Privacy Policy

Effective date: March 22, 2026  ยท  Last updated: March 22, 2026

Important: STRNGER is an anonymous emotional wellness and peer support app. It is not a medical service, mental health provider, therapy platform, or crisis intervention service. If you are experiencing a mental health emergency, please contact emergency services or a crisis helpline immediately.

At a glance โ€” what we collect

๐Ÿ“ง Email address Stored by Firebase Authentication for login. Never shown to other users.
๐ŸŒ Country You select this at signup. Stored in your profile. Never shown to other users.
๐Ÿ’ฌ Messages & content End-to-end encrypted. Only you and your conversation partner can read them.
๐Ÿ“ฑ Device & app data Device ID (for security) and crash logs (for stability). Not linked to your identity.

We do not collect your real name, phone number, location, contacts, photos, or any data that identifies you to other users. We never sell your data.

Contents

  1. Overview
  2. Not a Medical App
  3. Who We Are
  4. What We Collect
  5. How We Use Data
  6. Encryption & Security
  7. Data Sharing
  8. Data Retention
  9. Your Rights & Deletion
  10. Children
  11. Third-Party Services
  12. Policy Changes
  13. Contact Us

๐Ÿ“‹ 1. Overview

STRNGER ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your data when you use the STRNGER mobile application.

By using STRNGER, you agree to the practices described in this policy. If you do not agree, please do not use the app.

Our core privacy principle: STRNGER is built on anonymity. Your real identity is never shown to other users. We collect the minimum data necessary to operate the service safely, and we never sell your data to anyone.

โš•๏ธ 2. Not a Medical App

STRNGER is a peer-to-peer anonymous support and wellness journaling application. It is not a medical device, mental health treatment platform, therapy service, or clinical intervention tool of any kind.

If you are in crisis: Please contact emergency services (999 in the UAE) or a crisis helpline immediately. STRNGER is not a substitute for professional help.

๐Ÿข 3. Who We Are

STRNGER is an independent mobile application. For all privacy-related questions or data requests, please use the contact information provided in Section 13.

Our backend infrastructure is hosted on Google Firebase in the European Union (eur3 region), meaning your data is stored on servers located in Europe.

๐Ÿ“Š 4. What We Collect

4.1 Information you provide

DataHow it is storedVisible to other users
Email address Securely stored by Firebase Authentication for account login and email verification purposes. We do not display or share your email with other users. Internally, we also store a SHA-256 hash of your email for fraud prevention. Never
Password Managed entirely by Firebase Authentication using industry-standard secure hashing. We never see or store your password in plaintext. Never
Country Selected by you at signup. Stored in your profile. Never
Nickname & avatar emoji Auto-generated randomly at account creation. You do not choose them. Used as your anonymous identity inside the app. Shown anonymously

4.2 Content you create

DataEncryptedWho can read it
Chat messages AES-256-GCM E2E Only the two participants in the conversation
Journal entries (Keep mode) AES-256-GCM Only you
Express entries โ€” Burn / Float / Dissolve Never stored or transmitted No one. Text is cleared from the device immediately after the release animation. It never reaches our servers.
Garden memories Stored in your private subcollection Only you
Time capsules AES-256-GCM Only you, after the unlock date you set
Mood check-ins A numerical score (1โ€“5). No text is stored. Only you

4.3 Automatically collected data

4.4 What we do NOT collect

We do not collect your real name, phone number, precise or approximate location, contacts, photos, biometric data, browsing history, or any information that could directly identify you to other users.

Crisis detection runs entirely on your device. Any crisis-related keywords detected in typed text are processed locally and are never transmitted to our servers or stored anywhere.

โš™๏ธ 5. How We Use Your Data

We do not use your data for advertising, behavioural profiling, or any commercial purpose beyond operating the app. We display no advertisements.

๐Ÿ”’ 6. Encryption & Security

End-to-end encryption: Chat messages, journal entries, and time capsules are encrypted on your device using AES-256-GCM before being transmitted or stored. Encryption keys are derived from your account credentials and stored in your device's secure storage (Android Encrypted SharedPreferences / iOS Keychain). We do not hold the decryption keys and cannot read your encrypted content.

While we take extensive security measures, no system is completely immune to risk. We encourage you to use a strong, unique password.

๐Ÿค 7. Data Sharing

We do not sell your data. We do not share your personal data with advertisers, data brokers, or marketing companies.

Infrastructure provider

We use Google Firebase (Google LLC) as our backend infrastructure. Firebase processes data on our behalf under Google's data processing terms. Services used include Firebase Authentication, Cloud Firestore, Realtime Database, and App Check. Google's privacy policy: policies.google.com/privacy.

Legal requirements

We may disclose data if required by applicable law, court order, or governmental authority. We will notify you of such requests where legally permitted.

Safety

In cases of a credible and imminent threat to the life of any person, we may share relevant information with the appropriate authorities. This is the only circumstance under which user data may be shared without legal compulsion.

Anonymised aggregates

We may publish anonymised, aggregate statistics that cannot be traced back to any individual user.

๐Ÿ—“๏ธ 8. Data Retention

Data typeRetention period
Chat messages24 hours by default. Extended if both users agree, or until the conversation is ended.
Journal entriesUntil you delete them individually or delete your account.
Garden memoriesUntil you delete them individually or delete your account.
Time capsulesUntil you delete your account.
Mood check-insUntil you delete your account.
Account & profile dataDeleted immediately upon account deletion request, except as noted below.
Email address (Firebase Auth)Deleted from Firebase Authentication immediately upon account deletion.
Email hash (fraud prevention)Retained for up to 30 days after account deletion to prevent re-registration of banned accounts, then permanently purged.
Crash logs & diagnostics90 days, managed by Firebase. Anonymised.
Deletion summary: Most user data (account, messages, journals, memories, capsules, mood history) is deleted immediately upon account deletion. Limited hashed identifiers used for fraud prevention are retained for up to 30 days, then permanently deleted.

โš–๏ธ 9. Your Rights & Deletion

You have the following rights regarding your personal data:

How to delete your account

๐Ÿ—‘๏ธ Option 1 โ€” Delete directly in the app

1

Open STRNGER and go to the Profile tab (bottom navigation)

2

Scroll to the bottom and tap "Delete My Account & All Data"

3

Check the confirmation box and enter your password

4

Tap "Delete Everything" โ€” deletion is immediate and permanent.

This process deletes your STRNGER account and all associated data.

What gets deleted: Your account credentials, nickname, avatar, country, all conversations and messages, all journal entries, garden memories, time capsules, and mood history. See Section 8 for the limited data retained for fraud prevention.

Partial data deletion

You can delete individual journal entries, garden memories, and time capsules from within the app without deleting your entire account.

To exercise rights other than deletion, contact us at afrahyasin333@gmail.com. We will respond within 30 days.

๐Ÿ‘ถ 10. Children

STRNGER is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. The app displays an age confirmation screen at signup.

If we become aware that a user under 18 has created an account, we will immediately delete their account and all associated data. If you believe a minor has registered, please contact us immediately at afrahyasin333@gmail.com.

This app is not directed at children under 13 under any circumstances.

๐Ÿ”— 11. Third-Party Services

STRNGER uses the following third-party services. Each is governed by its own privacy policy:

ServicePurposeProvider
Firebase AuthenticationSecure account creation and sign-inGoogle LLC
Cloud FirestoreEncrypted data storageGoogle LLC
Firebase Realtime DatabaseOnline presence detectionGoogle LLC
Firebase App CheckApp integrity verification and abuse preventionGoogle LLC
Firebase CrashlyticsAnonymised crash reporting and diagnosticsGoogle LLC

We do not use any advertising SDKs, social media SDKs, or third-party analytics services beyond Firebase.

๐Ÿ“ 12. Policy Changes

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and displaying an in-app notice on your next login.

Continued use of the app after changes take effect constitutes acceptance of the updated policy.

๐Ÿ“ฌ 13. Contact Us

For privacy questions, data requests, or to report a concern:

STRNGER Privacy

๐Ÿ“ง Email: afrahyasin333@gmail.com

๐Ÿ—‘๏ธ Delete account form: forms.gle/iq5sQt1WpTL2PoKY7

๐Ÿ“ Data stored in: European Union (Firebase eur3 region)

We aim to respond to all privacy inquiries within 30 days.