Privacy Policy
This policy explains what Fyreflock collects, what we deliberately don’t collect, and what control you have. Fyreflock is built so that the most sensitive things, meaning your conversations, are unreadable to us even where they pass through our machines.
What we never see
- Your conversations with strangers. Video, audio, and typed messages flow peer-to-peer directly between you and the other person wherever the two networks allow it, on calls and in text chat alike. Roughly one call in seven cannot connect that way and is forwarded by our TURN relay instead. The relay passes the stream on without being able to open it: WebRTC encrypts it end to end between the two devices, so a forwarded call is as unreadable to us as a direct one. We do not record, store, or read them.
- Your friend messages. They are stored only on your device and delete themselves on a timer you choose (1 to 24 hours, 24 being the hard maximum). If your friend is offline when you send one, the message waits on our relay and is deleted the moment it’s delivered, or within 24 hours if it never is. While it waits it is readable by us in principle, so we hold it for as short a time as delivery allows and never longer.
- Your face, as biometric data. The camera check runs entirely inside your browser and no image is uploaded or stored. It looks for a moving, non-blank picture, which is a check on the camera rather than on you: it does not recognise a face, identify anyone, or confirm an age.
- We do not sell your personal data, and we do not run third-party advertising or tracking pixels.
What we do collect
- Account: email address, username, an auto-generated display name, date of birth, region, and optional gender.
- Preferences: interest tags, matching preferences, and message-timer setting.
- Usage: when you were online, who you were matched with and when, friendships, and anonymous quality ratings. We keep the fact that a match happened, never its contents.
- Safety: reports you file or receive, including the evidence described below; ban records; a device identifier and IP address used to enforce bans.
- Payments: which pass you bought, when it expires, and the payment reference. Card, UPI, and wallet details go directly to our payment processor. We never see or store them.
Reports and evidence
When someone files a report, we store a still frame of the reported person’s video from that moment, the text chat from that call, both account identifiers, and the reporter’s note. This is the one situation where content from a call is retained. Evidence is used solely to investigate, to enforce our rules, and where legally required to assist law enforcement. Resolved report evidence is deleted within 12 months unless a legal obligation requires us to keep it longer.
Who we share data with
We use a small number of service providers, each with a narrow purpose:
- Razorpay: payment processing (they receive your payment details, we don’t).
- Resend and Zoho: sending your login codes and our replies by email.
- Google: only if you choose to sign in with Google. They tell us your email address and a stable identifier for your account, and they know you signed in here. Signing in with a code by email instead means Google is never involved.
- Vultr: server hosting. Cloudflare: DNS and protection against attacks.
- STUN/TURN relays: these help two devices find each other. When a direct connection is impossible, a relay passes the encrypted stream through without being able to read it.
We also disclose information when the law compels us, or to report child sexual abuse material to NCMEC and law enforcement.
Cookies and local storage
We set one essential cookie to keep you signed in. Your browser’s local storage holds your preferences (mode, theme acknowledgements, device identifier) and your message history. No advertising or analytics cookies.
How long we keep things
- Account data: until you delete your account.
- Messages: on your device only, maximum 24 hours. Undelivered relay messages: maximum 24 hours.
- Match records: retained for safety investigations, then removed.
- Report evidence: up to 12 months after resolution. Ban records: retained to keep bans effective.
- Payment records: as long as tax and accounting law requires.
Your choices
- Burn your chats now: one button in Settings wipes every conversation from your device.
- Shorten the timer: set messages to vanish in as little as one hour.
- Delete your account: Settings → Leaving, and it happens immediately. Your profile, username, tags, friendships, stored messages, sessions and preferences are removed. You can also email [email protected] and we’ll respond within 30 days.
- What survives a deletion, and why: reports other people filed about you, because those are their safety record rather than yours to erase; payment records we’re required to keep; and a one-way hash of your email address and device. A hash cannot be read back into an address or turned into a profile. It answers exactly one question when somebody signs up: has this person been here before, and did they leave with a ban or an unresolved report. That is what stops the delete button being a way to shed a ban, and it is the only thing we keep for it.
Under-18s
Fyreflock is for adults. We do not knowingly hold data for anyone under 18, and an account we learn belongs to someone under 18 is deleted along with everything it created.
We ask for a date of birth at signup and keep it, because it is what the age rule is enforced against and the record that it was. This policy previously described data held for 16- and 17-year-old account holders, which was accurate while the account floor was sixteen. It is not any more.
Changes and contact
We’ll post updates here and announce material changes in the app. Privacy questions: [email protected].