Privacy Policy
Last Updated: August 2026
This Privacy Policy governs the collection, storage, processing, transfer, and protection of personal information, including sensitive personal data or information, by Friendly ("Friendly", "Application", "we", "our", or "us"). We are committed to protecting the privacy of all visitors and registered users of the Application ("Users", "you", or "your"), whether registered or unregistered.
Please read this Privacy Policy carefully to understand how the Application handles your personal information supplied by you to the Application.
Statutory Compliance: This Privacy Policy is published in accordance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (under the Information Technology Act, 2000), the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023 (DPDPA), which require the publishing of a privacy policy for the collection, use, storage, processing, and transfer of sensitive personal data or information.
⚠️ IMPORTANT SAFETY & MENTAL HEALTH DISCLAIMER
The Application does NOT commit to treat, diagnose, or provide solutions for users with severe mental health distress, including any user experiencing thoughts related to self-harm, suicide, or self-destruction.
Such Users are strictly advised to cease use of the Application with immediate effect and seek immediate professional or emergency medical assistance. Any continued use of the Application by such individuals is solely at the User's own risk, and the Application and its operators bear zero liability for any untoward event.
The Application explicitly declares that information regarding imminent self-harm, physical violence, or illegal activities may be disclosed to emergency medical services and law enforcement authorities where legally warranted. Such emergency disclosure is exempt from non-disclosure or confidentiality obligations. The Application does not guarantee or warrant the accuracy of advice or suggestions exchanged between independent Users.
1. User's Explicit Consent
We collect, use, store, share, or otherwise process your personal information shared with us strictly based on your explicit consent expressed electronically upon registration or continued access to the Application for the purposes set out in this Privacy Policy.
By accessing and using the Application, you indicate that you understand and expressly consent to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please discontinue using the Application immediately. Your continued use of the Application confirms your unconditional consent to our collecting, maintaining, processing, and disclosing your personal data in accordance with this Privacy Policy and applicable laws.
This Privacy Policy is to be read in conjunction with our Terms of Service and Community Guidelines.
Additional Clause (for GCC Countries)
For Users accessing the Application from the United Arab Emirates (UAE), Kingdom of Saudi Arabia (KSA), State of Qatar, or State of Kuwait, continued use of the Application also constitutes consent under the applicable regional data protection laws, including:
- UAE: Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL);
- Saudi Arabia: Personal Data Protection Law (PDPL 2023) issued by SDAIA;
- Qatar: Law No. 13 of 2016 on the Protection of Personal Data;
- Kuwait: Law No. 20 of 2014 on Electronic Transactions.
2. Information We Collect & Device Permissions (Prominent Disclosures)
Information qualifies as personal in nature when it identifies a specific User, either independently or in combination with other data. We collect personal data during the following interactions:
A. Account Registration & Profile Data
- Identity & Profile: Full name / display handle, phone number, gender, date of birth / age verification (strictly 18+ required), profile photograph / avatar, email address, and optional profile bio or conversational interests.
- User-to-User Interactions: When you connect with other Users via voice or video calls, profile display details you choose to share will be visible to connected peers.
B. Prominent Device Permissions & Sensor Disclosures
To deliver core real-time 1-on-1 voice and video calling features, Friendly requests the following runtime permissions on your Android device:
-
Microphone (
android.permission.RECORD_AUDIO&android.permission.MODIFY_AUDIO_SETTINGS): Allows the Application to capture your voice as digital audio data and stream it in real time to your connected peer during active voice and video calls. Important: Audio is streamed in real time using peer-to-peer WebRTC encryption; we never record, monitor, or store your private conversations on our servers. -
Camera (
android.permission.CAMERA): Allows the Application to capture your video feed during active 1-on-1 video calls. Important: Video is only transmitted while you are in an active video call with camera unmuted. Video streams are end-to-end encrypted in transit and are never recorded, captured, or saved on our servers. -
Photos, Media & Storage (
android.permission.READ_MEDIA_IMAGES,android.permission.READ_MEDIA_VIDEO,android.permission.READ_EXTERNAL_STORAGE): Used exclusively when you choose to select, crop, and upload a profile picture or avatar from your device storage to your user profile. -
Push Notifications (
android.permission.POST_NOTIFICATIONS): Required to send incoming call alerts, call ring notifications, account verification OTPs, and essential security notices. -
Location Data (
android.permission.ACCESS_COARSE_LOCATION,android.permission.ACCESS_FINE_LOCATION): Used for approximate regional matchmaking, language preference alignment, and routing WebRTC calls through the nearest low-latency relay servers. -
Phone State (
android.permission.READ_PHONE_STATE,android.permission.USE_FULL_SCREEN_INTENT): Used to detect active cellular telephone calls so the Application can gracefully pause or prevent audio conflict with ongoing in-app calls.
C. Financial & In-App Service Transactions
When you purchase in-app calling credits, recharge balances, or access premium digital services, we and our authorized payment aggregators collect transaction reference identifiers, purchase amounts, and timestamp logs. Payment Security: All digital transactions are processed directly by RBI-authorized, PCI-DSS compliant payment gateways (such as Google Play Billing, Razorpay, or UPI). Friendly does not store credit card numbers, CVVs, debit card PINs, or UPI PINs on its servers.
D. Technical Telemetry, Log Files & Cookies
When accessing the Application, we collect technical information including device model, operating system version, app build version, IP address, network carrier / ISP, internet connection speed, log files, session timestamps, and crash logs to optimize service performance.
User Representation & Indemnity: The User represents and confirms that all information provided to the Application is authentic, accurate, current, and updated. We shall not be responsible for the authenticity of User-provided information. The User shall be personally liable and agrees to indemnify us for any losses or claims arising from incorrect, fraudulent, or unlawful information provided.
Additional Clause (for GCC Countries)
To comply with Know Your Customer (KYC), taxation, and financial reporting regulations in the GCC, limited additional data points (e.g., country code, nationality, or payment verification receipts) may be collected. Such data will only be processed for lawful regulatory compliance and never for unauthorized marketing.
3. Purpose and Use of Information
Information collected from you is used for the following lawful purposes:
- Service Delivery: Providing core 1-on-1 voice and HD video calling, validating user registration, maintaining user profiles, and enabling interactive communication features.
- Transactional Operations: Managing user recharge balances, maintaining payment logs, generating invoices, sending transactional communications (OTPs, service confirmations, policy updates), and addressing customer support tickets.
- Trust, Safety & Security: Enforcing our Terms of Service and Community Guidelines, moderating reported abuse, preventing fraudulent activities, and safeguarding users from harassment.
- Platform Optimization & Analytics: Conducting technical research, measuring call latency, resolving bugs, improving WebRTC transmission quality, and customizing interface layouts.
- Legal Compliance: Cooperating with law enforcement agencies, complying with judicial summons, statutory tax rules, and regulatory evidentiary requirements.
Additional Clause (for GCC Countries)
For Users in the UAE, Saudi Arabia, Qatar, and Kuwait, personal data may additionally be used to fulfill local VAT/tax reporting requirements (e.g., UAE 5%, KSA 15% VAT) and respond to verified inquiries from regulatory bodies such as the FTA (UAE), ZATCA (KSA), MoTC (Qatar), and CITRA (Kuwait). No audio, message, or private video call content is ever shared for these purposes.
4. Cookies and Web Technologies
The Application and website may use session cookies and local storage tokens to recognize your device, remember authentication states, prevent repetitive logins, monitor web traffic patterns, and diagnose technical problems. Users may configure browser settings to decline cookies; however, certain interactive features of the Application or website may not function optimally as a result.
5. Third-Party Tools & SDKs
The Application utilizes trusted third-party SDKs and service providers to support essential backend operations:
- Google Firebase / Google Cloud: Secure user authentication, Cloud Firestore database synchronization, and Firebase Cloud Messaging (FCM) for push notifications.
- WebRTC Infrastructure: Open-source, encrypted real-time audio and video communication protocols (DTLS/SRTP).
- Payment Aggregators & Gateways: Google Play In-App Billing and authorized payment processors for secure monetary recharges.
These service providers receive only the minimum necessary information required to perform their functions and are contractually prohibited from using or transferring your data for any independent marketing purposes.
6. Confidentiality, DRM & Zero-Recording Policy
We treat all personal communications as strictly confidential. Friendly enforces the following core privacy measures:
- Zero Server Recording: Voice and video calls are transmitted in real time directly between participants via peer-to-peer WebRTC encryption. We do NOT record, listen to, intercept, or store private audio or video conversations on our servers.
-
In-App DRM & Anti-Screen Capture (FLAG_SECURE): The Application implements hardware-level secure window protections (Android
WindowManager.LayoutParams.FLAG_SECURE) across active calling and confidential screens. Screenshots and third-party screen recording utilities are blocked by the OS to prevent unauthorized capture.
Confidential information will not be disclosed to third parties except under the following narrow circumstances:
- Where there is an imminent and real threat to the life, physical safety, or health of a User or any other individual;
- Where disclosure is legally mandated under an enforceable court order, summons, or statutory investigation under applicable law;
- To establish, exercise, or defend the legal rights and property of the Application against unlawful activities.
7. Security Measures & Breach Notifications
In accordance with Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we implement industry-standard physical, electronic, and procedural safeguards (including TLS/SSL transport encryption, encrypted databases, and access control restrictions) to safeguard your personal data.
While we take all reasonable steps to prevent unauthorized access or loss, you acknowledge that no digital transmission over the internet can be guaranteed 100% immune from security vulnerabilities.
Breach Notification Timelines (GCC & Global)
In the event of a verified data breach affecting personal information, we will notify relevant regulatory authorities and affected Users within the statutory timelines:
- UAE & Saudi Arabia: Within 72 hours of confirmation;
- Qatar: Within 7 days;
- India: In accordance with Indian Computer Emergency Response Team (CERT-In) guidelines;
- Kuwait & Other Jurisdictions: As soon as reasonably practicable.
8. Children's Privacy (Strict 18+ Requirement)
The Application is strictly intended for adult individuals aged 18 years and older (or 21+ where required by regional law). We do not knowingly collect, request, or maintain personal information from individuals under 18 years of age.
IF YOU ARE UNDER 18 YEARS OF AGE, YOU ARE STRICTLY PROHIBITED FROM USING THE APPLICATION. If a parent or guardian becomes aware that a minor has registered an account, please contact our Grievance Officer immediately at support.friendlyekm@gmail.com. We will promptly investigate and permanently delete the minor's account and associated data from our systems.
9. Disclosure and Transfer of Information
We do not sell, rent, or trade your personal information to third parties. Information may only be shared under the following conditions:
- With trusted infrastructure partners (e.g., cloud hosting, database management, and SMS/OTP delivery services) bound by strict non-disclosure and data protection agreements.
- With payment aggregators to process user-initiated digital transactions.
- In connection with corporate reorganizations, mergers, acquisitions, or asset sales, with notice to affected users.
- To comply with legal obligations, judicial decrees, statutory investigative agencies, or to protect against suspected fraud or immediate physical threats.
🔒 Mobile Phone Number Protection: Mobile information and phone numbers will NOT be shared with or sold to third parties or affiliates for marketing or promotional purposes. SMS opt-in data and consent records will never be shared externally.
Cross-Border Data Transfer (GCC & Global)
By accessing the Application, Users in GCC countries expressly consent to the secure transfer and processing of personal data outside their country of residence (including India and secure cloud server regions) with adequate technical and contractual safeguards in compliance with:
- Articles 22 & 23 of UAE PDPL;
- Article 29 of Saudi Arabia PDPL;
- Article 14 of Qatar Data Protection Law; and
- Article 28 of Kuwait Electronic Transactions Law.
10. Data Retention & Account Deletion (Google Play Compliant)
Users have the absolute right to delete their account and associated personal data at any time. We provide both in-app and external email-based account deletion mechanisms:
How to Request Account & Data Deletion
Method 1: In-App Account Deletion
- Open the Friendly App on your device.
- Go to Profile → Settings.
- Select Account & Security.
- Tap on "Delete Account" and confirm your request.
Method 2: External Web / Email Request
You can email our Grievance Officer at support.friendlyekm@gmail.com with the subject line "Account Deletion Request" from your registered email address or mentioning your registered phone number.
Erasure Timeline: Upon receiving your verified deletion request, your profile, authentication credentials, uploaded avatars, and personal records will be permanently removed and purged from our active databases within 30 days.
Statutory Exception: Certain anonymized financial transaction records and tax invoice logs may be retained for up to 7 years solely to fulfill mandatory legal, tax, and GST/VAT compliance requirements under applicable Indian and GCC laws, after which they are permanently destroyed.
11. Your Legal Rights in Relation to Your Data
Under applicable data protection laws, you possess the following rights:
- Right of Access & Correction: You may review and update your profile details directly within the Application at any time.
- Right to Withdraw Consent: You may revoke your consent to data processing by writing to our Grievance Officer. Please note that revoking essential consent may prevent the Application from delivering calling services.
- Right to Data Portability & Erasure: You may request a copy of your personal data or request permanent erasure as outlined in Section 10.
12. Third-Party External Links Disclaimer
The Application or website may contain links to external third-party services or payment gateways. Any data provided on third-party platforms is governed exclusively by their respective privacy policies. Friendly disclaims all liability for the privacy practices, content, or data handling of external third-party services.
13. Communications and Notifications
By registering on Friendly, you consent to receive necessary service and transactional communications from us via:
- SMS text messages (e.g., OTP verification codes);
- WhatsApp / RCS notifications;
- In-app push notifications (e.g., incoming call ring alerts, account security alerts);
- Direct voice calls or IVR (strictly for urgent account verification or security notices).
You may opt out of non-essential promotional messages at any time by adjusting in-app notification toggles or contacting customer support. Essential transactional communications (e.g., login OTPs, call ringing alerts, security notices) cannot be disabled while using the service.
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect technological updates, operational adjustments, or changes in legal regulations. The updated Privacy Policy will be published within the Application and on our official website with a revised "Last Updated" date. Continued use of the Application after revisions constitutes acceptance of the updated policy.
15. Grievance Officer & Statutory Contact Details
In accordance with the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the details of the designated Grievance Officer for Friendly are as follows:
🇮🇳 India Grievance Redressal Officer
- Designation: Grievance Officer - Friendly App
- 📧 Official Email: support.friendlyekm@gmail.com
- 📞 Helpline / WhatsApp: +91 91760 69149
- 🏢 Physical Postal Address: Friendly Operations Desk, Ernakulam, Kochi, Kerala, India - 682001
- ⏱️ Statutory Redressal Timeline: Grievances will be acknowledged within 24 hours and resolved within 15 days of receipt as mandated by Rule 3(2) of IT Rules, 2021.
Regional Privacy Contacts (GCC Users)
Users residing in GCC countries may reach out to our dedicated regional support desk for data protection inquiries:
- 🇦🇪 UAE Support: support.friendlyekm@gmail.com
- 🇸🇦 Saudi Arabia Support: support.friendlyekm@gmail.com
- 🇶🇦 Qatar Support: support.friendlyekm@gmail.com
- 🇰🇼 Kuwait Support: support.friendlyekm@gmail.com