1. Who the controller is and how to reach us
- Controller: Falafy, an independent project maintained by Erick Torres. [TO BE FILLED IN BY THE OWNER: full name or company name, CPF/CNPJ (Brazilian taxpayer ID) and mailing address of the controller]
- Data protection officer (DPO, "encarregado"): [TO BE FILLED IN BY THE OWNER: name of the DPO and a dedicated email, for example privacidade@falafy.com.br]. Until that email is published, requests about personal data can be made through the "Suporte Falafy" contact inside the app.
- Authority: if you are not satisfied with our answer, you can file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD, Brazil's National Data Protection Authority).
2. What data we process
Data you provide
- Sign-up: email, username, display name, password and date of birth. The password is stored only as an argon2 hash, never in plain text. Your date of birth is used to enforce the minimum age and the protections for users under 18 (section 9); it does not appear on your profile and cannot be changed in the app after sign-up.
- Acceptance of the terms: the version of the Terms of use and of this policy that you accepted, and the date you accepted it.
- Reports: when you report a message or a person, we keep the reason, the details you wrote and a copy of the text of the reported message.
- Profile (optional): photo, bio, pronouns, colors, frame, custom status, profile links, time zone and working hours, if you choose to fill them in.
- Content: text messages, voice messages, attachments (images, videos and files), reactions, polls, events, notes, stories and the servers, channels and roles you create.
- Relationships: friends list, friend requests, blocks and membership in servers and conversations.
Data generated by use
- Sessions: device name, creation date, last use and expiry of each session, so you can see and end where you are signed in.
- Account security: the two-factor authentication secret (encrypted with AES-256-GCM), backup codes (hash only) and attempt counters.
- IP address: used on the spot, in memory, to limit login attempts and excessive requests (abuse protection). At sign-up we also store a salted hash of the IP, used to prevent fraud in the invite program. In addition, we keep the access logs required by the Marco Civil da Internet (IP, port, date and time of each login, session renewal and app connection) for 6 months; see section 6.
- Presence and activity: your status (online, away, etc.) is kept in memory while you are connected. "Playing X" is only enabled if you turn the option on and is not stored in the database.
- Push notifications: if you allow browser notifications, we store the technical subscription address (endpoint and keys) provided by your browser.
- Preferences: notification, privacy, appearance and layout settings.
What we don't collect
- We don't use analytics tools, ad pixels or trackers on the website or in the app.
- We don't sell data and we don't show ads.
- We don't record voice or video calls or screen shares on the server. Clips, when you turn the feature on, stay only on your computer.
- Noise suppression runs on your device; the audio is not sent to an external service.
- We don't ask for your phone number, contact list or ID document.
3. What we use it for and on which legal basis
| Purpose | Data | Legal basis (LGPD, art. 7) |
|---|---|---|
| Create and maintain your account and provide the service (messages, voice, servers) | Sign-up, profile, content, relationships, sessions, preferences | Performance of a contract (item V) |
| Protect accounts and the service against abuse, spam and fraud | IP (in memory), hash of the sign-up IP, login and 2FA attempts, server audit log | Legitimate interest (item IX) |
| Send push notifications | Browser push subscription | Consent (item I), given through the browser permission and revocable at any time |
| Show "Playing X" | Game name and start time | Consent (item I), option off by default |
| Enforce the minimum age and protect children and adolescents | Date of birth | Compliance with a legal obligation (item II; ECA Digital, Law 15.211/2025) and the best interests of children and adolescents (LGPD, art. 14) |
| Keep application access logs | IP, source port, date and time of logins, session renewals and connections | Compliance with a legal obligation (item II; Marco Civil, art. 15) |
| Record your acceptance of the terms and of this policy | Accepted version and date | Performance of a contract (item V) and regular exercise of rights (item VI) |
| Receive and review reports | Report, reported message and accounts involved | Legitimate interest (item IX) and compliance with a legal obligation (item II) |
| Comply with legal obligations and court orders | The data needed in each case | Compliance with a legal or regulatory obligation (item II) and regular exercise of rights (item VI) |
4. Who we share it with
We don't sell or rent data. Some third-party services are involved in running the service:
- Hosting: servers on Oracle Cloud, São Paulo region (Brazil), where the database and uploaded files are kept.
- Push notifications: your browser's push service (for example Google, Mozilla, Apple or Microsoft) receives the encrypted notification to deliver it to your device. You can hide notification content per device.
- GIFs: GIF searches and images go through a proxy run by Falafy; the provider (KLIPY) sees the search term and Falafy's server, not your IP or your account.
- Link previews: when a message contains a link, Falafy's server fetches the page to build the preview; the visited site sees Falafy's server, not you. You can turn previews off.
- Watch Together (YouTube): the video plays in the YouTube player (youtube-nocookie.com), loaded directly on your device; Google receives your IP and the player's technical data, under its own policy.
- Website fonts: falafy.com.br pages load fonts from Google Fonts, which exposes your IP to Google.
- Other users: what you post in servers and conversations is visible to the people in them, according to the permissions.
- Authorities: upon a court order or a valid legal request.
Some of these services (push, YouTube, Google Fonts) may process data outside Brazil. This international transfer takes place to provide the service you requested, under art. 33 of the LGPD.
5. How long we keep it
- Account and profile: for as long as the account exists.
- Account deletion: when you delete your account, we erase your email, profile, photo, friendships, server memberships, sessions, 2FA, push subscriptions, notes, stories, badges, favorites and preferences. By default, the messages you sent in servers and conversations remain so as not to break the history of the other participants, but they appear as from "Removed user". On the deletion screen you can tick "Also delete all the messages I sent" to have them deleted together with the account; the attachments of those messages are removed from the server within 24 hours.
- Access logs (Marco Civil): 6 months, even after the account is deleted (the law requires it), and automatically deleted after that.
- Reports: [TO BE FILLED IN BY THE OWNER: retention period for reports, for example as long as needed for moderation and up to 5 years for defense in legal proceedings]
- Messages and attachments: until you delete them, until the server or channel is deleted, or until moderation removes them.
- Stories: 24 hours.
- Sessions: up to 30 days without use or until you end them.
- Data export file: available for download for 24 hours.
- Server technical logs: errors and warnings only, with no record of each request, kept for as long as needed for troubleshooting.
6. Access logs (Marco Civil da Internet)
Art. 15 of the Marco Civil da Internet (Brazil's Internet Civil Rights Framework, Law 12.965/2014) requires application providers organized as for-profit legal entities to keep access logs (date, time and IP) for 6 months, confidentially and in a secure environment. Falafy already keeps these logs. [TO BE FILLED IN BY THE OWNER: confirm with legal advice whether the project falls under art. 15]
- What we keep: the IP address and source port, the date and time (with time zone, in UTC) and the account and session of each login, session renewal and app connection to the server. We do not log each message or page you open.
- For how long: 6 months. A daily routine automatically deletes older logs. Authorities may require, by court order, that a specific log be kept for longer (art. 15, § 2).
- Security and confidentiality: the IP is encrypted (AES-256-GCM) in the database, does not appear on any screen of the app or in the API, and can only be read on the server by the person responsible, with every lookup logged (Decree 8.771/2016, art. 13).
- When we hand them over: only upon a court order or a request from an authority with legal power to demand this data (arts. 10 and 22 of the Marco Civil).
7. Your rights
Under art. 18 of the LGPD (Lei Geral de Proteção de Dados, Brazil's General Data Protection Law, Law 13.709/2018), you can request: confirmation that we process your data; access; correction; anonymization, blocking or deletion of unnecessary data or data processed in breach of the law; portability; deletion of data processed based on consent; information about who we share it with; information about the possibility of not consenting; and withdrawal of consent. You can also object to processing based on legitimate interest.
- Directly in the app: in Settings you can edit your profile; in Settings > Privacy & safety you can export a copy of your data (a ZIP file with your profile, the messages you sent, friendships, servers, sessions, acceptance of the terms and the reports you made, up to 3 requests per day), end sessions, turn off notifications, link previews and "Playing X", and delete your account (with the option to delete your messages too).
- Other requests: through the DPO contact above or through "Suporte Falafy" in the app. We reply within 15 days.
8. Security
We use transport encryption (HTTPS/TLS) on the website, in the app, in the API and in calls; passwords hashed with argon2; optional two-factor authentication; and session control. End-to-end encryption for messages is still in development: today messages are stored on Falafy's server without that kind of encryption. No system is infallible; in the event of a security incident posing a relevant risk, we will notify those affected and the ANPD, as the LGPD requires. More details in Security and privacy.
9. Children and adolescents
Falafy is not directed at children. You must be at least 13 years old to create an account. [TO BE FILLED IN BY THE OWNER: confirm the minimum age with legal advice; if it changes, also adjust MIN_SIGNUP_AGE on the server]
- How we check today: sign-up asks for your date of birth without saying beforehand what the minimum age is; an answer below it ends the sign-up and blocks new attempts from that device and that network for 24 hours; the date cannot be changed in the app afterwards; and anyone can report an account that seems to belong to someone under the minimum age, which is then reviewed by the team. [TO BE FILLED IN BY THE OWNER: the ECA Digital (Brazil's Digital Statute of Children and Adolescents, Law 15.211/2025) requires reliable age verification mechanisms, and self-declaration alone is not enough; describe here the additional mechanism adopted after legal and technical review]
- Protections for users under 18: the account starts with direct messages from friends only, friend requests from friends of friends only, bio, stats, activity and local time visible to friends only, images and videos from non-friends always blurred (including in servers), and the profile hidden from username searches by strangers. Direct messages and friend requests cannot be opened up to everyone. Falafy does not show ads or build advertising profiles of anyone.
- Parents and guardians: [TO BE FILLED IN BY THE OWNER: parental supervision mechanism and linking of accounts of users under 16 to a parent or guardian's account, as required by the ECA Digital] Parents or guardians who identify a child's account, or who want to request the deletion of the account of a teenager in their care, can contact the DPO or Suporte Falafy.
10. Cookies and local storage
The website and the app do not use tracking or advertising cookies. We only use what is strictly necessary for the service to work, so we don't ask for consent for it; we just let you know:
- Web version (falafy.com.br/app): a session cookie called
falafy_rt(HttpOnly, Secure, SameSite=Strict, valid for up to 30 days) that keeps you signed in, and the browser's local storage for preferences, drafts and whether you have already seen the storage notice. - Windows app: the session token is stored protected by the operating system, and preferences and drafts in the app's local storage.
Clearing the app's or the browser's data, or signing out, removes this information.
11. Changes to this policy
When this policy changes in a relevant way, we will let you know in the app before the change takes effect: the app shows the new version and asks you to accept it to continue. The date of the last update is at the top of the page, and the version you accepted is shown in Settings > About.
See also: Privacy policy · Terms of use · Security and privacy