Last updated: May 28, 2026
Your privacy is fundamental to Pafly. Anonymity is not just a feature — it is at the core of what we build. This Privacy Policy explains what data we collect, how we use it, and the choices you have.
Pafly is designed so that no user can ever identify another user. Messages are anonymous by design. No personal information is visible between users. The sender and recipient of any message are never revealed to each other unless they choose to reveal themselves deliberately.
When you use Pafly, we create an anonymous account. No personal information is required — no email, no password, no real identity.
We store the messages you write, reactions you send, and replies you compose. Messages are stored to enable delivery to other users. We do not analyze your messages for advertising or profiling purposes.
We collect a unique device identifier and push notification token to deliver notifications and ensure proper app functionality. We store basic device information (platform, OS version) for technical support and compatibility.
We track writing activity dates (which days you sent a message) to display your writing calendar and streak statistics. We store aggregate counts of messages sent and received.
We store your notification preference settings (daily reminders, new messages, reactions, replies) so we can respect your choices about which notifications to receive.
Messages are processed through AI-powered content moderation before delivery. This is done solely to filter harmful content (hate speech, violence, harassment, illegal content). Moderation is automated and no human reads your messages during this process.
We do not use your messages to train AI models, build user profiles, or for any purpose beyond moderation and delivery.
We do not sell, rent, or trade your personal data to third parties. We share data only with the following service providers, strictly for app functionality:
We may disclose data if required by law or to protect the rights, safety, or property of Pafly, our users, or the public.
Your data is stored on secure servers. We use industry-standard security measures including encryption in transit (TLS) and at rest. Authentication tokens are stored securely on your device using platform-provided secure storage.
While we take reasonable precautions to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
Messages that cannot be delivered or are delivered expire after 30 days. Writing calendar data is retained for the duration of your account.
When you delete your account, all your device data is permanently removed from our systems, your messages are deleted after 30 days, including reactions and statistics. This action is irreversible.
Depending on your jurisdiction, you may have additional rights under applicable data protection laws (such as GDPR or CCPA), including the right to access, correct, or request deletion of your personal data. Contact us to exercise these rights.
Pafly is not intended for children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete that information.
The app stores minimal data locally on your device for functionality purposes: your authentication token (in secure storage), device identifier, onboarding status, and notification preferences. This data stays on your device and is cleared when you delete your account.
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app. Continued use of Pafly after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or want to exercise your data rights, please contact us at support@pafly-app.com.