires the submission of a government-issued photo identification document and a live facial capture (selfie) to verify age, identity, and tax status under Stripe Connect.
- Subscribers: We verify the age of Subscribers prior to processing payments. Subscribers must submit valid billing details to Stripe, which validates the cardholder's age and identity. We reserve the right to integrate automated age-estimation technology at any time to verify Subscriber eligibility.
3. Categories of Personal Data Collected
We collect and process the following categories of Personal Data:
3.1 Account Registration Data
We collect your username, email address, display name, biographical text, and account credentials. We encrypt and store your passwords locally on our servers using the bcrypt hashing algorithm.
3.2 Identity and Tax Verification Data (Creators Only)
Through our integration with Stripe Identity and Stripe Connect, we collect: legal name and date of birth, government-issued identification documents, and Taxpayer Identification Numbers via Form W-9. While Stripe securely stores and processes raw identification images, we retain verification identifiers and essential metadata (legal name and date of birth) to satisfy federal compliance obligations.
3.3 Transaction and Billing Data
We use Stripe as our exclusive payment processing platform. We do not store, process, or transmit raw credit card numbers. Stripe collects financial details directly. We retain only transaction history metadata, including billing state and ZIP code (used to enforce California exclusion), transaction date, amount, and currency.
3.4 User-Generated Content and Communications
We collect and store media assets you upload (images, videos, comments, and private messages). To protect your privacy, our backend worker pipeline programmatically strips all EXIF/GPS metadata from uploaded media prior to permanent storage.
3.5 Device and Technical Data
When you access the Platform, our servers automatically log technical metadata including your IP address, browser type, operating system, access times, pages viewed, and TLS version.
3.6 Pre-Launch Interest Data
When you sign up to express interest in the platform prior to launch, we collect your email address, designated role (Creator, Fan, or Both), Fansly and OnlyFans usernames (if applicable), features you love, estimated community size (optional), content niche (optional), preferred payout methods (optional), and suggestions. We also collect mandatory self-attestations regarding your age, United States residency, and California non-residency.
4. How We Process Personal Data and Legal Bases
We process your Personal Data for the following purposes and under the following legal bases recognized under the Minnesota Consumer Data Privacy Act (MCDPA):
| Processing Purpose | Category of Personal Data | Legal Basis |
|---|---|---|
| Contract Performance: Establishing accounts, gating subscription content, delivering direct messages, and processing payments via Stripe. | Account Registration, Transaction Data, User-Generated Content. | Necessary for the performance of a contract to which you are a party. |
| Identity & Age Verification: Processing Creator KYC through Stripe Identity and validating Subscriber age requirements. | Identity Verification Data, Transaction Data. | Necessary to comply with legal obligations and perform contract terms. |
| Legal Compliance: Satisfying tax reporting mandates (Form 1099-K) and maintaining records under federal recordkeeping laws. | Account Registration, Identity Verification Data, Transaction Data. | Necessary for compliance with federal and state legal obligations. |
| Platform Security & Fraud Prevention: Detecting and blocking California residents, preventing payment fraud, and implementing our IP geofences. | Device Data, Transaction Data (Billing State/ZIP). | Necessary for our legitimate interests in securing our Platform and complying with jurisdiction-specific exclusions. |
| Platform Optimization & Sizing: Analyzing pre-launch interest, sizing platform infrastructure, and evaluating requested features. | Pre-Launch Interest Data, Device Data. | Consent and our legitimate interest in tailoring features and preparing server infrastructure capacity. |
5. Data Sharing and Third-Party Disclosures
We do not sell, rent, or lease your Personal Data to third parties for marketing or advertising purposes. We limit data sharing to the following circumstances:
5.1 Service Providers and Sub-Processors
We share Personal Data with trusted service providers who perform critical operational functions on our behalf. These parties are contractually bound to process your data strictly in accordance with our instructions:
- Stripe, Inc.: For payment processing, subscription billing, identity verification (Stripe Identity), and tax reporting compliance (Stripe Connect).
- 2257Sentry: For third-party compliance auditing and public recordkeeping registration.
5.2 Self-Hosted Posture and Minimized Exposure
Unlike platforms that rely on commercial cloud ecosystems, we minimize third-party exposure through a self-hosted infrastructure design. We host and manage all processed user media on our private, self-hosted SeaweedFS storage clusters. We host and operate our email servers on our local network infrastructure.
5.3 Legal and Regulatory Disclosures
We disclose Personal Data if we believe in good faith that such disclosure is necessary to comply with a valid subpoena, court order, federal child exploitation reporting mandates (under the PROTECT Our Children Act), or to protect the rights and safety of our Users and Platform.
6. Biometric Data Consent (Creators Only)
To comply with the sensitive data consent requirements of the Minnesota Consumer Data Privacy Act (MCDPA), we require Creators to provide explicit, affirmative opt-in consent before processing biometric data.
During the Creator onboarding process, Stripe Identity analyzes your government photo identification and live selfie to generate a mathematical representation of your facial geometry to verify your identity. We do not store, access, or reconstruct your biometric facial templates on our local servers.
7. Data Retention, Deactivation, and Deletion
We maintain structured data retention intervals designed to balance User privacy rights with federal regulatory compliance.
7.1 Deactivation (Soft-Deletion)
When you choose to deactivate your account via settings, your profile, posts, and comments are hidden from public view, and all active automated subscription billings are cancelled. We retain your account data in our database during this soft-deletion state to allow you to reactivate your account in the future.
7.2 Hard Deletion (The MCDPA 45-Day Pipeline)
You may request the permanent deletion of your Personal Data by submitting a verified request to privacy@fankare.vip. We will execute the hard-deletion process within 45 days of verification. We physically destroy your media assets on our self-hosted disk clusters, bypassing standard storage redirects to prevent retention in cache layers.
7.3 Overriding Legal Holds and Retention Exceptions
We cannot delete data that is subject to overriding legal retention mandates. We must retain:
- Federal Recordkeeping (18 U.S.C. § 2257): Creator identification records, legal names, and compliance metadata for a minimum of 7 years following deletion.
- Tax Records (IRS / Stripe Connect): Transaction records and W-9 metadata for a minimum of 7 years.
- NCMEC / CSAM Evidence Holds: Terminated accounts involved in Child Sexual Abuse Material (CSAM) are quarantined on isolated, secure SeaweedFS volumes and retained for a minimum of 90 days to assist law enforcement.
8. Data Security and Technical Measures
Our backend worker servers operate within a private, network-isolated environment. All communication between our API gateway and our background workers requires authentication using an internal, cryptographically random security token transmitted via the X-Internal-Token header. We force all connections to use TLS 1.2 or TLS 1.3, and encrypt database storage volumes using AES-256.
9. Your Rights Under the Minnesota Consumer Data Privacy Act (MCDPA)
As a resident of the State of Minnesota, you possess specific statutory rights under the MCDPA. You may exercise these rights by contacting us at privacy@fankare.vip:
- Right to Confirm Processing and Access: Confirm whether we are processing your Personal Data and obtain a copy.
- Right to Correction: Request correction of inaccuracies.
- Right to Deletion: Request deletion of your data, subject to Section 7.3 legal exceptions.
- Right to Data Portability: Obtain your data in a portable, technically feasible, and usable format.
- Right to Opt-Out of Targeted Advertising: We do not engage in targeted advertising, sell your data, or perform profiling.
- Non-Discrimination: We will not discriminate against you or deny services because you choose to exercise your rights.
10. Contact Information and Appeals
10.1 Privacy Contact
If you have questions about this Privacy Policy, wish to exercise your rights, or want to submit a formal data deletion or access request, please contact our privacy officer at:
Attn: Privacy Compliance
1819 Glendale Hills Dr NE
Rochester, MN 55906
Email: privacy@fankare.vip
10.2 Right to Appeal
If we decline to take action on your request, you may appeal our decision within 30 days of receiving our denial by emailing privacy@fankare.vip with the subject line "Privacy Request Appeal." We will respond in writing within 45 days. If we deny your appeal, you have the right to submit a complaint directly to the Minnesota Attorney General.