Model Pilot

Privacy and Data Use

Privacy Policy

This Policy explains how Umbrella AI LLC processes data for Model Pilot on model-pilot.com.

Base effective date: 2026-09-09 Base version: 2026.09 Social integration notice updated: 2026-10-11 Commercial creator service

Supplemental notice 2026-10-11-social-integrations-v1 describes existing connected-platform processing. It does not activate an integration, change granted permissions, or enable AI automation. The base account agreement, billing and regional eligibility rules remain unchanged.

2Our Data Roles

Umbrella determines how it uses account, security, support, product-administration, and business records. For Fanvue, Instagram (Meta), and X messages, audience profiles, comments, publishing content, and related interaction data processed under a creator's settings and instructions, Umbrella generally acts as a processor or service provider for that creator.

3Data We Process

  • Account data: email, username, password hash, account settings, policy-acceptance version and time.
  • Connected-platform authorization and profile data: Fanvue UUIDs, Instagram professional-account and app-scoped identifiers, X user identifiers, account names, handles and profile details returned by authorized APIs, granted OAuth permissions, access and refresh tokens, connection status and expiry information.
  • Audience and conversation data: platform-scoped participant, conversation and message identifiers; received and sent message content; timestamps; reply and Story context; attachments; and available read, reaction, edit or deletion events. Fanvue workflows may also store subscriber/follower segments, language, interaction history, summaries and profile notes. Each platform exposes different fields and history windows.
  • Publishing, comments and engagement data: drafts, captions, selected targets and media, schedules, delivery status, remote post or Story identifiers and links, comment and reply content, authors and timestamps, and available engagement values such as likes, comment counts and follower counts where returned. Model Pilot records API/webhook observations and read errors; missing or unavailable values are not treated as zero. This notice does not promise an insights or growth dashboard.
  • Media and commerce context: attachment identifiers, URLs, uploaded originals and associated previews or derivatives, media type, price, currency, paid status, transaction/event context, and related metadata. Media may be retained locally or retrieved through an authorized provider connection for the requested feature.
  • Credits and usage data: Manager wallet balances, reservations and ledger entries, purchase references and status, amounts, currency, model identifiers, token counts, and timestamps.
  • Technical and security data: request metadata, IP address in security/access logs, browser/device information, timestamps, errors, audit events, and abuse-prevention signals.
  • Support and communication data: support requests, account emails, delivery status, and information you choose to provide.
  • Legacy billing records: historical plan, subscription status, invoice references, limited payment-method metadata, and transaction records from the former billing integration.

4Sources

We receive data from you, your team, your browser/device, Fanvue, Instagram/Meta and X through OAuth and authorized APIs/webhooks, service providers acting for us, and records generated when the Service operates. Data access depends on account type, permissions, platform approval, API availability and your settings; enabling a permission does not guarantee delivery of every event or access to historical data.

5Why We Process Data

  • Provide, personalize, maintain, and troubleshoot the Service.
  • Authenticate accounts and protect users, connected-platform integrations, and infrastructure.
  • Generate, schedule, route, and record creator-authorized publishing, manual messages, comments and other supported workflows.
  • Display authorized platform profiles, conversation history, available post engagement and delivery results, and reconcile supported API/webhook events.
  • Provide support, notices, and account administration.
  • Measure reliability, usage, and cost; prevent abuse and fraud.
  • Maintain entitlement, transaction, reconciliation, tax, audit, and legal records where applicable.
  • Improve features using appropriately limited operational information and creator-configured examples.

6AI and Automated Processing

For enabled Fanvue AI workflows, Model Pilot sends selected prompts, messages, summaries, media, and relevant context to configured AI or inference services to generate replies, classify intent, understand media, summarize conversations, and support creator workflows. Output may be stored with conversation and usage records. We limit context to what the requested feature needs, but creators must not submit data they are not authorized to process.

Instagram and X inboxes are manually managed. Their private messages and comments are not automatically passed to AI or used for model training simply because an account is connected. If you explicitly request an AI-assisted post caption, draft text, instructions, relevant workflow context, selected media derivatives or video frames and creator style examples may be sent to the configured AI or vision service. You select review or automatic publication for that caption workflow; automatic mode may publish the generated caption under the selected settings. Connecting an account does not enable automated Instagram or X replies.

Creators control whether and how automation is enabled and remain responsible for required AI/bot disclosures and review. Model Pilot does not make employment, credit, housing, insurance, health-care, or similarly regulated eligibility decisions about fans.

6aEncrypted X Chat

Where supported, an account owner can request read-only display of existing encrypted X Chat conversations using the official client library and the owner's existing keys. Model Pilot's backend uses the authorized connection to obtain public-key records, recovery authorization, conversation metadata, encrypted events and encrypted media. Existing-key recovery may involve X's configured recovery services.

The Chat PIN and private keys remain local to your browser and are not sent to or stored by the Model Pilot backend. Decrypted messages and media stay in that browser session and are not sent to the Model Pilot backend, AI services or training pipelines by this feature. The encrypted reader does not create or reset keys or send messages. It cannot guarantee access to every encrypted conversation: owner unlock, existing keys, platform permissions and browser/recovery-service availability are prerequisites.

7Credits and Billing Data

Model Pilot records shared Manager wallet balances, credit activity, purchase records, and metered AI usage to calculate charges and reconcile usage. No payment provider is connected and credit purchase checkout is currently unavailable. Fanvue fan subscriptions, tips, and content purchases remain separate platform interaction data.

Historical records from the former Stripe integration may remain available for invoice access, support, reconciliation, fraud prevention, and legally required retention. No new public checkout is offered through Stripe.

8Recipients and Service Providers

Depending on enabled features, recipients may include Fanvue, Meta/Instagram and X (OAuth, publishing, messaging, comments and other authorized platform APIs), X's configured encrypted-Chat recovery services for owner-requested browser recovery, Cloudflare (delivery and security), Resend or another email provider, hosting/database/backup providers, configured AI and inference providers for explicitly requested AI features, error logging or monitoring providers, and professional advisers where required.

Legacy Stripe records may continue to be processed for historical transactions. We do not sell personal data and do not use fan data for cross-context behavioral advertising.

9International Processing

Umbrella is a United States company and service providers may process data in the United States or other countries where they operate. Provider contracts and security measures are selected according to the data and service involved.

10Retention

We retain data only for as long as reasonably needed for the account, requested features, security, support, dispute resolution, reconciliation, or legal obligations. Retention depends on record type and creator configuration. Account deletion removes or schedules deletion of account-linked operational data, subject to limited backups, fraud/security records, legal holds, and historical transaction records that must be retained.

11Regional Availability

The Service is not offered to persons or businesses established in the European Union or European Economic Area and is not marketed there. Model Pilot does not use IP-based country blocking, Cloudflare country gates, billing-country checks, or invasive residence verification to enforce this restriction. Incidental technical access does not alter the intended market. If we become aware that an account does not meet the regional eligibility rule, we may restrict or terminate it.

12Cookies and Local Storage

We use technically necessary cookies and local storage for login security, sessions, CSRF protection, requested theme/interface preferences, and dismissal of the cookie information notice. We do not use analytics or marketing cookies on these public pages.

13Your Privacy Requests

Subject to applicable law and our role, you may request access, correction, deletion, or a portable copy of account data and may appeal or exercise additional state privacy rights where available. Send requests to support@model-pilot.com. We may need proportionate information to authenticate a request.

13aData Deletion Instructions

To request deletion of your Model Pilot account or data associated with a connected Instagram, X or Fanvue account, email support@model-pilot.com with the subject Data deletion request — Model Pilot. State whether you want account deletion or removal of a particular integration's data. Include your Model Pilot account email or identifier and, when relevant, the Model name and platform handle so we can identify the requested records.

We verify that you control the account or are authorized to make the request before deleting data, and may ask for proportionate confirmation. Do not send passwords, access tokens, PINs, or private keys. If your data appears in a creator's messages or comments, identify the creator and platform; we will handle the request according to our role and, where appropriate, coordinate with that creator.

You can also disconnect a platform in Model Pilot and revoke authorization using that platform's own controls. Disconnecting or revoking authorization does not delete your Model Pilot account or all previously stored messages, posts or media. A deletion request is separate. Platform-authenticated callbacks may remove connection-level records without covering all workspace history or media; for removal of all locally held integration data, use the support request above.

Deletion removes or schedules removal of the relevant operational data, subject to the retention limits described above, including backups, fraud/security records, legal holds and required historical transaction records. We do not promise an unsupported automatic purge period. Deleting Model Pilot data does not delete your original Instagram, X, or Fanvue account, nor necessarily remove posts or messages already delivered to those platforms; use their controls for provider-side removal. Support can confirm the scope and any required retention exceptions.

14Age Restriction

Model Pilot is a commercial creator service for companies, sole proprietors, and individual professional creators aged 18 or older. No formal business entity is required. The Service is not directed to children; do not create an account or submit children's personal data.

15Security

We use administrative, technical, and organizational safeguards designed for the sensitivity of the data, including access controls, encrypted transport, scoped OAuth, secret handling, audit records, and incident response. No system can guarantee absolute security.

16Changes and Contact

We may update this Policy as the Service, providers, laws, or business model change. The current version is published here. Material changes may also be communicated through the Service or account email. Questions and requests: support@model-pilot.com.