Privacy Policy
This English translation is provided for convenience only. The French version shall prevail in the event of any discrepancy.
Last updated: April 2026
1. Introduction and Identity of the Data Controller
The purpose of this Privacy Policy is to inform users of the EXODE service (hereinafter "the Service") about how their personal data is collected, processed and protected, in accordance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and the French Data Protection Act of 6 January 1978 as amended.
The data controller for the personal data is:
AMESIA EURL
SIRET: 891 553 828 00015
Registered office: 370 avenue des Jeux Olympiques, 73620 Hauteluce, France
Email: support@exode.ai
2. Data Collected
In connection with the use of the Service, EXODE collects and processes the following categories of data:
2.1. Identification Data
- Email address
- Name and/or username
- Account type (owner or employee)
- Password (stored in hashed form only)
2.2. Session Data from Third-Party Platforms
- Session cookies and authentication tokens for the connected OnlyFans, Fansly and MYM accounts
- This data is stored locally on the user's device, in isolated Electron partitions
2.3. Messaging Data
- Messages exchanged with subscribers pass through the application for the purposes of display and operation of the Service
- EXODE does not store a permanent copy of text messages on its servers
- By way of exception, media exchanged via the Telegram module, including media sent by subscribers, is retained for the time necessary for the display and operation of the Service within the relevant conversation (see section 2.6)
2.4. Usage Data
- Technical logs (IP addresses, device type, application version)
- Billing data (top-up history, monthly deductions)
- Performance and error data (via Sentry, for debugging purposes)
2.5. AI-Related Data
- Messages submitted to the AI assistant are transmitted on a one-off basis to generate suggestions
- This data is not retained beyond the processing of the request
2.6. Telegram Media
- Media uploaded by the user to their Telegram library (photos, videos, voice messages) is stored on the Cloudflare R2 hosting infrastructure
- Media exchanged in conversations, including media sent by subscribers, is cached on this same infrastructure in order to ensure its display
- Library media is purged 30 days after deletion by the user; conversation media is retained for the time necessary for the display and operation of the Service within the relevant conversation
3. Purposes of Processing
The personal data collected is processed for the following purposes:
| Purpose | Description |
|---|---|
| Operation of the Service | To enable access to the Service, the management of creator accounts, messaging and the display of media. |
| Billing | To manage balance top-ups, monthly deductions and payment history. |
| Customer support | To respond to user requests and resolve technical incidents. |
| Newsletter | To send commercial communications (only with explicit opt-in). |
| Improvement of the Service | To analyse use of the Service in order to fix errors and improve features. |
| Artificial intelligence | To generate message suggestions via the AI Copilot. |
4. Legal Bases for Processing
Each data processing operation relies on a specific legal basis:
- Performance of the contract (Article 6.1.b of the GDPR): for the operation of the Service, the management of the user account and billing. The processing is necessary for the performance of the contract concluded between the user and EXODE (the Terms of Service).
- Consent (Article 6.1.a of the GDPR): for sending newsletters and commercial communications. Consent is collected by explicit opt-in and may be withdrawn at any time.
- Legitimate interest (Article 6.1.f of the GDPR): for the analysis of Service usage and technical monitoring (Sentry), in the interest of improving the quality and security of the Service.
- Legal obligation (Article 6.1.c of the GDPR): for the retention of billing data in accordance with accounting and tax obligations.
5. Recipients of the Data
The personal data is accessible only to the following recipients:
- The EXODE team: authorised members of the EXODE team, strictly to the extent necessary for the performance of their duties.
- Cloudflare, Inc. (hosting): the data is hosted on the Cloudflare infrastructure (Workers, D1, Pages, R2). Cloudflare acts as a data processor.
- Sentry (technical monitoring): error reports and technical logs are transmitted to Sentry for debugging purposes. No user content data is transmitted to Sentry.
- Emailing provider (where applicable): if the user has consented to receive the newsletter, their email address is transmitted to the sending provider.
EXODE does not sell, rent or share the personal data of its users with third parties for commercial or advertising purposes.
6. Transfers of Data Outside the European Union
The personal data is hosted on the servers of Cloudflare, Inc., whose registered office is located in the United States. Cloudflare has data centres throughout the world, including in Europe.
This transfer of data to the United States is governed by Standard Contractual Clauses (SCCs) adopted by the European Commission, in accordance with Article 46.2.c of the GDPR, ensuring an adequate level of protection for personal data.
Sentry, Inc., also located in the United States, is subject to the same contractual safeguards for the processing of technical data.
7. Data Retention Period
| Type of data | Retention period |
|---|---|
| User account data | For the entire duration of use of the Service + 1 year after deletion of the account. |
| Billing data | 10 years from the transaction, in accordance with French accounting and tax obligations. |
| Session data (third-party platforms) | Stored locally. Deleted upon logout from the platform account or uninstallation of the application. |
| Telegram media | Library: purged 30 days after deletion by the user. Conversation media (including media sent by subscribers): retained for the time necessary for the display and operation of the Service within the relevant conversation. |
| Technical logs and error reports | 12 months maximum. |
| Newsletter data | Until consent is withdrawn (unsubscription). |
Upon expiry of the retention periods, the personal data is deleted or irreversibly anonymised.
8. Data Security
EXODE implements appropriate technical and organisational measures to protect personal data against any unauthorised access, loss, alteration or disclosure:
- Encryption of communications: all data is transmitted via HTTPS (TLS 1.2 minimum).
- Password hashing: passwords are hashed using the PBKDF2 algorithm, making it impossible to recover them in plain text.
- Session isolation: third-party platform sessions are isolated in separate Electron partitions, preventing any cross-access between accounts.
- Secure authentication: user sessions are protected by time-limited JWT tokens (24 hours) with a blacklist system for invalidation.
- Restricted access: access to the data is limited to authorised members of the EXODE team only, in accordance with the principle of least privilege.
9. Cookies
The exode.ai website uses exclusively technical cookies necessary for the operation of the Service. No advertising or tracking cookies are used.
For more information about cookies, please see our Cookie Policy.
10. Your Rights
In accordance with the GDPR and the French Data Protection Act, you have the following rights over your personal data:
- Right of access (Article 15 of the GDPR): to obtain confirmation that data concerning you is being processed and to receive a copy of it.
- Right of rectification (Article 16 of the GDPR): to request the correction of inaccurate or incomplete data.
- Right to erasure (Article 17 of the GDPR): to request the deletion of your personal data, subject to legal retention obligations.
- Right to portability (Article 20 of the GDPR): to receive your data in a structured, commonly used and machine-readable format.
- Right to object (Article 21 of the GDPR): to object to the processing of your data based on legitimate interest.
- Right to restriction (Article 18 of the GDPR): to request the restriction of the processing of your data in certain cases provided for by law.
- Right to withdraw your consent: at any time for processing based on consent (newsletter), without affecting the lawfulness of the processing carried out before the withdrawal.
To exercise your rights, send your request to: support@exode.ai, enclosing proof of identity. EXODE undertakes to respond within 30 days of receipt of your request.
11. Newsletter
Subscription to the EXODE newsletter is optional and relies on an explicit opt-in. Under no circumstances will the user's email address be added to a mailing list without their prior consent.
The user may unsubscribe from the newsletter at any time by clicking on the unsubscribe link present in each email, or by sending a request to support@exode.ai.
12. Amendments to the Privacy Policy
EXODE reserves the right to amend this Privacy Policy at any time in order to reflect changes to the Service or to legal obligations. Any substantial change will be communicated to users by email or by notification within the application.
The date of the last update is indicated at the top of this page. We encourage users to consult this page regularly.
13. Contact and Complaints
For any question regarding the protection of your personal data or to exercise your rights, you may contact our data protection officer (DPO):
Email: support@exode.ai
Address: 370 avenue des Jeux Olympiques, 73620 Hauteluce, France
If you consider that the processing of your personal data constitutes a breach of the GDPR, you have the right to lodge a complaint with the competent supervisory authority:
Commission Nationale de l'Informatique et des Libertes (CNIL)
3 Place de Fontenoy, TSA 80715
75334 PARIS CEDEX 07
Website: www.cnil.fr