This policy explains how AnonyFish handles information in its discussion app and on this website. The app is for people aged 18 and over, initially in the United States and Israel. Questions and privacy requests can be sent to the AnonyFish team at support@anony.fish.
1. Anonymous to other users
AnonyFish has no conventional public accounts, names, profiles, followers, contact syncing, social login, or direct messages. Other users are not shown your installation identifier. The app does not require your name, email address, telephone number, contacts, government identification, or an advertising identifier to participate.
This does not make you completely untraceable. Your writing may reveal who or where you are. The service retains the limited information described below, which may be relevant to safety, security, or valid legal obligations. Other people can copy or capture public content.
2. Installation identity and age checks
The app creates a random installation credential kept in secure storage on your device and sends it to establish an anonymous session. The server stores a derived identifier and an internal reference, rather than a public profile. These connect your content, ownership controls, blocks, restrictions, and policy acceptances. We also store the supplied app version, platform, and installation activity timestamps. Reinstalling or clearing app storage may affect your access to an existing installation identity.
The minimum age is 18. Age-check records contain the eligibility result, method, minimum-age requirement, policy version, and check time. We also record which versions of the terms, privacy policy, and community guidelines an installation has accepted.
In the month-and-year fallback, your birth month and year are processed temporarily to calculate eligibility and are not saved as birth-date fields. The app does not ask for a complete date of birth. The fallback applies a conservative calculation, so eligibility can begin at the start of the month following your eighteenth birthday month. Platform age signals are not a guarantee of verified identity.
3. How location is used
With your device permission, location is sent to find nearby posts within 3, 5, or 10 kilometers and determine the supported country used by Popular. Country selection follows physical location, independently of whether you choose English or Hebrew.
Viewer coordinates are processed temporarily for requests and live subscriptions; the application does not routinely store them as a browsing or movement history. When you create a post, its coordinates are reduced to a coarser location before storage, together with a country code. The original precise coordinates are not stored in the post record.
Your exact location, coordinates, address, and exact distance are not shown to other users. Reduced precision cannot prevent every inference about a place or person, especially if a post contains identifying details. You can manage location permission in your device settings; location-based features need that permission.
4. Content, reports, and technical records
- Conversations: post and comment text, timestamps, status, ownership references, and reactions support discussion and deletion controls. Other users see public content and aggregate emoji reactions.
- Safety: reports, optional report details, blocks, moderation decisions, and enforcement records help investigate abuse and apply the community guidelines. Reports are not public posts.
- Creation events: creating a post, comment, or report records restricted network metadata, including the IP address visible through the server’s network connection, an observed source port, request identifier, timestamp, app version, platform, and available proxy context. A proxy, shared network, or VPN may affect what these identify. They are not proof of an individual’s identity.
- Operations: limited request and error information, such as endpoint, status, timing, and request reference, supports reliability and security. Short-lived rate-limit records help prevent abuse. Routine feed browsing does not create the same retained source-IP record as posting, commenting, or reporting.
Creation-event IP records are not exposed to other users or ordinary moderators. Sensitive legal access is restricted to authorized roles and uses scoped access and audit controls. We do not promise that the operator can never associate records with an installation or respond to a valid legal process.
5. Public expiry and restricted retention
Posts leave public view 24 hours after creation. Comments become unavailable with their parent post. Removing your own content also removes its public availability. Public expiry and owner deletion do not erase every restricted record at that moment.
- Posts and comments: ordinarily become eligible for permanent database cleanup 30 days after the post’s public expiry. Related reactions follow the post lifecycle unless you remove a reaction sooner.
- Post/comment creation metadata: ordinarily becomes eligible for deletion 30 days after the creation event.
- Reports: become eligible for deletion after 90 days from submission once they are no longer pending. Report creation metadata normally has a 90-day retention period. Unresolved reports may delay deletion of related content.
- Moderation and sensitive-access audit records: ordinarily use a separate 730-day retention period. An active legal matter or relevant hold may require longer retention.
- Installation and policy records: remain while needed for access, ownership, age and policy state, blocks, enforcement, or associated records. They do not automatically disappear when a post expires.
- Operational logs, correspondence, and backups: have separate lifecycles from public content. Error logs may rotate by size rather than on a fixed daily schedule. Copies in backups are not immediately erased by an in-app deletion and may remain until those backups are replaced or removed.
Cleanup runs periodically, so these periods describe normal deletion eligibility, not an exact second of irreversible erasure. Restricted records may be kept longer when necessary for moderation, security, unresolved reports, legal obligations, or an active legal hold. A legal hold preserves specified records; it does not return them to public view. Normal cleanup resumes when the applicable restriction ends.
6. Service providers and legal requests
Hosting and infrastructure providers process information needed to operate the service. Email providers process correspondence you send to our contact addresses, including your email address and the information you choose to include. Providers and their systems may operate outside your country; a contact address does not indicate where all processing occurs.
Information may be preserved or disclosed when a valid legal obligation or other legally permitted safety process applies. Requests require assessment of authority, scope, and the information actually available. AnonyFish does not provide automatic or unrestricted law-enforcement access. Receiving a request does not automatically authorize disclosure of all records.
7. This website
You can read this website without an account. Its public pages have no advertising scripts, tracking pixels, analytics, public comments, or contact forms. Fonts are served locally. The server necessarily processes your connection information to deliver pages and may record technical errors for operation and security; routine website access logging is disabled in this deployment.
WordPress uses necessary authentication cookies for authorized administrator login; ordinary reading does not require login. If you follow a store or other external link, the destination’s privacy practices apply. Sending us email voluntarily shares your email address and message.
8. Security and your choices
Safeguards include encrypted connections, access controls, separation of ordinary moderation from sensitive legal functions, and audit records for sensitive actions. No system can guarantee absolute security or anonymity. Avoid including identifying or sensitive details in public posts, reports, or support messages unless necessary.
You can delete your own available posts, comments, and reactions in the app. See Data deletion for the actual steps. To request access, correction, or deletion of information, or ask about an applicable privacy right, write to support@anony.fish. Your rights and the available response may depend on applicable law and the records retained.
We may need a content reference or an anonymous installation reference, where available, to find records and verify authority. Do not send your installation secret, access tokens, or unnecessary identity documents. If you no longer have access to the installation, tell us; matching records may be more difficult.
9. Adults only and policy changes
AnonyFish is not intended for anyone under 18. Do not use the app if you do not meet this requirement. If you believe a minor is using the service, contact safety@anony.fish without sharing unnecessary personal information.
We may update this policy as the service or its practices change. The date and version above identify this notice; where required, a material change will be accompanied by an appropriate notice or a request to accept updated policies. Legal correspondence can be sent to legal@anony.fish.