Funtoosh
Policy DocumentProduction Ready

Privacy Policy

Your privacy is our foundation. Zero tracking, zero logs, complete anonymity β€” built for private humans worldwide.

Effective: July 31, 2026Last updated: July 31, 2026Verified β€’ Encrypted

1. Introduction

Welcome to Funtoosh. We are a premium international anonymous messaging platform built on the principle that privacy is a human right. This Privacy Policy describes how Funtoosh Private Technologies Private Limited ("Funtoosh," "we," "us," or "our") handles information when you use our website, progressive web app, and related services (collectively, the "Platform").

We have designed Funtoosh to minimize data collection by default. Our architecture prioritizes anonymity, end-to-end encryption, and user control. This policy is structured to be transparent and compliant with the Digital Personal Data Protection Act, 2023 (India), Information Technology Act, 2000, and general international privacy practices including principles from GDPR and CCPA, without claiming certification where none exists.

2. Definitions

  • Personal Data: Information that relates to an identified or identifiable individual, even if we do not collect it by design.
  • Anonymous Data: Data that cannot be used to identify an individual, including aggregated usage metrics.
  • End-to-End Encryption: A system where only communicating users can read messages; Funtoosh cannot decrypt content.
  • Wallet Data: Transaction metadata necessary for fraud prevention and regulatory compliance, stored in hashed form.
  • Essential Cookies: Small storage items required for theme, language, and secure session functionality.

3. Privacy Principles

  1. Data Minimization: We collect only what is essential to provide anonymous messaging, Email OTP login, wallet recharge, paid messaging, and advertisements.
  2. Purpose Limitation: Any data we process is used solely for providing, securing, and improving the Platform.
  3. Storage Limitation: We retain data only as long as necessary for stated purposes.
  4. Security by Design: Encryption, secure headers, and privacy-preserving architecture are default.
  5. User Control: You control your profile visibility, blocking, reporting, and account deletion.

4. Data We Collect (Minimal)

4.1 Account Information

  • Email address for Email OTP login
  • Full name provided during sign-up (optional display name)
  • Public key generated locally for encryption

4.2 Usage & Technical

  • Coarse region for edge routing (if discovery enabled, opt-in)
  • Aggregated, anonymized performance metrics (e.g., message delivery latency) without identifiers
  • Wallet transaction hashes for fraud prevention and regulatory records

5. What We Do Not Collect

  • Phone number or SIM verification (not required)
  • Exact location, contacts upload, or address book access
  • Message content (end-to-end encrypted, not readable by us)
  • Behavioral profiling, advertising trackers, or third-party analytics cookies
  • Government ID for messaging (KYC only for wallet payouts above regulatory thresholds where required)

6. Encryption & Security

6.1 Anonymous Messaging

All direct messages are protected with X25519 + XSalsa20-Poly1305 and AES-256-GCM. Keys are derived on-device. Servers act as blind relays.

  • Forward secrecy via rotating session keys
  • Screenshot detection alerts where operating system allows
  • Disappearing messages configurable from 10 seconds to 30 days

6.2 Account Protection

  • Email OTP login with 5-minute expiry and rate limiting
  • Secure cookies: HttpOnly, SameSite=Lax, Secure on HTTPS
  • Security monitoring for abuse detection and spam detection
  • Blocking users and reporting users features to enhance privacy protection

7. Cookies & Local Storage

Essential Cookies Only

  • funtoosh_theme: Light/Dark/System preference, 30 days
  • funtoosh_lang: Language choice EN/HI/ES/FR/DE/AR/JA/PT, 1 year
  • funtoosh_session: Secure session token for wallet and login, session/7 days
  • funtoosh_pwa_dismissed: PWA install prompt state, 90 days

No tracking cookies. No Google Analytics or advertising pixels. Local storage is used for public key cache, message drafts (local only), and service worker cache for offline support.

8. Data Retention & Deletion

  • Account: Username and public key retained until you delete account via Settings β†’ Danger Zone
  • Messages: Held in memory relay queue max 24 hours until delivered, then wiped; not stored server-side
  • Wallet: Hashed ledger retained up to 7 years where required for fraud prevention and regulatory compliance
  • Deletion: Upon account deletion, public key queued for deletion within 7 days, local keys wiped immediately

9. Your Rights

Under applicable laws, you have the right to:

  • Access your account data (profile and wallet history JSON export)
  • Correction of inaccurate name or email
  • Deletion of account and associated data
  • Opt-out of optional discovery, read receipts, typing indicators
  • Object to processing where applicable and withdraw consent

To exercise rights, contact privacy@funtoosh.app. We respond within 30 days per standard practices.

10. Children's Privacy

Funtoosh is for users 13 years and older (16+ in EEA where required). We do not knowingly allow children under 13. For users 13-17, discovery is disabled by default, DM limits apply, and wallet payouts require guardian verification where required by law. If you believe a child has created an account, contact safety@funtoosh.app for prompt removal.

11. International Data Transfers

We operate edge nodes in multiple regions for performance. Since content is end-to-end encrypted and we maintain zero logs, your messages remain unreadable regardless of routing. Where required, we implement safeguards consistent with Information Technology Act and international transfer principles. User profiles and discovery preferences are opt-in and region-configurable.

12. User Responsibilities

  • Keep your email secure; OTP is single-use and time-limited
  • Do not share identifiable information if you wish to remain anonymous
  • Respect others' privacy; do not attempt to de-anonymize, dox, or collect personal data of others
  • Use blocking and reporting features for unwanted interactions
  • Keep device OS and app updated

13. Platform Responsibilities

  • Provide privacy-preserving architecture with encryption and zero-logs relay
  • Implement content moderation for reported content, spam detection, and abuse prevention
  • Maintain security monitoring, fraud prevention, and rate limiting
  • Provide transparent policies and timely security updates
  • Honor deletion and data rights requests within stated timelines

14. Changes to This Policy

We may update this policy to reflect Platform improvements, regulatory changes, or security enhancements. Material changes will be notified via in-app banner and posted at /privacy with 30-day notice period where required. Version history will be maintained. Continued use after effective date implies acceptance of updated policy.

15. Contact Information

For privacy inquiries, data rights requests, or grievances:

  • Privacy Team: privacy@funtoosh.app
  • Security Team: security@funtoosh.app (PGP key available at /security)
  • Support: support@funtoosh.app β€” Response time 24-48 hours
  • Grievance Officer: grievance@funtoosh.app β€” Per IT Act and DPDP Act requirements, details at /grievance-redressal
  • Postal: Funtoosh Private Technologies, Attn: Privacy, Bengaluru, Karnataka, India β€” Contact via email preferred

This policy is future-ready and will be supplemented with jurisdiction-specific addenda as Funtoosh expands wallet, premium features, and advertisements globally.

Β© 2026 Funtoosh β€’ All rights reserved β€’ Production Ready← Return to Funtoosh Home