Cookie Policy
Minimal cookies, maximum privacy. Only essentials for theme, language, and secure Email OTP session.
1. Introduction
Funtoosh uses minimal cookies and local storage to provide anonymous messaging, Email OTP login, wallet recharge, paid messaging, and advertisements. We do not use tracking or advertising cookies. This policy explains what we store, why, and your controls, in line with ePrivacy Directive principles and DPDP Act.
2. Definitions
- Essential Cookies: Required for core functionality like theme, language, and secure session.
- Local Storage: Browser storage for public key cache, drafts, and UI preferences, local only.
3. Essential Cookies
| Name | Purpose | Duration | Type |
|---|---|---|---|
| funtoosh_theme | Light/Dark/System preference | 30 days | Essential, SameSite Lax |
| funtoosh_lang | Language EN/HI/ES/FR/DE/AR/JA/PT | 1 year | Essential |
| funtoosh_server_session | Secure session for Email OTP login (server-signed, not readable by scripts) | Session / 1 year | HttpOnly, Secure, SameSite Lax |
4. No Tracking Cookies
We explicitly do NOT use:
- Google Analytics, Mixpanel, Amplitude, Facebook Pixel, TikTok Pixel, Google Ads tags
- Third-party advertising cookies or cross-site trackers
- Fingerprinting scripts or behavioral profiling cookies
Future optional privacy-preserving analytics, if ever introduced, will be self-hosted, no cookies, opt-in only, and disclosed here per Transparency Page.
5. Local Storage & IndexedDB
- Public key cache (your own) for encryption
- Message drafts local only, never sent to server until you send
- Theme and language preferences duplicate for fast paint
- User wallet balance cache for offline display, synced on login
All local data can be cleared via Settings → Privacy → Clear Local Data without losing account, as keys remain in secure storage and session can be restored via Email OTP login.
6. Local Cache
Funtoosh does not install a service worker or an offline cache. Your browser's normal HTTP cache may keep static assets (icons, fonts, hero images) for faster loads; no personal data, no messages and no wallet data are ever cached by the site itself. Push notifications are delivered only by the Funtoosh Android app, which stores a device token for that purpose.
7. Your Control
- Browser: Settings → Privacy → Clear cookies or block third-party cookies; Funtoosh remains functional with essential cookies only.
- In-app: Settings → Privacy → Reset Preferences clears theme and language, keeps session.
- Do Not Track: We respect DNT header; we already do not track, but we log DNT respect for transparency per Privacy Policy.
- Opt-out: No opt-out needed for tracking as we do not track; essential cookies cannot be disabled without losing session.
8. User Responsibilities
- Keep device and browser updated to ensure secure cookie handling.
- Do not share Email OTP or session cookies; keep email secure.
- Clear local data on shared devices after logout via Dashboard → Logout.
9. Platform Responsibilities
- Use only essential cookies, no tracking, transparent disclosure here and in Privacy Policy.
- Secure cookies with HttpOnly, Secure on HTTPS, SameSite Lax, and short expiry where possible.
- Provide clear controls for clearing storage and resetting preferences.
- Monitor for abuse and ensure service worker does not cache sensitive data.
10. Changes to This Policy
If we introduce any non-essential cookies in future (unlikely given privacy-first approach), we will update this policy, post at /cookies, show banner for consent where required by ePrivacy, and maintain version history. Continued use after effective date implies acceptance.
11. Contact Information
- General Support: [email protected] — Response 24-48h
- Privacy Team: [email protected]
- Grievance Officer: [email protected] — 15 days per IT Act, details at /grievance-redressal
Effective Date: July 31, 2026 • Last Updated: July 31, 2026 • Built on a privacy-preserving architecture.
Grievance Officer (IT Rules 2021)
Somesh Mishra
D 24/8, Himalay Bhawan,
Shatabdi Nagar, Panki,
Kanpur,
Uttar Pradesh – 208020,
India
Email: [email protected]
Phone: +91 94540 43072 (10 AM – 6 PM IST)
Statutory timelines we work to: acknowledgement within 24 hours; disposal within 15 days; prohibited content under Rule 3(2)(b) within 72 hours; non-consensual sexually explicit or morphed content under Rule 4(1)(p) within 24 hours; court or government orders under Rule 3(1)(d) within 36 hours. Removed content and the associated records are retained for 180 days for investigation purposes. These are the limits set by law for us to act within; they are not a guarantee of any particular outcome on any particular report.
Before we remove or disable content on our own initiative, Rule 4(8) requires us to notify you with reasons and give you a reasonable opportunity to dispute it. Automated tools may flag content, but a human reviews before any account-level action is taken. See the Transparency Report.
Your rights under the DPDP Act 2023
- Notice and consent (§5): we tell you what we collect and why before you agree, and you can withdraw consent at any time in Settings.
- Purpose limitation (§4, §6): your data is used only for running Funtoosh, safety, payments and legal obligations — never sold, never used to build advertising profiles.
- Access and correction (§11): you can view and correct your profile data in Settings.
- Erasure (§12): you can delete your account from Settings → Account. See Data Retention for what the law requires us to keep afterwards, and for how long.
- Retention limit (§8(7)): we erase personal data once the purpose it was collected for is over, unless a law requires us to keep it.
- Grievance redressal (§13): write to the officer named above, or use Grievance Redressal. Unsatisfied with the decision? Appeal to the Grievance Appellate Committee within 30 days. Data protection queries: [email protected].
Age: Funtoosh is for users aged 18 and over. Under the DPDP Act 2023 a person under 18 is a Child and we do not knowingly create accounts for them. No guarantees: Funtoosh is provided on an as-is basis. Nothing on this page is a guarantee of any specific result, earning, delivery time or moderation outcome.