English Русский

Privacy Policy

Effective date: 13 May 2026 · Last updated: 14 July 2026

1. Operator

The JFF mobile application (the "App", iOS bundle identifier ru.jff.ios) is operated by Damir Kharisov (the "Operator").

Contact: jff.support@gmail.com.

2. Scope

This Policy governs the processing of personal data within the iOS and Android versions of the App and its backend infrastructure.

The Policy complies with Federal Law No. 152-FZ of the Russian Federation ("152-FZ") and, where applicable, the EU General Data Protection Regulation ("GDPR").

3. Categories of personal data

CategoryContentsSource
Identifiers Phone number; Apple ID identifier; Apple ID email (only where the user elects to share it) Provided by the user at sign-in
Profile data First name, date of birth, gender, "about" text, city (optional), profile photos, avatar Provided by the user
Face data (facial images) Short live camera frames captured during one-time liveness verification, used for (a) confirmation of a live human subject and (b) automated gender classification against the declared value. The face is not converted into a persistent biometric template or face-recognition vector, and is never used to identify or track the user across sessions. A single final selfie frame is retained only for the security cases described in §6. Captured with the user's prior in-app consent at registration
User-generated content Text, voice, photo and video messages; reactions; abuse reports Created by the user within the App
Technical data Device model, OS version, App version, language, push token, IP address, error logs Collected automatically

The App does not collect precise geolocation, contacts, calendar, health data, advertising identifiers, or payment data outside the platform stores.

4. Purposes and legal bases

5. Third-party processors

ServiceFunctionData transferredNotice
Telegram Gateway Delivery of one-time verification codes Phone number, OTP code core.telegram.org/gateway/privacy
CometAPI / Google Gemini Avatar generation from selfie One selfie frame and a text prompt; no identifiers attached cometapi.com/privacy · policies.google.com/privacy
face-api.js (executed on the Operator's backend) Liveness detection and gender classification Frames are processed in memory and discarded immediately; only the derived result is retained github.com/justadudewhohacks/face-api.js
Supabase Database, file storage, session storage Profile data, messages, media, technical identifiers under §3 supabase.com/privacy
Apple — Sign in with Apple Alternative authentication method Apple-issued opaque identifier and, where elected, name and relay email apple.com/legal/privacy
Timeweb Cloud Backend API and Socket.IO hosting All data processed by the backend timeweb.cloud/legal

Personal data is not transferred to advertising networks or data brokers and is not sold.

6. Retention of face data

6a. Other retention periods

During registration a single selfie frame, with no identifiers attached, is also sent to the avatar-generation provider (CometAPI / Google Gemini) to produce the profile avatar; the original selfie is not stored and only the generated avatar is kept. All persisted data, including any retained selfie, is stored on Supabase infrastructure located in the European Union. Face data is never sold and never shared with advertising networks or data brokers, and is used only for the liveness/anti-fraud checks and the avatar generation described in this Policy.

7. Rights of the data subject

Requests shall be addressed to jff.support@gmail.com. Response within 30 calendar days.

8. Age restriction

The App is restricted to users aged 18 and over. Age is enforced on the client and the server. Accounts identified as belonging to minors shall be deleted without delay.

9. Security

The Operator implements HTTPS/TLS for all network traffic, hashed session tokens, server-side row-level security, rate limiting on sensitive endpoints, and screen-capture protection. Suspected compromise shall be reported to jff.support@gmail.com.

10. Children

The App is not directed at children under 18; personal data of minors is not knowingly collected.

11. Amendments

The Operator may amend this Policy. The "Last updated" date shall be revised accordingly. Material changes shall be notified within the App prior to taking effect. Continued use after the effective date constitutes acceptance.

12. Contact

Operator: Damir Kharisov
Email: jff.support@gmail.com
Support: jff-legal.pages.dev/support