Privacy, in plain language
Frendy is built to know as little about you as technically possible. This page explains — plainly — what we can and cannot see, and what we would do if an authority came asking.
Last updated: July 2026
1What signing up requires
To create an account you need an invite code and a username you choose. That's all. No phone number, no email, no real name, no address — no personal data of any kind. Your recovery phrase is generated on your device; we never see it and cannot recover it for you.
2What we can never see
Frendy is end-to-end encrypted. The following is encrypted on your device and readable only by you and the people you talk to — never by us:
- The text of your messages;
- Your photos, videos, voice notes and files;
- Your call and conference audio/video;
- Your private keys, dialog keys and PIN;
- Your avatar.
The server only ever holds ciphertext it has no key to open. This isn't a promise to behave — it's an architectural fact.
3What the server does hold
To deliver messages, we keep the minimum needed to run the service:
- Your username and public key;
- Encrypted, unreadable message and file blobs, until they are delivered;
- Routing metadata — who communicates with whom, timestamps, and the sizes/types of items;
- Device and session tokens, so push notifications reach the right device;
- Invite relationships (who invited whom).
We keep this to the minimum and delete what we no longer need.
4If the authorities come asking
Let's be completely honest. If a court or a lawful authority sends a valid legal request, we will comply with the law — we are not here to shield criminals. But here is the technical truth: we cannot hand over your conversations, files, keys or media, because we do not have them and cannot decrypt them. We can only provide the limited metadata we actually hold. We can't give what we don't have — that is the entire point of end-to-end encryption.
Where permitted, we intend to publish a transparency report of the requests we receive and how we responded.
5What we don't do
- We don't sell or rent your data — to anyone, for any reason.
- We don't run ads or ad-targeting.
- We don't embed third-party trackers or analytics that phone home.
- Diagnostics, when enabled, are stripped of your content and personal data and encrypted before they ever leave your device (beta).
6Keeping and deleting data
Undelivered ciphertext is removed once it's delivered or after a reasonable period. Data cached on your own device belongs to you and is encrypted at rest. You can delete your account, which removes your server-side account data.
7Safety and abuse
Frendy is invite-only and governed by an acceptable-use principle: it is not a tool for illegal activity. We can suspend accounts and revoke invite chains based on reports and the limited metadata we hold — without reading anyone's messages. Report abuse to abuse@frendy.im.
8Children
Frendy is not intended for children below the minimum age in your country. Child sexual abuse material is absolutely forbidden; we act on every report and meet our legal reporting obligations.
9Changes and contact
We'll update this page as Frendy evolves and note the date at the top. Questions about privacy: privacy@frendy.im. Invite requests: inviteme@frendy.im.