Privacy Policy

This policy explains what Aanonimy collects, why, and what you can do about it. We have tried to write it plainly and to be specific β€” including about the things we cannot do for you.

1. Who we are

Aanonimy is operated by Damain Ross, a sole trader based in Kingston, Jamaica. We are the data controller for the information described in this policy.

Contact: info@aanonimy.com

2. What Aanonimy does

Aanonimy is a social app with two things most apps do not have: you can send end-to-end encrypted messages, and you can post and message anonymously, under a pseudonym the person you are talking to cannot connect to your account.

The app is free; optional one-time purchases add credits for anonymous posts.

Using Aanonimy without an account

You can browse without signing up. Without an account you can see the feed and read comments and replies. Posting, commenting, replying, liking, reposting, searching, opening someone's profile and messaging all need an account.

Even without an account, some information is still processed: crash reports, general usage measurement, and your device's advertising identifier for ads (Section 7). We do not have your email, your name or any profile, because you have not given us one.

Where Aanonimy is offered

Aanonimy is not offered in the European Economic Area, the United Kingdom or Switzerland, and is not made available to download there. Elsewhere it is available where the app stores list it.

The aanonimy.com website

Our website has a waitlist. If you join it, we store your email address and the date you joined, to email you once when Aanonimy launches. Nothing else is done with it β€” no newsletter, no sharing. The launch email is sent from our own aanonimy.com mailbox. We delete the list once the launch email has been sent, and we delete your address sooner if you ask β€” email info@aanonimy.com. The website does not use analytics or advertising cookies. It loads fonts from Google Fonts, which sees your IP address. The full notice is shown beside the form.

3. What we collect

What we do not collect

Location β€” only if you ask for nearby places

When you add a location to a post you can type a place name, or tap to find places near you. These are different, and only the second one uses your device's location:

We never track your location in the background, and we never read it unless you tap that button.

Account information

When you register: email address, username, display name, and date of birth.

Optional, only if you add them later: profile photo, biography, and phone number. Leaving them blank is fine, and you can remove any of them again at any time in the app. Removing your phone number also removes it as a way to sign in.

What you create

Posts (text, photos, video), comments, replies, voice notes, messages, chat and profile backgrounds, and a location label if you add one β€” either typed by you, or a place name you picked from the nearby-places list (Section 3).

Generated by using the app

Who you follow and who follows you, who you have blocked, what you have liked and reposted, your anonymous messaging identifier, whether you accept anonymous messages, your read-receipt preference, which one-time tips you have dismissed, your device's push-notification token, which version of the Terms and this Policy you accepted and when, and a fingerprint (a hash) of each photo or video you attach to a post, used only to find copies of a file when a copyright notice is actioned (Terms Section 18).

Presence and read receipts

A connection flag records whether you are online, so others can see it. It records connection state only.

Read receipts can be turned off in the app; when off, we do not share that signal.

⚠️ Online status cannot currently be switched off. Read receipts can; your online indicator cannot.

Reports

If you report content, we store the report with your account identifier, the content reported, and the reason. See Section 8 for how long.

4. How we use it

To provide the service; to operate anonymous messaging and posting; to show and deliver content; to enforce our rules and act on reports; to process purchases; to send account notices; and to meet legal obligations.

We do not sell your personal information.
We do not use your content to train AI models. The app contains no AI model integration of any kind.

5. End-to-end encryption, and its exact limits

Encrypted end to end β€” we cannot read it: the content of your messages, including text, media and voice notes. The keys are generated and held on your device. Our servers store only ciphertext. The only key material we hold is your encrypted key backup, which we cannot open β€” the password that unlocks it never leaves your device.

Not end-to-end encrypted:

Two consequences worth understanding:

  1. If encryption keys cannot be established, a message is not sent. It is held and retried. It is never sent unencrypted instead.
  2. If you forget your password and sign in on a new device, previously received messages cannot be recovered. They are lost permanently β€” we never had the keys.

Messages to someone who has blocked you

If you send a message to someone who has blocked you, it is not delivered. It is rejected and deleted on our servers, and the recipient receives nothing. Your app may still show it as sent β€” we do not tell you that you have been blocked, because doing so would expose the person who blocked you.

6. Anonymous messaging and posting

When you message someone anonymously they see a name like Nameless-XXXXX. That displayed name is derived from the pair of you, so a different person sees a different name for you, and nothing on screen lets two recipients tell they are talking to the same person. It never changes for that person β€” if you tell them who you are, that is irreversible for that conversation.

Underneath the displayed name, your account has one anonymous identifier that is the same in every anonymous conversation you have. It is not shown in the app, but it travels inside the message data that recipients' devices receive. Someone who inspected that data with tools could see that two of your anonymous conversations came from the same anonymous identity. It would still not tell them who you are: the link between that identifier and your account exists only on our servers.

Anonymous posts carry a per-post token unrelated to your account and unrelated to your messaging identifier, so posts and chats cannot be linked to each other, and two anonymous posts cannot be linked to each other either.

⚠️ This is anonymity towards other users, not towards us. We hold the mapping between your account and your pseudonyms, and will disclose it where legally compelled (Section 11).

7. Advertising

Aanonimy shows ads through Google AdMob. You will see them in the comments on a post, and on the opening screen.

Ads are not personalised. We ask Google for non-personalised ads on every request, so the ads you see are chosen from the app and the screen you are on, not from a profile of you. The AdMob SDK still reads your device's advertising identifier β€” a resettable ID that is not your name or your account β€” for frequency capping, fraud prevention and aggregate reporting, together with general information such as your device type, your approximate region and the app you are using. We do not send AdMob your email address, your username, your posts, your messages, or the link between your account and any anonymous pseudonym.

Each ad carries the AdChoices icon; tapping it opens Google's controls for that ad, including the option to stop seeing it. You can also reset or delete your advertising ID at any time in your device settings (on Android under Google settings β†’ Ads).

Usage measurement

The app includes Firebase Analytics, which records general usage β€” that the app was opened and for how long, your device model and operating system, your approximate region, and an app-instance identifier. It tells us how the app is used so we can improve it. It does not receive your messages, your posts, your profile, or the link between your account and any anonymous pseudonym.

The app also includes PostHog, a product-analytics service, on a small set of screens: the sign-up steps, the paywall and the post composer, the chat list and chat, Account Centre, and the activity feed. For those screens it records that the screen was opened, how long it was on screen, and named actions on it β€” for example that a purchase was started or cancelled, or that a message was sent and whether it was text, photo, video or voice. Events carry a random identifier for the app installation, not your account: we never give PostHog your account identifier, email, username, pseudonym, or any content, and PostHog never records what is on your screen. Its data is stored in the United States and kept for 12 months.

Crash reports

The app includes Firebase Crashlytics, which sends us a report when the app crashes so we can fix it. A report contains technical details of the crash β€” where in the code it happened, your device model, the operating system version, the app version, and a Crashlytics installation identifier. It does not contain your messages, your posts or your profile.

8. How long we keep things

DataKept
Account record and profileUntil you delete your account
Posts, comments, repliesUntil you delete them, or your account
Message contentUntil deleted by either participant; when both sides clear a conversation, messages up to the earlier point are deleted from our servers
Presence flagCleared when you disconnect
Reports you filed12 months after the report is resolved, while it still identifies you β€” longer only while an appeal or legal matter about it is open. Your identifier is removed when you delete your account, if that comes first
The anonymised copy of a reportKept indefinitely. It contains nothing that identifies anyone
Notices about your content12 months, or until you delete your account, whichever is first
Content we removed for breaking the rulesA copy is kept so the removal can be appealed and reversed, and so acting on a report is not what destroys the evidence. Deleted with your account. Child-safety material is the exception below
Usage analytics events (PostHog)12 months, then deleted. Never linked to your account
Copyright notices (Terms Section 18)At least 6 years, as a business record. If the notice named your account as the poster, we remove our internal link to your account when you delete it, although a username the claimant typed stays on their notice; the notice itself survives
Records of child-safety removalsKept indefinitely, including if the account is deleted. See our Child Safety Standards
Purchase and payout recordsAt least 6 years, because Jamaican tax law requires records substantiating income. These come from Google, the merchant of record β€” we never receive or store your card details, and they are records of money paid to us, not a history of what you bought. RevenueCat, which validates purchases, holds a record of your purchases against your account identifier; we delete that record when your account is deleted. Google keeps its own order records as the merchant, and we keep Google's payout reports as our tax records

Deleting your account

You can delete your account in the app (Account Center β†’ Account status β†’ Delete account). Deletion is not immediate: there is a 14-day grace period, and signing back in during those 14 days cancels a deletion you requested yourself; a deletion we started for repeated copyright complaints is not cancelled by signing in. After that, your data is erased (within about a day).

What is not deleted, and why

Deleting your account removes your profile, your posts, comments and replies, your private encryption keys and key backups, your purchase balance, your follows, your blocks and everything else that points at you. Six things stay, each on purpose:

Everything else we hold is either deleted with your account or contains nothing that identifies anyone.

9. Who else processes your data

ProviderPurposeTheir policy
Google (Firebase)Sign-in, database, file storage, presence, push notifications, server functions, anti-abusefirebase.google.com/support/privacy
Google PlayPurchases and refunds (merchant of record)policies.google.com/privacy
Google AdMobServing ads in the comments and on the opening screen β€” see Section 7policies.google.com/technologies/ads
Firebase CrashlyticsCrash reports, so we can fix what breaks β€” see Section 7firebase.google.com/support/privacy
Firebase AnalyticsGeneral usage measurement β€” see Section 7firebase.google.com/support/privacy
PostHogProduct analytics on selected screens β€” see Section 7 (random install identifier; no account data; United States)posthog.com/privacy
RevenueCatPurchase validation and entitlementsrevenuecat.com/privacy
Google Maps PlatformPlace search β€” receives what you type when searching for a place, and your coordinates only when you tap β€œfind places near you” (Section 3)policies.google.com/privacy
vxtwitterFetching a preview image when a post links to X/Twitter. Called from our server, not your device β€” it receives the link, never your IP addressgithub.com/dylanpdx/BetterTwitFix
YouTube Β· TikTok Β· Vimeo Β· Spotify Β· SoundCloudWhen a post links to one of these, your device asks that platform's own public preview service for a title and thumbnail β€” so the platform sees the link and your device's IP address, as it would if you opened the linkEach platform's own policy

Link previews

When a post contains a link, we try to show a preview of it.

Copyright notices

If you send us a copyright notice (Terms Section 18), we keep what you gave us β€” your name, email address, organisation, the work, the content you identified, your statements and signature β€” for at least six years, as the record that we acted. We tell the person who posted the content that a complaint was received. If they send a counter-notice, we send it to you, and we send your notice to them, so that the two of you can take the matter further; that is how the counter-notice procedure works. We do not use a notice for anything else, and the notice form sets no cookies.

People who work on Aanonimy

A small number of people help run Aanonimy β€” for example reviewing content that has been reported. They act on our instructions and under obligations of confidentiality. They are not separate controllers of your information, and they may not use it for their own purposes.

Access to the moderation tools is restricted: it requires a specific authorisation on the account, enrolment on an allow-list, and a second authentication factor.

A reviewer sees the content that was reported. They are not shown the real account behind an anonymous post or an anonymous message β€” that link stays on our servers and is never sent to the tools they use.

10. Where your data is stored

All personal data we store is in the United States, on Google's infrastructure.

Why we may do that. Aanonimy cannot be provided without hosting it, and you contract with us for the service β€” so the transfer is necessary to perform our contract with you, the condition in section 31(4)(b)(i) of Jamaica's Data Protection Act.

11. When we disclose information

We may disclose information, including the link between an account and its anonymous pseudonyms, where required by law or where necessary to investigate serious harm β€” including child sexual abuse material.

If we believe someone is at imminent risk of death or serious injury, we may share what we hold about the account β€” including the link to its pseudonyms β€” with emergency services or the police, so that they can act.

12. Children

You must be at least 16 to use Aanonimy, anywhere it is available. This is checked at sign-up from your date of birth, and enforced on our servers as well as in the app β€” so editing the app does not get past it.

See our Child Safety Standards for what we prohibit and what we do about it.

13. Your rights

If you are in Jamaica: you have the right to access and to correct your personal data under the Data Protection Act, and the right to complain to the Information Commissioner. We respond within 30 days.

If you are in California: the right to know, delete and correct, and to opt out of sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising β€” the ads in Aanonimy are not personalised (Section 7).

What allows us to process your data

What we doOn what basis
Run your account, store and deliver your posts and messages, operate anonymous posting and messaging, process purchasesNecessary to perform our contract with you β€” DPA s.23(1)(b)(i)
Keep the service secure, prevent abuse, enforce our rules, act on reportsOur legitimate interests, and those of other users β€” s.23(1)(f)
Meet legal obligations, including child-safety and law-enforcement dutiesCompliance with a legal obligation β€” s.23(1)(c)
Show content you chose to make publicYou published it β€” s.23(1)(g)
Optional profile details you choose to addYour consent β€” withdraw it by removing them β€” s.23(1)(a)

You can change your name, username, photo, biography and phone number yourself in Edit Profile and Account Center, and delete your posts, comments and replies, or your whole account, from the app. For anything else: email info@aanonimy.com. We respond within 30 days.

14. Security

Data is encrypted in transit. Message content is end-to-end encrypted (Section 5), and key material is held in your device's secure storage; we hold only an encrypted backup of it that we cannot open. Access to our systems is restricted by server-side rules, and most requests from the app are attested to reduce abuse.

If there is a breach. If personal data is lost, exposed or accessed without authorisation, we report it to Jamaica's Information Commissioner within 72 hours of becoming aware, and we tell everyone whose data is affected β€” what happened and what we are doing about it.

15. Changes

We will post material changes here with a new β€œlast updated” date. For significant changes, we will also tell you in the app.

16. Contact

info@aanonimy.com

Last updated: 5 September 2026