Privacy Policy
Effective September 23, 2026 · Portfolio beta revision 1
This Policy explains how FRFR processes information for personal pages and its gradually available networking features. FRFR is for adults aged 18 and older, is not directed to children, and may not be used by anyone under 18.
Information we process
- Account information: your verified email address or phone number, sign-in provider and stable account identifier, chosen name, session identifiers, and the date and version of your age confirmation and policy acceptance. When you choose Google or another enabled sign-in provider, that provider shares the identity information needed to authenticate you. FRFR does not receive your Google or Apple password.
- Information you provide: your username, headline, workplace, chosen location, interests, profile cards, photos, videos, documents, links, visibility settings, early-access interest, bookmarks, likes, notes, conversations, message reactions, notification preferences, and support or abuse reports.
- Technical information: IP address, browser and device information, request and error logs, security events, required session-cookie data, and push-subscription identifiers.
Location-based discovery uses the location you provide on your profile, not live device tracking. Your authentication email and phone number are not shown on your public page unless you separately choose to put contact information in content you publish.
How we use information
We use information to authenticate accounts, create and share personal pages, preserve your account across devices, operate available discovery and conversation features, record early-access interest, deliver notifications, prevent abuse, secure and troubleshoot the service, respond to requests, enforce our Terms, and comply with law. Where discovery is enabled, recommendations use profile information you make public and discovery preferences such as location. Joining the early-access list does not itself make your page appear in discovery. We do not sell personal information, use it for targeted advertising, or operate an advertising profile.
Providers and disclosures
We use service providers to operate the beta:
- Google Firebase Authentication authenticates enabled email-link, Google, and phone sign-in methods. It processes identity information, email addresses or phone numbers, and technical information needed for delivery, verification, and abuse prevention. Phone authentication also sends and stores phone numbers with Google for spam and abuse prevention across Google services. An additional provider such as Apple is only used if offered and chosen by you.
- Firebase Cloud Messaging delivers notifications when you opt in.
- Cloudflare Workers, D1 and R2 host the application, provide security and operational processing, and store profile records, networking records, and uploaded media.
- Upstash Redis stores session and identity metadata, rate limits, push registrations and notification retry records.
Providers process information under their own terms and our service arrangements and may process it in the United States or other locations where they operate. We may also disclose information when required by law; to investigate fraud, abuse, or security incidents; to protect rights and safety; or as part of a merger, financing, acquisition, or transfer of the service, subject to appropriate notice and protections.
What other people can see
Anyone with your public portfolio link can view the cards and details you make public, and can share links to public cards. Public content may be copied, captured, or indexed outside FRFR. Turning off your public portfolio hides its public page and removes it from discovery; it cannot retrieve copies already made elsewhere. Pausing discovery is separate: it keeps an enabled public portfolio link available while stopping new discovery and requests. Turning off new message requests alone does not hide an otherwise discoverable page. These networking controls appear when your account has networking access.
Conversations and saved context
Where networking is available, a card like or note can begin a conversation. FRFR keeps a snapshot of the card that started that interaction, including its relevant text or media, as context for the participants. That snapshot may remain even if the original card is edited or removed from the profile. Removing a connection or deleting either account removes the conversation and its context from both participants’ access. Reports and limited security records may be retained separately where needed to handle abuse or legal obligations.
Cookies and notifications
FRFR uses a required secure, HTTP-only session cookie to keep you signed in; it expires after 30 days. Firebase may retain sign-in state in browser storage. For email-link sign-in, FRFR temporarily remembers the address you entered on that device so you can confirm it when completing sign-in; it is cleared after successful completion. We also store device preferences such as appearance. We do not use advertising cookies. If you opt in to notifications, your browser’s push service receives the notification data needed for delivery. Lock-screen previews are controlled by you and your platform. Permission can be withdrawn in browser or device settings.
Retention and deletion
We retain your profile and its media while needed to provide your account, until you remove them or delete the account, subject to conversation snapshots, security, dispute handling, and legal obligations. Pausing discovery is not deletion. Sessions expire after 30 days; infrastructure caches and operational records have separate retention periods. Some historical records from the retired meetup beta may remain subject to their original retention rules or account deletion; the retired meetup features are no longer offered.
Account deletion removes application records tied to the account and requests deletion of the Firebase account. If a provider operation fails, the app may ask you to retry to complete deletion. Deletion from provider backups and security logs may take longer than removal from the live application.
Security
We use safeguards including encrypted transport, restricted secrets, secure session cookies, access controls, rate limits, and short-lived authentication links. No internet service can promise absolute security. Do not share sign-in links or verification codes. Contact us if you believe an account has been compromised.
Your choices and requests
You can edit or remove profile content, change public visibility, withdraw early-access interest, decline notifications, block profiles, manage available networking controls, request a copy of your data, sign out, or delete your account in Settings. Copies saved outside FRFR are not under our control. You may also ask to access, correct, or delete information, or appeal a privacy-request decision where applicable, by emailing contact@frfr.link. We may verify your identity before fulfilling a request.
Changes and contact
Material changes will receive a new effective date and, when appropriate, an in-product notice and renewed acceptance. For a privacy request, abuse report, security concern, or question, email contact@frfr.link.
Back to fr fr.