Transparency
What we moderate, what we can and cannot see, how enforcement works, and what we keep. Written to be accurate rather than reassuring.
1. Transparency Commitment
Funtoosh lets people answer questions anonymously. That only works if you can trust what we say about the system — so this page describes it plainly, including the parts that are less flattering. Where we have not built something yet, we say so instead of describing an intention as though it were a feature.
We do not make claims about our moderation that we cannot stand behind. Automated filtering catches a lot and misses some; describing it as flawless would be a lie, and regulators have repeatedly penalised anonymous-messaging apps for exactly that kind of marketing.
2. What We Can and Cannot See
This section corrects earlier versions of this page, which described Funtoosh as end-to-end encrypted with zero logs. That was never accurate for this platform and has been removed.
- Messages are not end-to-end encrypted. Questions, answers, Results, and chat messages are stored on our servers in a form our systems can read. They are encrypted in transit (HTTPS) and at rest by our database provider, but we hold the keys.
- Our automated filter reads message text. It has to — that is how abuse, threats, sexual content, and contact-detail sharing get blocked before delivery.
- A human reviewer can read reported content. When you report something, a reviewer sees that specific content in order to decide on it.
- We do not read conversations for any other reason. No advertising profiles, no browsing content out of curiosity, no training on your messages. Staff access to user content is limited to reviewing reports and investigating specific safety incidents.
- Anonymity is at the product level, not the infrastructure level. Other users cannot see who wrote an anonymous answer. Funtoosh can, because the answer is linked to an account so that abuse can be acted on and orders from a court can be answered. Anyone promising you more than this is describing a different product.
3. Content Moderation Approach
Moderation runs in two layers.
- Automated filtering, at the moment of posting. Every question, answer, Result, and chat message is scanned before it is stored. Clear violations — sexual content involving minors, credible threats, slurs, and sexual harassment — are refused outright and never delivered. Borderline content is held for human review rather than published or silently discarded. In chat, phone numbers, email addresses, and UPI IDs are refused too, because moving people off-platform is how anonymous contact turns into harassment we cannot see or stop.
- Human review, after a report. Reports are read by a person. Automated tools flag; people decide. No account is suspended by an algorithm alone.
The filter is deliberately conservative about false positives — it evaluates whole words and deliberate obfuscation (spacing, symbol substitution, repeated letters), and it works in both Roman and Devanagari script. It will still miss things, and it will occasionally block something harmless. If it blocks you wrongly, tell us at [email protected].
Self-harm language is treated differently: it is never grounds for a strike or a block. It surfaces crisis-helpline information instead.
4. User Reports
- How to report: the ⋯ menu on any question, answer, Result, or chat message → Report → pick a reason. You can also email [email protected] with the link, username, and timestamp.
- Every piece of content is reportable and deletable. Questions, answers, and Results all carry the same controls. Deleting your own content is free and unlimited.
- Timelines: we acknowledge complaints within 24 hours and dispose of them within 15 days, as required by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Non-consensual intimate imagery and child-safety reports are actioned within 24 hours; other prohibited content within 72 hours; court and government orders within 36 hours. These are the statutory deadlines we are bound by. Most reports are handled well inside them, but we publish the deadline rather than an average, because an average is not a commitment.
- Confidentiality: we never tell the reported user who reported them.
- Outcome: reporters are told that their report was closed. We do not disclose what action was taken against another user's account, because that is their personal data.
5. Policy Enforcement
Enforcement is proportionate to severity and history:
- Content removal: the specific post, answer, Result, or message is taken down.
- Warning: an in-app notice naming the rule that was broken.
- Temporary restriction: a hold on posting or on anonymous replies.
- Discovery removal: the profile stops appearing in discovery.
- Wallet restriction: a hold on recharges, tips, and payouts during a fraud review, per the Wallet Policy.
- Suspension: sign-in stays possible so the notice can be read and appealed.
- Permanent termination: for the most serious violations.
Child sexual abuse material, grooming, credible threats of violence, doxxing, and organised fraud result in immediate permanent removal and, where the law requires it, a report to the relevant authority.
Before content you posted is removed by us, you are notified and given an opportunity to be heard, as Rule 4(8) of the IT Rules requires. This does not apply to content you deleted yourself, or where an immediate takedown is legally mandated.
6. Strikes and Appeals
- A confirmed violation earns one strike. Strikes are issued by a human reviewer, never by the filter.
- Three active strikes lead to suspension.
- A strike expires after 90 days. Strikes for the most serious categories do not expire.
- A strike that is overturned on appeal is revoked and stops counting.
- You can see your own strike record and your policy-acceptance history in the app at any time.
- To appeal, write to [email protected] with the notice you received. Appeals are read by someone who was not involved in the original decision where staffing allows.
7. Identity and Reveals
- Revealing is always the anonymous person's own choice. Nobody else can reveal them — not the question owner, not other users, and not by paying us. We do not sell, and will not build, any feature that unmasks someone who has not chosen to be unmasked. We do not sell hints, clues, or guesses about who someone is either.
- Reveals are scoped. When you reveal yourself on an answer you choose whether your name is shown only to the person who asked the question, or to everyone who opens it.
- Reveals are irreversible and the confirmation screen says so before you commit.
- Golden Cards are consent-based. A Golden Card is a request. The anonymous side accepts or declines it. Payment buys the request, never the answer.
- We never generate fake messages. Every question, answer, Result, and chat message on Funtoosh was written by a real user. We do not seed accounts with synthetic activity to make the app feel busier, and we never will.
8. Government and Legal Requests
- We comply with valid, lawful orders from Indian courts and authorised government agencies under the Information Technology Act, 2000 and the IT Rules, 2021. Content covered by such an order is actioned within 36 hours.
- Because message content is readable by us, we can be compelled to disclose it. We will not pretend otherwise. We disclose only what a specific valid order requires — never bulk access.
- Requests are checked for legal validity before anything is handed over, and overbroad or improperly authorised requests are pushed back on.
- Where the law permits, we notify the affected user. Some orders forbid this, in which case we cannot.
- Aggregate numbers of government requests received and complied with will appear in the transparency reports described below.
9. Data and Retention
- Deleted content is really deleted. When you delete a question, answer, or Result, it disappears from the platform immediately and is destroyed permanently after 180 days. That window exists so removed content is still available if an investigation into it is already under way, as the IT Rules contemplate. After it, an automated job erases the record for good.
- What we keep while your account is open: your email address, profile details, your content, and wallet transaction records.
- You can leave. Settings → Account & Data lets you deactivate (reversible, hides your profile and everything you wrote) or delete permanently. Deletion runs on a 15-day countdown you can cancel throughout. After it, your content is removed and your name is severed from it; an admin-only copy is kept for 90 days so any report already under way is not left unfinished, and is then erased. Full detail at /data-retention.
- Financial records are retained for the period tax and anti-fraud law requires, even after deletion, because we are not permitted to destroy them earlier.
- Moderation records — what was flagged and why — are kept for 180 days and then purged, so a filter log does not become a permanent shadow file on a user.
- No advertising trackers and no sale of personal data to third parties.
- Under the Digital Personal Data Protection Act, 2023 you may request access to, correction of, or erasure of your personal data. Write to [email protected].
- Funtoosh is for users aged 18 and over. Accounts found to belong to minors are removed.
10. Live Numbers
Live figures are temporarily unavailable. They are generated from our own records rather than entered by hand, so rather than show a stale or made-up table we show nothing. Please check back, or write to [email protected].
11. Transparency Reports
The table above is the rolling 30-day view. In addition we intend to publish a formal report covering the first full half-year of operation, and semi-annually after that, containing:
- Reports received, by category, and how many led to action
- How many reports were closed within the statutory deadline
- Content blocked automatically versus held for human review
- Strikes issued, appeals received, and appeals upheld
- Government and court requests received and complied with, where disclosure is permitted
- Security incidents and what was done about them
These are counts we already record, so the report will be generated from the live data rather than assembled by hand.
12. What We Ask of You
- Report violations rather than retaliating or publicly shaming — reports are the only signal we can act on reliably.
- Include enough detail for a reviewer to find the content: the link, the username, the time.
- Do not file reports in bad faith. Deliberate abuse of the reporting system is itself a violation.
- Remember that anonymity from other users is not anonymity from the law.
13. What We Owe You
- Enforce the rules consistently, state which rule was broken, and allow an appeal.
- Describe our own capabilities accurately, here and in every piece of marketing.
- Never build or sell a way to unmask someone without their consent.
- Never fabricate activity on the platform.
- Delete what you asked us to delete, on the schedule set out above.
- Correct this page when the system changes, rather than letting it drift out of date.
14. Contact
- Safety and urgent reports: [email protected]
- General support: [email protected]
- Privacy and data requests: [email protected]
- Legal: [email protected]
Grievance Officer: Somesh Mishra — [email protected]
D 24/8, Himalay Bhawan,
Shatabdi Nagar, Panki,
Kanpur,
Uttar Pradesh – 208020,
India
Full escalation process, statutory timelines, and your appeal rights are set out at /grievance-redressal.
Effective Date: August 19, 2026 • Last Updated: August 19, 2026
Grievance Officer (IT Rules 2021)
Somesh Mishra
D 24/8, Himalay Bhawan,
Shatabdi Nagar, Panki,
Kanpur,
Uttar Pradesh – 208020,
India
Email: [email protected]
Phone: +91 94540 43072 (10 AM – 6 PM IST)
Statutory timelines we work to: acknowledgement within 24 hours; disposal within 15 days; prohibited content under Rule 3(2)(b) within 72 hours; non-consensual sexually explicit or morphed content under Rule 4(1)(p) within 24 hours; court or government orders under Rule 3(1)(d) within 36 hours. Removed content and the associated records are retained for 180 days for investigation purposes. These are the limits set by law for us to act within; they are not a guarantee of any particular outcome on any particular report.
Before we remove or disable content on our own initiative, Rule 4(8) requires us to notify you with reasons and give you a reasonable opportunity to dispute it. Automated tools may flag content, but a human reviews before any account-level action is taken. See the Transparency Report.
Your rights under the DPDP Act 2023
- Notice and consent (§5): we tell you what we collect and why before you agree, and you can withdraw consent at any time in Settings.
- Purpose limitation (§4, §6): your data is used only for running Funtoosh, safety, payments and legal obligations — never sold, never used to build advertising profiles.
- Access and correction (§11): you can view and correct your profile data in Settings.
- Erasure (§12): you can delete your account from Settings → Account. See Data Retention for what the law requires us to keep afterwards, and for how long.
- Retention limit (§8(7)): we erase personal data once the purpose it was collected for is over, unless a law requires us to keep it.
- Grievance redressal (§13): write to the officer named above, or use Grievance Redressal. Unsatisfied with the decision? Appeal to the Grievance Appellate Committee within 30 days. Data protection queries: [email protected].
Age: Funtoosh is for users aged 18 and over. Under the DPDP Act 2023 a person under 18 is a Child and we do not knowingly create accounts for them. No guarantees: Funtoosh is provided on an as-is basis. Nothing on this page is a guarantee of any specific result, earning, delivery time or moderation outcome.