Who we are
OnlyTool operates the website onlytool.ai and the product at app.onlytool.ai. We decide how the data described here is handled, and you can reach us about any of it at support@onlytool.ai or on Telegram.
What we collect
Your account. Your email address and a password, which is stored only as an argon2id hash, which we cannot read. Plus the settings you choose in the dashboard.
The creator accounts you connect. To answer fans as a creator, the product signs in to that OnlyFans account on your instruction. We store what is needed to hold that session and to operate the account you asked us to operate.
Content from those accounts. Copies of vault media and their captions, chat history, message metadata, and purchase and earning events. This is what the AI reads to learn a creator's voice and to know what it can offer a fan.
Usage. A count of the messages the AI sends, because that is what we bill.
What you do in the product. We keep an activity log of your account: the screens you open, the dialogs we show you and whether you answered or dismissed them, a form you started and did not finish, the buttons you press, and the things the product does for you (a sign-in, a creator added, a connect attempt and whether it worked, the AI switched on or off, a creator removed). An entry is a moment in time, a short name for what happened, and the internal id of the account or creator it happened to. We read it to see where accounts get stuck.
What that log does not hold: no fan message, no vault content, no password or OnlyFans credential, no revenue, invoice or payout figure from your account, and none of the free text you type into the product. When a dialog asks you why, the log keeps only which of the offered answers you picked and whether you wrote something alongside it, never what you wrote. The one piece of wording it does keep is the error OnlyFans or our gate returned when a connection failed, because that is the only record of what stopped you.
What the AI wrote, saved at the moment you stop it. There is one thing we keep that is a message, and it is our own. When the AI is switched off for one of your creators, and again if that creator is later removed, we save a copy of the last 100 messages the AI sent as that creator. This is the outgoing side only: the words our software wrote on your instruction, on your creator's behalf. The fan's replies are not copied into it. Fewer than 100 is ordinary, and a creator whose AI never sent anything is not copied at all, because there is nothing of ours to read.
With each of those messages we save the time it was sent, whether it was a paid offer and for how much, whether the fan opened it, how many attachments it carried, whether it went to that fan alone or to many, and the text of the message itself, in full. One thing about the fan travels with it, and we would rather name it than leave you to find it: the numeric id OnlyFans uses for the fan it was sent to, so that a run of a hundred messages can be told apart into the separate conversations it came from. The fan's name, username and own words are not copied. The saved copy also carries the creator's name and OnlyFans account id, and it stays after that creator is removed and after the account is closed. Only our own administrator accounts can open one.
Why we keep it. When somebody switches the AI off, the most useful thing anyone can read is what the AI was actually saying in the days before they did. Everything else we hold tells us that an account stopped, not whether it stopped because the product was bad at its job, and reading our own output back is the only way we have to tell a product problem from a change of mind. The messages themselves are not rescued from anywhere: they stay in the system that runs the OnlyFans connection, and removing a creator does not delete them there. What a removal does end is our ability to go and ask for them, because we ask through the connection the removal releases. So the copy is taken at that moment or it is never taken.
Where you came from. On your first visit we note an advertising click id if the link carried one (Google's, Meta's, Microsoft's or TikTok's), any utm tags on it, the site that referred you and the page you landed on. It is stored with your account when you sign up, so we can tell which channels bring people who stay.
All three of those are first party: written by our own code, kept in our own database, and not handed to the advertising or analytics companies named below.
Website data. Standard server and CDN logs, and the advertising cookies described below.
Fans' messages
Operating a creator's inbox means processing messages written by their fans. We handle that data on the creator's instruction and for no other purpose: we do not sell it, we do not use it to train models for anyone else, and we do not use it to advertise to fans. If you connect a creator account, you are responsible for having the right to do so and for your own obligations to your fans under the platform's terms and your local law.
That line is also why the saved copy described above is one-sided. A fan never came to our site and never agreed anything with us, so when we keep what the AI wrote at the moment somebody stops using it, the fan's half of the conversation is left out of the copy and only their numeric id comes along. Keeping their side would be a different decision with a different consequence for them, and we have not taken it.
Why we are allowed to hold it
For everything in the product, because you asked us to run a service that cannot work without it. That is performance of our contract with you. For security, abuse prevention and keeping the service up, our legitimate interest. The same for the activity log, the saved copy of what the AI wrote when you stop it, and the first-touch capture above: understanding where accounts get stuck, whether our own AI was any good on the way out, and which channel they arrived from is our own interest in a product that works, and none of the three is used to make a decision about you. For advertising cookies, consent where the law requires it.
Cookies, advertising and analytics
onlytool.ai loads four tags. Two are advertising: the Google Ads tag
(AW-18163078601) and the Meta Pixel (1094219503396728), which set
advertising cookies and allow remarketing and click attribution. The third is Google
Analytics (G-K5E4Q1VEM2), which counts visits and which pages get read. It
is measurement rather than advertising, and it is not used to target you.
The fourth is different and we would rather spell it out than bury it. Microsoft Clarity is a session recorder, and it runs on both onlytool.ai and the product at app.onlytool.ai. It records how a page is used: mouse movements, the places you click and tap, clicks that get repeated in frustration and clicks that do nothing, how far you scroll, where the keyboard focus is, how long you stay, and the changes that happen on the page while you are on it. We play those recordings back and aggregate them into heat maps. On this marketing page there is no form and nothing to sign in to, so there is nothing here for you to type in the first place.
Inside the product, that means the application itself is recorded, so here is exactly what our code does about it. Every screen you see once you are signed in is rendered inside a single element that carries Clarity's masking attribute, and each field you type a credential into carries that attribute again in its own right. Masking is applied because of where something appears on screen rather than because somebody remembered to list it, so it covers creator names and OnlyFans account names, fan names and the text of fan messages, vault captions and the descriptions written for them, revenue and invoice figures, personas, scripts and mass messages, and the free text you type into a dialog. The mask is a rule about text, so it is not what protects the vault pictures themselves, and we would rather name the thing that does: every image on those screens is fetched from our own server through a link that works only with your signed-in session's cookie, and that link redirects to a storage address which stops working five minutes later. Someone watching a recording of your session on Microsoft's side is not signed in as you and cannot load either one, so the pictures are absent from the replay rather than blurred in it. Credentials are masked on the signed-out pages too: your OnlyTool password, the creator's own OnlyFans email and password, and any one-time code OnlyFans asks you for. What a replay of a signed-in session gives us is the layout and the movement through it, blocked out where the words were, plus the clicks, the scrolling and the pauses in between. Replays are labelled with your account's internal identifier, never your email address. That masking lives in our own markup, in the repository, and applies on every visit. Clarity has a separate account-wide masking setting on Microsoft's side, which no code of ours can set or prove to you, so we make no claim about it here.
Why it is on the product at all. When an account goes quiet, the activity log described above tells us what happened and in what order: the connect form opened and never submitted, the screen that turned out to be the last one anybody looked at. What it cannot tell us is what that looked like from your side, and that is usually where the answer is: the button pressed six times because nothing seemed to happen, the field typed into and cleared three times, the screen nobody scrolls to the bottom of. That is a shape rather than a sentence, it is the one thing we cannot find out any other way, and watching it back is what stops us guessing at the reason behind a line in the log.
About fans. Those screens render messages written by fans, and a fan never came to our site and never agreed to anything with us. So they do not depend on us remembering them: the mask is placed on the container that every signed-in screen renders inside, which means a fan's message is hidden because of where it sits rather than because a screen made a list, a screen added tomorrow is covered on the day it ships, and no part of the product is permitted to opt back out of it. What a fan wrote is never the point of a recording. The shape of the visit is.
The product at app.onlytool.ai also carries the same Google Ads tag, Meta Pixel and Google Analytics named above. The ad tags are there for one reason: creating an account is the outcome our ads pay for, and that happens there rather than here, so the tag has to be on that page to report it. Analytics is there so we can see where people get stuck between signing up and connecting a creator. None of those three records what is on a page. What they receive is the event and the address of the screen it happened on, which for a creator's page is our own internal id for that creator and not its name. They do not receive the contents of the screen: no creator name, no vault item, no fan message.
Being straight about this: all of them load for every visitor, including visitors in the EEA and the UK, before any consent is asked for. We have no cookie banner and no consent mode, and adding a recorder makes that gap wider rather than different. We are changing it. Until we do, you can block all of these in your browser's cookie and tracker settings, turn off personalised advertising in your Google Ads settings, adjust yours in Meta's ad settings, and opt out of Analytics entirely with Google's browser add-on.
Deleting a recording, honestly. A recording can only be found again if it has a name on it. Inside the product it does: your session is labelled with your account's internal identifier, so write to support@onlytool.ai and we will have the recordings held against your account deleted. On this marketing site it does not. Nothing here signs you in, so a visit carries no identifier of yours at all and there is no way for us, or for you, to point at which recording was yours. The honest answer for a visit to onlytool.ai is to block the recorder in your browser before it runs, and we would rather say that than promise a search we cannot perform. Either way Clarity is Microsoft's system and the recordings sit on it, so a deletion is a request we pass on to them rather than something we carry out ourselves.
Who else touches the data
We keep this list short on purpose. Each of these is a company that processes data on our behalf:
- Amazon Web Services: hosting, file storage and databases (United States).
- Resend: the transactional emails we send you (sign-up, password reset, account notices).
- Google: the advertising and analytics tags above, and the Gemini models that generate replies.
- Meta: the advertising pixel above (United States).
- Microsoft: Clarity, the session recording and heat maps described above (United States).
- OpenRouter: routes our requests to those models.
- Cal.com: if you book a call with us.
- Telegram: if you contact support there.
Some of these are in the United States, so data reaches the US. We do not sell your data or share it with anyone for their own marketing.
How long we keep it
Account and content data stays while your account is open, because the product needs it to work. Ask us to delete it and we will, along with the account. Write to support@onlytool.ai. You can also ask for a copy of what we hold. We answer within 30 days.
Two exceptions, and we would rather write them down than let you discover them. The activity log and the saved AI messages described above both outlive the account on purpose. They are the record of why accounts leave, and a record that vanishes with its subject cannot answer the one question it was kept for. So when we delete an account we delete the account itself, your email address, your creators and their content, and we leave two things behind. The first is the timeline: the moments, the short names of what happened, and the internal ids they happened to. It holds no email address, no password or OnlyFans credential, no fan message, no vault content and no money figure from your account, and the only wording in it is the error text OnlyFans or our own connector returned on a failed connection. The second is the copy of the last messages the AI sent, which holds our own outgoing words and what they were priced at, the fan's numeric id, and never the fan's side or the fan's name. We keep both for 12 months after the account closes, which is long enough to compare a season against the same season a year before, and then we delete them too. If you would rather they went with the account, say so when you ask us to delete and we will remove both then instead.
Security
Traffic is encrypted in transit and data is encrypted at rest. Passwords are hashed with argon2id. Access to production data is limited to the people who operate the service.
Your rights
You can ask for access to your data, correction of it, deletion of it, a portable copy, or object to a particular use. Write to support@onlytool.ai. If you are in the EEA or the UK and think we have handled your data badly, you can also complain to your local data protection authority.
Changes
When this page changes, the date at the top changes with it. If a change matters to you (a new processor, a new purpose), we will tell you by email rather than leave you to find it.
Contact
support@onlytool.ai reaches a person.