Security
Encryption in transit and at rest, a privacy-first architecture, and monitoring — described accurately, without overclaiming.
1. Overview
Funtoosh is built with security by design for anonymous messaging, secure login (email + password or Google, with optional 2FA), user wallet, wallet recharge, paid messaging, premium features, advertisements, user profiles, blocking users, and reporting users. This page details our security practices, without claiming certifications that do not exist, and guides you on account protection and abuse detection.
2. Encryption
Anonymous Messaging
- Encryption in transit: HTTPS/TLS on every connection, with HSTS. Encryption at rest: AES-256 on our database provider. Funtoosh is not end-to-end encrypted and holds the keys.
- Keys generated locally on device via secure random; private key never leaves device, public key shared for encryption.
- Forward secrecy via rotating session keys; old keys cannot decrypt new messages if compromised.
- Disappearing messages: Configurable 10 seconds to 30 days, auto-wiped locally and from relay queue.
Data at Rest
- Wallet ledger hashed, AES-256 encrypted at rest, access-controlled, retained per Data Retention & Deletion Policy.
- Essential cookies encrypted with HttpOnly, Secure on HTTPS, SameSite Lax per Cookie Policy.
3. Privacy Protection
- No phone number required; username is identity; sign in with email + password or Google (no email codes), with rate limiting on sign-in attempts.
- Logging: we keep operational, security and moderation logs (hosting logs, database logs, moderation events, admin audit log). We do not run behavioural profiling or advertising trackers. Retention periods are listed in the Data Retention Policy.
- Blocking users prevents messaging, tipping, discovery; reporting users triggers content moderation per Safety Policy and Content Policy.
- Internal advertisements marked Sponsored, no third-party trackers, controlled via future admin panel.
4. Data Security
- Secure headers: HSTS max-age 1 year includeSubDomains preload, X-Content-Type-Options nosniff, X-Frame-Options SAMEORIGIN, X-XSS-Protection, Referrer-Policy strict-origin-when-cross-origin per next.config.ts.
- Transport Layer Security: TLS 1.2+ for all connections, edge nodes via HTTPS.
- cold storage 90% wallet funds, hot wallet 10% for instant payouts per Wallet Policy, with withdrawal whitelist and device binding.
- Regular dependency updates and vulnerability scanning for high severity issues.
5. Account Protection
- Sign in with email + password or one-click Google; no email codes are sent. Rate limiting per IP and email on sign-in attempts.
- Secure cookies: HttpOnly, Secure on HTTPS, SameSite Lax, 7-day expiry, future JWT ready.
- Optional 2FA via TOTP authenticator app (no SMS to preserve anonymity) as a second step at login, with one-time backup codes.
- Password reset and change require signing in with Google on the same email plus your 2FA code — no email codes.
- Device binding and anomaly detection for unusual login, wallet recharge, or tip patterns.
- Logout option clears session, localStorage, and secure cookies; session 30 days expiry with future refresh token readiness.
6. Abuse Detection & Prevention
- Abuse detection: automated filters run over content and metadata (word lists, frequency limits). Matches are logged for human review; no automated filter is presented as accurate or final.
- Spam detection: Rate limiting 20 new conversations per hour for new accounts, 100 per day, adjustable, plus community reports.
- Fraud prevention: Anomaly detection for wallet recharge, paid messaging, tips, chargeback abuse, tip farming, per Wallet Policy and Payment Terms.
- Content moderation for reported content per Content Policy, Acceptable Use Policy, User Conduct Policy.
7. Spam & Fraud Prevention
- Wallet spam: Fake tips, tip farming, wallet recharge abuse via stolen cards, money laundering detection.
- Discovery spam: Multiple profiles with identical bios to dominate discovery prohibited per Anti-Spam Policy.
- Advertisement spam: User-posted ads via DMs prohibited except via approved creator tools; internal ads marked Sponsored.
8. Security Monitoring
We operate 24/7 security monitoring for:
- Unusual login, wallet, and messaging patterns
- Edge node health, latency, and error rates (anonymized)
- Dependency vulnerabilities and patching high severity issues
- Abuse reports via [email protected] and [email protected] per Grievance Redressal Policy
Monitoring is privacy-preserving, no message content inspection, only metadata and aggregated metrics.
9. User Safety Education
- Safety tools: Block and report in one tap, disappearing messages, hide from discovery, screenshot alerts, DM filters, wallet limits per Safety Policy and Trust & Safety.
- Funtoosh is 18+; we do not knowingly operate accounts for anyone under 18 (DPDP Act 2023) — reported under-18 accounts are removed.
- Resources: Mental health helplines at /safety, digital safety guide at /trust-safety, and Privacy Policy guidance.
10. Responsible Disclosure
If you discover a security vulnerability, please report responsibly:
- Email: [email protected] with subject "Responsible Disclosure - [Brief Description]"
- Include steps to reproduce, impact, and suggested fix if known
- Do not access other users data, do not disrupt service, do not publicly disclose before we have had 90 days to fix per industry practices
- We will acknowledge within 48 hours, provide updates, and credit you in our hall of fame with permission (no bounty program currently, but recognition and future reward consideration)
We do not claim ISO 27001 or SOC 2 certification at this time; we follow industry best practices and publish transparency via Transparency Page.
11. User Responsibilities
- Keep your account password and 2FA backup codes secure, do not share your session, enable 2FA where available, keep your device OS updated.
- Use a strong, unique password, and keep the email behind your account secure — it anchors your sign-in and password reset.
- Use blocking users and reporting users for unwanted interactions, not retaliation.
- Do not attempt to bypass security, reverse engineer, or scrape at scale per Acceptable Use Policy.
12. Platform Responsibilities
- Provide encryption, privacy protection, secure cookies, security monitoring, fraud prevention, abuse detection, spam detection, and timely patching.
- Maintain clear Security Page, Safety Policy, Trust & Safety, Transparency Page, and responsible disclosure process.
- Educate users about account protection and safe anonymous communication.
- Respond to security reports within 48 hours and provide fixes within 90 days where feasible.
13. Contact Information
- Security Team: [email protected] — 48h acknowledgment, PGP key at /security#pgp (future)
- General Support: [email protected]
- Safety: [email protected] — 24h for safety
- Grievance Officer: [email protected] — 15 days per IT Act, details at /grievance-redressal
Effective Date: August 19, 2026 • Last Updated: August 19, 2026
Grievance Officer (IT Rules 2021)
Somesh Mishra
D 24/8, Himalay Bhawan,
Shatabdi Nagar, Panki,
Kanpur,
Uttar Pradesh – 208020,
India
Email: [email protected]
Phone: +91 94540 43072 (10 AM – 6 PM IST)
Statutory timelines we work to: acknowledgement within 24 hours; disposal within 15 days; prohibited content under Rule 3(2)(b) within 72 hours; non-consensual sexually explicit or morphed content under Rule 4(1)(p) within 24 hours; court or government orders under Rule 3(1)(d) within 36 hours. Removed content and the associated records are retained for 180 days for investigation purposes. These are the limits set by law for us to act within; they are not a guarantee of any particular outcome on any particular report.
Before we remove or disable content on our own initiative, Rule 4(8) requires us to notify you with reasons and give you a reasonable opportunity to dispute it. Automated tools may flag content, but a human reviews before any account-level action is taken. See the Transparency Report.
Your rights under the DPDP Act 2023
- Notice and consent (§5): we tell you what we collect and why before you agree, and you can withdraw consent at any time in Settings.
- Purpose limitation (§4, §6): your data is used only for running Funtoosh, safety, payments and legal obligations — never sold, never used to build advertising profiles.
- Access and correction (§11): you can view and correct your profile data in Settings.
- Erasure (§12): you can delete your account from Settings → Account. See Data Retention for what the law requires us to keep afterwards, and for how long.
- Retention limit (§8(7)): we erase personal data once the purpose it was collected for is over, unless a law requires us to keep it.
- Grievance redressal (§13): write to the officer named above, or use Grievance Redressal. Unsatisfied with the decision? Appeal to the Grievance Appellate Committee within 30 days. Data protection queries: [email protected].
Age: Funtoosh is for users aged 18 and over. Under the DPDP Act 2023 a person under 18 is a Child and we do not knowingly create accounts for them. No guarantees: Funtoosh is provided on an as-is basis. Nothing on this page is a guarantee of any specific result, earning, delivery time or moderation outcome.