Extension privacy policy
Applies from Flower 2.1.0 while this data handling remains unchanged ยท Updated 8 October 2026This policy describes the Flower browser extension for creators on OnlyFans, Fansly and Fanvue, its server translation, its optional server features, and its usage and diagnostic records. It does not describe the earlier Flower chatbot, the marketing website, or the separate account connector.
Records on your device
Flower stores its working records in your browser profile on your device. These local tools do not need a Flower account or a Flower server. The extension uploads them only when you turn on an optional server feature described below.
While you use OnlyFans, Fansly or Fanvue, Flower observes relevant responses that the site normally sends to the pages you open. It uses selected fields to identify the creator and current fan, match media, record available send and purchase evidence, and save observed fan earnings. It does not record a complete chat history, request a full account history, or treat a missing local record as proof that a fan has not bought an item.
Local records can include:
- Creator and fan IDs, names, usernames, and conversation links.
- Media identifiers, titles, types, durations, linked copies, and file fingerprints.
- Recorded sends and purchases, with prices, currencies, and dates when available.
- Observed fan earnings, subscription status, and capture times, and transaction history you import from CSV files.
- Custom orders, recurring commitments, calendar plans and offer drafts. An order created from a message can use that message's text as its notes.
- Notes, tags, follow-ups, segment rules, saved replies, reply sequences, content sets, and order templates that you save.
- Appearance and notification settings, and bounded diagnostic codes.
Files and message drafts
If you select an original file to compare duplicates, Flower calculates its SHA-256 fingerprint on your device. It stores the fingerprint and relevant file details, not the selected file bytes. It does not upload the file.
A saved reply is inserted into the current chat draft only after your action. Flower checks the creator, fan, and draft, and asks before replacing a nonempty draft. Segments help you choose an audience; they do not send anything. Flower does not send messages, mass messages or media automatically. If you send a message or media through a platform, that action is handled by the platform under its own policy.
Access and third parties
The release requests storage for local records and sessions, identity for Flower sign-in, and alarms for queued delivery and reminder checks. It can request notifications, only when you turn on reminder notices. Its content scripts run only on onlyfans.com, fansly.com and www.fanvue.com. API access is limited to https://my.getflowerapp.com. It does not request permission to read cookies, tabs or all browsing activity. It does not ask for your platform password or copy platform authentication credentials into its records.
Fonts, icons, and program code are included in the extension. Flower does not sell your records or use them for personalized advertising. Flower uses user data only for the creator tools described here, in line with the Limited Use requirements of the Chrome Web Store User Data Policy.
Flower sign-in and translation
Translation and the optional server features require a Flower account. The extension stores a temporary Flower access token in browser storage. Your Flower account email and session identify you to the server; this is separate from your platform accounts.
When you choose Translate, the selected text and language pair are sent to Flower, then to OpenRouter for model processing. A successful translation is stored encrypted and cached for your Flower account for the current month. If you add translation rules, Flower stores that glossary encrypted for the creator account until you remove the rules. Provider processing is subject to OpenRouter's privacy policy.
Optional server features
Each feature below is off until you agree to it after Flower sign-in. You can stop it in Settings or the matching tool. Operators with the storage key can read encrypted server data. Separate operator backups have their own retention.
- AI fan profiles. With a separate account agreement, Flower reads chat history through your connected account and messages loaded in your browser. It sends message text, speaker IDs, dates and existing profile facts through OpenRouter to build fan profiles. Media and platform credentials are not sent. Source messages and profiles are stored encrypted until you delete the profile. You can correct, pin or dismiss facts, pause history import, or turn profiles off.
- Record sync. With account consent and this device's opt-in, Flower copies fan notes and tags, reminders, saved replies, order templates, segment rules, fan language preferences and reply sequences to the server. Orders, calendar entries, media evidence, earnings and imported transactions stay local. You can pause the device, stop account sync or delete the server copies.
- Chat sharing. With a separate agreement, Flower sends contact IDs, names, usernames and the text of messages loaded in your browser to help improve Flower. Attachments, contact emails and session material are excluded. Shared chats are stored encrypted and removed 90 days after their last capture. Settings can stop sharing, export the saved chats and delete them.
Messages can contain other people's personal data. Check that you are permitted to share or translate them before you use these features.
Feature usage and presence
Flower records defined tool opens and successful feature actions. Each event has an action name, random event ID, and time. Before sign-in, events use a separate installation ID; signed-in events are linked to your Flower account. Events also include the active creator profile as reported by the platform: account ID, username, name, and email when present. Usage events do not contain message text, fan IDs, notes, file names, or media.
The extension queues at most 500 events and retries delivery. Server usage records are kept for up to 366 days. While a supported platform tab is open, Flower reports about once a minute which documents are open, whether they are visible, the extension version, and the installation and creator identity. Presence expires after 90 seconds and stored presence rows are deleted after one day.
Technical diagnostics
Flower automatically sends fixed operation and error codes, build versions, times, durations, status codes, and random request, session and installation support IDs to its server. Reports exclude messages, notes, files, page URLs, passwords, cookies, tokens, arbitrary exception text and stacks. The extension keeps 200 recent events and up to 500 pending uploads. Settings shows delivery status and offers export and manual sending. Server reports expire after 30 days.
Your control
You can edit and delete records in Flower. Settings lets you export an account backup or orders CSV and import a backup. Exports are files on your device; protect them because they can contain private fan and order data.
Local records remain in the browser profile until you delete them or remove the extension's stored data. Local browser storage is protected by your device and browser access controls; Flower does not add its own encryption layer to the local database. Removing extension storage does not remove server records. Use the controls above or the developer contact below for requests about server-held data. You can also contact the Dutch Autoriteit Persoonsgegevens or your local data protection authority.
Questions
Use the developer contact listed on Flower's Chrome Web Store page for questions about this extension.