This notice supplements the OnStat Privacy Notice for the OnStat Connect browser extension. It describes the extension's current permissions and data handling.
1. What the extension does
OnStat Connect allows an authenticated OnStat user to connect a creator-platform account to
the Service. It uses the browser’s storage and cookie permissions and access to the
configured creator-platform and app.onstat.io domains.
The current manifest requests:
storage, to retain OnStat login/session state, selected tenant, user details, theme, and connection status in the extension; andcookies, to retrieve creator-platform cookies needed for an authorized connection.
The current manifest does not request webRequest.
2. Data collected and transmitted
When used, the extension may handle:
- an OnStat email address and password transiently during sign-in; the password is sent directly to the OnStat authentication endpoint over HTTPS and is not stored in extension storage;
- OnStat access token, user ID/email, tenant list, selected tenant, and role/context;
- creator-platform account ID, username, profile identifiers, and user-agent information;
- all creator-platform cookies returned through the permitted cookie API, including authenticated session and fingerprint-related values;
- connection status, timestamps, errors, and diagnostic metadata; and
- dynamic creator-platform request-signing or configuration values extracted from the web application and submitted for OnStat’s connection service.
These values are transmitted over HTTPS to app.onstat.io / the OnStat API and stored or
used under the main Privacy Notice, DPA, and supplied
Security Measures. Retention is described in
Privacy Notice section 9 and DPA section 11.
The extension code itself is not designed to scrape the visible DOM of private messages for local collection. However, after a creator account is connected, the OnStat backend may synchronize message text and other account data through authenticated platform endpoints if the Customer enables those features. The extension notice must not be read as saying that the OnStat Service as a whole never processes messages.
3. Purposes
Data is used to:
- authenticate the OnStat user and select the correct tenant;
- establish and maintain the authorized creator-account connection;
- obtain required connection/signature configuration;
- diagnose connection failures and protect against misuse; and
- provide the Service features selected by the Customer.
The extension does not sell browser data, inject advertising, or use creator-platform session cookies for an unrelated purpose.
4. Highly sensitive credentials
Creator-platform session cookies can allow account access. Do not use the extension in a shared or untrusted browser profile. Log out and disconnect the account when access is no longer authorized. Report a lost device, suspicious session, or former staff access immediately.
OnStat must complete the database and application-layer credential-encryption launch gates in the Security Measures before describing these values as encrypted at rest.
5. Retention and deletion
Authentication and cached creator identity values are removed from extension storage on logout or authentication expiry. Other extension-local preferences remain until extension removal or browser-data clearing. Server-side session material is retained only while needed for the connection and is deleted according to Privacy Notice section 9 and DPA section 11.
Uninstalling the extension does not by itself delete server-side OnStat data. Use account deletion/disconnect controls or contact [email protected].
6. Sharing
Data is shared with OnStat infrastructure and subprocessors needed to run and secure the Service. Connected-platform data may be sent back to that platform to perform Customer-authorized actions. AI providers receive data only through separately enabled server-side AI features, not merely because the extension is installed.
7. User choices and rights
The extension operates only after installation and user sign-in. You can decline to connect an account, disconnect it, log out, clear extension storage, or uninstall the extension. Privacy rights and contact routes are described in the main Privacy Notice.
8. Platform independence
OnStat is an independent third-party management and analytics service used with creator-authorized accounts. OnStat is not affiliated with or endorsed by OnlyFans. Customers must comply with applicable platform terms. OnStat may restrict or disable functionality in response to platform requirements, security controls, or legal risk.
Technical compatibility does not establish platform permission. The applicable platform rules and disclaimer appear in the B2B Terms.
9. Contact
Privacy: [email protected]
Security: [email protected]
Support: [email protected]