Last updated: August 10, 2026
Account data: username, display name, email address, password (stored only as a secure hash), and optional profile details you add (bio, interests, social handles, profile & cover photos).
Content: questions and messages you send, answers you publish, chat messages and photos you share.
Technical data: we do not store your raw IP address alongside your activity. Instead we store a one-way keyed hash (HMAC) of it, used exclusively for rate limiting (e.g. the daily question limit), blocking and abuse prevention. We also use strictly necessary session cookies.
When you ask a question or start a chat anonymously, the recipient never sees your identity, username or contact details — they see only an anonymous label (e.g. “Anonymous 4432”). You may voluntarily reveal your identity in a chat; this cannot be undone for that chat. Who you follow is private: nobody — including the person you follow — can see your follow list; only you can.
To operate the Service (deliver questions and chats, show public answers), to secure it (rate limits, blocks, moderation of reported content), and to communicate with you: email verification, password reset, and — if enabled in your settings — notifications about new questions. We do not sell your personal data, show third-party ads, or use third-party analytics trackers.
Uploaded images (profile, cover, chat photos) are re-processed on our servers, which strips hidden metadata such as EXIF location data. Chat photos can only be sent to a host who has explicitly enabled photo sharing for that conversation.
Your profile, published answers and answer pages are public. Your inbox (unanswered questions), chats, blocked lists, notification settings and follow list are private to you. Site administrators can access content for moderation purposes (including reported content and account details) under confidentiality.
Content stays until you delete it: you can delete questions, unpublish answers, and delete chats (one-sided). Deleting your account removes your profile, questions, answers, conversations, messages and uploaded photos from our systems. Rate-limit records expire automatically within days.
You may access, correct or delete your data at any time via Settings or by contacting us. Depending on your jurisdiction (e.g. GDPR/KVKK) you may also have rights to data portability and to object to processing — write to us to exercise them.
Passwords are hashed with modern algorithms, traffic is encrypted in transit (HTTPS), uploads are validated and re-encoded, and access to production data is restricted. No system is 100% secure — please use a unique password.
The Service is not directed at children under 13, and we delete accounts we discover belonging to them.
We may update this policy; material changes will be announced on the Service. Contact: privacy@fyn.me