Privacy Policy
Version 3.0 · Effective August 6, 2026
toska is built around pseudonymity. We collect as little as we can, we never sell your data, and this policy is written to match what the code actually does — no more, no less.
1. What we collect
Everything below is collected only because a feature needs it. We collect no real name, phone number, location, contacts, photos, camera data, or advertising identifiers, we serve no advertising, and we do no cross-app tracking. (One literal caveat, so this reads true: Firebase Analytics pulls in Google's ads-attribution library as a transitive dependency, so that code is present in the binary. We never call it, no ads are served, and the app declares no tracking.)
- Email address — sign-in, password reset, account recovery, support. Stored with Firebase Auth only — it is never copied into our post/profile database.
- Random handle — your display identity (generated; never your real name).
- Posts, replies, reflections, prompt responses — the app itself.
- Drafts — posts you saved but didn't publish (only you can read them).
- Likes, saves, reposts, follows, blocks — core features. Your lists are private to you; a like/repost's existence is visible on the content it touches.
- Feeling tag, breakup stage, mood (if you set them) — feed personalization. Stage and mood live in your private, owner-only profile area.
- Days you opened the app (date only) — powers your streak; only you can read it.
- Push notification token — delivering notifications you opted into; private area.
- Reports you submit (including the reported text) — readable only by moderators.
- Crash reports — Firebase Crashlytics, not linked to your account, error text scrubbed of identifiers before sending.
- Usage analytics (event names only; opt out in Settings → Privacy) — a fixed event vocabulary that never includes what you wrote, your handle, your ID, or search terms.
- Performance data (app start time, screen render time, network request timing; opt out with the same Settings → Privacy toggle) — Firebase Performance Monitoring. No content, handle, or account identifier.
Timestamps on content are server-assigned and used for ordering and expiration — we don't collect device clocks, time zones, device models, or OS-version analytics of our own.
2. What "anonymous" actually means here — the honest version
- To other users: you are a random handle. Nothing in the app shows any other user your email, name, or account identifiers, and our database rules — not just the interface — prevent other users from reading your private data.
- To us (the operator): toska is pseudonymous, not anonymous. Your posts are stored against your account ID, which is connected to your email. We can technically connect content to an email address, and will do so only for moderation, safety, or valid legal process. We can't honestly claim otherwise, and we won't.
- One persistent handle: all your posts appear under the same handle. Whisper and midnight posts are ephemeral, not extra-anonymous — they show your handle like any post until they expire.
- Crisis signals: if our systems detect crisis language in a post, the post is held for human review and crisis resources are shown to you. Since July 2026 our database rules structurally prevent moderation and crisis flags from ever being readable by other users, and content restored after review is scrubbed of all such markers.
3. How we use data
To run the app (feeds, threads, notifications), personalize your feed, detect and act on content that violates the Terms, keep the service safe (report review, crisis-content review, abuse rate-limiting), and fix crashes. We do not sell, rent, or share your personal data with advertisers or data brokers, we do not use your data for advertising at all, and we do not use your content to train AI models or allow anyone else to.
4. Public sharing of posts (your control)
If your allow sharing setting is on (default on; Settings → Privacy): other users can render a post of yours as a share-card image — words and feeling tag only, never your handle; and a small number of posts, hand-picked by us, may appear on toskaapp.com and its share pages — same rule: words, tag, felt-count, and an approximate age (e.g. "3h ago") only, no handle, no identifier, no profile link.
Turning it off ends both, including for existing posts. Deleting a post removes it everywhere, including the website — the website's cache can take up to about ten minutes to catch up. Letters and expiring posts are never shareable regardless of this setting.
5. Third-party services
- Firebase / Google Cloud — our infrastructure: authentication, database, serverless functions, push delivery, crash reporting, analytics, performance monitoring, and app-integrity checks all run on Google's servers under Firebase's privacy documentation. We use them to run toska, not to advertise.
- Apple — push notifications are routed through Apple's service; the payloads contain no post content and no handles — only generic text and routing IDs. Sign in with Apple shares your email with us (or Apple's private relay address if you Hide My Email).
- Google Sign-In (optional) — shares your Google account email with us.
- Giphy — GIF search goes through our server, so Giphy does not receive your identity, account ID, or IP address for searches. When a GIF is displayed, your device loads the image directly from Giphy's servers, which — like any image host — see your IP address. Giphy privacy policy.
No other third party receives user data. There are no ad networks, no data brokers, no tracking SDKs.
6. Retention — exact windows
- Posts, replies, profile: until you delete them or your account.
- Drafts: until you delete them or your account (only you can ever read them).
- Whisper posts: 1 hour after posting, then hard-deleted from the live database — usually within about ten minutes — by a cleanup that runs every ten minutes (a database time-to-live policy is the backstop if a run fails). Midnight posts: same, from your local midnight.
- Notifications in your inbox: pruned after 90 days.
- Reports and moderation records: retained after content deletion for safety, abuse-pattern, and legal-defense purposes.
- Admin action log: retained as an internal accountability record; contains no post content beyond what moderation required.
- Re-registration block list: if we remove an account for serious violations (including underage use), we retain a one-way cryptographic hash of its sign-in identifiers (email address and Apple/Google account identifier) to prevent the removed account from re-registering. The hashes cannot be reversed to reveal the identifier; no plaintext identifier is retained. (Added 2026-07-29.)
- Backups: point-in-time 7 days; daily backups 7 days; weekly backups 8 weeks — deleted data ages out of all backups within about 60 days.
7. Account deletion — exactly what it deletes
Deleting your account (Settings) starts an automated server-side cascade that removes: your profile and handle, private profile data (mood, stage, settings, push token), posts, replies, likes and their effect on counts, saves, reposts, follows/followers, blocks, drafts, streak days, notifications you received, notifications you triggered in other users' inboxes, and your authentication account (which is where your email lives). Sign-in-with-Apple tokens are revoked with Apple. The cascade retries hourly until complete if any step fails. What survives: reports about content and reports you filed that we already acted on (for safety); our internal moderation-action log — note that the deletion itself writes entries there, one per removed post, each recording the account identifier and handle as a permanent moderation record; the one-way hash that blocks re-registration if the account was removed for a serious violation; and backup copies until they age out. We aim for the live-database cascade to complete within minutes, not days.
8. Your rights
Available to everyone, in-app, today: export my data (Settings — a JSON file of everything you've authored and own), deletion (per-item and full-account), correction (edit posts/replies, change email), analytics opt-out, and sharing opt-out.
Do Not Track / Global Privacy Control: we do no cross-app or cross-site tracking and serve no advertising, and we do not sell or "share" personal information — so there is no tracking or sale to opt out of. The in-app analytics opt-out (Settings → Privacy) turns off the only optional collection we do, and we treat a browser Global Privacy Control (GPC) or Do-Not-Track signal on our websites as a valid opt-out preference.
If you're in the EU/EEA/UK, these mechanisms are how we honor GDPR access, portability, erasure, and rectification; if you're in California, they cover CCPA/CPRA access, deletion, correction, and opt-out rights (we do not sell or "share" personal information as those laws define the terms, and we honor these rights regardless of whether the laws technically cover us, and we do not discriminate against you for exercising them). Email salte@saltedevelopments.com for anything the in-app tools don't cover; we respond within 30 days. toska is US-based and your data is processed on Google Cloud infrastructure in the United States.
9. Legal requests
We may disclose data when required by law — a valid subpoena, court order, or equivalent legal process. We will notify affected users when legally permitted. We do not voluntarily hand data to law enforcement or governments, with one exception: we may report imminent threats of serious harm.
10. Security
Data is encrypted in transit and at rest on Google's infrastructure. Access rules are enforced in the database layer (not just the app), are covered by an automated test suite, and are audited regularly. App integrity checks limit API access to genuine builds of the app. No system is perfect: if we learn of a breach affecting your personal data, we will notify affected users and any required regulators without undue delay after confirming it.
11. Age
toska is for users 18 and older, and your age confirmation is recorded at signup. We do not knowingly collect data from anyone under 18; if we learn we have, we delete the account and its data. toska is not directed at children under 13, and we never knowingly collect their data.
12. Changes to this policy
Each version is numbered and dated. Material changes are shown in the app for re-acceptance before continued use, and your accepted version and timestamp are recorded on your account.
13. Contact
© 2026 SALTE DEVELOPMENT LLC