MyPersonas / AliaSpaces

Privacy Notice

This notice explains the data the current MyPersonas / AliaSpaces service uses, what can be public, and what happens when you connect an external account or an AI provider.

Effective July 28, 2026
Current connector scope matters. Gmail mailbox tools are deployed but remain subject to Google's test-user or production-verification gate. X identity/read authorization code is deployed but cannot accept connections until its developer credentials and current API access are installed. The Meta foundation can pair Facebook Pages and Page-linked professional Instagram accounts only after its Business app credentials are installed; it does not have publishing permission. Other provider records are private planning inventory until an official connector is added. A saved account name, email match, password, or cookie is never treated as provider authorization.
Private owner recordYour AliaSpaces sign-in is linked to your data internally, but the owner is not displayed on public persona pages.
No external passwordsDo not give MyPersonas passwords, recovery codes, API secrets, or session cookies for social, creator, or mailbox accounts.
You control actionsScheduled AI work creates drafts. Mailbox changes require a separate exact preview and owner approval.

1. Who operates this service

This notice uses MyPersonas / AliaSpaces as the operator label for the website, persona network, private management studio, and related automation features.

The service uses Supabase for authentication, database records, server-side Edge Functions, encrypted secret storage through Supabase Vault, and media storage.

2. Information handled by the service

Sign-in and private account information

Persona and social content

Saved external-account inventory

The private account ledger can contain a provider name, username, login email, profile URL, persona assignment, notes, and connection status. It is designed for identifiers and planning—not credentials. Do not enter provider passwords, app passwords, recovery codes, API keys, or browser cookies.

Connected provider data

Diagnostics you choose to submit

The in-app Report a problem control sends your note, the current page route, up to 200 characters of browser user-agent information, and a short list of recent in-app error or status messages. When you are signed in, the report can include your user identifier; signed-out reports have no account identifier.

3. How information is used

4. What is public and what is private

Your profile and owner-to-persona relationship are private database records protected by owner-based access rules. Public and unlisted persona pages can expose the content, links, interactions, and profile details you put on those pages. Private persona visibility restricts the page, but it is not a promise of absolute anonymity.

Uploaded media uses a public media bucket. Treat an uploaded media URL as public even when it appears on a private or unlisted persona. Do not upload material that must remain confidential.

Other people, search engines, external links, or caches can retain copies of public material. Avoid including identifying information if separation between personas matters to you.

5. OAuth, tokens, and external accounts

Official provider authorization redirects you to the provider’s own sign-in and consent page. MyPersonas receives authorization results and tokens, not the password you enter on the provider page.

For providers without an official connector—including OnlyFans and Signal—MyPersonas can hold private planning records, links, drafts, and the posted/sent status you mark for staged items. It will not collect provider passwords, session cookies, or reverse-engineered login sessions.

6. AI processing

When you choose an AI backend, the relevant prompt, persona instructions, conversation content, or draft context is sent through a server-side proxy to that provider. Supported hosted endpoints can include OpenAI-compatible services, Anthropic, Azure OpenAI, Google Gemini endpoints, OpenRouter, xAI, Groq, Mistral, DeepSeek, Together, Fireworks, and explicitly approved custom hosts. Which provider receives data depends on the model connection you select.

Optional AI mailbox classification is off until you select a model for that mailbox and accept the mailbox-specific disclosure. It sends only bounded sender/subject/preview-snippet inputs for ambiguous messages—not full bodies or attachments. A custom mailbox AI host needs separate confirmation.

If you use a locally configured Stable Diffusion endpoint, the prompt is sent to the endpoint URL stored in that browser. A generated image is uploaded to the public media bucket only when you choose to save it.

AI providers process submitted data under their own terms and privacy notices. Avoid sending secrets or information you are not permitted to disclose.

7. Service providers and third-party requests

Data can be transmitted to:

The current application does not include a behavioral-ad tracking or personal-data sale workflow.

8. Browser storage and cookies

The current web client uses browser local storage and session storage for the Supabase sign-in session, content filters, selected local endpoint, owner-chat backup, OAuth same-tab binding, age-gate choice, and a random fan-chat visitor token. Session items normally end with the browser tab; local items remain until cleared by the feature, content erasure where applicable, or your browser’s site-data controls.

MyPersonas does not import or store session cookies from external social, creator, or mailbox accounts. Supabase Auth, provider sign-in pages, and embedded third-party content can use their own cookies or browser storage under their notices.

9. Security safeguards

The current design uses HTTPS provider flows, Supabase row-level access rules, owner-bound server functions, encrypted Vault storage for connector tokens and model keys, limited service-role access, exact-action approvals, safety pauses, and audit records. Sensitive OAuth tables are not readable by ordinary browser roles.

No system can guarantee perfect security. Protect your AliaSpaces sign-in, enable two-factor authentication when available, review connected applications at each provider, and report unexpected activity without including credentials.

10. Retention and deletion

Owner content and operational records generally remain until you remove them, clear the relevant history, remove the connected account, or use the content-erasure control. Short-lived authorization, scan, lease, and action-preview records expire according to their task. Gmail scan checkpoints are bounded to seven days, action previews to 24 hours, and the current Gmail undo window to no more than 28 days.

Deleting all content removes owned personas, pages, posts, albums, media, account inventory and connections, drafts, schedules, linked models and encrypted credentials, automation/chat history, display name, preferences, and owner problem reports. The in-app content-erasure control intentionally retains your Supabase sign-in record.

For complete steps, provider revocation links, and sign-in deletion instructions, see the Data Deletion Guide.

11. Your choices and controls

12. Children and adult content

MyPersonas is not directed to children under 13, and children under 13 should not create accounts or use public fan chat. Do not submit a child’s personal information through the service.

Adult/NSFW persona features are for adults age 18 or older. The current 18+ page prompt is a visitor self-attestation, not identity-based age assurance. Public AI fan chat remains disabled for NSFW personas. Users are responsible for complying with provider rules and applicable age, consent, and content laws.

13. Affiliate and sponsored content

MyPersonas can store approved links, offers, and disclosure language and can display sponsored or affiliate destinations. The persona owner is responsible for accurate, prominent disclosures and for following the destination platform’s advertising, endorsement, and affiliate rules. A link stored in MyPersonas is not an endorsement or verification of the offer.

14. Privacy questions and changes

Use the Report a problem button in the MyPersonas / AliaSpaces application and begin the note with “Privacy.” Do not include passwords, provider tokens, recovery codes, payment information, or other authentication secrets.

Material changes to connected providers or data uses should be reflected here with a new effective date before the new behavior is relied on.