Skip to content
Privacy Policy

How Fameoria handles personal data

This Privacy Policy explains what Fameoria processes when you browse the site, use a free tool, create an account, place an order, join the newsletter or contact support. It also explains the purposes, providers, retention approach and rights that may apply.

Last reviewed August 2026

  • No Instagram or TikTok passwords
  • Payment credentials stay with the hosted provider
  • Public-tool lookups are separated from customer accounts
  • Access, correction and deletion requests are supported

01Controller and scope

Fameoria is the controller for the personal data described here and operates from the United Arab Emirates. This policy covers Fameoria visitors, free-tool users, newsletter subscribers, customers, account holders and people who contact support. It does not control the independent processing performed by Instagram, TikTok, a hosted payment provider or another external site.

Privacy requests can be sent through Reach Us.

02Data you give us

Depending on the feature, you may provide:

  • an email address, customer name and account password, which is stored as a hash
  • a public Instagram or TikTok username, post URL or video URL
  • the selected product, quantity, variation, locale and currency
  • newsletter consent or other communication preferences
  • support messages, screenshots and order details
  • information needed to verify a privacy, refund, security or legal request

Never send a social account password, payment credential, wallet seed phrase or private key.

03Order and transaction records

When you place an order, Fameoria creates records such as the order number, customer email, service lines, public target, starting count where available, quantity, displayed price, USD or TRY totals, locale, currency, payment provider, payment identifier, payment status, fulfilment status, timestamps, provider responses and refill or refund history.

These records are used to release paid orders, show status, investigate failures, prevent duplicate fulfilment, handle support, reconcile payment and document what was purchased. They can also be needed for accounting, tax, fraud prevention, chargebacks and legal claims.

04Free-tool and public-platform data

A free tool may process the public username or URL you enter and public profile, post, story, feed or video data returned by an external lookup provider. This can include public counters, captions, thumbnails, profile images and post metadata where the platform exposes them. Private or restricted information is not intentionally requested.

Lookup inputs and results may pass through validation, rate limiting, abuse controls and short-lived caches. They are not automatically attached to a Fameoria customer profile merely because the same person later places an order. A public result can still relate to another person, so use the tools only for a lawful purpose.

05Technical and security data

The service may process IP address, request time, route, browser or device information, security headers, session identifiers, error data, rate-limit events and records needed to investigate abuse. Server, hosting and provider logs can contain similar technical information.

This data is used to deliver pages, maintain sessions, protect APIs, detect automated abuse, troubleshoot failures and preserve evidence of fraud or unauthorised access. We do not currently use it to build advertising profiles.

06Why we process data and legal bases

The legal basis depends on the activity and applicable law. Typical purposes are:

  • contract performance for account creation, checkout, payment status, fulfilment, tracking and order support
  • legitimate interests in site security, fraud prevention, service diagnostics, claim defence and accurate business records, balanced against user rights
  • legal obligations for accounting, tax, sanctions, law-enforcement requests or consumer records where applicable
  • consent for optional marketing or any optional cookie category that legally requires it

Where consent is the basis, it can be withdrawn for future processing without making earlier lawful processing invalid.

07Payment processing

Payment details are entered on the hosted page of the provider shown at checkout. Fameoria receives and stores the identifiers, amount, currency, status and timestamps needed to match the transaction to the order. We do not need your wallet private key or seed phrase.

The payment provider acts under its own terms and privacy notice for the data it collects directly. Blockchain transactions may also be visible on a public ledger and cannot be deleted by Fameoria. Check the asset, network, address and amount before sending funds.

08Service providers and recipients

Data is disclosed only where needed for an assigned function, a transaction, security or law. Current categories include:

  • Supabase for database and authentication-related infrastructure
  • Resend for transactional email and, where chosen, newsletter delivery
  • the hosted payment provider shown at checkout for payment creation and status
  • fulfilment providers receiving the public target, product and quantity required for delivery
  • public-data or scraping API providers receiving a public username or URL when a lookup is run
  • hosting, security, professional advisers or authorities where reasonably necessary

Providers must not receive a social account password because the Fameoria product flow does not require one.

09International transfers

Providers may process data in countries other than your own. Where European or similar transfer restrictions apply, the operator should use an adequacy decision, approved contractual safeguards or another valid mechanism and assess provider documentation where required.

The internet and public blockchain networks can route or replicate technical data across borders. This section does not reduce a right to ask where a specific provider processes data.

10Cookies and browser storage

Fameoria currently uses first-party storage for consent state, locale, currency and customer sessions. The Cookie Policy lists fam_consent, bf_locale, bf_currency and bf_session, their purpose and current duration. The site does not currently load advertising or audience-measurement cookies.

A hosted payment page or external platform may set its own cookies after you leave Fameoria. Those values are controlled by that provider. If optional analytics or advertising is added later, this policy and the consent flow must be updated before the relevant storage loads where consent is required.

11Email and communications

Transactional email can include registration, security, payment, order, fulfilment, refund and support messages. These communications are needed to operate the requested service. Marketing or newsletter messages are handled separately and include the applicable unsubscribe route.

Unsubscribing from marketing does not stop necessary order or security messages. Delivery providers can retain suppression records so an address that opted out is not accidentally re-added.

12Retention

Retention is tied to purpose rather than one duration for every record. Current first-party preference cookies can last up to one year, the consent record up to 180 days, and a signed-in customer session up to 30 days unless revoked earlier. Public lookup caches are intended to be short-lived operational copies.

Order, payment-status, refund and support records are retained while needed to perform the contract, answer disputes, prevent fraud and satisfy accounting, tax or legal obligations. Security logs are retained for a proportionate investigation period. Newsletter data is retained until unsubscribe or another valid deletion event, subject to a minimal suppression record. Data is then deleted, anonymised or isolated when continued retention is no longer justified.

13Your privacy rights

Depending on your location and the legal basis, you may have rights to:

  • receive information and request access to personal data
  • correct inaccurate or incomplete data
  • request deletion or restriction
  • object to processing based on legitimate interests
  • receive portable data where the legal conditions apply
  • withdraw consent for future processing
  • complain to a competent data-protection authority

These rights are not absolute. For example, transaction records may need to remain for accounting, fraud prevention or legal claims. We will explain a material refusal or limitation where law requires it.

14How to make a request

Use Reach Us and identify the email address, order number or account needed to locate the record. Describe the right you want to exercise and the relevant scope. Do not send an identity document unless requested through an appropriate verification step.

We may ask for proportionate verification to prevent disclosure or deletion of another person's data. Authorised agents may need to show their authority. We aim to respond within the period required by applicable law and will explain if a complex or repeated request lawfully needs more time.

15Automated processing and sale of data

Fameoria uses automated validation, rate limiting, payment-status handling and fulfilment workflows. These processes help operate orders and tools, but the current service does not make solely automated decisions that produce legal or similarly significant effects about a person. Support can review an order or access restriction when appropriate.

Fameoria does not sell personal data or share it for cross-context behavioural advertising. If the business model changes in a way that creates a legally defined sale, sharing right or targeted-advertising choice, the policy and user controls must be updated first.

16Security

Measures include access controls, service-role separation, hashed customer passwords, signed or expiring sessions, validation, rate limits, webhook signature checks, hosted payment pages and restricted operational access. Providers are selected for the function they perform, and sensitive credentials should not be sent through support.

No internet service can promise absolute security. If an incident creates a legally reportable risk, the operator will follow applicable assessment, notification and remediation duties. You should use a unique Fameoria password and report suspected unauthorised access promptly.

17Children and third-party targets

Paid Fameoria services are for customers aged 18 or older and are not directed to children. Do not submit unnecessary information about a child through support or free-text fields.

An order or public-tool lookup can concern a public account operated by somebody other than the customer. You remain responsible for authority and lawful use. Fameoria processes the submitted public target to provide the requested function, but a public profile does not remove the account owner's privacy, publicity or other legal rights.

18Changes, complaints and contact

This policy is reviewed when data flows, providers, cookies, products or legal requirements change. Material updates will change the review date and may receive an additional notice where required. Older transaction records remain governed by the rights and duties that applied when they were created, subject to later mandatory law.

Use Reach Us for a privacy question or request. You may also complain to the data-protection authority that is competent for your residence, workplace or the alleged infringement.

Ask about your data

Send a focused privacy request through the support form.

Reach us