1. How the app makes money
This is the most revealing question. Apps that live on ads have an incentive to collect data and build interest profiles. Apps that charge a subscription, receive donations or are run by an organization have other incentives. No model is a guarantee, but knowing where the money comes from helps you understand what happens to your data.
2. Encryption: in transit or end-to-end
- Transport encryption (HTTPS/TLS) protects data on its way between you and the app's server. Almost every serious app uses it. The server, however, can read the content.
- End-to-end encryption means only the people in the conversation can read it. Not even the app has access to the content. It's the strongest standard for private messages.
Read carefully what the app promises: "encrypted" on its own may mean transport only. In community apps with large servers, end-to-end encryption is technically harder, and many don't offer it.
3. What is collected and for how long
The privacy policy should say what data is collected (email, phone number, IP address, contact list, messages, usage data), what for and how long it's kept. Be wary of apps that ask for your contact list without a clear need or that don't explain retention.
4. ID, selfies and age verification
Some services have started asking for a photo ID or a selfie to verify age in certain countries. There can be good reasons, such as protecting minors, but your ID and your face are sensitive data: ask who processes them, where they're stored and when they're deleted.
5. Your rights under the LGPD
Brazil's Lei Geral de Proteção de Dados (General Data Protection Law, Law 13.709/2018) guarantees, among other things, the right to confirm whether your data is processed, to access it, correct it, request portability and request deletion. A good app makes exporting your data and deleting your account simple, without emailing someone and waiting weeks. Questions and complaints can be taken to the Autoridade Nacional de Proteção de Dados (ANPD, Brazil's National Data Protection Authority). If you live elsewhere, your own country's data protection law may give you similar rights.
6. Account security
- Two-step verification (2FA): even if someone finds out your password, they can't get in without the second factor.
- Session list: see where your account is signed in and end sessions you don't recognize.
- Properly stored passwords: serious services store passwords with hashing algorithms designed for this, such as argon2 or bcrypt, never in plain text.
7. App permissions
Microphone, camera and screen capture are necessary in a voice app, but they should only be used when you ask. A good sign: the camera starts off and the app clearly shows when it's broadcasting.
8. Scams that don't depend on the app
No encryption protects you from social engineering. Never share verification codes, be wary of "free gift" links and of profiles claiming to be support that offer help by direct message.
The checklist in one table
| Question | How Falafy measures up |
|---|---|
| Does it live on ads? | No. No ads and no selling data; voluntary support via Pix. |
| Transport encryption? | Yes, on the website, in the app and in calls. |
| End-to-end for messages? | Not yet. It's in development. |
| What data does sign-up ask for? | Email, username and password. No phone number and no contact list. Details in the privacy policy. |
| 2FA and session control? | Yes, two-step verification and sessions you can end. |
| Export and delete data? | Yes, right in the app, as required by the LGPD. |
| How are passwords stored? | With argon2. |
| Does the camera start off? | Yes, always. |
More details in Security and privacy on Falafy. If you're setting up a space for work, see also voice chat for remote teams.