Closed betaFree during the closed beta and for 12 months after it.Join the beta →
Security

How erscope handles your data and your fans’ data.

erscope works with earnings and fan data, so it is built on the assumption that this data is personal and sensitive. This page explains, in plain words, how data gets in, how it is stored, who can see it and how you get it out or delete it.

How data gets in

A browser extension reads the earnings and fan data your dashboard loads while you are logged in. Your platform password is not asked for, and your session stays in your browser.

  • The extension turns platform data into erscope’s own format in your browser, so raw platform responses are not sent to us
  • Each connected browser has its own signing key; every upload is signed and checked, and you can remove a browser at any time
  • Uploads are rare: at most one batch per account every few minutes

What we store about fans

We keep only what the analysis needs: a display name, when a fan was first seen and last active, their purchases and subscription. We do not store avatars, usernames, bios or message contents.

  • Platform fan ids are replaced by a one-way keyed hash before they reach our database, different in every workspace
  • Fan display names are encrypted at field level (AES-256-GCM)
  • Your notes about fans are encrypted and never sent to AI

Who can see it

Every workspace is isolated at the database level with row-level security, so one workspace cannot read another’s data even through a mistake in the application. Within a workspace, roles decide who sees what, and owners can hide revenue from chatters.

Sign-in uses a one-time email link, with optional two-factor authentication. If our support team ever needs to look at your dashboard to help you, they must give a reason, access lasts one hour, and workspace owners are emailed.

Every access is recorded

Reading data, exports, deletions and permission changes are written to an audit log that the application can add to but not change.

AI, only when you turn it on

AI features are off until a workspace owner turns them on. When they are on, the model sees purchase facts in words, with the fan always shown as [FAN]. Names, ids, links and anything people typed are never sent, and a check refuses any prompt that contains them.

We only use AI providers with whom we have a zero data retention agreement. AI writes drafts; a person sends every message, and nothing is sent to fans automatically.

Where it lives

erscope runs on servers in the European Union and follows the GDPR. Connections are encrypted with TLS. Nightly backups are kept for a limited time.

Export and deletion

Workspace owners can export everything as a ZIP of CSV and JSON files at any time.

  • Deleting a fan or a connected account’s data takes effect immediately
  • Deleting a workspace or an account takes effect after 7 days, so a mistake or a stolen session can be undone; access stops at once
  • Deleted data leaves backups within 14 days

Not built yet: optional server sync

Today, data only comes in through the extension. We plan an optional server sync for creators who want updates while their browser is closed. It will only start with your explicit consent, and it will follow these rules:

  • Credentials encrypted with envelope encryption (AES-256-GCM), with the master key kept outside the database
  • Only the sync worker can decrypt them; the dashboard, logs and AI never see them
  • Never shown back, and deleted permanently with one click
  • No two-factor secrets stored; you enter a code when one is needed
  • Every use recorded in a log you can see, and read-only: nothing is posted or sent from our servers

Reporting a problem

If you think you have found a security issue, write to [email protected] with the details. Please give us a chance to fix it before sharing it publicly.

Related

See this for your own page.

erscope is in closed beta: free during the closed beta and for 12 months after it. Join the waitlist and we will let you in as soon as there is room.

Join the beta →