Fartnet — Privacy Policy
Last updated: 2026-08-22.
1. Who we are
Fartnet ("the Service", "we", "us") is operated by Artem Morozov pr Racunarsko programiranje Novi Sad, Bulevar Cara Lazara 44 L41, 21000 Novi Sad, Serbia. For privacy questions: [email protected].
2. What data we collect
We deliberately collect as little as possible. Fartnet is built around anonymous use. The following categories may be processed:
| Category | Examples | Purpose |
|---|---|---|
| User Content | Audio recordings (1.5–15 s), tags, comments, reactions, bookmarks | The service itself |
| Identifiers (anonymous) | Auto-generated nickname (e.g. WaspGiggle1234), an internal user UUID, an install_id derived from your device, a salted device fingerprint hash |
Account continuity, abuse prevention |
| Optional account credentials | If you choose to set them: a chosen nickname and a password (stored as a salted hash, never in plain text). Five recovery codes (stored as salted hashes). | Cross-device login and password recovery |
| Optional recovery email | If you choose to attach one: your email address and its verification status. Used only to send password-recovery codes. | Password recovery |
| Device metadata | OS platform, OS version, app version, locale, time zone, device model | Compatibility, abuse prevention |
| Push tokens | Expo push token registered with our backend | Sending you notifications about likes / comments on your content |
| Diagnostics | Crash reports and performance metrics via Sentry | Stability monitoring |
| Audit metadata | Counts, timestamps, IP-derived rate-limit keys (the IP itself is not persisted long-term beyond standard webserver logs) | Spam / abuse prevention |
We do not request a phone number, real name, contacts, location, or any biometric data. An email address is optional and is used only for password recovery. We do not show advertising and do not integrate any third-party analytics or marketing SDKs at this time.
2.1 Automated speech check
Fartnet is for fart sounds only. Every upload is analysed by an automated speech-recognition model, running on our own servers, for one purpose: to detect whether the recording contains spoken words. The audio itself is never modified.
- If no speech is detected, the clip is published exactly as recorded.
- If speech is detected, the clip is not published: it is quarantined, you are notified in-app, and it is handled under our moderation rules (typically deleted). You can re-record without words.
- The detected words are not saved to your account and are not used for anything other than this publish/quarantine decision. Short-lived server logs may record the detection result for moderation diagnostics.
This check exists to keep the service speech-free and to protect the privacy of anyone who might be audible in a recording.
3. Why we process it (legal bases under GDPR)
- Performance of a contract with you (the Terms of Service) — to provide the service.
- Legitimate interest — to keep the service running, prevent abuse, improve reliability, and run the automated speech check described in §2.1.
- Consent — for push notifications and microphone access; you can revoke either at any time in your device settings.
4. Who we share data with
We share only with infrastructure providers strictly necessary to operate the service:
- Cloud hosting / object storage — your audio files and waveform metadata.
- Sentry (diagnostics) — anonymized crash logs may include device model, OS version, app version.
- Expo Push Service (650 Industries, Inc.) — your push token and the body/title of notifications we send to you.
- Apple / Google — the operating system push gateways at the very last hop of delivering a notification.
We do not sell, rent, or share data with advertisers, brokers, or analytics partners.
5. Where data is stored
Servers are located in the European Union. International transfers, where they occur, rely on Standard Contractual Clauses or equivalent safeguards.
6. How long we keep data
- Audio recordings — until you delete them (soft-delete to
removed, removed from public surfaces immediately) or until you delete your account, whichever is sooner. Originals are retained in cold storage for up to 30 days for abuse review, then permanently destroyed by an automated background job. - Identifiers and metadata — for the lifetime of your account. On account deletion (see §8) we destroy or irreversibly anonymize them; tombstoned account records are permanently removed within 30 days alongside their content.
- Diagnostics (Sentry) — Sentry default retention applies (90 days at time of writing).
- Moderation records — retained as long as required for safety and legal-defense purposes, even after account deletion. These do not contain readable account identifiers.
7. Children
Fartnet contains crude humor (fart sounds) and is intended for users aged 13 and over. We do not knowingly collect data from children below this age. If you believe a child has used the service, please contact [email protected] and we will delete the account.
8. Your rights
If you are in the EU, EEA, UK, or California (and in any other jurisdiction with comparable laws), you have the right to:
- Access the data we hold about you.
- Rectify inaccurate data (you can change your nickname yourself, or contact us).
- Delete your account and all associated content. You can do this directly inside the app: Me → Delete account permanently, or via the API
DELETE /v1/auth/me. Public-surface removal is instant; full destruction (including S3-stored audio originals) completes within 30 days via an automated cleanup job. - Restrict or object to processing.
- Data portability — request an export of your content. Contact [email protected]; we will respond within 30 days.
- Withdraw consent to push notifications or microphone access at any time via OS settings.
- Lodge a complaint with your national data-protection authority (e.g. CNIL, ICO, BfDI).
To exercise any of these rights, write to [email protected]. We may need to verify your control of the account (e.g. by asking you to authenticate from the app).
9. Security
- Passwords are hashed with
pbkdf2_sha256(Django default) before storage. - Recovery codes are hashed identically.
- Tokens use signed JWTs over TLS.
- Data in transit uses HTTPS / TLS.
- We follow industry-standard practices, but no system is perfectly secure; in case of a breach affecting your data we will notify you and the relevant authority within 72 hours per GDPR Article 33.
10. Cookies and on-device storage
Fartnet (mobile) stores small pieces of data locally on your device using MMKV: your authentication tokens, your install ID, your selected theme and language, your filter preferences, your bookmarks. This data does not leave your device unless explicitly transmitted to our backend as part of normal operation. It is removed when you tap "Forget this device" or "Delete account permanently".
Our website (fartnet.app) is static: it sets no cookies and uses no analytics.
11. Changes to this policy
If we materially change how we process data we will:
- update the "Last updated" date at the top,
- notify you in-app at next launch,
- and (where required) ask for renewed consent.
Continued use of the service after a change indicates acceptance of the revised policy.
12. Contact
Privacy questions and rights requests: [email protected].