Privacy
What fofiy holds, for how long, and what it deliberately does not hold.
Last updated: 2026-08-20
Most apps ask you to trust a privacy policy. The three rings this product is built on are columns and row-level security rules in the database: the server cannot return ring 2 to somebody whose request has not been accepted, whatever the app asks for. That is why the homepage states the rule and this page states the mechanism.
The short version: fofiy knows the place you chose and the moment you chose it, and it forgets both. It never holds a trail of where you have been, it never stores your phone number, and it never sells or shares anything for advertising.
1 · Who is responsible
fofiy is operated from Cannes, France. For anything in this document — a question, a correction, a request to see or delete your data — write to hello@fofiy.com. A person reads it.
2 · What we hold, and for how long
| What | Why | How long |
|---|---|---|
| Your email address | It is how you sign in. There is no password. | Until you delete your account |
| First name and year of birth | The name is shown only after a request is accepted. The year proves you are over 18. | Until you delete your account |
| Username, display name, bio, city, photo | Your public profile. All optional. | Until you remove them |
| The fact that a phone was verified | It unlocks adding places and starting a club. The number itself is never stored — there is no column for one. What is kept beside it is a one-way hash, so that somebody who already has your number can find you. | Until you delete your account |
| Presence: the place, your mood, your look note, when it started and ended | It is the product. Only people who are fofiy On at the same place can see it, and only while it lasts. | Deleted 90 days after it ended |
| Location readings | To prove you are actually at the place, rather than claiming it from a sofa. Taken only while the tab is open and visible. | Deleted after 30 minutes |
| Requests and the conversations they open | So the two of you can arrange to meet. | A conversation closes 24 hours after it opens |
| Posts, photos, videos, reviews | What you chose to publish. | Until you delete them — a story deletes itself after 24 hours |
| Trips, host offers, clubs, events, routes | Plans you made. A trip is a city and two dates, and neither a trip nor a day host offer has an address column — the one address in the product is a night’s stay, on the row below. | Until you delete them |
| Reports and blocks | Safety. A report keeps the conversation it is about. | Kept while the account exists |
| Rooms and what is said in them | A room is a host, a subject and whoever came. It is a conversation, not a place: no room reads where anybody is. | Deleted a week after the room ends |
| Messages in an event's room | So the people going to something can talk before it happens. | Deleted 30 days after the event |
| A host listing, including the home address | The address is returned to one person: the guest of a request you accepted, and only around those nights. Every other screen is written against the city centre. | Until you take the listing down |
| Stay requests and references | A request carries what you wrote about yourself to a stranger. A reference is written by somebody you actually stayed with, and it is public. | The message goes 90 days after the last night; a request nobody answered goes 30 days after the dates it asked for; a reference stays |
| The fact that an identity document was checked | It is what hosting and staying cost. The document itself is never stored — no image, no number, no column for one. | Until you delete your account |
| Your blood type, if you fill it in | It is health data, so it is optional and blank by default, and it does exactly one thing: it decides whether you are told about a call for blood near you. Nothing shows it to anybody — there is no reader that lists who has which type, and no screen where yours appears to another person. | Until you clear it or delete your account |
| A call for blood you raised | A hospital, a type and a point. The person it is about is never named — the table has no column for them. | It expires after 12 hours and is deleted a day later |
| A topic you opened, and the fofiy you wrote in one | A topic is a public room, and this is the one thing here that is meant to stay: everything else on this page expires, and a subject that expired would be a conversation with no memory. A fofiy on a topic is public and can be read by anybody, signed in or not, and by a search engine — the composer says so before you type. Who opened a topic is not shown anywhere. | Kept — until you delete it, or your account |
| Who invited you, and who you invited | fofiy is entered by invitation, so one row records that an invitation existed and was used. Nobody can look up who invited whom — there is no reader for it, and the row is readable only by the person who sent it. If you delete your account, the row stops pointing at you: what is left is a used invitation with nobody on the end of it. | Kept while the account that sent it exists |
| An application for a code, if you make one | If nobody has invited you, five people who know you can confirm that they do. What we keep is a first name for each of them, so your own screen can tell you who has answered, and a one-way hash of the one address you chose to reach them on, so the same person cannot answer twice. Their email, phone and Instagram never reach us — they stay in the browser you typed them into, because the card is sent by your phone and not by fofiy. Nobody is told they were asked, and nobody who answers hears from us again. | Deleted when you withdraw it, when your account goes, and 90 days after it is decided |
| A notification subscription, if you turn notifications on | The address your browser gives us to reach that one device, its two encryption keys, and roughly where it is, so that something happening near you can reach you and something far away cannot. | Until you turn notifications off on that device, or delete your account |
Two rows say “kept”, and they are the exceptions to everything above. Almost all of this page is a list of endings — presence at ninety days, a room a week after it closes, a location reading after thirty minutes — because a product about who is here now has no use for what was true last year. A topic is the opposite and is the only surface built that way: it is a subject people come back to, and one that forgot itself every season would be a conversation with no memory. An invitation is kept for a narrower reason: it is how the door works, and a door that forgot who it let in could be walked through twice.
3 · What we deliberately do not hold
These are not omissions. Each one is a thing the database has no column for, or a job that removes it:
- No movement history. There is no way — for us or for anybody else — to ask where a person has been. The only readers of past presence return counts of distinct people at a place, and they return nothing at all below a floor of five people over 28 days.
- No phone numbers. Twilio needs the number to deliver a message; we do not need it afterwards, so it is never written down. What is kept is one row saying a phone was proven, and a one-way hash of the number — the same hash your device makes when you look for friends, so that somebody who already has your number can find you. The number itself cannot be read back out of it.
- No address book. Finding friends by contacts hashes the numbers on your device. A number that matches nobody leaves no trace on the server, and an invitation to somebody who is not on fofiy is sent by your own phone — we never see that number and never message anybody.
- No "active 12 minutes ago". A past location is not shown, by name or otherwise, to anybody.
- No advertising, no trackers, no analytics. There is no third-party script on this site or in the app — the two libraries the app uses are committed to this repository and served from this domain, so no other company's code ever runs in your browser. Nothing is sold or shared for marketing.
- No recording of a room. The voice in a room is live and then it is gone. There is no recording call anywhere in this product — not in the token the server signs, not in the app — and no bucket, table or column a recording could be put in. What survives a room is what somebody typed on the floor, which is in the table above.
- No exact position broadcast. fofiy works in terms of places, not coordinates. A distance reading is not a blurred position — three of them intersect.
- No identity documents. A passport or an ID card is checked by a provider whose job that is, and what reaches this database is one row saying a check passed. There is no image, no document number and no face template here, and no column that could hold one.
4 · Who else processes it
fofiy is small, so it runs on other people's infrastructure. These are the only companies that touch your data, and each one does one job:
- Supabase — the database and sign-in. Hosted in the European Union.
- Vercel — serves this site and the app.
- Twilio — delivers the phone verification message. It receives the number for that one message and we keep no copy.
- Resend — delivers the sign-in email.
- Google Places — answers "what is around this point" while you are looking for the place you are standing in. It receives a coordinate and nothing else. The request is made by our server, not by your browser, so it never sees you.
- Ticketmaster — answers "what is on near here" on the events screen. Same shape: a coordinate, sent by our server, carrying no account of yours. Nothing of yours is kept there.
- LiveKit — carries the voice in a room, and only while you are in one. This is the one connection your browser makes directly, because that is what live audio is: it sees your IP address and the sound you send, for as long as you are connected and no longer. It is told your account's identifier and nothing else — no name, no handle, no email. Nothing is recorded, by them or by us: there is no recording call anywhere in this product and no place to put a recording if there were one.
- The push service of whoever made your browser — Google, Apple, Mozilla or Microsoft, depending on the browser, and only if you turn notifications on. There is no way round it: a notification reaches a device through its own maker's service. It sees that device and when something was sent to it. It does not see what was sent — every notification is encrypted before it leaves our server with keys only your device holds, so the service passes on a sealed envelope it cannot open.
The typeface is not on that list. It used to be — Google Fonts served it and your browser fetched it from them, which handed a third party your address on every page you opened. It is a file in this site now, so nobody outside the list above learns that you were here. That also makes the sentence about LiveKit above exact rather than nearly true: it is the only connection your browser makes to anybody but us.
Both of the map and ticket lookups are asked from our side rather than from your phone. That is deliberate: a request made by your browser would also hand them your address and your device, and neither of them needs to know you exist to answer a question about a point on a map.
5 · Why we are allowed to
Under the GDPR: your email, name and year of birth are processed to perform the contract — there is no account without them. Presence, posts and everything you publish are processed on your consent, given each time you press the button, and withdrawn by pressing it again or deleting the thing. Reports, blocks and rate limits rest on our legitimate interest in keeping the product safe to use.
6 · Your rights
You can ask to see everything we hold about you, to correct it, to delete it, or to receive a copy in a portable form. Write to hello@fofiy.com and we will answer within 30 days. Deleting your account removes your profile, your posts and your presence history; a report you are named in survives, because it is somebody else's safety record. If you think we have got this wrong, you can complain to the CNIL (cnil.fr).
7 · What is stored on your device
No advertising cookies, because there is no advertising. The app keeps three things in your browser's local storage: your sign-in session, your language, and whether you chose light or dark. Clearing your browser data removes all three and signs you out.
8 · Under 18
fofiy is closed to people under 18. The year of birth is asked at the door, and it is a condition of the record itself rather than a checkbox. If you believe an under-18 has an account, write to hello@fofiy.com and it will be removed.
9 · Changes
If this document changes in a way that affects what we hold or for how long, the date at the top changes and the app says so once. We will not quietly widen it.