Privacy
This notice explains what we do with personal data on the OFM-Brain website and inside the product. It is written to be read, not to be survived.
Who we are
OFM-Brain is operated by Zero Percent Models ("we", "us"). We are the data controller for the personal data described here. For anything in this notice, including any request about your data, write to sam@ovington.io.
What we collect
If you request access: the email address you submit, and the name and agency-size range if you choose to give them, plus which page you submitted from.
If you are a member: the email address on your account, the chats you create (your questions and the answers returned), and any notes or links you submit to the shared library.
Automatically: standard server logs kept by our hosting provider, which include IP address and request metadata. We run no analytics, no advertising pixels and no third-party trackers, and we set no cookies beyond the session cookies required to keep you logged in.
Why we use it, and our lawful basis
Access requests. To contact you about access to OFM-Brain. Lawful basis: legitimate interests, namely responding to a business enquiry you initiated. You can object at any time (see below) and we will stop.
Running the product. To authenticate you, keep your chat history, and generate answers. Lawful basis: performance of our contract with you or your agency.
Keeping it working and secure. Server logs, rate limiting and abuse prevention. Lawful basis: legitimate interests in keeping the service available and not abused.
We do not sell personal data, rent it, share it for advertising, or add you to unrelated mailing lists. We do not use it for automated decision-making that produces legal or similarly significant effects.
Who else processes it
We use a small number of providers who process data on our behalf:
- Vercelhosts the site and runs the server code. Our functions are pinned to Vercel's London region.
- Supabase provides authentication and the database, hosted in the London (eu-west-2) region.
- OpenRouter, which routes to the model provider xAI, generates the answers. When you ask a question, your message and the vault excerpts selected to answer it are sent to them for that request. If a shared-library submission is used as an excerpt, the submitting member's email address can appear in it.
- If you connect an agency tool, we read from it on your behalf. Those providers are OnlyFansAPI, OnlyMonster, Zernio, Metricool and Postpone. The connection is yours: you paste your own key, we store it encrypted, and we only ever read — we do not post, message or spend on your behalf. Nothing is sent to a tool you have not connected, and disconnecting one deletes both the key and the data we pulled from it.
We do not use your content to train any model, and we do not sell or share it with anyone outside this list.
Performance data from your connected tools
When a tool is connected we pull the numbers behind your dashboard: earnings and transactions, message and campaign counts, per-chatter response times and volumes, post and follower analytics. We deliberately do not pull fan identities, chat transcripts or message text into the answers — where a provider sends them anyway, they are dropped at the point the record is written, and what reaches the AI model is numbers and creator names only.
Some providers can push events to us in real time instead of us asking. Those deliveries are signature-verified, and the raw delivery is kept for 30 days so a figure can be audited or recalculated, then deleted automatically. The numbers derived from it stay for as long as your account does.
Per-chatter performance data is about identifiable staff. If you connect a tool that reports it, you are the controller for that data and should tell your team what is measured and why.
Data leaving the UK
OpenRouter and xAI are based in the United States, so question and excerpt content is transferred outside the UK when an answer is generated. The United States does not have full UK adequacy, so these transfers rely on the providers' standard contractual terms as the safeguard. Ask us and we will point you to the current terms. Hosting, authentication and the database stay in London.
How long we keep it
Access requests: until you are onboarded, you ask us to delete the entry, or it is clearly stale, whichever comes first. Member accounts, chats and submissions: for as long as the account is active, and deleted on request or when the account is closed. Server logs: for the retention period set by our hosting provider, which is short and measured in weeks rather than years.
Your rights
Under UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or hand it over in a portable format. Email sam@ovington.io from the address concerned and we will action it, usually the same day and always within one month. There is no charge.
Your right to object
Where we rely on legitimate interests, including holding your access request, you have the right to object to that processing at any time. Tell us and we will stop unless we have compelling grounds that override your rights. Say the word and the entry is gone.
Complaints
If you think we have handled your data badly, tell us first and we will try to put it right. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113.
Security
Access is invite-only and enforced twice, at the edge and inside every server route. Member chats and submissions are isolated per account with row-level security in the database. The public site holds no vault content. The security page covers this in detail. If a breach affects your data and is likely to be a risk to you, we will tell you and the ICO within the timescales the law requires.
Changes
If we change how we use personal data we will update this page and move the date at the top. Material changes affecting members will also be emailed.