Felvo is built to know as little about you as possible. We never receive your name or email. What you write disappears on a schedule. There is no advertising, no analytics, and no tracking of any kind.
What we never receive
When you sign in with Apple, we request no personal information. Not your name, not your email address, not your Apple ID. Apple gives us only an anonymous identifier that is unique to Felvo and cannot be linked back to you by anyone else.
We do not collect your phone number, contacts, photos, precise location, or advertising identifier. We use no analytics or crash-reporting tools that capture what you write.
What we do hold
- An anonymous account identifier. Randomly generated. It is not derived from your Apple ID or any personal detail, and a leak of one could not produce the other.
- A device identifier. Used with Apple's App Attest to confirm requests come from a genuine, unmodified copy of Felvo — this is how we keep automated abuse out of a service with no other identity checks.
- What you write. Posts and weekly prompt responses, retained as set out below.
- A trust score. A number reflecting your account's standing, used to limit spam and abuse. It is computed on our servers and never accepted from the app.
- A notification token, if you enable notifications, so we can send them.
Stored only on your iPhone
Your Vault, your streak history, your muted-word list, your mood filters, and your app preferences live on your device — not on our servers. Your Vault is included in your iCloud device backup, so restoring a phone brings it back.
Your muted words never leave your phone. Filtering happens on the device after posts arrive, which is slower than doing it server-side and deliberately so. A list of words someone is avoiding is among the most revealing things they could hand over, and we would rather not have it.
How long things last
| What | How long |
|---|---|
| Posts | 7 days from creation, then permanently deleted |
| Weekly prompt responses | 28 days after the prompt week closes |
| Content removed for policy violations | Up to 30 days |
| Reported content | A copy is kept as part of the moderation record |
| Content under legal preservation | As long as legally required |
| Account identifier | Until you delete your account |
| Database history (Cloudflare Time Travel) | 30 days — see below |
Deletion runs every hour, so content is removed within an hour of its expiry rather than at the end of a day.
Our database provider, Cloudflare, keeps a rolling 30 days of database history so a database can be restored after a fault or a mistaken change. This is always on and cannot be disabled by us.
It is a whole-database recovery tool, not an archive: it cannot be used to look up or retrieve an individual deleted post, and we do not use it for that. But we would rather tell you it exists than claim a cleanliness we can't deliver. The honest version is that your post leaves Felvo after seven days, and leaves our provider's recovery window within thirty.
Content removed for a policy violation is kept up to 30 days, including after you delete it or delete your account. This lets us handle appeals, respond to legal requests, and meet mandatory reporting obligations. Nobody but us can see it during that time.
Reported content is copied into our moderation record at the moment it's reported, and that copy can outlive the original post. Without it, anything reported shortly before expiry would be gone before a human could review it.
Content subject to a legal preservation order is retained for as long as the law requires, regardless of any deletion you request.
What we don't do
- No advertising. No ad networks, no advertising identifiers, no ad SDKs.
- No tracking. We don't track you across apps or websites, and we don't ask permission to, because we don't do it.
- No analytics. No third-party analytics or attribution tools.
- No selling or sharing. We do not sell, rent, or share your information for anyone else's purposes. We never have.
- No algorithmic ranking. The feed is chronological.
- No AI training. We don't use your writing to train machine learning models.
Who can see what you write
Posts and prompt responses are visible to other Felvo users anonymously. Nothing attached to a post identifies you — no name, no handle, no persistent public identifier. Other users cannot tell which posts came from the same person.
Our staff can access content only where necessary to investigate a report or diagnose a technical fault.
Who processes data for us
- Cloudflare, Inc. — hosting and database, United States.
- Apple Inc. — sign-in and push notification delivery.
Both are service providers acting on our instructions. Servers are located in the United States. If you use Felvo from elsewhere, your information is processed there.
Your rights
Delete your account. Available in the app under Dashboard → Privacy & Safety. Your account and content are deleted immediately, subject to the exceptions above.
Access. Because we hold so little and it deletes on a schedule, there is usually little to provide — but you can ask.
Notifications. Manage them in the app or in iOS Settings.
Depending on where you live you may have further rights under the GDPR, the CCPA, or similar laws — access, correction, deletion, and objection among them. Write to support@felvo.app and we'll respond within the timeframe the applicable law requires. We do not discriminate against anyone for exercising these rights.
Children
Felvo is not intended for anyone under 17, and the App Store age rating is set accordingly. We do not knowingly collect information from children. If you believe a child has used Felvo, contact us and we will delete the account.
Legal requests
We comply with valid legal process. We will only produce information we actually hold — which, by design, is very little. We may preserve specific records when legally required to do so, and such records are exempt from the deletion schedule for as long as the preservation lasts.
We are required by U.S. law to report apparent child sexual abuse material to the National Center for Missing & Exploited Children.
Security
Every request is authenticated: your identity is derived on our servers from a cryptographic attestation rather than taken from anything the app claims about itself. Requests are encrypted in transit, access to production systems is limited and logged, and we never log the content of posts.
No system is perfectly secure, but Felvo is designed to hold as little as possible — the strongest protection against a breach is not having the data.
Changes
We'll post any changes here and update the date above. Material changes will be notified in the app.
Questions: support@felvo.app