← Back to Fantasi
Legal

Privacy Policy

This describes what Fantasi actually collects, why, who it's shared with, and how to access, correct, or delete it — kept accurate to what the Service does today, not aspirational.

Last updated: September 13, 2026
Contents
  1. 1. Overview
  2. 2. Information We Collect
  3. 3. How We Use Information
  4. 4. Sharing With Third Parties
  5. 5. Cookies
  6. 6. Data Retention
  7. 7. Your Rights & Choices
  8. 8. Security
  9. 9. Children's Privacy
  10. 10. Data Location
  11. 11. Changes to this Policy
  12. 12. Contact
1

Overview

This Privacy Policy explains how Fantasi collects, uses, shares, and protects information when you use the Fantasi Service. It's part of our Terms of Service. Fantasi is currently operated as an individually-owned, unincorporated business under the working name "Fantasi."

2

Information We Collect

CategoryExamples
AccountEmail address, password (stored hashed, never in plain text), full legal name, display name, date of birth
Identity verificationA copy of a government-issued ID, submitted at registration and reviewed by an administrator before your application is approved
ProfileBio, photos (up to 6 plus an avatar), interests and preference tags, heading, "looking for," education, relationship status, smoking preference, height/weight (weight optionally hidden)
ContactPhone number, only if you choose to verify one
LocationA free-text location you enter (e.g. "Baton Rouge, LA"); if you're a Black-tier member and set up geofenced privacy zones, the address you enter for each zone is geocoded to approximate coordinates so the Service can exclude nearby members from seeing your profile in Discover/Search
ActivityMessages you send, forum posts and comments, likes, profile views (unless you enable incognito browsing), blocks and reports you file or are named in
Support & moderationMembership tier requests, data-subject requests (access/correction/deletion/etc.) you submit, reports filed against you and their resolution
TechnicalIP address and basic request metadata collected by standard web server/security logging (e.g. rate limiting, abuse prevention)
3

How We Use Information

We do not use your information for third-party advertising, and we do not sell your personal information.

4

Sharing With Third Parties

We share information only as needed to operate the Service, or when legally required:

If paid membership is introduced in the future: payment details will be collected and processed directly by a third-party payment processor under their own privacy practices; we will update this section with the specific processor and what, if anything, we retain (e.g. a transaction reference) before any payment feature goes live.

5

Cookies

We use a small number of strictly necessary cookies to keep you signed in — a short-lived access token and a longer-lived refresh token, both httpOnly and SameSite=strict so they can't be read by page scripts or sent cross-site. We do not currently use advertising or third-party analytics cookies.

6

Data Retention

We retain your information for as long as your account is active. If you request deletion (Section 7) or an administrator removes your account for a Terms violation, your profile, photos, ID document, and associated data are permanently erased from our systems; we do not maintain a "shadow" copy of a deleted profile.

Your ID document specifically is stored separately from the rest of your profile, is never given a public URL, and can only be opened by an administrator through the admin review screen — never displayed to other members or exposed anywhere in the app's normal browsing experience.

7

Your Rights & Choices

From the Privacy & Data section of your account, you can submit a request to:

Every request is reviewed by a person, not resolved automatically; we aim to respond within 30 days. You can also directly control several privacy settings yourself at any time without filing a request: blurred-photo mode, who can message you, whether your location or last-active time is shown, and (Black tier) incognito browsing and geofenced privacy zones.

8

Security

Passwords are hashed (never stored in plain text) before being saved. Authentication uses signed, httpOnly session cookies rather than storing tokens in a way client-side scripts can read. The Service applies rate limiting and standard HTTP security headers to reduce common attack surfaces. No method of transmission or storage is 100% secure, and we can't guarantee absolute security — if we become aware of a breach affecting your personal information, we will notify you as required by applicable law.

9

Children's Privacy

The Service is not directed to, and is not intended for use by, anyone under 18. We do not knowingly collect personal information from anyone under 18. If we learn an account belongs to someone under 18, we will terminate it and delete the associated data.

10

Data Location

Our infrastructure is currently operated from the United States, and your information is processed and stored there. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.

11

Changes to this Policy

We may update this Privacy Policy from time to time. If we make a material change, we will update the "Last updated" date above and, where required by law, provide additional notice before the change takes effect.

12

Contact

Questions about this Policy, or to exercise a privacy right outside the in-app flow, contact privacy@fantasi.app.

Note: privacy@fantasi.app is a placeholder pending a registered business domain and formal business entity. Update this address once one is established.