Overview
This Privacy Policy explains how Fantasi collects, uses, shares, and protects information when you use the Fantasi Service. It's part of our Terms of Service. Fantasi is currently operated as an individually-owned, unincorporated business under the working name "Fantasi."
Information We Collect
| Category | Examples |
|---|---|
| Account | Email address, password (stored hashed, never in plain text), full legal name, display name, date of birth |
| Identity verification | A copy of a government-issued ID, submitted at registration and reviewed by an administrator before your application is approved |
| Profile | Bio, photos (up to 6 plus an avatar), interests and preference tags, heading, "looking for," education, relationship status, smoking preference, height/weight (weight optionally hidden) |
| Contact | Phone number, only if you choose to verify one |
| Location | A free-text location you enter (e.g. "Baton Rouge, LA"); if you're a Black-tier member and set up geofenced privacy zones, the address you enter for each zone is geocoded to approximate coordinates so the Service can exclude nearby members from seeing your profile in Discover/Search |
| Activity | Messages you send, forum posts and comments, likes, profile views (unless you enable incognito browsing), blocks and reports you file or are named in |
| Support & moderation | Membership tier requests, data-subject requests (access/correction/deletion/etc.) you submit, reports filed against you and their resolution |
| Technical | IP address and basic request metadata collected by standard web server/security logging (e.g. rate limiting, abuse prevention) |
How We Use Information
- To provide the Service — creating and displaying your profile, enabling messaging and forum participation, showing you other members in Discover/Search, and enforcing your own privacy choices (blurred-photo mode, incognito browsing, geofenced privacy).
- To keep the Service safe — reviewing new applications, investigating reports, enforcing blocks, and enforcing our Terms.
- To communicate with you — account, security, and (if you don't opt out where applicable) service-related emails, such as password resets and membership-request updates.
- To verify eligibility — confirming you're 18 or older, and, if you choose to add a phone number, confirming you control it.
We do not use your information for third-party advertising, and we do not sell your personal information.
Sharing With Third Parties
We share information only as needed to operate the Service, or when legally required:
- Other members — your profile, photos (subject to your blur/approval settings), forum posts, and messages are visible to other members according to the visibility settings you control.
- Geocoding provider — if you use geofenced privacy (Black tier), the address you enter for a zone is sent to OpenStreetMap's Nominatim service to resolve it to coordinates. We do not send your precise real-time location, only the address text you choose to enter.
- SMS verification provider — if you choose to verify a phone number, that number is shared with our SMS verification provider (Twilio) solely to deliver and confirm a verification code.
- Email provider — your email address is shared with our transactional email provider solely to deliver account-related emails (e.g. password resets).
- Hosting & infrastructure providers — our database and application hosting providers process data on our behalf under standard hosting agreements; they do not use it for their own purposes.
- Law enforcement — where required by law, or to protect the safety of a member or the public (e.g. suspected exploitation of a minor, credible threat of harm).
If paid membership is introduced in the future: payment details will be collected and processed directly by a third-party payment processor under their own privacy practices; we will update this section with the specific processor and what, if anything, we retain (e.g. a transaction reference) before any payment feature goes live.
Cookies
We use a small number of strictly necessary cookies to keep you signed in — a short-lived access token and a longer-lived refresh token, both httpOnly and SameSite=strict so they can't be read by page scripts or sent cross-site. We do not currently use advertising or third-party analytics cookies.
Data Retention
We retain your information for as long as your account is active. If you request deletion (Section 7) or an administrator removes your account for a Terms violation, your profile, photos, ID document, and associated data are permanently erased from our systems; we do not maintain a "shadow" copy of a deleted profile.
Your ID document specifically is stored separately from the rest of your profile, is never given a public URL, and can only be opened by an administrator through the admin review screen — never displayed to other members or exposed anywhere in the app's normal browsing experience.
Your Rights & Choices
From the Privacy & Data section of your account, you can submit a request to:
- Access a copy of the personal data we hold about you
- Correct inaccurate information
- Restrict or object to certain processing
- Export your data (portability)
- Delete your account and associated data permanently
Every request is reviewed by a person, not resolved automatically; we aim to respond within 30 days. You can also directly control several privacy settings yourself at any time without filing a request: blurred-photo mode, who can message you, whether your location or last-active time is shown, and (Black tier) incognito browsing and geofenced privacy zones.
Security
Passwords are hashed (never stored in plain text) before being saved. Authentication uses signed, httpOnly session cookies rather than storing tokens in a way client-side scripts can read. The Service applies rate limiting and standard HTTP security headers to reduce common attack surfaces. No method of transmission or storage is 100% secure, and we can't guarantee absolute security — if we become aware of a breach affecting your personal information, we will notify you as required by applicable law.
Children's Privacy
The Service is not directed to, and is not intended for use by, anyone under 18. We do not knowingly collect personal information from anyone under 18. If we learn an account belongs to someone under 18, we will terminate it and delete the associated data.
Data Location
Our infrastructure is currently operated from the United States, and your information is processed and stored there. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.
Changes to this Policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the "Last updated" date above and, where required by law, provide additional notice before the change takes effect.
Contact
Questions about this Policy, or to exercise a privacy right outside the in-app flow, contact privacy@fantasi.app.
Note: privacy@fantasi.app is a placeholder pending a registered business domain and formal business entity. Update this address once one is established.