Fr. ("we", "us", "our") is a messaging application operated by Sircle Networking Pvt Ltd, a private limited company incorporated in India.
For users in the European Economic Area (EEA) and the UK, we are the data controller of your personal data as defined under the General Data Protection Regulation (GDPR) and UK GDPR.
Our designated representative for GDPR and privacy enquiries: support@cocial.in
| Data item | Why collected | Stored as |
|---|---|---|
| Display name | Shown to contacts | Plain text |
| Age (integer) | Safety routing, minor protections | Plain integer (not shared) |
| Age group | Feature gating | Enum (u18 / 18-24 / 25+) |
| Phone number | Account verification only | Stored securely — your raw number is never retained |
| Email address | Google/Apple sign-in (if used) | Managed by Google/Apple — we receive only a stable user ID |
| Profile photo | Optional avatar | Uploaded to secure cloud storage |
| Organisation / university | Optional, for Discover features | Plain text |
| Gender | Optional, personalisation | Enum (male / female / prefer not to say) |
| Data item | Used for |
|---|---|
| Device platform (iOS / Android) | App experience, safety |
| Device brand & model | Safety (ban prevention) |
| Operating system version | Compatibility |
| Device fingerprint | Ban evasion prevention — stored securely and never used for advertising |
Messages sent between users are ephemeral by default — they expire and are deleted from our servers automatically. For end-to-end encrypted (E2EE) chats, message content is encrypted on your device before transmission and can only be decrypted by the intended recipient. We do not have the ability to read the content of E2EE messages.
For non-E2EE chats, message content is stored encrypted at rest and is automatically deleted according to the expiry setting you or your chat partner chose.
Under GDPR, we rely on the following legal bases:
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing and operating the Fr. service | Contract (Art. 6(1)(b)) |
| Account safety, minor protection, ban enforcement | Legitimate interests (Art. 6(1)(f)) |
| Compliance with legal obligations (e.g. GDPR deletion requests) | Legal obligation (Art. 6(1)(c)) |
| Optional features (avatar, bio, organisation) | Consent — you provide these voluntarily (Art. 6(1)(a)) |
| Retaining hashed ban identifiers after account deletion | Legitimate interests — preventing re-registration of sanctioned users (Art. 6(1)(f)) |
When you enable E2EE in a chat, messages are encrypted on your device before they leave it. Only you and the person you're talking to can read them.
We do not sell your data. We share data only with:
| Recipient | Purpose | Location |
|---|---|---|
| Cloud infrastructure provider | Database hosting and authentication infrastructure | USA (EU data centre available) |
| Google Firebase | Secondary authentication (social sign-in verification) | USA |
| Apple | Apple Sign-In | USA |
| Expo / Expo Push | Push notification delivery | USA |
| Law enforcement | Only when required by valid legal process (court order, subpoena) | Jurisdiction-dependent |
All third-party processors are bound by data processing agreements and are required to protect your data to at least the same standard as this policy.
| Data type | Retention period |
|---|---|
| Ephemeral messages | Deleted automatically at the expiry time set for each chat (minimum 1 hour, default 24 hours) |
| Account data | Retained while your account is active |
| Soft-deleted accounts | 7-day grace period, then permanently purged from all systems |
| Hashed ban identifiers (phone, device) | Retained indefinitely to prevent re-registration — stored as irreversible hashes, not raw data |
| User reports submitted against others | Retained for safety review purposes; anonymised after 2 years |
| Backup logs | Rolling 30-day window |
Fr. is not intended for children under 13 years of age. We do not knowingly collect personal data from anyone under 13. If we become aware that we have collected data from a child under 13 without verifiable parental consent, we will delete that account promptly.
Users who indicate they are between 13 and 17 years old are flagged as minors internally and receive additional protections:
Fr. is primarily a private messaging application. Under Australia's Online Safety Amendment (Social Media Minimum Age) Act 2024, messaging services are currently excluded from the under-16 age restriction obligation. We monitor eSafety Commissioner guidance and will update our practices if Fr. is ever classified as an age-restricted social media platform.
Fr. is directed at users aged 13 and above. We do not knowingly collect personal information from children under 13 as defined under the Children's Online Privacy Protection Act (COPPA). If you believe a child under 13 has created an account, please contact us at support@cocial.in and we will delete the account.
You have the right to:
California residents have the right to:
To submit a CCPA request, email support@cocial.in or use the in-app deletion flow. We will confirm receipt within 10 business days and respond within 45 calendar days.
We use industry-standard technical and organisational measures to protect your data, including encryption in transit and at rest, access controls, and regular security reviews.
Phone numbers are never stored in plain text. Message content in E2EE chats is inaccessible to us by design. Access to our systems is strictly limited to authorised personnel.
No system is 100% secure. If you discover a security vulnerability, please report it responsibly to support@cocial.in.
Fr. is operated from India by Sircle Networking Pvt Ltd. If you access Fr. from the EEA, UK, or other regions with data protection laws, your data may be transferred to and processed in countries that may not provide the same level of data protection as your home country.
For transfers of EEA personal data to our US-based processors, we rely on:
In addition to California (CCPA/CPRA) rights described in Section 9.3, residents of the following states have rights similar to those under GDPR — including rights to access, delete, correct, and opt out of the sale of personal data:
To exercise any of these rights, contact us at support@cocial.in.
For users in Australia, this privacy policy is supplemented by our compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
You have the right to:
We are not currently classified as an age-restricted social media platform under the Online Safety Amendment (Social Media Minimum Age) Act 2024. We continue to monitor eSafety Commissioner guidance and will update this policy if our classification changes.
We may update this Privacy Policy from time to time. When we do, we will:
Your continued use of Fr. after changes take effect constitutes acceptance of the revised policy.