20MG
← BackLegal

Privacy Policy

Last updated: 15 August 2026

1. The short version

You tell us about yourself so we can decide whether we can help. We read it, we reply, and we don't do anything else with it. We don't sell it, we don't share it for anyone's marketing, and we don't tell anyone you contacted us.

The rest of this page is the detail behind that.

2. Who is responsible for your information

Twenty Management Group is responsible for the personal information you send us. We are registered in the United States and work with creators in the United States, the United Kingdom, Australia and Canada, which means we are subject to applicable United States state privacy law — and, where we handle the information of people in those countries, to regimes such as the Australian Privacy Principles and the UK GDPR. Where those regimes differ, we apply the stricter standard rather than the more convenient one.

Privacy questions or requests: hello@20mg.co.

3. Enquiry-button measurement

We count clicks on the standalone chatting page’s enquiry buttons to understand which parts of the page help visitors contact us. These events contain only the button position, a fixed page name and whether the event is a test. We do not add visitor identifiers, IP addresses, email addresses, browsing histories or cookies to these analytics events. Cloudflare processes the network request to deliver and protect this service.

A button click does not tell us whether an email was sent. This measurement respects browser Do Not Track and Global Privacy Control signals.

4. What we collect

When you apply or contact us, we collect:

  • Your name, email address and telephone number
  • Your main social handle and which platform it is on (Instagram, X or TikTok), if you choose to give it
  • Whether you already have an OnlyFans page and, if you do, any monthly revenue figure you choose to give us and whether you currently have an agency
  • Anything else you write in the free-text field
  • Your confirmations that you are at least 18 and agree to be contacted about your application
  • Technical request data processed by Cloudflare to deliver and protect the site, such as IP address, user agent, request timing and rate-limiting signals. We do not add your IP address or user agent to the application record stored in Notion

5. Age verification at onboarding

If we take you on, we ask for government-issued photo identification once, at onboarding. It has one purpose: confirming you are over 18. The laws around underage content are strict and absolute, the platforms require this verification, and we will not work with anyone whose age we have not confirmed. There are no exceptions to this for anyone, under any circumstances.

It is never requested through this website or the application form — only later, through a secure channel we set up with you directly, once you have decided to proceed.

We use it for that check and nothing else. It is never used for marketing, never shared outside the people who must complete the verification, and never passed to anyone else except where a platform's own verification requires it or the law compels us.

6. What we never collect through this website

Do not send government ID, banking details, payment card numbers or explicit material through this website or the application form. We do not ask for them here, we do not want them here, and if you send them anyway we delete them.

Identity verification is a real part of onboarding (see above) — but it happens later, once you have decided to proceed, through a secure channel we set up with you. A web form is the wrong place for a passport, and anyone in this industry who asks you to upload ID to a public form should be treated with suspicion.

7. Why we use it

Only for these purposes:

  • Assessing whether your application is a fit for us
  • Contacting you about your enquiry
  • Preparing a proposal if we take it further
  • Meeting our legal and record-keeping obligations

8. What we never do

We do not sell, rent, trade or share your information for anyone else's marketing. We do not add you to a mailing list because you enquired. We do not tell anyone that you approached us — including other creators, other agencies, and anyone who asks.

We do not use your information to train any automated or machine learning system.

9. Who sees it

Only the people inside our team who need it to assess and respond to your enquiry, and the service providers needed to run the form: Cloudflare processes the submission and technical request data at the website boundary, and Notion stores the accepted application. Their access is limited to providing those services and governed by their contractual privacy and security obligations.

Beyond that, we disclose your information only with your explicit consent, or where a law or a court order compels us. If we are ever compelled, we will tell you unless we are legally prohibited from doing so.

10. Where it is held

Accepted applications are stored in our restricted Notion workspace. Before storage, Cloudflare processes the form submission and technical request data to serve the site, enforce the form's security checks and apply technical rate limits.

Cloudflare, Notion and their service providers may process or store information in countries outside your own, including the United States. If you are outside the United States, this is an international transfer. We take reasonable steps to ensure the information is handled consistently with applicable safeguards and the privacy rules of your country, including the Australian Privacy Principles or UK GDPR where they apply.

11. How long we keep it

If we decline your application, it is deleted within a week. We don't keep a file on people we aren't working with.

If we take you on and you later leave, everything we hold on you is deleted within 30 days of sign-off — your application, your details and your verification documents.

The only exception is where the law requires us to retain a specific record for longer. You can ask us to delete something sooner and we will, unless that same exception applies.

12. Security

We take reasonable technical and organisational steps to protect your information against loss and unauthorised access. This site is served over HTTPS, and access to applications is restricted.

No transmission over the internet is perfectly secure and we won't pretend otherwise. If you would rather not put sensitive detail in a web form, email us instead — or say less in the form and tell us the rest on the call.

13. Changes to this policy

We may update this policy. The version published here, with the date at the top, is always the current one. If we make a change that materially affects how we handle information you have already given us, we will contact you about it.

14. Contact

Twenty Management Group

hello@20mg.co