Less is more, especially with your data.
Effective: 17 June 2026
FRIENDA exists so two people can confidentially agree to keep something confidential. The whole product would fall apart if we treated your data the way most apps do. This page tells you exactly what we collect, what we do with it, and how to make us forget you.
What we collect
Account information (senders)
To send NDAs, you sign in with Apple. We collect:
- The display name you provide during onboarding.
- A username — a unique handle, defaulted from your email but editable, used to address and route NDAs to you.
- Your Apple Sign In identifier (a stable, opaque token from Apple) and the email Apple shares — which may be a private relay address if you use Hide My Email.
- An optional contact email you can add and verify (useful if you signed in with Apple's Hide My Email) so sent NDAs can find your account. Each username and email is unique to one account.
- A per-install device id (a random UUID) that ties NDAs you create on a device to your account.
- If you enable notifications, an Apple Push Notification token so we can tell you when an NDA is signed or declined.
Recipients don't need an account. Someone signing an NDA you send can do it through the App Clip or the web with no sign-in at all.
NDA content
- The topic you typed, the term you picked, your name, and (after signing) the recipient's typed legal name.
- The signed PDF, stored in our object storage (Cloudflare R2) for as long as you want access to it.
- Audit metadata: signing timestamp, IP address at sign-time, browser/device user-agent, whether the signer confirmed with Face ID / Touch ID, and a tamper-evident hash chain of state changes.
Recipient identity lock (optional, Pro)
If you lock an NDA to a specific person, we store the email address or phone number you choose to lock to — so we can send the recipient a one-time verification code. The code itself is short-lived (it lives in a temporary cache and expires in minutes), and it's never stored after it's used. A recipient may instead verify with Sign in with Apple, in which case we briefly check whether their Apple-verified email matches the locked address — we don't keep their Apple identifier.
A note on Face ID
Signing is confirmed with Face ID / Touch ID on the signer's device. Your biometrics never leave your device and we never see them — iOS only tells the app whether the check passed, and we record that single yes/no in the audit trail.
Things we deliberately do not collect
- Your iMessage conversations. Apple sandboxes our extension from reading them.
- Your address book. We never read your contacts — the system contact picker runs outside the app and only hands back the one detail you tap (a name, or the email/phone you choose for a recipient lock).
- Analytics events tied to your identity. We use aggregate Cloudflare logs to keep the service running, not to profile you.
- Third-party trackers, marketing pixels, or ad SDKs. None.
How we store it
Everything sits on Cloudflare infrastructure (D1 for structured data, R2 for signed PDFs, KV for short-lived token caches), encrypted at rest by Cloudflare and in transit with TLS. On top of that we apply application-layer encryption: the NDA's content (party names and topic), the signed PDFs, and any recipient-lock contact are encrypted with keys we hold separately (AES-256), so a stolen copy of the database or file storage is unreadable ciphertext. The server can still decrypt to render and verify your agreements — this is encryption at rest, not end-to-end encryption (true E2EE, where even we can't read it, is incompatible with link-based signing and public verification, and remains a longer-term Business-plan goal).
How we use it
- To operate the product — render your NDAs, generate signed PDFs, show you your library.
- To maintain the audit trail — so a signed NDA is verifiable months or years later.
- To prevent abuse — rate limits, spam detection, debugging. We look at logs only when we need to.
Sharing
We don't share your data with third parties for marketing or analytics. We may be required to share it in response to a valid legal request (subpoena, court order). If that happens to your account specifically, we'll notify you unless we're legally prohibited from doing so.
Where your data is processed — international transfers
FRIENDA's servers and storage run on Cloudflare infrastructure in the United States. If you are in the European Economic Area, the United Kingdom, Switzerland, or Japan, using FRIENDA means your personal data is transferred to and stored in the United States.
- EEA / UK / Switzerland (GDPR): our infrastructure provider, Cloudflare, is certified under the EU–US Data Privacy Framework (with its UK and Swiss extensions), and we additionally rely on the European Commission's Standard Contractual Clauses as a transfer safeguard. Email us for a copy of the applicable mechanism.
- Japan (APPI, Art. 28): we transfer your personal data to the United States. The United States is not a country designated by Japan's Personal Information Protection Commission as having an equivalent data-protection system; the U.S. uses a sectoral privacy framework rather than a single comprehensive law. We protect your data there with encryption in transit and at rest, access controls, and contractual data-protection terms with our sub-processors that are equivalent to APPI standards. By signing in you consent to this cross-border transfer; you can withdraw consent by deleting your account.
- India (DPDP Act 2023 & DPDP Rules 2025): we transfer your personal data to the United States. India permits cross-border transfers under a "negative list" model — transfers are allowed to any country the Central Government has not expressly restricted. We process your data on the basis of the consent you give when you sign in and use FRIENDA, in line with the notice in this policy, and you can withdraw it by deleting your account.
How long we keep it — retention
- Signed (executed) NDAs — the signed PDF and tamper-evident audit trail are kept for the life of your account, and after account deletion as the counterparty's legal record of an agreement they entered into. You can ask us to delete a specific executed agreement and we'll coordinate with the other party where the law allows.
- Unsigned / draft NDAs — expire 7 days after creation (they can no longer be opened or signed); their records are removed when you delete your account.
- Account data (name, email, Apple identifier) — kept while your account is open; nulled immediately when you delete it.
- Push-notification tokens & passkeys — kept while active; deleted immediately on account deletion.
- Recipient-lock contact + one-time codes — codes expire in 10 minutes; the locked email/phone is removed when the NDA reaches a final state or you delete your account.
- IP address & device user-agent — recorded in the audit trail as signing evidence; anonymized on your signatures when you delete your account.
- Rate-limit / abuse counters — ephemeral (minutes to hours).
Legal bases for processing (EEA / UK users)
- Performance of a contract (Art. 6(1)(b)) — creating, sending, and signing NDAs and running your account.
- Legitimate interests (Art. 6(1)(f)) — security, fraud and abuse prevention, recording IP/device data in the audit trail, and product reliability, balanced against your rights.
- Consent (Art. 6(1)(a)) — recipient-lock messages and any future marketing; withdrawable at any time.
- Legal obligation (Art. 6(1)(c)) — responding to lawful requests and keeping records we're required to keep.
Sub-processors
- Cloudflare — hosting, storage (D1 / R2 / KV), and edge compute.
- Apple — Sign in with Apple identity exchange and Apple Push Notification service.
- Resend — sends recipient verification codes by email (only when an NDA is locked to an email address).
- Twilio — sends recipient verification codes by SMS (only when an NDA is locked to a phone number).
The current, authoritative list — with each sub-processor's role, location, and our change-notice commitment — lives at ndafriend.com/subprocessors. Business customers can review our Data Processing Agreement.
Your controls
- Export — every signed NDA is downloadable as a PDF from your library, and Profile → Export data returns a machine-readable copy of your account, the NDAs you created, the ones you signed, and your audit records.
-
Delete — Profile → Delete account does the following, immediately:
- nulls your display name and email and marks the account deleted, so it can no longer be signed into;
- anonymizes the IP address and device user-agent recorded on signatures you made;
- removes any email address or phone number you locked an NDA to;
- permanently deletes your push-notification tokens and any passkeys you registered.
- Email us — hi@frienda.chat for anything we missed.
Your privacy rights
Wherever you live, you can exercise the rights below by emailing hi@frienda.chat or using Profile → Export data / Delete account in the app. We verify the request against your account and respond within the time the law requires — one month under the GDPR (extendable by two months for complex requests) and without undue delay under Japan's APPI and U.S. state laws. Reasonable requests are free and we won't discriminate against you for making one.
- Access / know — a copy of the personal data we hold about you.
- Rectification / correction — fix inaccurate data (you can update your name in the app).
- Erasure / deletion — delete your account and data (see "Delete," above).
- Portability — your data in a machine-readable format (Export data).
- Restriction / objection — ask us to pause or stop processing based on legitimate interests.
- Withdraw consent — for recipient-lock messaging or marketing, at any time.
- Complain — to your supervisory authority (Japan's Personal Information Protection Commission, the Data Protection Board of India, an EEA Data Protection Authority, or the UK ICO, as applicable). We'd appreciate the chance to put it right first.
California (CCPA / CPRA)
We do not sell or share your personal information, and never have — no ad SDKs, no trackers, no data brokering. There is nothing to opt out of, but we honor the Global Privacy Control browser signal regardless. California residents have the rights to know, delete, correct, and to non-discrimination, exercisable as above.
EU / UK
FRIENDA currently offers its service in the United States, Japan, and India and does not target the European Economic Area or the United Kingdom. If and when we begin offering FRIENDA to people in the EEA/UK, we will appoint and name a GDPR Article 27 representative here. In the meantime, anyone may reach our privacy team directly at hi@frienda.chat.
Children
FRIENDA isn't for anyone under 13. We don't knowingly collect data from anyone under 13. If you believe we have, please email us and we'll delete it.
Changes
If we change this policy in a way that affects your data, we'll update the effective date and notify signed-in users by email before the change takes effect.
Contact
Questions, requests, complaints — hi@frienda.chat. A real person reads it.