How data gets in
A browser extension reads the earnings and fan data your dashboard loads while you are logged in. Your platform password is not asked for, and your session stays in your browser.
- The extension turns platform data into erscope’s own format in your browser, so raw platform responses are not sent to us
- Each connected browser has its own signing key; every upload is signed and checked, and you can remove a browser at any time
- Uploads are rare: at most one batch per account every few minutes
What we store about fans
We keep only what the analysis needs: a display name, when a fan was first seen and last active, their purchases and subscription. We do not store avatars, usernames, bios or message contents.
- Platform fan ids are replaced by a one-way keyed hash before they reach our database, different in every workspace
- Fan display names are encrypted at field level (AES-256-GCM)
- Your notes about fans are encrypted and never sent to AI
Who can see it
Every workspace is isolated at the database level with row-level security, so one workspace cannot read another’s data even through a mistake in the application. Within a workspace, roles decide who sees what, and owners can hide revenue from chatters.
Sign-in uses a one-time email link, with optional two-factor authentication. If our support team ever needs to look at your dashboard to help you, they must give a reason, access lasts one hour, and workspace owners are emailed.
Every access is recorded
Reading data, exports, deletions and permission changes are written to an audit log that the application can add to but not change.
AI, only when you turn it on
AI features are off until a workspace owner turns them on. When they are on, the model sees purchase facts in words, with the fan always shown as [FAN]. Names, ids, links and anything people typed are never sent, and a check refuses any prompt that contains them.
We only use AI providers with whom we have a zero data retention agreement. AI writes drafts; a person sends every message, and nothing is sent to fans automatically.
Where it lives
erscope runs on servers in the European Union and follows the GDPR. Connections are encrypted with TLS. Nightly backups are kept for a limited time.
Export and deletion
Workspace owners can export everything as a ZIP of CSV and JSON files at any time.
- Deleting a fan or a connected account’s data takes effect immediately
- Deleting a workspace or an account takes effect after 7 days, so a mistake or a stolen session can be undone; access stops at once
- Deleted data leaves backups within 14 days
Not built yet: optional server sync
Today, data only comes in through the extension. We plan an optional server sync for creators who want updates while their browser is closed. It will only start with your explicit consent, and it will follow these rules:
- Credentials encrypted with envelope encryption (AES-256-GCM), with the master key kept outside the database
- Only the sync worker can decrypt them; the dashboard, logs and AI never see them
- Never shown back, and deleted permanently with one click
- No two-factor secrets stored; you enter a code when one is needed
- Every use recorded in a log you can see, and read-only: nothing is posted or sent from our servers
Reporting a problem
If you think you have found a security issue, write to [email protected] with the details. Please give us a chance to fix it before sharing it publicly.