Privacy
What we hold, and what we do with it
Friendword handles a friend’s voice, someone’s face, and a decision about who may contact them. This page says exactly what is collected, who else sees it, how long it stays, and how to remove it.
The short version
- Nothing about you becomes public until you approve it, item by item — the words, each photo, who may reach out, and for how long.
- Your email address lives in our authentication system only. We never copy it into the product tables, and sign-in is a one-time emailed code — there is no password and no social login.
- Nothing is sent to an external AI provider unless you separately agree to it on the screen that asks. Uploading a recording or a photo reaches our own storage and stops there.
- We do not sell your data. There is no advertising network, no advertising identifier, no third-party analytics SDK, and no crash-reporting SDK in the app.
- Reporting, blocking, pausing your page, withdrawing consent and deleting your account are free, and none of them is behind a purchase.
What we collect, and why
Your account
An email address, held in our Supabase authentication store, and an account record with your display name, date of birth and account status. We need the address to sign you in and to send the few transactional emails listed below; the date of birth is how we keep the service to adults only.
A display name is seeded from the first part of your email address when the account is created. Until you confirm a name of your own, that seeded value is never shown on any public page — you appear as “A friend”.
Your profile
If you are the person being introduced: photos, a short bio, what you are looking for, and an approximate location. You choose how precisely the location is shown — city, region, or hidden entirely. We never collect a precise location, and the app never asks for the location permission.
The pitch itself
A 30–60 second voice recording made by your friend, the photos they suggest, the transcript of that recording, and the structured text built from it. These live in private storage. They are not public, and cannot become public, until the person being introduced approves them.
When a pitch is approved we freeze a snapshot of exactly what was approved — the headline, the text, the transcript and the list of photos. That snapshot is the record of what the person actually agreed to publish, and it is kept even after the campaign ends.
The invitation to approve
When your friend invites you to review a pitch, the email address or phone number they used is stored as a one-way hash, never as the address itself. It exists only to bind that invitation to the account that claims it.
Interest and conversations
If someone expresses interest, we store that interest and — once both sides agree — the text messages in the private one-to-one room. Message contents are never written to our analytics, and are never sent to an AI provider.
Purchases
Purchases are made through Apple and processed by RevenueCat. We store the purchase events, the product identifier, and which campaign or pitch the purchase applies to. Your Friendword account identifier is the identifier RevenueCat knows you by. We never see or store your card details.
Product analytics
We record a small set of usage events in our own database. The properties an event may carry are restricted by a server-side allowlist — a campaign or pitch identifier, a source or channel label, a duration, a product identifier — and nothing else is accepted. Outcome events are written by the database itself rather than by the app, so the numbers cannot be inflated from a client.
Reports
When content is reported we store the report, the target, and who reported it. A report from someone who is not signed in is attributed to a salted hash of the network address instead, so that repeated reports can be recognised without keeping the address.
The waitlist
If you leave your address on the landing page we store the address and which link brought you. It is used for exactly one email — the day the iOS app is available — and the record is deleted as that email goes out.
AI processing, and the consent it needs
Building a pitch uses an external AI provider — currently OpenAI — to transcribe the recording, structure it into text, and run a safety review over the text and photos. The same provider runs the safety review over a photo and note attached to an expression of interest.
Private one-to-one messages are never sent to an AI provider. That is a deliberate trade-off: those conversations are not screened before they are delivered, and are reviewed only when someone reports them.
We do not synthesise faces, generate AI avatars, clone voices, or produce lip-synced video. A pitch is your friend’s actual recording. The AI drafts words from it, a human edits them, and the person being introduced approves them before anything is public.
How long we keep it
These are the retention rules the service actually enforces today.
- The original voice recording is removed seven days after the pitch is approved and rendered.
- A published page stays public for the window its owner chose — 14 days for a free campaign, 30 days for a purchased pass — and then expires automatically.
- Media that never got attached to anything is swept away after 48 hours.
- Emails we queued but could not send are closed out after 72 hours.
- Payment records held for manual review have their personal details scrubbed 90 days after the review is resolved; a summary is kept.
Deleting your account
You can delete your account yourself, from the Friendword app under “Your activity → Account”, or on this site from the bottom of your inbox. It takes a two-step confirmation. Nobody at Friendword can press it for you, by design.
Confirming closes the account immediately: every part of the service stops accepting requests from it, your own voice recordings are removed, and any page of yours that depended on them is taken out of public view. The physical erasure of the rest runs on a scheduled job afterwards. We do not promise a completion time, and a deleted account cannot be restored.
What is removed
- Your account, profile, dating profile and profile photos, along with the pages, pitches and media you own.
- Interest you sent — it disappears from the other person’s inbox rather than becoming anonymous.
- The one-to-one rooms you were in, including the other person’s messages in them, since those rooms have only two participants.
What is kept, and why
- If you recorded a pitch about someone else and they published it, your voice recording and every video rendered from it are erased — but the text of that pitch and the snapshot of what they approved remain. That snapshot is their record of what they consented to publish, and it is not yours to withdraw.
- Safety reports are kept with the reporter and reported identifiers removed, so that a pattern of abuse does not vanish when an account does.
- Analytics, provider-usage and moderation records are kept with the link to your account severed.
- A single record that a deletion ran, so we can show the erasure was carried out.
Anything that was already public and has been downloaded, screenshotted or reshared by someone else is outside our reach. Deleting your account cannot recall it.
If you only want to remove a pitch you drafted that never became a page, the app deletes that outright — text, transcript and media together — because there is no approver whose record needs preserving.
Your controls
- Approve, edit, or refuse. Before anything is public you can rewrite the words, drop individual photos, set who may reach out, and choose how long the page lives — or decline the pitch entirely.
- Take it down. A published page can be paused or taken down for good from your inbox at any time.
- Refuse the AI step. A pitch can be written by hand instead. Declining means nothing leaves our storage.
- Report and block. Available on public pages, on people, and inside one-to-one rooms. Blocking stops visibility and messaging in both directions immediately.
- Delete your account, as described above.
None of these is a paid feature, and none of them is affected by whether you have bought anything.
What we do not claim
Friendword is 18 and over. We check a date of birth and a confirmed phone number; we do not run identity verification, face matching, or background checks, and we do not describe anyone on this service as verified or vetted.
A recommendation from a friend is not proof. A friend and the person they are introducing can be mistaken, or can agree to say something untrue. Treat what you read here as what it is — one person’s account of another.
Contact and changes
Questions about this policy, or about the data we hold on you, go through our support page.
If this policy changes in a way that affects what we collect or who we send it to, we will update the review date at the top of this page, and say so in the app before the change takes effect.