Privacy Policy

Less is more, especially with your data.

Effective: 17 June 2026

FRIENDA exists so two people can confidentially agree to keep something confidential. The whole product would fall apart if we treated your data the way most apps do. This page tells you exactly what we collect, what we do with it, and how to make us forget you.

What we collect

Account information (senders)

To send NDAs, you sign in with Apple. We collect:

Recipients don't need an account. Someone signing an NDA you send can do it through the App Clip or the web with no sign-in at all.

NDA content

Recipient identity lock (optional, Pro)

If you lock an NDA to a specific person, we store the email address or phone number you choose to lock to — so we can send the recipient a one-time verification code. The code itself is short-lived (it lives in a temporary cache and expires in minutes), and it's never stored after it's used. A recipient may instead verify with Sign in with Apple, in which case we briefly check whether their Apple-verified email matches the locked address — we don't keep their Apple identifier.

A note on Face ID

Signing is confirmed with Face ID / Touch ID on the signer's device. Your biometrics never leave your device and we never see them — iOS only tells the app whether the check passed, and we record that single yes/no in the audit trail.

Things we deliberately do not collect

How we store it

Everything sits on Cloudflare infrastructure (D1 for structured data, R2 for signed PDFs, KV for short-lived token caches), encrypted at rest by Cloudflare and in transit with TLS. On top of that we apply application-layer encryption: the NDA's content (party names and topic), the signed PDFs, and any recipient-lock contact are encrypted with keys we hold separately (AES-256), so a stolen copy of the database or file storage is unreadable ciphertext. The server can still decrypt to render and verify your agreements — this is encryption at rest, not end-to-end encryption (true E2EE, where even we can't read it, is incompatible with link-based signing and public verification, and remains a longer-term Business-plan goal).

Plain-language summary: we keep what's necessary to make signed NDAs verifiable later, and almost nothing else. We never sell your data, and we don't run ads.

How we use it

Sharing

We don't share your data with third parties for marketing or analytics. We may be required to share it in response to a valid legal request (subpoena, court order). If that happens to your account specifically, we'll notify you unless we're legally prohibited from doing so.

Where your data is processed — international transfers

FRIENDA's servers and storage run on Cloudflare infrastructure in the United States. If you are in the European Economic Area, the United Kingdom, Switzerland, or Japan, using FRIENDA means your personal data is transferred to and stored in the United States.

How long we keep it — retention

Legal bases for processing (EEA / UK users)

Sub-processors

The current, authoritative list — with each sub-processor's role, location, and our change-notice commitment — lives at ndafriend.com/subprocessors. Business customers can review our Data Processing Agreement.

Your controls

Your privacy rights

Wherever you live, you can exercise the rights below by emailing hi@frienda.chat or using Profile → Export data / Delete account in the app. We verify the request against your account and respond within the time the law requires — one month under the GDPR (extendable by two months for complex requests) and without undue delay under Japan's APPI and U.S. state laws. Reasonable requests are free and we won't discriminate against you for making one.

California (CCPA / CPRA)

We do not sell or share your personal information, and never have — no ad SDKs, no trackers, no data brokering. There is nothing to opt out of, but we honor the Global Privacy Control browser signal regardless. California residents have the rights to know, delete, correct, and to non-discrimination, exercisable as above.

EU / UK

FRIENDA currently offers its service in the United States, Japan, and India and does not target the European Economic Area or the United Kingdom. If and when we begin offering FRIENDA to people in the EEA/UK, we will appoint and name a GDPR Article 27 representative here. In the meantime, anyone may reach our privacy team directly at hi@frienda.chat.

Children

FRIENDA isn't for anyone under 13. We don't knowingly collect data from anyone under 13. If you believe we have, please email us and we'll delete it.

Changes

If we change this policy in a way that affects your data, we'll update the effective date and notify signed-in users by email before the change takes effect.

Contact

Questions, requests, complaints — hi@frienda.chat. A real person reads it.