ZinelyLegal

Privacy Policy

Last updated: 29 Aug 2026

This policy explains how the agency operating Zinely (the “Operator”, “we”, “us”) handles personal data in connection with the Zinely operations console at zinelycrm.com, the Zinely Companion browser extension, and the application screening at zinelycrm.com/apply. The Operator is the controller of the personal data described here. To contact us about anything in this policy, write to zinelyagency@gmail.com or speak to your administrator. The Operator’s full legal entity name and address are available on request and are stated in staff engagement and client management agreements.

Zinely is an internal business tool, not a public app. It processes personal data about four groups of people: our staff, job applicants, the clients whose creator accounts we manage, and the fans who interact with those managed accounts.

1Staff (chatters, assistants, leads, admins)

If you work through Zinely, we process:

  • Account and identity data — your username, internal login identifier, display name, avatar, and linked accounts you provide (such as your Discord ID or Telegram handle) used for work notifications and shift coordination.
  • Work records — schedules, clock-ins and clock-outs, breaks, overtime requests and approvals, attendance and lateness records, warnings/strikes (including any penalty applied), training and certification results, workload alerts (for example when conversations wait unanswered during your shift), and quality-review findings on your work conversations.
  • Pay data — your pay rate, computed hours, bonuses, tips and revenue attribution, payout records, and the payout references you provide.
  • Usage and security logs — sign-ins and actions in the console, kept to secure the service and to keep an audit trail of who accessed what.

Why and on what legal basis. We process this data to run your engagement and calculate your pay (performance of a contract, GDPR Art. 6(1)(b)); to meet bookkeeping, accounting, and tax obligations (legal obligation, Art. 6(1)(c)); and for quality assurance, training, security, and preventing misuse of managed accounts (legitimate interests, Art. 6(1)(f)). Work-conversation review is disclosed to you in the console and acknowledged there; it covers work you do on managed business accounts only — never your personal devices, accounts, or private communications.

2Job applicants

The screening at /apply collects the details you enter (name or nickname, contact handles such as Telegram, Discord, or email) and your exam answers, timings, and scores. To protect exam integrity we also record your IP address and basic interaction signals during the sitting (such as the window losing focus or text being pasted), and the page uses Cloudflare Turnstile — which receives your IP address — solely to block automated abuse.

We use this data to assess your application (steps taken at your request before entering a contract, Art. 6(1)(b), and our legitimate interest in fair, consistent screening, Art. 6(1)(f)). Answers are scored in part by AI-assisted grading; a human reviews every application and makes the decision — no hiring decision is made by a machine alone. Application records for unsuccessful candidates are kept no longer than 12 months from the decision, then deleted.

3Clients (creators and their representatives)

For clients whose accounts we manage, we process contact and account details (name, company, email, phone or messaging handles), the platform accounts under management, and business data about those accounts — earnings, activity, and service statistics — to perform the management agreement (Art. 6(1)(b)) and for accounting (Art. 6(1)(c)). Client portal reporting anonymises the staff working on an account.

4Fans of managed accounts

When our staff operate a client’s creator account, the conversations on that account pass through Zinely. We receive this data from the platform (for example Fanvue) under the client’s authorisation — not from fans directly. It includes:

  • platform identifiers and profile basics (a stable account reference, handle, display name, and profile-photo link) and, where a staff member adds one, a work nickname, note, or country tag for the conversation;
  • message content and metadata (timestamps, message type, price, paid/read status), purchase/tip amounts, and subscription status on the managed account;
  • AI-assembled conversation summaries used by staff to pick up a conversation with context, and pseudonymised references (such as “Fan #A1B2”) in quality-review tooling.

Purpose limitation. Fan data is used to operate the managed account (responding to the fans who message it), for quality assurance and training of our staff, and for security. It is not sold, not used for advertising or profiling beyond the conversation itself, and not shared outside the service providers listed below.

Sensitive content. Conversations on adult platforms can include messages that reveal information about a person’s sex life. We do not seek this out or use it to build profiles; it is processed only as an inherent part of operating and quality-checking the conversation, under strict access controls, with pseudonymisation in review tooling and automatic deletion windows for message content. Fans can obtain a copy of, or require deletion of, the data we hold about them — see section 10.

Legal bases are performance of the client management agreement and our and our clients’ legitimate interests in operating their accounts (Art. 6(1)(f)). Because we receive this data from the platform rather than from each fan, this public policy serves as the transparency notice (Art. 14).

5AI and automated decision-making

  • Quality review: selected work conversations are assessed by an AI service after automated redaction of personal identifiers (emails, phone numbers, URLs, social handles; free-text names on a best-effort basis). Findings only become coaching records after a human manager confirms them.
  • Work assistance: to help staff respond, conversation excerpts may be sent to our AI provider to draft a suggested reply or summarise a conversation. These drafts are suggestions for the staff member. Text sent to the provider is not used to train its models and is retained by it at most briefly for abuse monitoring.
  • Applicant screening: AI-assisted scoring of exam answers feeds a human decision (see section 2).
  • No solely automated decisions producing legal or similarly significant effects are made about any person. AI providers we use do not train their models on data we submit.

EU AI Act. Some of these uses — AI-assisted evaluation of job applicants and of staff work quality — fall within the EU AI Act’s rules for AI used in recruitment and workforce management. As the deployer of those tools we apply the Act’s safeguards: every AI-assisted assessment is reviewed by a named human who can and does override it before it affects anyone; staff and applicants are informed of these tools before they are used (through this policy, the application consent notice, and the in-console monitoring notice); the tools are used only for the purposes described here; and anyone affected by an AI-assisted assessment can ask us, via the contact in section 10, for an explanation of how it was made and the role it played in the decision.

6Service providers (processors)

We use a small set of service providers to run Zinely. Each acts on our instructions under a data-processing agreement:

  • Supabase — database, authentication, and storage hosting.
  • Vercel — application hosting and delivery.
  • OpenAI — the AI processing in section 5 (quality review, work assistance, applicant scoring).
  • Google — calendar synchronisation for administrative scheduling reminders.
  • Resend — email delivery for internal operational alerts.
  • Discord — work notifications, shift commands, and operational alerts for staff who link a Discord account. Operational alerts can reference the managed account and the conversation concerned (for example a fan handle waiting on a reply).
  • Cloudflare — bot protection (Turnstile) on the public application page.

Fanvue (and any other managed platform) is a separate controller of the data on its own platform, under its own terms and privacy policy. Scheduled tasks are triggered by an external scheduler that calls our endpoints but carries no personal data. We do not sell personal data and we do not share it with advertisers or data brokers.

7International transfers

We are based in the European Union; staff typically work from the Philippines; and some of the providers above process data in the United States. Where personal data leaves the EU/EEA, we rely on the safeguards in each provider’s data-processing agreement — the EU–US Data Privacy Framework where the provider is certified, and the European Commission’s Standard Contractual Clauses otherwise.

8Retention

  • Staff and pay records — for the engagement and afterwards for as long as accounting, tax, and employment-law obligations require.
  • Applications — unsuccessful: up to 12 months from the decision; successful: become part of the staff record.
  • Fan message content and pending quality reviews — deleted automatically after a set window. Confirmed coaching records are retained for staff training, together with the specific messages cited as evidence in them.
  • Work notes about fans and conversations — kept while the related account remains under management.
  • Security and audit logs — kept for accountability; records of who accessed, exported, or erased data are retained even after the underlying data is deleted.

9Security and breaches

Data is encrypted in transit; access is role-restricted and logged; database access is governed by row-level security; service credentials are stored in a secret manager and rotated on suspicion of exposure. We maintain an incident-response runbook; if a breach is likely to put people’s rights at risk, we will notify the competent supervisory authority within 72 hours of becoming aware, and affected people and platforms where required.

10Your rights

Under the GDPR (and equivalent laws such as the UK GDPR and the Philippine Data Privacy Act), you can ask for access to your data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interests. We can export or erase the data we hold about a fan or a staff member on request.

To exercise a right, email zinelyagency@gmail.com (staff and clients can also ask their administrator). We may need to verify your identity, and we respond within one month. Deletion requests are honoured except where we must keep data for legal obligations (for example pay records) — we will tell you if so. You can also complain to your data-protection authority: in the EU, the supervisory authority of your country; in the Philippines, the National Privacy Commission.

US residents: we do not sell personal information or share it for cross-context behavioural advertising. Where a US state privacy law applies to you, you may exercise its access, correction, and deletion rights through the same contact, without discrimination for doing so.

11Cookies and local storage

  • Authentication cookies (Supabase, sb-*) — keep you signed in. Strictly necessary.
  • Remember-me (th_remember, local storage) — stores your username on this device if you tick “Remember me”. Optional; cleared by unticking or clearing browser data.
  • Sign-in flow cookies — short-lived cookies used only during a sign-in or account-connection flow (for example OAuth state), expiring within minutes.
  • Turnstile — Cloudflare’s bot check on /apply may set its own cookie strictly for abuse prevention.

We use no advertising, analytics, or cross-site tracking cookies, which is why the site shows no cookie banner: everything set is strictly necessary for a service you asked for.

12Minors

The service is strictly 18+. We do not knowingly process data about minors; managed platforms age-gate their own users. If you believe a minor’s data has reached the service, contact us immediately and we will delete it.

13Changes

We will update this policy when our processing changes; the date above shows the current version. Material changes are announced in the console. Questions or concerns: zinelyagency@gmail.com.

The Zinely Companion browser extension has its own store-listing policy at /companion-privacy.html describing exactly what the extension itself reads and stores; this policy governs the data once it reaches Zinely.