Privacy Policy

Effective: March 27, 2026  ·  Last updated: March 27, 2026  ·  v1.0

Plain-English Summary
Fr. is built around the idea that your conversations should disappear. We collect the minimum data needed to keep the app running and you safe. We do not sell your data to anyone. Most messages are encrypted end-to-end — even we cannot read them. You can delete your account and all your data at any time from inside the app.
Contents
  1. Who we are
  2. What data we collect
  3. How we collect it
  4. Why we process it (legal bases)
  5. End-to-end encryption
  6. Who we share data with
  7. How long we keep data
  8. Children and minors
  9. Your rights
  10. Security
  11. International transfers
  12. US state-specific rights
  13. Australian users
  14. Changes to this policy
  15. Contact us

1. Who we are

Fr. ("we", "us", "our") is a messaging application operated by Sircle Networking Pvt Ltd, a private limited company incorporated in India.

For users in the European Economic Area (EEA) and the UK, we are the data controller of your personal data as defined under the General Data Protection Regulation (GDPR) and UK GDPR.

Our designated representative for GDPR and privacy enquiries: support@cocial.in

2. What data we collect

2.1 Account data

Data itemWhy collectedStored as
Display nameShown to contactsPlain text
Age (integer)Safety routing, minor protectionsPlain integer (not shared)
Age groupFeature gatingEnum (u18 / 18-24 / 25+)
Phone numberAccount verification onlyStored securely — your raw number is never retained
Email addressGoogle/Apple sign-in (if used)Managed by Google/Apple — we receive only a stable user ID
Profile photoOptional avatarUploaded to secure cloud storage
Organisation / universityOptional, for Discover featuresPlain text
GenderOptional, personalisationEnum (male / female / prefer not to say)

2.2 Device data (collected automatically on first launch)

Notice
The following device information is collected automatically when you first open Fr. — before you interact with any settings. It is used solely for safety (ban evasion prevention) and to display your correct platform experience. No permission is required to read this data.
Data itemUsed for
Device platform (iOS / Android)App experience, safety
Device brand & modelSafety (ban prevention)
Operating system versionCompatibility
Device fingerprintBan evasion prevention — stored securely and never used for advertising

2.3 Message data

Messages sent between users are ephemeral by default — they expire and are deleted from our servers automatically. For end-to-end encrypted (E2EE) chats, message content is encrypted on your device before transmission and can only be decrypted by the intended recipient. We do not have the ability to read the content of E2EE messages.

For non-E2EE chats, message content is stored encrypted at rest and is automatically deleted according to the expiry setting you or your chat partner chose.

2.4 Usage and activity data

2.5 Data we do NOT collect

3. How we collect data

4. Why we process your data (legal bases)

Under GDPR, we rely on the following legal bases:

PurposeLegal basis (GDPR Art. 6)
Providing and operating the Fr. serviceContract (Art. 6(1)(b))
Account safety, minor protection, ban enforcementLegitimate interests (Art. 6(1)(f))
Compliance with legal obligations (e.g. GDPR deletion requests)Legal obligation (Art. 6(1)(c))
Optional features (avatar, bio, organisation)Consent — you provide these voluntarily (Art. 6(1)(a))
Retaining hashed ban identifiers after account deletionLegitimate interests — preventing re-registration of sanctioned users (Art. 6(1)(f))

5. End-to-end encryption

When you enable E2EE in a chat, messages are encrypted on your device before they leave it. Only you and the person you're talking to can read them.

6. Who we share data with

We do not sell your data. We share data only with:

RecipientPurposeLocation
Cloud infrastructure providerDatabase hosting and authentication infrastructureUSA (EU data centre available)
Google FirebaseSecondary authentication (social sign-in verification)USA
AppleApple Sign-InUSA
Expo / Expo PushPush notification deliveryUSA
Law enforcementOnly when required by valid legal process (court order, subpoena)Jurisdiction-dependent

All third-party processors are bound by data processing agreements and are required to protect your data to at least the same standard as this policy.

7. How long we keep data

Data typeRetention period
Ephemeral messagesDeleted automatically at the expiry time set for each chat (minimum 1 hour, default 24 hours)
Account dataRetained while your account is active
Soft-deleted accounts7-day grace period, then permanently purged from all systems
Hashed ban identifiers (phone, device)Retained indefinitely to prevent re-registration — stored as irreversible hashes, not raw data
User reports submitted against othersRetained for safety review purposes; anonymised after 2 years
Backup logsRolling 30-day window

8. Children and minors

Fr. is not intended for children under 13 years of age. We do not knowingly collect personal data from anyone under 13. If we become aware that we have collected data from a child under 13 without verifiable parental consent, we will delete that account promptly.

8.1 Users aged 13–17

Users who indicate they are between 13 and 17 years old are flagged as minors internally and receive additional protections:

8.2 Australia

Fr. is primarily a private messaging application. Under Australia's Online Safety Amendment (Social Media Minimum Age) Act 2024, messaging services are currently excluded from the under-16 age restriction obligation. We monitor eSafety Commissioner guidance and will update our practices if Fr. is ever classified as an age-restricted social media platform.

8.3 COPPA (USA)

Fr. is directed at users aged 13 and above. We do not knowingly collect personal information from children under 13 as defined under the Children's Online Privacy Protection Act (COPPA). If you believe a child under 13 has created an account, please contact us at support@cocial.in and we will delete the account.

9. Your rights

9.1 Rights for all users

9.2 Rights under GDPR (EEA & UK users)

You have the right to:

GDPR Deletion & Erasure Note
We will respond to all GDPR rights requests within 30 days (extendable by a further 60 days for complex requests, with notice to you). To submit a request, email support@cocial.in with the subject line "Fr. - Support | GDPR Data Request". We may ask you to verify your identity before processing the request.

Exception: If your account was permanently banned for serious safety violations, we retain hashed identifiers (phone hash, device hash) to prevent re-registration. This is based on our legitimate interest in platform safety. You may contest this at the above email address.

9.3 Rights under CCPA / CPRA (California users)

California residents have the right to:

To submit a CCPA request, email support@cocial.in or use the in-app deletion flow. We will confirm receipt within 10 business days and respond within 45 calendar days.

10. Security

We use industry-standard technical and organisational measures to protect your data, including encryption in transit and at rest, access controls, and regular security reviews.

Phone numbers are never stored in plain text. Message content in E2EE chats is inaccessible to us by design. Access to our systems is strictly limited to authorised personnel.

No system is 100% secure. If you discover a security vulnerability, please report it responsibly to support@cocial.in.

11. International data transfers

Fr. is operated from India by Sircle Networking Pvt Ltd. If you access Fr. from the EEA, UK, or other regions with data protection laws, your data may be transferred to and processed in countries that may not provide the same level of data protection as your home country.

For transfers of EEA personal data to our US-based processors, we rely on:

12. US state-specific rights

In addition to California (CCPA/CPRA) rights described in Section 9.3, residents of the following states have rights similar to those under GDPR — including rights to access, delete, correct, and opt out of the sale of personal data:

To exercise any of these rights, contact us at support@cocial.in.

13. Australian users

For users in Australia, this privacy policy is supplemented by our compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

You have the right to:

We are not currently classified as an age-restricted social media platform under the Online Safety Amendment (Social Media Minimum Age) Act 2024. We continue to monitor eSafety Commissioner guidance and will update this policy if our classification changes.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will:

Your continued use of Fr. after changes take effect constitutes acceptance of the revised policy.

15. Contact us

Privacy enquiries & data requests support@cocial.in Security vulnerabilities support@cocial.in General support support@cocial.in EU/UK GDPR representative support@cocial.in Postal address Sircle Networking Pvt Ltd
Plot 299, 300, 311, Mallampet
Jeedimetla, Hyderabad
Telangana, India — 502325