Cookie Policy
Minimal cookies, maximum privacy. Only essentials for theme, language, and secure Email OTP session.
1. Introduction
Funtoosh uses minimal cookies and local storage to provide anonymous messaging, Email OTP login, wallet recharge, paid messaging, and advertisements. We do not use tracking or advertising cookies. This policy explains what we store, why, and your controls, in line with ePrivacy Directive principles and DPDP Act.
2. Definitions
- Essential Cookies: Required for core functionality like theme, language, and secure session.
- Local Storage: Browser storage for public key cache, drafts, and PWA assets, local only.
- Service Worker Cache: Cache for offline PWA support, no personal data.
3. Essential Cookies
| Name | Purpose | Duration | Type |
|---|---|---|---|
| funtoosh_theme | Light/Dark/System preference | 30 days | Essential, SameSite Lax |
| funtoosh_lang | Language EN/HI/ES/FR/DE/AR/JA/PT | 1 year | Essential |
| funtoosh_session | Secure session for Email OTP and wallet | Session / 7 days | HttpOnly, Secure, SameSite Lax |
| funtoosh_pwa_dismissed | PWA install prompt dismissed state | 90 days | Essential |
4. No Tracking Cookies
We explicitly do NOT use:
- Google Analytics, Mixpanel, Amplitude, Facebook Pixel, TikTok Pixel, Google Ads tags
- Third-party advertising cookies or cross-site trackers
- Fingerprinting scripts or behavioral profiling cookies
Future optional privacy-preserving analytics, if ever introduced, will be self-hosted, no cookies, opt-in only, and disclosed here per Transparency Page.
5. Local Storage & IndexedDB
- Public key cache (your own) for encryption
- Message drafts local only, never sent to server until you send
- Theme and language preferences duplicate for fast paint
- User wallet balance cache for offline display, synced on login
All local data can be cleared via Settings β Privacy β Clear Local Data without losing account, as keys remain in secure storage and session can be restored via Email OTP login.
6. PWA & Service Worker Cache
Service worker caches static assets (/, manifest, icons, hero images) for offline support. Cache name: funtoosh-pwa-v1, max age 7 days, then revalidated. No personal data, no messages, no wallet data cached by service worker. Offline page shows cached landing with login prompt.
7. Your Control
- Browser: Settings β Privacy β Clear cookies or block third-party cookies; Funtoosh remains functional with essential cookies only.
- In-app: Settings β Privacy β Reset Preferences clears theme and language, keeps session.
- Do Not Track: We respect DNT header; we already do not track, but we log DNT respect for transparency per Privacy Policy.
- Opt-out: No opt-out needed for tracking as we do not track; essential cookies cannot be disabled without losing session.
8. User Responsibilities
- Keep device and browser updated to ensure secure cookie handling.
- Do not share Email OTP or session cookies; keep email secure.
- Clear local data on shared devices after logout via Dashboard β Logout.
9. Platform Responsibilities
- Use only essential cookies, no tracking, transparent disclosure here and in Privacy Policy.
- Secure cookies with HttpOnly, Secure on HTTPS, SameSite Lax, and short expiry where possible.
- Provide clear controls for clearing storage and resetting preferences.
- Monitor for abuse and ensure service worker does not cache sensitive data.
10. Changes to This Policy
If we introduce any non-essential cookies in future (unlikely given privacy-first approach), we will update this policy, post at /cookies, show banner for consent where required by ePrivacy, and maintain version history. Continued use after effective date implies acceptance.
11. Contact Information
- General Support: support@funtoosh.app β Response 24-48h
- Privacy Team: privacy@funtoosh.app
- Grievance Officer: grievance@funtoosh.app β 15 days per IT Act, details at /grievance-redressal
Effective Date: July 31, 2026 β’ Last Updated: July 31, 2026 β’ Future-ready for PWA, offline, and privacy-preserving architecture.