toska

Privacy Policy

Version 3.0 · Effective August 6, 2026

toska is built around pseudonymity. We collect as little as we can, we never sell your data, and this policy is written to match what the code actually does — no more, no less.

1. What we collect

Everything below is collected only because a feature needs it. We collect no real name, phone number, location, contacts, photos, camera data, or advertising identifiers, we serve no advertising, and we do no cross-app tracking. (One literal caveat, so this reads true: Firebase Analytics pulls in Google's ads-attribution library as a transitive dependency, so that code is present in the binary. We never call it, no ads are served, and the app declares no tracking.)

Timestamps on content are server-assigned and used for ordering and expiration — we don't collect device clocks, time zones, device models, or OS-version analytics of our own.

2. What "anonymous" actually means here — the honest version

3. How we use data

To run the app (feeds, threads, notifications), personalize your feed, detect and act on content that violates the Terms, keep the service safe (report review, crisis-content review, abuse rate-limiting), and fix crashes. We do not sell, rent, or share your personal data with advertisers or data brokers, we do not use your data for advertising at all, and we do not use your content to train AI models or allow anyone else to.

4. Public sharing of posts (your control)

If your allow sharing setting is on (default on; Settings → Privacy): other users can render a post of yours as a share-card image — words and feeling tag only, never your handle; and a small number of posts, hand-picked by us, may appear on toskaapp.com and its share pages — same rule: words, tag, felt-count, and an approximate age (e.g. "3h ago") only, no handle, no identifier, no profile link.

Turning it off ends both, including for existing posts. Deleting a post removes it everywhere, including the website — the website's cache can take up to about ten minutes to catch up. Letters and expiring posts are never shareable regardless of this setting.

5. Third-party services

No other third party receives user data. There are no ad networks, no data brokers, no tracking SDKs.

6. Retention — exact windows

7. Account deletion — exactly what it deletes

Deleting your account (Settings) starts an automated server-side cascade that removes: your profile and handle, private profile data (mood, stage, settings, push token), posts, replies, likes and their effect on counts, saves, reposts, follows/followers, blocks, drafts, streak days, notifications you received, notifications you triggered in other users' inboxes, and your authentication account (which is where your email lives). Sign-in-with-Apple tokens are revoked with Apple. The cascade retries hourly until complete if any step fails. What survives: reports about content and reports you filed that we already acted on (for safety); our internal moderation-action log — note that the deletion itself writes entries there, one per removed post, each recording the account identifier and handle as a permanent moderation record; the one-way hash that blocks re-registration if the account was removed for a serious violation; and backup copies until they age out. We aim for the live-database cascade to complete within minutes, not days.

8. Your rights

Available to everyone, in-app, today: export my data (Settings — a JSON file of everything you've authored and own), deletion (per-item and full-account), correction (edit posts/replies, change email), analytics opt-out, and sharing opt-out.

Do Not Track / Global Privacy Control: we do no cross-app or cross-site tracking and serve no advertising, and we do not sell or "share" personal information — so there is no tracking or sale to opt out of. The in-app analytics opt-out (Settings → Privacy) turns off the only optional collection we do, and we treat a browser Global Privacy Control (GPC) or Do-Not-Track signal on our websites as a valid opt-out preference.

If you're in the EU/EEA/UK, these mechanisms are how we honor GDPR access, portability, erasure, and rectification; if you're in California, they cover CCPA/CPRA access, deletion, correction, and opt-out rights (we do not sell or "share" personal information as those laws define the terms, and we honor these rights regardless of whether the laws technically cover us, and we do not discriminate against you for exercising them). Email salte@saltedevelopments.com for anything the in-app tools don't cover; we respond within 30 days. toska is US-based and your data is processed on Google Cloud infrastructure in the United States.

9. Legal requests

We may disclose data when required by law — a valid subpoena, court order, or equivalent legal process. We will notify affected users when legally permitted. We do not voluntarily hand data to law enforcement or governments, with one exception: we may report imminent threats of serious harm.

10. Security

Data is encrypted in transit and at rest on Google's infrastructure. Access rules are enforced in the database layer (not just the app), are covered by an automated test suite, and are audited regularly. App integrity checks limit API access to genuine builds of the app. No system is perfect: if we learn of a breach affecting your personal data, we will notify affected users and any required regulators without undue delay after confirming it.

11. Age

toska is for users 18 and older, and your age confirmation is recorded at signup. We do not knowingly collect data from anyone under 18; if we learn we have, we delete the account and its data. toska is not directed at children under 13, and we never knowingly collect their data.

12. Changes to this policy

Each version is numbered and dated. Material changes are shown in the app for re-acceptance before continued use, and your accepted version and timestamp are recorded on your account.

13. Contact

salte@saltedevelopments.com