Privacy Policy
Last updated: 2026-07-31
LinkWhale ("LinkWhale", "we", "us") provides link attribution and revenue analytics for Fanvue creators and agencies. The data controller responsible for the personal data described in this policy is LinkWhale. LinkWhale is an independent product and is not affiliated with Fanvue Ltd.
1. Overview
This policy explains what data we access from your Fanvue account, why we access it, where it is stored, how long we keep it, and the rights you have over it. We access your Fanvue data through Fanvue's official OAuth 2.0 authorization flow, on a read-only basis. We never post, message, or make any change on your Fanvue account, and we never ask for or store your Fanvue password.
2. Data we read via Fanvue OAuth
When you connect a Fanvue account, you grant LinkWhale a set of read-only OAuth scopes. We request only the following scopes, and use each solely to power the analytics you see in the app:
openid- confirms your identity so we can create your LinkWhale login.offline_access- lets us refresh access without asking you to sign in again (required to keep your analytics up to date).read:self- your basic Fanvue account identity.read:creator- your creator account details (handle, display name, avatar).read:fan- your subscribers/fans, used for subscriber lists, top spenders, whale detection, and churn analytics.read:tracking_links- your promotional/tracking links and their click and revenue totals.read:insights- your earnings and analytics figures.read:media- your vault media metadata (used for vault performance analytics; we do not download or store your media files).read:chat- mass-DM/broadcast metadata, used for message-campaign analytics.
All scopes are read-only. You can revoke LinkWhale's access at any time from your Fanvue account settings, and via the in-app deletion action described in section 6.
3. What we store
We store the following categories of data in our database:
- Account & profile - your LinkWhale login identity and subscription tier/status.
- Connected creators - the Fanvue creator profiles you connect, and the encrypted OAuth access/refresh tokens needed to sync them.
- Tracking links - your promotional links, click totals, and attributed revenue.
- Subscribers / fans - subscriber handles, join/churn dates, and aggregated spend used for whale and churn analytics.
- Transactions - earnings events (subscriptions, tips, PPV, renewals) in aggregate.
- Content analytics - vault media metadata and mass-DM campaign metadata.
- Notifications - in-app alerts we generate for you (e.g. whale and churn alerts).
- Agency data - for agency accounts, roster/portfolio associations across the creators you connect.
4. Where and how it is stored
Data is stored in a managed PostgreSQL database hosted by Supabase, protected by row-level security so each account can access only its own data. OAuth tokens are held as credentials solely to sync your data on your behalf and are never shared. All access to the app is over HTTPS/TLS.
5. Retention
We retain your data for as long as your LinkWhale account is active. When you delete your account (see section 6), we permanently remove your creators, tracking links, subscribers, transactions, content analytics, notifications, and agency associations, and we delete the stored Fanvue OAuth tokens from our systems so we can no longer access your Fanvue account. Because these are read-only tokens held by Fanvue, any residual grant expires on Fanvue's side; you can also revoke LinkWhale's access at any time from your Fanvue account settings. Limited operational logs that do not identify you may be retained for security and debugging for a short period.
6. Your rights & how to exercise them
Under the GDPR and similar laws you have the right to access, rectify, erase, port, and object to the processing of your personal data.
- Erasure (deletion): Use Delete my account & data in the dashboard account area to permanently and irreversibly delete all of your data and revoke Fanvue access. As a fallback, email support@linkwhale.app from your account email and we will action the deletion.
- Access / portability / rectification / objection: email support@linkwhale.app and we will respond within the timeframes required by law.
7. Cookies & sessions
We use only the cookies and local/session storage necessary to keep you signed in and to run the app (for example, your authentication session and a per-session sync marker). We do not use advertising or third-party tracking cookies.
8. Security
We apply least-privilege data access, row-level security, HTTPS/TLS, and encrypted token storage. To report a security vulnerability, contact security@linkwhale.app. The data controller is LinkWhale.
9. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with a new "Last updated" date.
10. Contact
Questions about this policy or your data? Email support@linkwhale.app.