Privacy
Privacy Policy
Last updated July 15, 2026.
Fellowly is developed and operated by hebe wu, an independent individual developer. Fellowly is designed as a private relationship-care app for iOS. You choose the people, notes, prompts, drafts, feedback, and settings you save or submit. Fellowly does not create public profiles, social feeds, follower graphs, relationship scores, or automatic message sending.
Store Disclosure Commitment
This policy is the public privacy URL used for App Store review. Fellowly keeps the App Store app privacy details aligned with the data practices described here. If a future app release changes collection, sharing, permissions, security, or deletion behavior, this page and the store disclosures must be updated before or with that release.
Short Version
- Fellowly does not require a Fellowly account.
- Relationship data is local-first and stays on your device unless you choose a feature that sends limited context.
- Fellowly does not sell personal data and does not use relationship data for advertising targeting.
- AI features are user-initiated, optional, and can be turned off in Settings.
- Firebase product analytics is on by default, can be turned off in Settings, and never receives relationship content.
- Subscriptions are handled by the Apple App Store.
Data You Choose To Save
The app can store people, rhythms, notes, contact logs, settings, drafts, and subscription state needed to run the product. The first product implementation is local-first, so relationship data is not uploaded to a Fellowly account and no Fellowly account is required.
- Relationship content stays on the device unless you choose a feature that sends limited context.
- Fellowly does not upload a full address book by default.
- Fellowly does not sell relationship data or use it for advertising targeting.
AI Features
When you choose AI Assist, Fellowly sends only the current draft and the context described in the in-app disclosure to the Fellowly backend. Grounded message help may include the person's display name and relationship category, an optional direction, your selected writing preferences, and eligible non-sensitive notes, contact summaries, or important dates you saved for that person. The backend may forward that limited context to a third-party AI provider, such as DeepSeek, once to propose an editable message and once to check that its personal facts are supported. Provider keys stay on the backend, not in the mobile app. Fellowly does not send your full address book, hidden social graph, historical drafts, private messages, city, time zone, or pronouns to AI.
Before the first AI action, the app explains what context will be used. You can disable AI processing in Settings and can report unsafe, offensive, or incorrect AI output through the in-app feedback flow or by contacting Fellowly.
If a successful free-preview response is lost before the app receives it, Fellowly can return that same verified result without running AI or consuming the preview again. For this delivery recovery, the backend stores only AES-GCM-encrypted response ciphertext. Recovery access expires after 23 hours. Expired rows are deleted by scheduled hourly cleanup; if a cleanup run fails, the next run retries. The ciphertext is scoped to the anonymous backend account, an opaque request key, and a server-computed request fingerprint. The Fellowly backend does not store the plaintext result in D1 or copy it to logs, analytics, or Fellowly training datasets.
Permissions
Mobile permissions are optional and purpose-limited. Contacts, notifications, photos, images, and other platform permissions are requested only when needed for the feature you choose. You can deny permissions and still use the core manual relationship loop.
Website Preferences
The public website may store a first-party `fellowly_locale` cookie when you choose a language. This preference only keeps the website route consistent in the same browser. It does not create a Fellowly account, store relationship content, or support advertising targeting.
Android Closed-Test Waitlist
If you join the Android waitlist, Fellowly collects the Google or Workspace email you submit, your website language, the signup location on the page, your consent version, waitlist status, and limited administrator notes used to coordinate testing. Fellowly uses the email only to contact you about Android testing and to add eligible participants to the Google Play closed-test list. This waitlist does not create a Fellowly account. Fellowly does not store your IP address or browser User-Agent with the entry and does not put the email into logs, analytics, or error messages.
To enroll a tester, an administrator may provide the submitted email address to Google Play. Google then processes that address under its own terms and privacy policy. No confirmation or marketing email is sent by default. You can request deletion at any time by emailing contact@usefellowly.com from the address you submitted.
Analytics And Crash Reports
Fellowly uses Firebase Analytics and Firebase Crashlytics, Google Firebase services, to understand product use, reliability, and crashes. Anonymous product analytics is on by default on a fresh install. You can turn off future app-recorded Firebase Analytics events anytime in the app under Settings > Privacy & data > Product analytics. Turning analytics off does not limit the core relationship loop, paid features, subscription management, export, or Delete All Local Data.
When analytics is on, events are limited to product and funnel signals such as screens, actions, results, coarse counts, duration, experiment variant, week bucket, app/build/device metadata, Firebase app instance identifiers, and a pseudonymous app identifier not linked to your name, email, or any login. Crash reporting remains a separate Firebase Crashlytics boundary for crash logs and reliability diagnostics.
Fellowly does not send person names, note bodies, draft text, prompt text, contact-log text, address book data, feedback body, reply email, StoreKit proof, provider prompts, provider responses, API keys, or secrets to analytics or crash reports. Fellowly does not use analytics for advertising targeting and does not sell relationship data. Firebase privacy and security information is available from Firebase, and Google's general privacy policy is available from Google.
Feedback And Support
If you submit feedback, Fellowly receives the message you type, any optional reply email, any images you choose to attach, and a small non-content diagnostics summary used to debug your report, such as app version, device or OS, language, subscription status category, recent request IDs, and coarse record counts. These diagnostics do not include person names, notes, drafts, prompts, contact logs, message text, or address book data. Feedback is separate from analytics and is not a Fellowly account.
Payments And Subscriptions
Fellowly Plus purchases are processed by the Apple App Store. Fellowly may process subscription status, entitlement category, purchase validation result, StoreKit or purchase proof when available, decoded transaction identifiers, a non-personal randomly generated account identifier (not linked to your name, email, or any login), and timestamps needed to unlock paid features, support restore flows, prevent abuse, and review subscription errors. Fellowly does not receive or store your full payment card details, Apple ID password or store account profile.
Service Providers
Fellowly may use Cloudflare for hosting and backend services, Firebase for analytics and crash reporting, Apple for billing and platform services, and AI providers through Fellowly's backend for user-approved AI actions. These providers are used to operate, secure, debug, and improve the product, not to sell relationship data.
Data Categories
- Local relationship data: people, rhythms, notes, contact logs, prompts, drafts, settings, and local subscription state stored on your device.
- AI request data: the person's display name and relationship category, current draft, optional direction, structured writing preferences, and eligible saved details needed for the selected Assist mode, processed through the Fellowly backend and AI provider.
- AI delivery-recovery data: an opaque request key, server-computed request fingerprint, expiry time, and encrypted free-preview response ciphertext. Recovery access expires after 23 hours. Expired rows are deleted by scheduled hourly cleanup, which retries after a failed run. This is short-lived response delivery, not relationship-data sync or backup.
- Analytics data: product interactions, coarse counts, duration, experiment variant, week bucket, app/build/device metadata, Firebase app instance identifiers, and a pseudonymous app identifier not linked to your name, email, or any login.
- Crash and diagnostics data: crash logs, app/device metadata, and safe diagnostic details needed to debug failures.
- Feedback data: the message you type, optional reply email, optional images, and non-content diagnostics used to debug your report.
- Subscription data: entitlement state, purchase validation result, non-sensitive store identifiers, the pseudonymous identifier, and timestamps used for paid access and restore support.
- Website preferences: first-party language preference cookie for this public website.
- Android waitlist data: submitted Google or Workspace email, locale, page source, consent version, recruitment status, timestamps, and administrator notes used only to coordinate the closed test.
Your Control
You control every message. Fellowly never sends messages automatically. Delete and export controls are part of the product so relationship data remains understandable and user-controlled. Deleting local data removes locally stored relationship content from the device, but it does not cancel an App Store subscription.
You can manage or cancel subscriptions through Apple. You can turn off anonymous product analytics in the app settings where available, and Delete All Local Data does not turn a previous analytics opt-out back on. You can request deletion of feedback/support records associated with your message, or an Android waitlist entry, by contacting Fellowly from the email you used.
Delete All Local Data also removes the device's opaque AI recovery request keys. Because Fellowly has no account-management or relationship-sync service, that local action does not issue a remote deletion request; any already encrypted recovery ciphertext becomes inaccessible from the app and is removed automatically when its short retention period expires.
Retention And Deletion
- Local relationship data stays on your device until you delete it, use Delete All Local Data, uninstall the app, or remove it through device/system storage controls.
- Feedback and support records are kept only as long as needed to respond, diagnose issues, improve reliability, or meet security/legal obligations. You can request deletion of feedback records tied to your reply email.
- Android waitlist entries are retained for no longer than 24 months, may be removed earlier after testing ends, and are deleted sooner when the submitter makes a verified deletion request. Scheduled cleanup removes records that reach the maximum retention period.
- Subscription validation records, including non-personal store identifiers, the pseudonymous identifier, decoded transaction identifiers, and timestamps used for entitlement checks and restore support, are retained for up to 24 months after the related subscription ends or is refunded, after which entitlement-relevant fields are deleted or aggregated. A shorter period may apply when fraud, dispute, accounting, or legal-compliance obligations no longer require the record.
- Analytics and crash records are retained according to Firebase/Google retention settings and platform controls. Turning off analytics in Settings stops app-recorded Firebase Analytics events from that point forward where available.
- AI request content is processed to return the feature you asked for. Fellowly does not use relationship content for advertising targeting, training, or analytics, and does not send AI prompts or provider responses to analytics or crash reports.
- A verified free-preview response may remain as AES-GCM-encrypted ciphertext solely to recover a response lost in transit. Access expires after 23 hours. Scheduled hourly cleanup deletes expired rows and retries after a failed run; rotating the recovery encryption key makes any unexpired rows unreadable.
Fellowly has no app account module, so there is no Fellowly account to delete. Account-level store records, subscription billing history, and refund decisions are handled by Apple through the App Store.
Children
Fellowly is not directed to children under 13. If you believe a child has provided personal data to Fellowly, contact us so we can review and delete it where required.
Your Privacy Rights
Depending on where you live, you may have legal rights over personal data Fellowly processes about you. Fellowly honors these rights for residents of the European Economic Area, the United Kingdom, Switzerland, California, and other jurisdictions with comparable laws, even though Fellowly does not require a Fellowly account.
- EEA, UK, and Swiss residents (GDPR / UK GDPR / FADP): right of access, rectification, erasure, restriction of processing, data portability, objection to processing, withdrawal of consent (without affecting the lawfulness of prior processing), and the right to lodge a complaint with your local data-protection supervisory authority.
- California residents (CCPA / CPRA): right to know what personal information is collected and how it is used, right to delete, right to correct, right to opt out of sale or sharing (Fellowly does not sell or share personal information as defined by the CCPA), right to limit use of sensitive personal information, and right to non-discrimination for exercising these rights.
- Other jurisdictions: rights described under applicable privacy law (for example Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act) are honored where they apply to the data Fellowly processes.
To exercise any of these rights, including for analytics, subscription validation, AI request processing, and feedback records, contact Fellowly at contact@usefellowly.com from a reliable contact channel. Fellowly responds within the timelines required by applicable law and may need to verify your request before acting on it. Because the core product is local-first and does not require a Fellowly account, in some cases the requested data is stored only on your device and is removed by using the in-app delete, export, or uninstall controls; Fellowly will explain when that is the only available path.
International Users
Fellowly is built for a global audience. Data processed by service providers may be handled in the countries where those providers operate, subject to their security and data-processing commitments.
Contact
For privacy questions, data requests, deletion requests, or store disclosure questions, contact contact@usefellowly.com.