fisfis.ccHome

Privacy policy

In effect from 9 October 2026

fisfis (fisfis.cc and the fisfis apps for Android and iPhone) is run by Azraf Al Monzim, an individual in Bangladesh. For anything this policy covers, write to privacy@fisfis.cc. That person is the controller of your personal data.

This page says what is collected, why, who else handles it, how long it is kept and what you can ask for. It applies wherever you are. Where the law of your country gives you more, you get more.

Who this is for

fisfis is for adults. You must be 18 or older to make an account, write to anyone, call anyone or use Match.

We do not knowingly collect data from anyone under 18. If we learn an account belongs to somebody under 18, we close it and erase its data. If you believe that has happened, write to abuse@fisfis.cc.

What anonymous means here

When you write to somebody or ask them for a call, they are not told who you are.

The service still keeps a record of each arrival, so that abuse can be stopped and the law can be followed: the network address it came from, the network and device it came from, and a rough place worked out from the network. The person you wrote to can see the rough place and the kind of device, never your address and never your account.

Your exact location is collected only if you allow your browser to share it when you send. Even then, the person you wrote to sees only an area about a kilometre across. The exact reading never leaves our servers.

Voice calls always pass through a relay, so neither side learns the other’s address. Calls are not recorded. We keep that a call happened, how long it lasted and how it ended.

What we collect

Every stored field is listed below, grouped by what it is about, with the reason it is kept. Nothing is stored that is not on this list.

What you wrote (31)

The message itself, and what happened to it.

  • Your message. It is the thing you came here to send.
  • Who wrote it. Separates what you sent from what was written back to you.
  • Whether you wrote something or sent a song. Decides which of the two the page draws when the message is read.
  • What the page was asking for when you wrote. A page can be asking for anything, for a confession, for two words. This is which of those was on when you pressed send, so the person reading it later sees it the way you were asked, not the way their page happens to ask today.
  • The boxes you filled in, when the page asked for more than one. Two words is two boxes and a match is a name and a reason. This is what you typed, kept in that shape so it is drawn as you wrote it. It is the same words as the message itself, never anything extra.
  • The song you picked. The title, so the person you sent it to can see what it is. Read back from Spotify when you sent it, never from your browser.
  • Who made it. Drawn under the title, the way every music app draws it.
  • The album it is on. Drawn under the artist. Also what a search of the inbox matches on.
  • The address of the album artwork. The picture itself is Spotify's and stays on Spotify's servers. This is where it is, and it is fetched by this site rather than by the browser reading the message, so the artwork is not a request you make to them. Spotify's player, further down the same card, is, see the list of who else hears about you.
  • The link back to Spotify. Spotify's own address for the track, so “Open in Spotify” goes to the right place.
  • The same link, in the form the Spotify app understands. Opens the installed application rather than the website, where there is one.
  • How long the track is. Shown beside the album. The track's own length, not the length of what Spotify's player will play.
  • Whether Spotify marks it explicit. Spotify's own marking, carried through so it is not lost between their app and this page.
  • When you sent it. Orders the conversation and starts the retention clock below.
  • The reference in your link. It is the link. Anyone holding it can read the thread, which is why it is 26 random characters and not your name.
  • When the thread began. Distinguishes a first message from a follow-up on an older one.
  • Whether it reached the inbox. Messages can be stopped by a filter or a block. You are not told which, and a stopped message still gets a thread and a link.
  • Which filter caught it, if one did. Lets the owner see why something was marked without re-running the rules.
  • Whether this site's own screening flagged it. Every message is read by a word list this site keeps, and this records when that list caught one. It flags a message for the person you wrote to; it does not delete it and does not tell them who you are.
  • Which word on that list matched. The word the rule looks for, not the sentence you wrote. Kept so the person reviewing a flag can tell whether the rule is catching the right thing.
  • What kind of thing that word is. A slur, a threat, spam and so on. It is what the owner sees beside the flag instead of the word itself.
  • Which rule it was. Names the rule so one that keeps catching ordinary messages can be found and changed.
  • When it was flagged. The screening runs after a message is stored, so this is not the time you sent it.
  • Whether somebody decided the flag was wrong. A flag that has been looked at and dismissed stays on the record as dismissed rather than disappearing, so nobody reviews the same message twice.
  • Who dismissed it. The account name of whoever looked. It is the operator or the owner, never you.
  • Whether the owner has this one still waiting. Drives the unread count in their console, and moves both ways, they can put something back to unread to deal with later. That is their own filing and is never shown to you.
  • When they first opened it. Your thread page marks a message you sent as Seen once it has been opened. You are told that it happened and never when: the comparison is made here and only the answer leaves.
  • Whether the owner starred it. The owner's own bookmark.
  • Whether the owner archived it. Moves it out of the inbox without deleting it.
  • Whether the owner deleted it. Deletion is recorded rather than silent, so a thread that is gone can say it is gone instead of looking broken.
  • Whether the whole thread was deleted. Deleting a thread takes its messages and images out of reach with it.
Images you attach (16)

The file is kept exactly as you sent it, including the camera and location data a phone writes inside a photograph. A smaller WebP copy is made for displaying it quickly, and the details in the original are read out and shown to the person who received it.

  • The image itself. Re-encoded, resized to at most 1600 pixels on its longest edge, and stored.
  • A smaller copy of it. So a thumbnail does not cost a full-size download.
  • What you called the file. So the owner sees something recognisable next to the image.
  • How large the stored copy is. The size after re-encoding, not the size of what you sent.
  • The stored format. Always WebP. Recorded so nothing has to guess what the bytes are.
  • When you uploaded it. Uploads that are never sent are cleared out on their own.
  • A one-way hash of your device token. So only the browser that uploaded an image can attach it to a message. The token itself is not stored.
  • Whether it is still shown. An image is visible as soon as it arrives. This records it being taken down again, which is the only thing that hides one.
  • When that decision was made. Records that a person made it, and when.
  • The file exactly as you sent it. Kept unchanged, beside the smaller copy used to display it. Nothing is stripped out of it.
  • What format that file was. Read from the file itself rather than from what your browser called it.
  • How large it was. The size of what you sent, before the smaller copy was made.
  • What the camera wrote inside it. Make, model, lens, the moment the shutter opened, and the coordinates if the photograph carries them. Read out of your file and shown to the person you sent it to.
  • The result of the automatic check. Confirms the stored file is still a readable image. It cannot approve anything; only a person can.
  • What that check saw. The format and pixel dimensions of the stored copy.
  • When it ran. So an image that was never checked is visible as such.
The network you are on (13)

Cloudflare works this out from the connection itself. None of it needs your permission and none of it can be turned off from this page, the only way to change it is to change the network you are using.

  • Your IP address. The one identifier here that usually points at a single household or phone. It is removed when the record is coarsened, the section below gives the figure, read from the policy that does it.
  • Country. The coarsest location, and the one kept longest.
  • Region or state. Narrows the country down, usually to something the size of a county.
  • City. Usually accurate to the city, not the street.
  • Postal code. Sometimes present, sometimes wrong. Kept because it is part of what was reported.
  • Approximate latitude. A guess from your address, typically the middle of a city.
  • Approximate longitude. The other half of that guess.
  • Network number. Identifies the operator carrying your traffic.
  • Network operator. The name behind that number, a phone network, an ISP, a data centre.
  • Kind of network. Mobile, home broadband, or a hosting provider. Worked out from the operator's name.
  • Which Cloudflare location served you. A rough sanity check on the rest.
  • Whether you look like you are using a VPN. A judgement, not a fact. Traffic from a data centre reads as likely.
  • Cloudflare's bot score. How much the request looks automated.
Your location, only if you share it (4)

This group is empty unless you press the button and your browser asks you first. Nothing here is collected silently. And the reading itself is not shown to anybody: the person you wrote to sees a box about a kilometre across that you were somewhere inside, never the coordinate your phone gave.

  • Precise latitude. What your device reported. On a phone this can be accurate to a few metres, which is why it stays on the server and is never sent to the person reading your message, they are shown the rough area it falls in.
  • Precise longitude. The other half of that reading, kept and shown the same way.
  • How accurate it claims to be. A reading with 2 km of error means something different from one with 8 m. This one is shown, because it says what the rough area is worth without saying where in it you were.
  • What happened when you were asked. Whether you were never asked, shared, gave an approximate answer, or your device could not tell.
Your device (7)

What your browser tells every site it visits, and a little that this page asks it for.

  • Browser identification string. Sent by your browser on every request, to every site.
  • Device class. Phone, tablet, or desktop. Read out of the line above.
  • Operating system. Also read out of that line, so it is a guess rather than a reading.
  • Browser. Which browser, and roughly which version, from that same line.
  • Screen size. Read from the page. Distinguishes one device from another more than you would expect.
  • Language. The language your browser asks for pages in.
  • Time zone. Your device's own setting, which does not always agree with your network.
What is worked out from all of that (4)

Nothing new is collected here. These are conclusions drawn from what is above.

  • Whether your two locations disagree. Set when the network guess and the shared reading are further apart than the accuracy allows.
  • How much of the above is trusted. A word, not a score: high, medium, low, or unknown.
  • When this was recorded. It is what the retention period below is counted from.
  • When the raw identifiers were removed. Empty until the retention run has been through this record.
How you are recognised when you come back (27)

You have no account here and there is nothing to sign in to. These exist so that /my can show you your own threads, and so the owner can tell one anonymous sender from another.

  • A label like “Sender 4F92”. What the owner sees instead of a name.
  • A one-way hash of a cookie in your browser. The cookie is a random value with no meaning. Only its hash is stored, so the stored value cannot be put back into a browser.
  • A one-way hash of your browser identification. Notices when the same cookie appears from a visibly different browser.
  • When that browser was first seen. Distinguishes a new device from a long-standing one.
  • When it was last seen. Used to age out devices that stop being used.
  • A one-way hash of a random number your browser made, together with a few things your browser already tells every page. So that clearing a cookie does not turn you into a second stranger in somebody’s inbox. The random number is the part that identifies you and it means nothing anywhere else; the things beside it are your screen size, your time zone, your language, your platform and how many processor cores you have, values shared by every phone of the same model in the same country, which is exactly why they are safe to combine and useless to collect on their own. They are hashed together and neither half is stored, so this cannot be read back into a screen size or into the number itself. Nothing here reads a page you visit, and nothing draws on a canvas or listens to your audio to tell your browser apart.
  • A one-way hash of that random number on its own. The same value without the things about your browser. It is what still recognises you after a browser update or a new monitor changes them. On its own it is enough to keep your messages under one label and deliberately not enough to open your threads, that takes the cookie, which this site will only give back when both halves agree.
  • When that number was first seen here. Distinguishes a browser that is new to this inbox from one that is not.
  • When it was last seen. The same use as the cookie beside it: aging out what has stopped being used.
  • When the things about your browser last changed under it. Stamped when the random number matched and the rest did not, a browser update, a resized screen, a different machine. Kept as a time and never as a count, because the only thing worth knowing is that it happened.
  • A one-way hash of your recovery key. The key is shown once and never stored. If you lose it, nobody, including the owner, can recover it.
  • When it was issued. Each send issues a fresh one.
  • Whether it has been used. A recovery key works once.
  • When you first wrote. Tells a first-time sender from a returning one.
  • When you last wrote. Orders the sender list, so the most recent is at the top.
  • How many messages you have sent. Shown next to your label.
  • When this record was made. The first time a message of yours was accepted.
  • The owner's private notes about you. Written by the owner, never shown to you, and free text.
  • Whether you were linked to another sender. The owner can decide two senders are the same person. The decision is recorded and can be undone.
  • Whether you have been blocked. Recorded here, and never shown to you.
  • Why. The owner's reason, written for the owner and never shown to you.
  • When you were linked to another sender. Nothing is ever linked automatically. A person decided, and this is when.
  • What that link moved. Which of your threads and devices changed hands, and your message count before it. Kept so the link can be undone exactly.
  • Whether that link was taken back. A link that was made and withdrawn stays on the record as both.
  • Two senders the owner decided are not the same. The opposite decision to the one above, recorded for the same reason: so nothing keeps asking, and so it can be reversed.
  • The other sender in that pair. The decision is about a pair, so both sides of it are stored.
  • When that decision was made. So a judgement made once is visible as having been made once.
If you report a thread (7)

Only what the report form asks for.

  • The reason you chose. Sorts what arrives, so the serious reports are not buried.
  • Anything you added. Optional, and only what you typed.
  • Your email, if you gave one. Optional. Leaving it blank does not make the report count for less; it only means nobody can reply.
  • Whether it has been dealt with. Waiting, escalated, resolved, or dismissed.
  • What was decided. The owner's note on the outcome. You are not shown it, see below.
  • When it was decided. How long your report waited. Kept so it is possible to tell a queue that gets worked through from one that does not.
  • When you sent it. Orders the queue, oldest complaint first.
If you ask somebody to talk (10)

A voice call leaves a row saying it happened and how it ended, and, like a message, a record of how the request arrived: the network, who rents it, the kind of device, roughly where. It does not leave the call itself. Nothing is recorded, at either end or in the middle, and neither of you is ever told the other's address: the sound goes through a relay for exactly that reason, and the arrival record above is what this site saw when you pressed the button, which never travels to the other end of the call. It is trimmed on the same clock a message's is, and everything in it is listed under “If you send a message” already.

  • How the request ended. Waiting, answered, declined, stopped by you, or nobody picked up in two minutes. It is what your own call screen is drawn from.
  • Whether it reached them. The same as for a message. If that person has blocked you it is written and reaches nobody, and you are told the same thing you would be told if they had simply not picked up.
  • A scrambled copy of your call link. Your way back to the call after a reload. Hashed, so the stored value cannot be turned back into the link, and it stops opening anything within minutes.
  • When it stopped being answerable. Two minutes after you asked. It is what makes the request stop on its own.
  • When they answered or declined. A time. Never which of the two, to anybody but them, that is the row above.
  • When the two of you connected. Empty when a call was answered and never connected, which is the one number that says whether this works on real networks.
  • When it finished. A time. Nothing about what was said, because nothing about what was said exists.
  • How long you talked. Whole seconds. It is what the relay is billed on, and what your own daily allowance with that person is counted against.
  • Who or what ended it. One of five: you hung up, they hung up, it reached their length limit, nobody picked up, or the two browsers never managed to connect.
  • When you asked. Orders the list the person you called sees.
If you join Fisfis Match (74)

Match is optional and separate. Nothing below is on your Fisfis page, in search, or seen by anybody before a reveal you both agree to, except the few lines Discover shows: an age, a city, a university if you chose to show it, your interests, one line and a song. Your name, exact area and handles are encrypted before they are stored, and the key is kept apart from the database.

  • Your name, encrypted. Handed over only after a mutual reveal. Set once, so you are the same person to everybody you reveal to.
  • Your date of birth. Proves Match's 18+ rule and works out the age others see. The date itself is never shown.
  • Your gender. Match currently supports matching between men and women, and this decides which side you are on.
  • Who you want to meet. Worked out from your gender, and used to decide whose Discover you can appear in.
  • The youngest age you are open to. Keeps people outside the range you chose out of your Discover.
  • The oldest age you are open to. The other end of the same range.
  • Where you actually are, encrypted. What you typed, used to find people near you. Never shown, never a map, never a distance.
  • The city others see. The only place Discover ever prints: a city, not a street.
  • Your university. Helps match you with people near your world. Shown only if you chose “Show university”.
  • Your college. Helps matching. Never shown to anybody before a reveal.
  • Your school. Helps matching. Never shown to anybody before a reveal.
  • Whether your university is named. Your choice between the university’s name and “University student” in Discover.
  • What you are looking for. One of four answers. It shapes who you are shown and is not printed in Discover.
  • Your interests. The main signal for who you are shown, and what Discover shows as yours.
  • Music genres you chose. One signal among several for who you are shown.
  • Your first prompt answer. Shown to people you match with, so there is something to start from.
  • Your second prompt answer. The same, for the second question.
  • Your one line. The sentence Discover prints in handwriting under your interests.
  • Your Instagram handle, encrypted. Optional. Shared only after a reveal, and only if you share it.
  • Your Facebook link, encrypted. Optional. Shared only after a reveal, and only if you share it.
  • Your phone number, encrypted. Optional. Shared only after a reveal, and only if you share it.
  • How far through setup you got. So “Finish setting up” takes you back to the right step.
  • When you agreed to Match’s rules. The record that you said you are 18 or over and agreed to the three rules.
  • When you finished your Match Profile. An unfinished profile is in nobody’s Discover; this is what says yours is finished.
  • Active or paused. Paused takes you out of new Discover batches without touching anything else.
  • When you started. Orders things, and nothing more.
  • When you last changed it. Lets newer profiles be told apart from ones nobody has touched in a long time.
  • The order of your photos. Which photo comes first when, after a reveal, they are shown.
  • When you added a photo. Orders photos added at the same position. The photo itself is stored privately and only you can open it.
  • The song you picked. Today’s song on Discover for a day, then part of your song history.
  • Who it is by. Printed beside the song, the way any song is.
  • The album it is from. Kept with the song so it can be drawn without asking Spotify again.
  • The sleeve’s address on Spotify. So the cover can be drawn. Fetched through this site, so your browser never asks Spotify for it.
  • When you picked it. A song is “today’s” for 24 hours from this, and history after.
  • Which day somebody was in your Discover. Today’s Fisfis is one batch a day; this says which day a person belonged to.
  • Their place in that day’s batch. So the batch is shown in the same order every time you open it.
  • How well we thought you two fit. Orders the batch. Never shown to you or to them; the card prints a percentage made from it.
  • What you decided about them. Interested, show later, skip or reported. Skip and report keep that person out of your Discover for good.
  • When you decided. Orders your decisions, and nothing more.
  • When the batch was made. Orders things, and nothing more.
  • The line you sent with an interest. Shown to the person you were interested in, with the interest. Checked against the same words a message is.
  • Whether they answered. Waiting, accepted or passed. A passed interest stays so the same person cannot be approached again.
  • When they answered. Orders things, and nothing more.
  • When you sent an interest. Counts the three interests a day each person may send, and an interest nobody answers closes three days after it.
  • A song you sent instead of words. Shown to the person you were interested in, with the interest, and becomes the first message if they accept.
  • Who that song is by. Printed beside the song.
  • That song’s sleeve on Spotify. So the cover can be drawn, fetched through this site.
  • When the person you were interested in first opened it. Takes “New” off it on their Interests page. You are not told.
  • When the two of you revealed yourselves to each other. Set only when you both said yes. From then, each of you sees the other’s name and Match photos.
  • When a conversation ended. An ended conversation stays readable for both of you and cannot be written in.
  • How a conversation ended. Ended or blocked. Never shown to either of you; both see only that it ended.
  • When either of you last wrote. Orders your conversations. Seven days without a message and a conversation goes quiet.
  • When a conversation started. Reveal is not open until three days after this.
  • The name you go by in one conversation. “Moon”, “Cloud”, chosen for each conversation, so it says nothing about you anywhere else.
  • When you said you were ready to reveal. Waits for the other person’s yes. They are not told unless they say yes too, and you can take it back until then.
  • How far you have read. Counts what is unread, and lets the other person see “Seen” under their last message.
  • When you last had the conversation open. Says “active now” to the other person for a few minutes, and nothing finer.
  • When you joined a conversation. Orders things, and nothing more.
  • Whether a message was words or a song. So it is drawn as what it is.
  • What you wrote in a Match conversation. Shown to the one person you were talking to. Checked against the same words an inbox message is. Kept, read-only, after the conversation ends.
  • The conversation prompt a message answered. Shown above your answer, and answering one moves the Connection Meter.
  • A song you sent in a conversation. Shown to the person you were talking to.
  • Who that song is by. Printed beside the song.
  • That song’s sleeve on Spotify. So the cover can be drawn, fetched through this site.
  • When the other person hearted a message. Shows the heart. A song they heart counts as kept, which moves the Connection Meter.
  • When a message was sent. Orders the conversation, and counts the days you both wrote towards the Connection Meter.
  • When you blocked somebody in Match. From then, neither of you is shown to the other again. They are not told.
  • Why you reported somebody in Match. Read by the people who run Fisfis, to decide what to do. The person you reported is not told.
  • What you added to a report. The same, in your words.
  • What happened to a report. Open until somebody who runs Fisfis looks at it.
  • When a report was dealt with. Orders things, and nothing more.
  • When you reported. Orders the queue it is read from.
  • Where you reported from. Discover, an interest, a conversation or one message, so the people who run Fisfis know what they are looking at.
  • The message you reported, as it was. A copy of the one message or opener you reported, read by the people who run Fisfis instead of the rest of the conversation.
If you use the Fisfis app (54)

The phone app is your own console in your pocket. It never sends a message for you, and nothing below is about anybody who writes to you. It is what lets your phone stay signed in, and be told when something arrives.

  • Whether a sign-in is a browser or the app. So your list of sign-ins can say which one is your phone, and a browser's sign-in can never be used as the app's or the other way round.
  • Your app's sign-in as it was one refresh ago, as a hash. The app swaps its sign-in for a fresh one every few minutes. If the old one is ever used again, somebody copied it, and the whole sign-in is ended.
  • How you chose to sign your phone in. Through a browser on the phone, or by typing a short code on another screen.
  • The short code you type to sign your phone in. Matches the code on your phone to the screen you approve it on. It stops working after ten minutes and is deleted an hour after that.
  • What your phone calls itself. Shown to you before you approve, so you can tell it is your own phone asking.
  • Whether a phone sign-in is waiting, approved, declined or used. Each one can be used exactly once.
  • When a phone sign-in stops working. Ten minutes for a typed code, two for a browser handoff.
  • When you started signing your phone in. Lets the sign-in be cleared away once it is finished with.
  • Whether your phone is reached through Apple or Google. Phone notifications can only be delivered by the company that made the phone's system. That company is told that something arrived for your phone, never what.
  • The address Apple or Google gave your phone. Where a notification is sent. It identifies your phone to them and to nobody else. It is deleted when you turn notifications off for that phone, and stops being used when the app is removed.
  • Which of your sign-ins registered your phone. Signing the phone out silences it at once, without your having to turn anything off.
  • Whether your phone runs a test build of the app. Test builds are reached through a different Apple address.
  • Whether your phone is an Android phone or an iPhone. A call rings differently on each, so the server has to know which kind of ring to send.
  • The address Apple gave your iPhone for incoming calls. Where a call is sent so your iPhone can ring like a phone call. Only Apple can use it, it is told only that a call arrived and the sender's label, and it is forgotten when Apple says it no longer works or the phone stops sending it.
  • What you call your phone. So your list of devices is readable.
  • What you want that phone told about. Each kind of notification is your choice, phone by phone.
  • When your phone was last reached. Shown beside the phone, so a silent one can be noticed.
  • How many times in a row it could not be reached. A phone that cannot be reached ten times in a row is stopped, so nothing keeps knocking on an address that is gone.
  • When notifications to that phone stopped. Because the app was removed, or it could no longer be reached.
  • Why they stopped. What Apple or Google answered, so the list can say why.
  • When you turned notifications on for that phone. Orders your list of devices.
  • A random number the app made up for itself when it was installed. So opening the app twice counts as one phone rather than two. It is not taken from your phone, it means nothing anywhere else, and removing the app throws it away.
  • Whether the app is on an Android phone or an iPhone. So the people who run Fisfis know how many of each to build and test for.
  • Which version of the app you have. So a fix can be checked to have reached people, and an old version nobody uses any more can be retired.
  • The build number of that version. Tells two builds of the same version apart.
  • Which version of Android or iOS your phone runs. So the app is not made to need a newer system than the phones that use it have.
  • Your phone's model name, like “Pixel 9”. So the app is tested on the phones it is actually used on. A model name, never a serial number.
  • The language your phone is set to. So the people who run Fisfis know which languages the app should speak.
  • The account the app was last opened under. So the people who run Fisfis can see which accounts use the app. Signing out does not clear it; it changes when another account signs in on that phone.
  • Whether a problem report came from you or from the app. You can send a report from the app's About screen; the app also sends one by itself when a call breaks, so the people who run Fisfis can fix it.
  • What you wrote in a problem report. Read by the people who run Fisfis to fix what went wrong. A report the app sent itself holds one line about the call that broke.
  • Android or iPhone, on a problem report. So the report is read against the right app.
  • The app's version, on a problem report. So a fix can be matched to the version it was reported on.
  • The app's build number, on a problem report. Tells two builds of the same version apart.
  • Your phone's Android or iOS version, on a problem report. Many problems only happen on one version of a system.
  • Your phone's model name, on a problem report. Many problems only happen on one maker's phones. A model name, never a serial number.
  • The app's own notes on a problem report. Whether notifications, the microphone and full-screen calls are allowed, and what the last call did, never a message, a token or an address.
  • The account a problem report was sent from. So the people who run Fisfis can look at the account it happened on.
  • When a problem report was sent. Orders the list of reports.
  • The account a report to fisfis was sent from. So the people who run fisfis can follow up with the person who reported.
  • Whether you reported a message or a call. Tells the people who review it what to look at.
  • Which message or call you reported. Points the review at the thing you reported.
  • The sender label on what you reported. The anonymous label you saw, such as Sender 4F92, so other reports about the same sender can be connected. Never who they are.
  • Why you reported it. Lets the most serious reports, such as child safety, be read first.
  • What you added to a report. Read by the people who review the report.
  • A copy of a reported message. Taken when it is reported, so the review sees what you saw even if the message is deleted afterwards.
  • When you reported it. Orders the review queue.
  • When the app was last opened signed in. Says whether an account still uses the app or only used it once.
  • When the app was first opened on that phone. Counts how many people install the app each day.
  • When the app was last opened on that phone. Counts how many phones still use the app this week and this month.
  • How many times the app has been opened on that phone. Tells a phone that opens the app every day from one that opened it once.
  • Each day the app was opened on that phone. Counts how many phones used the app on each day. A date and two numbers, nothing about what you did in it.
  • How many times it was opened that day. Tells a busy day from a quiet one.
  • Whether it was opened signed in that day. Tells phones that are used from phones where the app was installed and never signed in.
If you open somebody's page (2)

Reading a page tells its owner that somebody did. Once a day per reader, in one sentence, and the sentence is the whole of what is stored.

  • One line saying somebody read your page. The kind of device and the rough area your network is in, written as a sentence, “iPhone · Dhaka · approx”. It is worked out from the same two things listed further up this page and then thrown away: the line is kept, the address and the browser string behind it are not. On a rented address it says so instead of naming a city, because the city an address in a datacentre is registered to is not where anybody is.
  • What makes you the same reader all day. A keyed hash of your address, your browser and today's date, so a page opened four times is one line rather than four. It cannot be run backwards, it is not stored anywhere else, and at midnight it becomes a different value, so it cannot join today's reading to tomorrow's.
If a rate limit refuses you (6)

A limit that stops a script has to remember who it stopped, or the owner cannot let a person back in.

  • What was counted. Your address, or the sender identity your browser is bound to, depending on which rule refused you. It is the same value already recorded above; this row is a note that it hit a limit.
  • What you were doing. Sending, uploading or reporting. Which limit it was.
  • How many times. Counted since the last time somebody let you through, not for ever. It is what tells a person in a hurry apart from a script.
  • When it started. The first refusal in this run of them.
  • The most recent one. Also decides when this row stops being shown at all, a day after the last refusal, it drops off the list.
  • When you were let back in. Set when the owner releases a limit by hand. Blank means the limit ran its course on its own.
What the owner's own actions leave behind (18)

Running the inbox creates records too, and some of them are about you.

  • What a block applies to. A sender, an address, a range of addresses, or a whole network operator.
  • The value blocked. Which may be your IP address or the network you are on, kept for as long as the block stands.
  • Why. The owner's reason for adding it, in the owner's own words.
  • Any notes. Anything else the owner wrote alongside it.
  • When it was added. Orders the block list by age, so old blocks can be reviewed.
  • Whether a reply to you was rewritten. The owner can change a reply after sending it. Your page says so, and this is the stamp it says it from, a reply that changed silently under someone who already read it is a record nobody can rely on.
  • What the owner did. Deleting, blocking, approving, changing a setting.
  • Who did it. The owner, or the system acting on a schedule.
  • What kind of thing it was done to. A message, a sender, an attachment, a setting.
  • Which one. So the record points at something specific.
  • The address the owner acted from. The owner's own address, not yours.
  • What it looked like before. Which can include a copy of your message, kept so a deletion can be shown to have happened.
  • What it looked like after. The other half of that record.
  • When it happened. This log is only ever added to. Nothing in the application can change or remove a line of it.
  • A word the owner may put on your message. The owner's own filing, in their own words. It is never shown to you and never leaves this system, but it is a label attached to something you wrote, so it is named here.
  • When one was put on. Orders the owner's own filing. Nothing about it reaches you.
  • The line in a held notification. When the owner has quiet hours or a digest switched on, the fact that you wrote is written down until it can be sent. It carries your sender label and never a word of what you wrote.
  • When the thing it is about happened. So a summary arriving in the morning can say when each thing actually happened rather than when it was sent.
That you were here at all (42)

Separate from anything you sent, and recorded whether you sent anything or not. A page opened is a request to a server, and a request carries where it came from and what it came from. This is the part of that which is written down rather than passing through, how it is deduplicated, how long it is kept, and what it is never used for is on the visitor tables in the schema.

  • The name this site gives your browser. One identifier per browser, so forty pages read in one sitting are one record rather than forty. It is kept in a cookie your browser sends back and is not derived from anything about you.
  • A one-way hash of your address, browser and language. How a browser that will not keep cookies, a crawler, usually, lands on one record instead of a new one every time. Hashed with a key only this server holds, so it cannot be turned back into an address by anyone reading the table.
  • Whether your browser came back carrying the name it was given. The difference between a browser that is recognisably the same one and something that merely arrived from a familiar address. Nothing is concluded from a record where this is false.
  • The first time this browser was seen. Distinguishes somebody arriving for the first time from somebody who has been here before.
  • The most recent time this browser was seen. Starts the clock on the retention below. The raw address is kept for the retention window measured from this, not from the first visit.
  • How many times. A count of recorded visits, which is not a count of requests, it moves at most once a day for one browser on one network. A number, with no page named.
  • The country of the most recent visit. Copied from the newest observation below so a list can be read without a lookup per row.
  • The network of the most recent visit. The same copy, for the network number. What it means is described under the observation below.
  • What kind of connection that was. Mobile, home broadband, or a datacentre. The same judgement described under the observation below.
  • Whether that looked like a VPN. The same judgement, copied down. A guess about a network, never a claim about a person.
  • What kind of device it was. Phone, tablet or desktop, guessed from what the browser calls itself. Cosmetic, and nothing branches on it.
  • Which operating system. The same guess, for the system family. Not the version, so an update does not read as a new machine.
  • Which browser. The same guess again. Chrome, Safari, Firefox and so on, without a version number.
  • A hash that says “this browser, on this network, on this device”. What makes a returning visit update one row instead of writing another. It carries the browser identifier inside it, so it cannot be compared against anybody else's.
  • A hash of the network alone. Shared by everybody on one network in one city. It is what makes “a burst of messages from one small network in one hour” a question that can be asked, and it identifies nobody on its own.
  • A hash of the device alone. Shared by identical machines, the same phone model, on the same system build, in the same timezone, with the same language. It is how a browser whose cookies were cleared can be recognised as probably the same one, and it is evidence rather than proof.
  • The address the request came from. The single most identifying thing here, which is why it is stripped on the schedule below and why the hashes above exist to answer most questions without it.
  • Country. From the network, not from you. Nobody was asked and nothing was granted.
  • Region or state. The same guess, one level finer. Frequently wrong, and never treated as though it were not.
  • City. Usually accurate to the city, not the street. Wrong entirely behind a VPN.
  • The network number. Which network operator carried the request. An internet provider, a phone carrier, or a datacentre.
  • The name of that network. The operator's own name for itself, which is what makes the judgement below possible.
  • What kind of connection. Mobile, home broadband, or a datacentre, guessed from that name. A heuristic, and wrong in both directions sometimes.
  • Which of this network's locations answered. A fact about the delivery network rather than about you, kept because it explains an odd-looking country.
  • Whether this looks like a VPN or a rented address. A word rather than a score, because the signals behind it do not support the precision a number would imply.
  • How much like a person the request looked. A number the network in front of this site produces. It is about the shape of a request, not about who made it.
  • What your browser calls itself. The string every browser sends to every site it loads. Stripped on the same schedule as the address below.
  • The device that string suggests. Phone, tablet or desktop. A guess made from the line above, shown so nobody has to read the raw string.
  • The operating system it suggests. The system family and not the version, so a routine update does not read as a different machine.
  • The browser it suggests. Chrome, Safari, Firefox and so on. Also a guess from the same string.
  • The language your browser asks for. The first entry of the list every browser sends. Used to tell one machine from another, never to change what a page says.
  • Nine things your browser tells every site it loads. Screen size, colour depth, pixel ratio, timezone, language, platform, processor count, memory and touch points. Read as properties, with deliberately no drawing, no audio and no font probing, the techniques that would make this precise enough to identify a browser on its own are the ones left out.
  • When this combination was first seen. The first visit on this network, on this device. A new phone or a new office produces a new one of these.
  • When it was last seen. What the retention schedule below is measured from, so a combination nobody returns to ages out and stays aged out.
  • How many recorded visits on it. A count that moves at most once a day. Not a count of pages and not a count of requests.
  • When the address and browser string were stripped from it. Set when that happened, and cleared if the same browser comes back on the same network, which starts the clock again.
  • What this browser did about somebody. One of three things: opened their page, sent them a message, or signed in to that account. Opening a page is the weakest of the three and is recorded separately from the counter that says how many people opened it, that one is still an integer with nothing beside it.
  • Which one. The sender an inbox already knows you as, or the account you signed in to, or the page you opened. This is the row that connects a browser to a name, and no inbox holder can read it.
  • Which inbox that was learned in. A sender exists inside one inbox, so the record of being one names it. For a sign-in it is the account's own.
  • When that was first true. The first message to that inbox, or the first time that account was opened from this browser.
  • When it was last true. Moved on each later message or sign-in, so a connection that stopped being used is visible as one.
  • How many times. A count of messages to that inbox, or of recorded sign-ins. A number, with nothing about any one of them.

If you hold an account we also keep: how you sign in (an email address and a scrambled password, or the id your GitHub, Spotify or Apple account gives us), your username, name, picture and page settings, the phones and browsers you are signed in on, and your notification choices. If you use Match, we keep the Match profile you fill in; your name, exact area and contact handles there are stored encrypted.

Why, and on what legal basis

Under the GDPR and laws modelled on it, every use needs a legal basis. These are ours.

  • To provide the service you asked for (contract): delivering messages and calls, your inbox, your account, push notifications, Match.
  • To keep people safe and the service working (legitimate interests): arrival records, spam and abuse checks, blocking, moderation, rate limits, security logs, crash reports, backups. We have weighed these against your interests; you can object, see your rights below.
  • To understand how the product is used (legitimate interests, or your consent where the law requires it, including in the EU, the UK and Switzerland): counts of what people do, sent from our server, never from a tracking script in your browser. You can switch this off in the app at any time.
  • To follow the law (legal obligation): answering lawful requests, and reporting child sexual abuse material, see Child safety.

We do not sell your personal data, we do not share it for cross-context behavioural advertising, there are no adverts, and no decision with legal effect is made about you by automated means alone.

Who else handles it

A small number of companies process data for us, under contract, only to run the parts named here.

  • Cloudflare: hosting, the database, file storage, bot checks, the voice relay and sending email.
  • PostHog (United States): product analytics. Events are sent from our server and carry no message content.
  • Google Firebase: delivering push notifications to the apps, and crash reports from the apps.
  • Apple: delivering notifications to iPhones, and Sign in with Apple if you use it.
  • GitHub and Spotify: only if you sign in with them or attach Spotify to your page.
  • Google Play and the App Store: they distribute the apps and handle downloads under their own privacy policies.

Pages on fisfis.cc also make your browser contact these hosts directly:

  • challenges.cloudflare.com (Cloudflare, who also host this site). The send page and thread pages, where there is a form to submit. They learn: Your IP address, your browser, and signals about how the page is being used, enough to tell a person from a script.
  • open.spotify.com (Spotify). Any page showing a song message: their player loads with the page and starts playing, and the code that drives it, theirs, not ours, runs in the page beside it. This is the only piece of somebody else’s code anywhere in this product. They learn: Your IP address and your browser, which track you were sent, and that you opened the message carrying it. Their code is running in the page rather than sealed inside the player, so what it can see is the page, not a box on it, that is the honest way to put it, and it is why this is the only script here.
  • turn.cloudflare.com (Cloudflare, who also host this site). Only during an anonymous voice call, and only once somebody has answered. Never on an ordinary page, and never before a call is accepted. They learn: Your IP address, and that a call is passing through them, which is unavoidable, because a relay is a computer your audio physically travels through. What they do not get is the sound: the call is encrypted between the two browsers and the relay carries packets it cannot read. It is the same company that already sees this request, because they run the network this site is on.

We may disclose data when the law requires it, to protect somebody from serious harm, or to a successor if the service changes hands, in which case this policy still applies to what was collected under it.

Where it is stored

Our providers run servers in many countries, including the United States.

When data leaves the EU, the UK, Switzerland or another country that restricts transfers, it is protected by the European Commission’s Standard Contractual Clauses (with the UK and Swiss addenda) or another mechanism the law recognises. Write to privacy@fisfis.cc for a copy of the safeguards.

How long it is kept

  • Arrival records: the network address and exact coordinates are removed after 90 days. The country, city and network stay with the message.
  • Messages, replies and pictures: until the inbox owner deletes them, or the account is erased.
  • Your account: until you ask us to delete it, see below.
  • Sign-in links and codes: thrown away soon after they expire.
  • Backups: copies of the database are taken weekly and used only to recover the service after a failure. An account erased after a backup was taken is erased again if that backup is ever restored.

Deleting your account

Ask in Settings, Account, Delete account, on the web or in the app. Your page goes offline at once and we erase the account and everything in it within 30 days.

Until it is erased you can sign in and keep your account. You can also ask by writing to privacy@fisfis.cc from the address on the account. The details are on Delete your account.

Your rights

Write to privacy@fisfis.cc. We answer within 30 days, or sooner where your law says so, and we may need to confirm the request is yours. We will not treat you differently for using any of these rights.

  • EU and EEA (GDPR), United Kingdom (UK GDPR) and Switzerland (FADP): access, correction, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawing consent at any time. You may complain to your data protection authority, such as your national supervisory authority in the EU, the ICO in the UK or the FDPIC in Switzerland.
  • California (CCPA as amended by the CPRA) and other US states with privacy laws (such as Colorado, Connecticut, Virginia, Utah and Texas): to know what we collect and why, to access, correct and delete it, and to opt out of sale, sharing and targeted advertising. We do none of those three. The categories we collect are identifiers (account details, network address), internet activity (use of the service), approximate geolocation, precise geolocation only if a sender allows it, and the content of messages you send or receive. An authorised agent may ask on your behalf. If we refuse a request you may appeal by replying to our answer.
  • Brazil (LGPD): confirmation, access, correction, anonymisation or deletion, portability, information about sharing, and withdrawing consent. You may complain to the ANPD.
  • Argentina, Mexico, Colombia, Chile and Peru: access, correction, cancellation and objection (ARCO rights) under each country’s data protection law, and a complaint to its authority, such as the AAIP in Argentina, the SIC in Colombia or the ANPD in Peru.
  • Canada (PIPEDA): access and correction, and a complaint to the Office of the Privacy Commissioner.
  • Australia (Privacy Act): access and correction, and a complaint to the OAIC.
  • India (DPDP Act): access, correction and erasure, nominating someone to act for you, and grievance redress through privacy@fisfis.cc, then the Data Protection Board.
  • Bangladesh and everywhere else: access, correction and deletion as described here, and any further rights your local law gives you.

Security

Connections are encrypted, passwords are stored scrambled, sessions can be ended from Settings, and sensitive Match fields are encrypted at rest. No system is perfectly secure; if a breach puts you at risk we will tell you and the authorities the law requires us to tell.

Notifications and analytics choices

Push notifications are sent only if you allow them, and you can switch each kind off in Settings or in your phone’s settings. Product analytics can be switched off in the app’s settings, and in the EU, the UK and Switzerland the website asks before counting anything optional. What remains is the minimum needed to run the service and keep it safe. Wherever you are, you can change your answer for this browser here.

Changes

If this policy changes in a way that matters, we will say so in the app and on this page before the change takes effect. Questions go to privacy@fisfis.cc; anything else to support@fisfis.cc.

Meet someone differently

Fisfis Match · coming soon

A new way to meet through Fisfis. Start with a reason to talk. Names and faces can wait.

That is all we are saying for now. Close this and it stays out of the way for two days.