Privacy Policy
Toffe is a social app built around polls, where people meet through the questions they ask and answer, intended solely for adults aged 18 and over. This Privacy Policy explains what personal data we process when you use the Toffe app and toffeapp.com, why we process it, and how you can exercise your rights. The service is operated by TOFFE LLC (30 N Gould St Ste R, Sheridan, WY 82801, USA). You can reach us anytime at contact@toffeapp.com.
What information we process
We process only the data needed to provide the service. The information we collect falls into three groups: information you provide to us, information collected automatically as you use the app, and information generated in connection with your account.
- Information you provide: your phone number, your username, your birthday (used to determine your age and derive your zodiac sign; you must be 18 or older), your gender, your profile photos, your poll category selections, your profile description (bio), and your help/support requests. Your country and language preference are not asked for separately; they are read from your device's region and language settings.
- Phone number and verification code: when you sign in or register, we process your phone number and send a one-time verification code (OTP) to it by SMS. The code is retained only briefly and is invalidated after verification.
- Information collected automatically: a persistent identifier for your installation of the app, your platform (iOS/Android), the app version, your country and language preference, and basic technical records needed for the security of the service and troubleshooting. These are sent every time you open the app and bring it to the foreground, including before an account exists.
- Data tied to your account: your follow relationships (followers/following), profile view records (to make the 'Profile viewers' feature work, your visit is recorded when you view a profile and shown to the profile's owner), your account status, and your recent search terms.
- We do not collect face or biometric data: we do not collect, store on our servers or receive your face data or any biometric identifier, and we perform no face recognition, face matching or identification. When you turn on one of the optional face effects in a video call, available to members at level 10 and above, the effect software in the app detects your face and computes and tracks its position and shape on your device, in real time, solely to draw the effect. This information is held only temporarily in your device's memory while the effect is running; it is not saved on your device, is not sent to us or to the effect provider, is not used to identify anyone, and is cleared from memory no later than the end of the call. An effect you turn on stays on for your later video calls until you turn it off or restart the app. The other party receives only the video with the effect applied, as part of the call. Your profile photos are processed only as ordinary images.
- Your password (phone-number accounts only): you set it yourself during registration. It is stored on our servers only in irreversibly hashed form and is never stored on your device. Accounts created with Google or Apple have no password.
- Information we receive from the provider when you sign in with Google or Apple: your account identifier at that provider, your email address and — with Apple, only on the first authorization — your name and the identity token signed by Apple. Google sign-in requests only the email and profile scopes.
- Device identifier and push token: every time the app is opened and brought to the foreground — including before your account exists — we send our servers a persistent identifier for your installation of the app, your platform (iOS/Android), the app version and your language preference. The same identifier is also sent at registration. If you allow notifications, we additionally process your device's push token.
- Messaging data: the content of the text messages you send and receive, the photos you send in a chat, the machine translation created when translation is on, a copy of any message you quote, the last-message preview shown in your inbox, delivery and read receipts, typing indicators and online / in-call status. Messages you send during a call are stored in the chat history in exactly the same way.
- Call records: the calling and called account, the type of call (voice/video), its outcome, its start and end time, its duration, the coins spent by the caller and each individual charge. We do not record the content of voice or video calls: audio and video are never recorded or stored by us at any point.
- Purchase and wallet data: the transaction identifier or purchase token and the receipt we receive from the store, the product identifier, the platform, the localized price label shown on screen, the state and time of the purchase, together with your coin balance and your records of coins spent and acquired. We never see your card details or any information about your payment method; payment is processed entirely by Apple or Google.
- Poll data: the question, options, categories, duration and visibility settings of the polls you create, and which option you chose in which poll and when. Your vote is shown, with your username and profile photo, to the member who created that poll. If that member chose, when creating the poll, to make its voters public (this setting is off by default and cannot be changed once the poll is published), your vote is shown in the same way to the other members who can see that poll; the poll card says so before you vote. Otherwise your vote is not shown to other members. We also record the text and time of the comments you write on polls, and which comments you like and when. Your comment is shown, with your username and profile photo, to the members who can see that poll — including those who have not voted — except members with whom there is a block between you, and it is shown to no one while your account is suspended or banned. How many times a comment has been liked is visible to everyone who can see the comment; the list of who liked it is not shown. However, when you like a comment its author, and when you comment on a poll its owner, receives a notification containing your username and profile photo. When you or the poll's owner delete a comment, when the poll's owner deletes the poll, and when you close your account, the comments are deleted from our servers together with their likes; the text of a reported comment is nevertheless kept in the report record. When you boost one of your polls, we record when the boost was started, its duration, its end time and the coins spent; while the boost runs, your poll is shown to other members with a 'Boosted' label, and the end time is shown only to you. When a translation of a poll is requested, the translation is stored on our servers and also served to other members who ask for a translation into the same language. Our authorized staff can also access these records for moderation and abuse investigation.
- Report and support records: the reason you select, the note you add, and a copy of the content the report concerns. When you report from a chat, an image of the part of the conversation then on screen is attached to the report automatically, and the reported message's text, its media link if any, and the time it was sent are recorded as well. When you report a poll, the poll's question is recorded. When you report a poll comment, the comment's text and the poll it was written on are recorded. If you rate a call poorly, that rating is stored as a moderation record about the other person. When you submit the Help Centre form, the topic you choose, your description, the screenshot you attach, the phone number you give and the email address held on your account are sent to us.
- Measurement data: account creation, sign-in and purchase events, together with the sign-in method used and, for purchases, the amount paid, the currency and the product identifier. These events are tagged with your in-app account identifier and sent to Google and Meta. These software development kits may also record basic events such as installation, app launch and sessions on their own. On Android this measurement may use your device's advertising ID; on iOS no advertising identifier (IDFA) is collected. Your phone number and email address are not shared with these providers.
Why we process it
We process your personal data only for clear and limited purposes:
- Operate the service: create your account, display your profile in Toffe Club, in search, and on discovery screens, and manage your follow relationships.
- Authentication and session management: secure sign-in and session security, using your phone number together with the password you set, a one-time SMS verification code (OTP) at registration and password reset, or your Google or Apple account.
- Personalize discovery: your poll categories and profile information are used to determine suggested members and to make the filters work.
- Notifications: tell you about new messages, incoming calls, new followers, new comments on your polls and likes on your comments, inside the app and — if you have allowed it — in your device's notification centre.
- Moderation and safety: enforce our community rules and the 18+ age requirement, prevent abuse, and apply temporary or permanent bans for rule violations.
- Support: respond to your help requests and contact you about matters related to your account.
- Paid features and purchases: verify your store receipt, maintain your coin balance, process spending on messages, photos, gifts, calls and poll boosts, and show you your purchase history.
- Preventing abuse: using the device identifier to apply the welcome coin grant only once per device, to limit verification-code requests, and to apply device-level restrictions imposed for rule violations.
- Notifications: tell you about new messages, incoming calls, new followers, new comments on your polls and likes on your comments. The content of a notification (the sender's username, a preview of the message and, for notifications about another member, that member's profile photo) travels through the notification infrastructure.
- Translation: when your account languages differ and translation is on, sending the message text to our translation provider to produce a translation. This option switches itself on the first time it becomes possible for a pair with different languages, and you can switch it off at any time. When a translation of a poll or a bio is requested — including by another member, for your polls and your bio — that text is sent to the same provider; messages in support conversations may also be translated by it.
- Face effects in video calls: when you turn on a face effect, computing your face's position and shape on your device, in real time, to draw the effect; and having the effect software's license validated and its use counted under that license.
- Measurement and marketing performance: understanding how the app is found and used, and measuring installs and conversions.
Users under 18
Toffe is intended for users aged 18 and over and is not directed to children. We do not knowingly collect personal data from anyone under 18. If we learn that a child has provided us with data, we will delete the relevant account and data. If you have any concern about this, please contact us at contact@toffeapp.com.
Who we share it with
We do not sell your personal data. We share your data only in the following cases and with contractually bound service providers (data processors):
With trusted infrastructure providers that process data solely on our instructions to deliver the service. We may also share data with competent authorities where necessary to comply with a legal obligation, protect our rights, or ensure the safety of our users.
We do not sell your personal data, and we do not share your phone number or email address with advertising partners. We do, however, share limited event data with Google and Meta for measurement and advertising performance: account creation, sign-in and purchase events, together with the amount, currency and product identifier of a purchase. This data is tagged with your in-app account identifier. In some legal regimes a transfer of this kind may be treated as sharing data for advertising purposes. When you use face effects in video calls, the effect software sends DeepAR limited technical device information and your device's IP address for license validation and usage counting; the details are in the provider list below. Your camera images and face data are not part of this.
Providers we rely on
Toffe relies on the following third-party services to provide the service:
- SMS provider: delivery of the one-time verification code (OTP) to your phone number by SMS during sign-in and registration.
- Cloud hosting and storage providers: server-side storage of service data, including profile photos.
- Apple App Store and Google Play: distribution of the app.
- These providers' processing of your data is also subject to their own privacy policies.
- Google LLC — Firebase Cloud Messaging: delivery of notifications to your device. The content of a notification — including the sender's username, a preview of the message and, for notifications about another member (for example a new message, a new follower, a profile visit, an online reminder, a poll comment or a comment like), a link to that member's profile photo — passes through this infrastructure. On iOS devices notifications are also delivered through Apple's notification infrastructure.
- Google LLC — Firebase Cloud Storage: storage of photos sent in chats and of report attachments.
- Google LLC — Cloud Translation: translating message text when translation is on; a poll's question and options, or a profile description (bio), when a translation is requested; and messages in support conversations. The text to be translated and the target language code are sent to this service, plus, for a poll, the code of the language it was written in where known. Poll and bio translations are requested by the member viewing them, so the polls you create and your bio may be sent to this service when another member asks for a translation.
- Google LLC — Gemini: automated screening of uploaded profile photos for nudity, explicit sexual content, severe violence and hate symbols. This screening only assesses whether the content complies with our rules; it performs no face recognition, no face matching, and generates no biometric identifier. Photos sent in a chat do not go through this automated screening.
- Google LLC — Firebase Analytics, Google Sign-In and Firebase Authentication: usage and conversion measurement, and signing in with a Google account. When you sign in with Google, a Firebase authentication session is also created on your device.
- Apple Inc. — Sign in with Apple: signing in with an Apple account on iOS devices.
- Meta Platforms, Inc. — Facebook app events: install and conversion measurement. Account creation, sign-in and purchase events, together with the amount, currency and product identifier of a purchase, are sent to Meta; your phone number and email address are not.
- I LOVE ICECREAM LTD — DeepAR: face effects in video calls. The effects run on your device; your camera images and face data are not sent to DeepAR. The effect software is started only while a face effect is on in a video call. When it starts — the first time on your device and from time to time after that — it connects to DeepAR's server for license validation and usage (monthly active user) counting, and sends: the app's identifier, name and version; the version of the effect software; your device's make and model; its operating system and version; its screen resolution; the device's standard browser identification string (user agent); a random number; and a random installation identifier generated and stored on your device. Your device's IP address is also visible to DeepAR during this connection. DeepAR uses this information to count your device only once per month and records the date the effects were used. Your account identifier, phone number and email address are not sent to DeepAR.
- Connecting voice and video calls: where possible, a call is established directly between the two devices. To establish it, your device's public IP address becomes visible to the other party, to our own relay server and to Google's public STUN server. Where network conditions do not allow a direct connection, the audio and video may be relayed, encrypted, through our own relay server.
Transfers outside your country
Toffe is operated by TOFFE LLC, established in the United States. As a result, your personal data may be transferred to and processed on servers located outside your country of residence. We take reasonable measures to ensure that data transfers are carried out in compliance with applicable data protection law and under appropriate safeguards.
How long we keep it, and deleting your account
We retain your personal data only as long as necessary for the purposes described in this policy. You can close your account yourself from within the app, or send the same request by emailing contact@toffeapp.com. Closing an account cannot be undone.
Retention of chat data: messages are automatically deleted from our servers 60 days after they are created, and conversations 60 days after their last activity. The 'delete conversation' action in the app only hides the conversation on your side; the other person's copy is unaffected and a new message makes the thread visible again. When you delete a message for everyone, the message record is deleted; the file of a photo sent in a chat may nevertheless remain in our storage.
Closing your account from within the app: you can close your account yourself at Settings → Account Settings → 'Delete my account'; no email is required. After a single confirmation it takes effect immediately and cannot be undone: every session is ended, your phone number and username are released, your open polls are closed (which also ends the boost on a boosted poll), the votes you cast are separated from your identity and anonymized, the comments you wrote on polls and your likes on comments are deleted, and both the push registration on your device and the push token held on our servers are deleted. After your account is closed, your profile and your content are no longer visible to other members.
Closing your account does not destroy every record at once. A de-identified account record is retained, together with reports and moderation records about you or filed by you, call records, coin, poll boost and purchase records, and records we need for accounting and legal obligations; we keep these to prevent abuse, to handle legal claims and to meet our legal obligations. Your messages are deleted at the end of their own 60-day retention period. Screenshots attached to reports, the copy of a reported message and the text of a reported comment remain in the moderation record after the conversation or the comment itself has gone. Poll boost records are kept after the poll concerned has been deleted. If deleting your poll comments and comment likes cannot be completed during the closure for a technical reason, we complete it afterwards; the same deletion is applied when you ask us to close your account by email. Entries in your in-app notification list (for example an entry telling you, with that member's identity, that a member commented on your poll or liked your comment) are kept with no fixed time limit and are not removed when the like is withdrawn, the comment is deleted or that member closes their account; entries about a member whose account is closed, suspended or banned, or with whom there is a block between you, are not shown in your list. Event data already sent to our measurement providers cannot be recalled; when your account is closed we reset the measurement record held on your device. Likewise, license and usage information already sent to DeepAR for face effects cannot be recalled by closing your account; it is subject to DeepAR's own retention rules.
How we protect your data
We apply reasonable technical and organizational measures to protect your data. Data is encrypted in transit, and access is limited through authenticated sessions and authorization controls. While no method is completely secure, we continuously work to protect your data.
Your password is held on our servers only in irreversibly hashed form and is not stored on your device. On your device the app stores only your session details and a few preferences (onboarding flags, your discovery filter, your recent search terms); your messages, your wallet and your poll data are not stored on your device. If you use face effects in video calls, the effect software also stores on your device a random installation identifier and the result of its most recent license check; these are not linked to your account, and they are deleted when you remove the app from your device, not when you close your account. Voice and video call traffic is encrypted in transit. Your messages are not end-to-end encrypted: message content is held in readable form on our servers, is sent to our translation provider when translation is on, and passes through the notification infrastructure when a push notification is sent. Anyone who obtains the link to a photo sent in a chat can open that photo without being signed in.
The rights you have (GDPR and KVKK)
Under the EU General Data Protection Regulation (GDPR) and Turkiye's Law No. 6698 on the Protection of Personal Data (KVKK), you have the following rights:
- The right to access your personal data and learn whether it is being processed.
- The right to request correction of incomplete or inaccurate data.
- The right to request erasure or destruction of your data.
- The right to object to the processing of your data and to withdraw consent you have given.
- The right to data portability where the relevant conditions apply.
- To exercise these rights, contact us at contact@toffeapp.com. We will assess your request within the timeframes required by applicable law.
The website and cookies
The toffeapp.com website uses the minimum technical data necessary to provide the site's core functions. The mobile app uses no cookies; it does, however, include Google and Meta software development kits for measurement and advertising performance, and it reports account creation, sign-in and purchase events to those providers. Those kits may also record basic events such as installation, app launch and sessions on their own. On Android this measurement may use your device's advertising ID; on iOS no advertising identifier (IDFA) is collected and the app does not ask for permission to track you across other companies' apps and websites. We will update further detail on the site as needed.
Updates to this notice
We may update this Privacy Policy from time to time. When we make significant changes, we will update the "last updated" date above and, where appropriate, notify you in the app. We encourage you to review this policy periodically.
Getting in touch
If you have any questions or requests regarding this Privacy Policy or your personal data, please contact us.
Data controller: TOFFE LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA. Web: toffeapp.com. Email: contact@toffeapp.com