← fogo

Privacy policy

Draft — will be finalized before store release

The short version

We cannot read what you write — and it's deleted anyway. Fogo has no accounts, collects no names, emails, or phone numbers, shows no ads, and sells nothing about you, because it knows nothing about you.

What the app stores, and where

What the server can see

Only participation metadata: that a pair exists, and that encrypted messages of a certain size passed at certain times. We use daily aggregates of this (pairs created, pairs active) to understand whether Fogo is alive. Nothing in it identifies you, and pair identifiers are cryptographically hashed before any analysis.

Optional, anonymous question feedback

If — and only if — you opt in, the app sends anonymous events about which questions get answered, swapped, or skipped (never your answers, never who you are, no device or pair identifiers). This helps us retire bad questions and write better ones. You can switch it off at any time in Settings.

Your rights (GDPR)

Data minimization is built in: there is almost nothing to request a copy of, and erasure is a button — Settings → Unpair & delete everything immediately and permanently erases the pair on the server and resets both apps. For anything else: fogo@generativeobjects.com.

Children and teens

Fogo is designed for a parent and their teen, together. The teen joins without providing any personal data (no email, no phone number, no real name required), and the consenting parent is structurally part of every pair. The app never reports a teen's activity, or inactivity, to anyone — including the parent.

No third parties

No analytics SDKs, no advertising SDKs, no trackers. Infrastructure runs on Cloudflare (relay and hosting), which processes only the ciphertext and metadata described above.

Working name "Fogo". This draft will be completed (controller identity, store-specific disclosures) before public store release.