Effective date: July 14, 2026
Fenrid is built around a simple rule: communication data should be used to provide and protect the service, not to turn users into an advertising product.
This Privacy Policy explains what Fenrid LLC ("Fenrid," "we," "us," or "our") collects, why we process it, when it may be shared, how long it may be kept, and the choices and rights available to you.
This policy applies to Fenrid's websites, applications, community servers, messaging, voice features, waitlists, subscriptions, credits, safety systems, and related services, collectively called the Services.
Privacy in plain language
- We do not sell, rent, or trade personal data.
- We do not operate an advertising network, share data with data brokers, or use your activity for behavioural advertising.
- AI does not read what you share on Fenrid. We do not run server-side generative AI, large language model, or similar AI inference over your messages, files, voice communications, video, or screen shares.
- We do not use your content to train, fine-tune, or evaluate AI or machine-learning models.
- Direct messages and supported direct-message attachments are end-to-end encrypted. Fenrid stores encrypted data and the metadata required to deliver it, but does not normally have the keys needed to read the content.
- Community server messages are not end-to-end encrypted. They are processed so we can deliver the service, enforce permissions, investigate reports, and protect users.
- Supported images and GIFs uploaded outside end-to-end encrypted direct messages may be checked using narrow, non-AI safety technology such as Microsoft PhotoDNA.
- We collect limited account, device, network, security, and activity information needed to operate and protect Fenrid.
- You may edit your information, delete supported content, close your account, and exercise privacy rights that apply where you live.
- Some records may be preserved after deletion where required for security, payments, legal compliance, child safety, disputes, or the rights of other users.
This summary is provided for convenience. The full policy below controls.
1. About Fenrid
Fenrid LLC is a limited liability company registered in New Mexico, United States. Fenrid LLC operates the Services and is the controller of personal data described in this policy, except where a provider acts as an independent controller under its own terms.
Privacy requests and questions may be sent to:
General support requests may be sent to:
We have not appointed a formal Data Protection Officer. We will review whether an appointment or regional representative is legally required as the Services, user base, and processing activities develop.
2. Information we handle
We collect information in four main ways:
- information you provide;
- information created when you use the Services;
- limited technical and security information collected automatically;
- information received from other users or service providers.
2.1 Account and profile information
When you create or manage an account, we may process:
- your email address;
- username and display name;
- password credentials stored in hashed form;
- date of birth and age-check information;
- phone verification status if phone verification is enabled;
- profile biography, avatar, banner, status, badges, and appearance settings;
- account plan and role;
- account creation, confirmation, login, recovery, and policy-acceptance timestamps;
- privacy, communication, and account settings.
Some profile information is visible to other users according to the feature you use and the settings you select.
We do not store your password in readable form.
2.2 Content and communications
We process content you create or share through Fenrid, including:
- community server messages and replies;
- images, videos, audio, files, embeds, stickers, and other attachments;
- reactions, mentions, pins, and message references;
- server, channel, role, event, giveaway, and forum content;
- profile content;
- reports, appeals, and support communications;
- information sent through bots, webhooks, or integrations you choose to use.
You choose where and with whom most content is shared. Content posted in a server is available to users who have access to that server or channel. Other users may copy, quote, screenshot, download, or redistribute content they can access. Fenrid cannot control copies created outside the Services.
2.3 End-to-end encrypted direct messages
Fenrid direct messages and supported direct-message attachments are designed to use end-to-end encryption.
For encrypted direct messages, Fenrid may store or process:
- encrypted message and attachment data;
- encrypted headers and key-wrapping information;
- conversation and participant identifiers;
- sender identifiers;
- timestamps;
- message, reply, edit, delete, reaction, and pin metadata;
- public encryption keys and key identifiers;
- encrypted recovery bundles, where enabled;
- trusted-device and device-approval records.
Fenrid does not normally possess the private keys or passphrase required to decrypt direct-message content.
End-to-end encryption protects message content, but it does not conceal every operational detail. Fenrid may still know that an account participates in a conversation, when encrypted messages were sent, the approximate size of encrypted data, which device is trusted, and other metadata required to route, synchronize, secure, and troubleshoot the feature.
2.4 Reports involving encrypted messages
A participant may report an encrypted direct message. When that happens, the reporting user's device may decrypt and submit the reported content, relevant attachments, and a limited amount of surrounding context to Fenrid.
The submitted report copy is no longer hidden from Fenrid by the conversation's end-to-end encryption. It may be reviewed and preserved for investigation, enforcement, appeals, user safety, legal compliance, and legally required child-safety reporting.
Fenrid does not routinely scan or review the plaintext content of end-to-end encrypted direct messages.
2.5 Communities and social activity
We process information needed to provide community and social features, such as:
- servers you create, join, own, or moderate;
- server memberships, roles, permissions, nicknames, and join dates;
- channel access and permission overrides;
- friend requests, friendships, follows, blocks, and direct-message permissions;
- server invitations and invitation use;
- event registrations, application answers, attendance, and bans;
- giveaway entries, eligibility, and winner records;
- private nicknames or notes you save about another profile.
Private notes are intended to be accessible only to the account that created them, except where access is required for security, legal compliance, or operation of the Services.
2.6 Voice, video, and realtime information
When you use voice, video, screen sharing, presence, typing, or other realtime features, we may process:
- user, server, channel, room, and session identifiers;
- participant and connection status;
- IP address and routing information;
- browser, device, codec, microphone, and camera information;
- connection quality, latency, packet loss, and performance metrics;
- audio, video, and screen-share streams while they are transmitted to participants;
- online status, last-seen timestamps, and client type.
Fenrid does not record voice, video, or screen-share content by default.
Community voice channels are encrypted in transit but are not end-to-end encrypted. Participants are trusting Fenrid's media infrastructure and relevant infrastructure providers to transmit the communication securely.
Optional client-side media features, such as noise suppression, may use a machine-learning model locally on your device. This local processing is used to improve audio quality. It is not used to understand what you say, create a transcript, build a profile, or train a model.
2.7 Device, network, and security information
We and our providers may collect or generate:
- IP address;
- encrypted IP information or keyed hashes derived from an IP address;
- browser and user-agent information;
- operating system and device type;
- approximate country or location derived from network information;
- session, request, and device identifiers;
- hashed server-issued device tokens;
- device labels and trusted-device status;
- login, registration, password-change, and security events;
- rate-limit, spam, bot, and account-takeover signals;
- anti-fraud device intelligence and confidence scores;
- CAPTCHA or challenge results;
- error and performance information.
We may use browser or device fingerprinting only for narrowly scoped fraud, abuse, and account-security purposes. We do not use fingerprinting to advertise to you or track you across unrelated websites.
Infrastructure providers may temporarily process raw IP addresses and request logs to route traffic, prevent attacks, investigate incidents, and maintain their services.
2.8 Encryption and recovery information
To support end-to-end encrypted messaging and trusted devices, we may process:
- public encryption keys;
- public-key identifiers and key status;
- device public keys;
- encrypted key and recovery bundles;
- trusted-device status;
- device approval requests;
- hashed approval codes;
- ephemeral public keys;
- trust, revocation, and last-use timestamps.
Fenrid does not intentionally store your encryption passphrase in readable form.
You are responsible for protecting your passphrase and trusted devices. If you lose them and no supported recovery method is available, encrypted content may be permanently inaccessible. Fenrid cannot decrypt it for you.
2.9 Payments, subscriptions, and Fenrid Credits
If paid features are enabled and you make a purchase, we may process:
- your Fenrid account identifier;
- purchased plan, product, or Credits amount;
- transaction amount, currency, date, and status;
- subscription period and renewal status;
- Stripe customer, subscription, checkout, payment-intent, and invoice identifiers;
- billing country and limited payment metadata supplied by Stripe;
- internal Credit balances and transaction history;
- chargeback, refund, and fraud-related information.
Stripe generally collects and processes payment-card details directly. Fenrid does not ordinarily receive or store full payment-card numbers.
Fenrid Credits are an internal, account-bound service balance. Additional contractual rules appear in our Terms of Service.
2.10 Waitlist and referral information
If you join a waitlist, use an access code, or participate in a referral program, we may process:
- email address;
- access, invitation, and referral codes;
- referrer and referral source;
- visitor or browser identifier;
- IP-derived hash;
- user-agent information;
- country;
- request identifier;
- anti-abuse confidence or risk score;
- approval and access status.
2.11 Reports, moderation, and legal records
We may process:
- reports and report descriptions;
- reported account, server, event, giveaway, message, or attachment identifiers;
- evidence submitted with a report;
- moderation classifications and decisions;
- warnings, restrictions, suspensions, bans, and account-standing records;
- administrator and moderator notes;
- report, security, server, and administrator audit logs;
- records of evidence access;
- records of disclosures to child-safety organizations, law enforcement, courts, or regulators;
- information needed to establish, exercise, or defend legal claims.
Sensitive evidence is separated from ordinary product data where practical and access may be restricted and audited.
2.12 Information from other people and services
We may receive information about you from:
- users who invite, mention, follow, block, message, report, or moderate you;
- server owners and moderators;
- payment processors;
- authentication and email providers;
- network, hosting, and security providers;
- anti-fraud and bot-prevention providers;
- courts, regulators, child-safety organizations, or law enforcement;
- integrations you choose to connect.
3. Why we use information
We use information to:
- create, authenticate, and maintain accounts;
- deliver messages, attachments, communities, voice, events, giveaways, and other requested features;
- route and synchronize encrypted communications;
- manage trusted devices and recovery flows;
- maintain profiles, settings, permissions, memberships, and read state;
- process subscriptions, Credits, and transactions;
- provide support and important service communications;
- protect accounts against theft and unauthorized access;
- prevent spam, fraud, bots, malicious automation, referral manipulation, and platform abuse;
- investigate reports and enforce our Terms of Service and Community Guidelines;
- detect and respond to known child sexual abuse material in supported unencrypted uploads;
- preserve evidence and make reports where required or permitted by law;
- maintain reliability, debug failures, and measure aggregate feature performance;
- comply with legal obligations;
- protect the rights, safety, and property of users, Fenrid, and the public;
- resolve disputes and defend legal claims.
Operational metrics are designed to measure events such as feature use, errors, delivery, latency, and service health. We do not need to read message content to count that a message was sent or a call was connected.
4. What we never do
We do not use your messages, files, calls, or other user content to:
- train, fine-tune, or evaluate AI or machine-learning models;
- run server-side generative AI or LLM inference;
- create advertising profiles;
- target behavioural advertisements;
- sell, rent, or license the content for another company's independent use;
- provide data to brokers;
- mine conversations for unrelated commercial research;
- feature private content in marketing without separate permission.
We do not use third-party advertising trackers.
These promises do not prevent processing that is strictly necessary to deliver a feature you use, perform non-AI safety checks described below, investigate a report, comply with law, or protect someone from serious harm.
5. Direct messages and encryption
End-to-end encryption means supported direct-message content is encrypted on a sender's device and is intended to be decrypted only on authorized participant devices.
Fenrid's servers still perform limited operations needed to deliver encrypted data. We may store ciphertext, route it to conversation participants, synchronize it to trusted devices, and retain the metadata described in this policy.
End-to-end encryption does not apply to:
- community server messages;
- community voice channels;
- profile and server information;
- reports submitted to Fenrid;
- content a user voluntarily sends to support or safety staff;
- public or community uploads outside encrypted direct messages.
Encryption does not prevent a recipient from copying, screenshotting, recording, forwarding, or reporting content after it reaches their device.
6. Safety systems and reports
Fenrid combines limited automated safety controls with human review in defined cases.
6.1 No AI moderation of user content
Fenrid does not run server-side AI or LLM systems to read, classify, summarize, moderate, or profile user messages, files, calls, or screen shares.
6.2 PhotoDNA and supported upload checks
Supported images and GIF frames uploaded outside end-to-end encrypted direct messages may be converted into perceptual hashes and compared with hashes of previously identified child sexual abuse material using Microsoft PhotoDNA.
PhotoDNA hash matching is a narrow safety process. It does not understand a conversation, create a description of an image, train on the upload, or provide the image for advertising.
A match or serious safety signal may result in:
- preventing or quarantining an upload;
- preserving relevant evidence;
- restricting an account;
- human review by an authorized person;
- a report to the National Center for Missing & Exploited Children, law enforcement, or another authorized recipient where required or permitted by law.
Fenrid does not use PhotoDNA to decrypt direct messages.
6.3 Human review
Authorized personnel may review specific unencrypted content or submitted report evidence when needed to:
- investigate a user report;
- review a PhotoDNA match or serious safety event;
- enforce our policies;
- respond to a credible threat;
- handle an appeal;
- comply with legal obligations.
Access is limited according to role and operational need. Sensitive evidence access may be recorded in an audit log.
6.4 Report confidentiality
We try not to disclose a reporter's identity to the reported user unless disclosure is necessary for due process, safety, or law. We cannot promise complete anonymity, especially where the facts make the reporter identifiable or disclosure is legally required.
7. Legal bases where GDPR or similar law applies
Where a law requires a legal basis, we rely on one or more of the following:
Contract. Processing needed to provide the Services you request, including accounts, messages, communities, encrypted delivery, subscriptions, and support.
Legitimate interests. Security, fraud prevention, abuse prevention, service reliability, limited aggregate product measurement, policy enforcement, and protection of users. We do not use legitimate interests as a back door for advertising or AI training.
Legal obligation. Accounting, tax, lawful requests, evidence preservation, child-safety reporting, and other requirements imposed by law.
Consent. Optional communications, permissions, or processing where applicable law requires consent. Consent may be withdrawn, but withdrawal does not make earlier lawful processing unlawful.
Vital interests. Urgent processing or disclosure reasonably necessary to protect a person from death or serious physical harm.
8. When information is shared
We share information only in the circumstances below.
8.1 Sharing you choose
Content is shared with recipients and communities you select. Profile details, memberships, reactions, roles, or activity may be visible according to the feature and your settings.
Bots, webhooks, and integrations can receive information within the permissions and context you enable.
8.2 Service providers
Providers process limited information on our behalf to operate Fenrid. Depending on the feature and current deployment, these may include:
- Supabase for database, authentication, and backend services;
- Vercel for application hosting, deployment, and server-side execution;
- Cloudflare for content delivery, object storage, network security, bot prevention, and related infrastructure;
- Microsoft Azure for servers, realtime infrastructure, and media routing;
- Stripe for payment processing and subscription management;
- Resend for transactional email delivery;
- Fingerprint for narrowly scoped anti-fraud and device-intelligence checks;
- Upstash for rate limiting, temporary operational state, or Redis services;
- Microsoft PhotoDNA for child-safety hash matching.
LiveKit software may be used on Fenrid-controlled infrastructure to provide realtime media features. Where a third party hosts a feature rather than merely supplying software, we will update this policy when the change is material.
Providers may also process information to protect their own systems, comply with law, and enforce their service terms. Some providers act as independent controllers for limited interactions, such as payment processing or security challenges.
We may replace or add providers as the Services evolve. Material changes will be recorded in our Policy Changelog.
8.3 Server owners and moderators
Server owners and moderators can access information made available through server membership, permissions, moderation tools, reports, and audit features. They may create and enforce rules stricter than Fenrid's platform-wide rules.
Fenrid does not control every independent moderation decision made by a server administrator, but administrators remain subject to our Terms of Service and Community Guidelines.
8.4 Legal and safety disclosures
We may preserve or disclose information where we reasonably believe it is necessary to:
- comply with applicable law, court orders, subpoenas, or enforceable legal process;
- make a legally required child-safety report;
- address an emergency involving risk of death or serious physical harm;
- investigate fraud, abuse, security incidents, or illegal activity;
- enforce our agreements;
- protect users, Fenrid, or the public;
- establish, exercise, or defend legal claims.
Where legally permitted and safe, we may notify an affected user before or after disclosure. We may reject or narrow requests we believe are invalid, unlawful, or overbroad.
8.5 Business transactions
If Fenrid is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal data may be transferred as part of that transaction.
Where reasonably practicable and legally permitted, we will provide advance notice of a material transfer and an opportunity to close your account before it takes effect. Any successor holding the data must respect this policy until it lawfully replaces it with proper notice and any consent required by law.
8.6 Aggregated or de-identified information
We may use and share information that has been aggregated or reasonably de-identified so it no longer identifies a person. We do not attempt to re-identify data we have designated as de-identified except to test our safeguards or where law permits.
9. International processing
Fenrid LLC is based in the United States and uses infrastructure and providers operating in multiple countries.
Depending on the feature, information may be processed in the United States, the European Economic Area, Türkiye, or other locations where Fenrid or its providers operate. Realtime traffic and cached media may pass through network locations near the user.
We do not promise that every request, backup, log, email, media packet, or stored object remains in one country.
Where required, we use recognized safeguards for international transfers, such as contractual data-protection clauses and technical or organizational protections. No transfer mechanism eliminates every risk of lawful government access.
10. How long information is kept
We keep information only for as long as reasonably necessary to provide the Services, protect users, satisfy legal obligations, resolve disputes, and enforce agreements.
Retention depends on the data and purpose.
10.1 Active accounts and content
Account, profile, membership, message, and community data is generally retained while needed to operate an active account and until it is deleted under the relevant feature or account-deletion process.
10.2 Deleted accounts and content
Deletion removes or anonymizes eligible information from active systems through Fenrid's deletion processes. Some community messages may remain with the author replaced by a deleted-user placeholder to preserve conversation and moderation integrity.
Deleted data may remain temporarily in restricted backups until the normal backup rotation completes. Backup copies are not used as active product data.
Other users may retain copies they previously received or created.
10.3 Security and device records
Security events, session information, device records, IP-derived identifiers, and anti-abuse signals are retained for a limited period based on security need. Some records may be retained longer during an active investigation, dispute, legal hold, or repeated-abuse prevention process.
Cryptographic public-key history or limited device metadata may remain as long as needed to preserve the ability of participants to decrypt historic encrypted messages.
10.4 Reports and evidence
Ordinary report evidence is generally retained for up to one year from the report date to support investigation, enforcement, appeals, and accountability.
Evidence may be kept longer where required for child safety, a legal hold, law-enforcement cooperation, a court process, or another binding legal obligation. Access to retained sensitive evidence is restricted.
Deleting the original content or account does not automatically delete a preserved report copy during its lawful retention period.
10.5 Payment records
Payment and transaction records are retained for the period required by accounting, tax, fraud-prevention, chargeback, and consumer-protection laws.
10.6 Waitlist and referral records
Waitlist and referral records are retained while the access program is active and afterward as needed for reconciliation, fraud prevention, support, or legal compliance. Data no longer needed is deleted or anonymized.
11. Your settings and privacy rights
Depending on the feature, you may be able to:
- edit your profile and settings;
- delete individual messages or attachments;
- leave or delete servers you control;
- block users;
- manage trusted devices;
- revoke sessions;
- close your account.
You may contact [email protected] to request:
- access to personal data;
- correction of inaccurate data;
- deletion of eligible data;
- restriction of processing;
- objection to processing based on legitimate interests;
- portability where legally required and technically applicable;
- withdrawal of consent;
- information about data categories and disclosures;
- review of certain automated access or security decisions;
- an appeal of a privacy-request decision where local law provides that right.
We may need to verify your identity before acting. We respond within the period required by applicable law.
A request may be limited where necessary to protect another person's rights, preserve security, comply with law, retain financial records, preserve child-safety evidence, or defend legal claims.
You may complain to the data-protection or consumer authority responsible where you live.
Fenrid does not sell personal information or share it for cross-context behavioural advertising. Where local law provides an opt-out from those activities, Fenrid's current practice is already to not perform them.
12. Cookies and local device storage
Fenrid uses cookies, local storage, session storage, IndexedDB, and similar device technologies for:
- authentication and session management;
- language, theme, and interface settings;
- trusted-device identification;
- storing or recovering local encryption material;
- application state and offline behavior;
- security, CAPTCHA, rate limiting, and fraud prevention;
- realtime connection management.
Deleting local encryption storage or trusted-device cookies can sign you out, trigger device approval, or make encrypted messages inaccessible until you restore access.
Cloudflare and other security providers may set or read strictly necessary security identifiers.
We do not use third-party advertising cookies.
13. Security
We use technical and organizational safeguards intended to protect personal data, including:
- encryption in transit;
- end-to-end encryption for supported direct messages;
- hashing or encryption of selected security identifiers;
- database access controls and row-level authorization;
- restricted evidence storage;
- device trust and approval controls;
- audit logging;
- rate limiting and abuse prevention;
- account and session security controls;
- infrastructure monitoring and backups;
- secure development and incident-response practices.
No online service can guarantee absolute security. You should use a unique password, protect your passphrase and devices, review active sessions, and notify us promptly if you suspect unauthorized access.
If a personal-data breach occurs, we will investigate, take appropriate remedial action, and provide notices required by applicable law.
14. Younger users
Fenrid is not intended for children under 13.
You must be at least 13 and meet any higher minimum age required where you live. We may use date of birth and approximate country information to apply age restrictions.
If local law requires parental or guardian permission for a user who is above 13 but below another legal age, the user may use Fenrid only with the required permission.
If we learn that an account belongs to a child below the applicable minimum age, we may suspend the account and delete eligible information. Evidence that must be preserved for safety or legal reasons may be retained separately.
Parents and guardians who believe a child is using Fenrid below the applicable age may contact [email protected].
15. Legal requests and emergencies
Government and law-enforcement requests must identify the requesting authority, legal basis, account or data sought, and appropriate scope.
We may require formal legal process and may reject requests that are defective, informal, overbroad, or outside the requesting authority's jurisdiction.
In an emergency involving a credible risk of death or serious physical injury, we may disclose limited information where permitted by law and reasonably necessary to address the emergency.
Child-safety reports are handled according to applicable law and our safety obligations.
16. Updates to this policy
We may update this policy as Fenrid changes.
The current version will show its last-updated and effective dates. Material changes will be described in our Policy Changelog and communicated through an appropriate channel before taking effect where reasonably practicable or legally required.
We will request renewed consent where law requires it. Continued use does not replace consent where consent is legally necessary.
17. Contact
Fenrid LLC
New Mexico, United States
Privacy: [email protected]
General support: [email protected]