Skip to content

Privacy Policy.

Last updated September 2, 2026.

This policy explains what data Fellowing handles, what we can and cannot see, and the choices you have. It covers the Fellowing app, the services behind it, and this website.

Fellowing is made by Fellowing PBC, a Delaware public benefit corporation. We’ve written this policy to be read. If anything is unclear, email legal@fellowing.com and we’ll explain it plainly.

  1. The short version

    • Everything your group shares in Fellowing is end-to-end encrypted. We store it, but we cannot read it.
    • You sign in with a passkey or a recovery phrase. It holds the key to your encrypted data and never touches our servers.
    • We never ask for your email address or phone number, and nothing on our servers links your account to your name or contact details.
    • We don’t sell data, we don’t show ads, and we don’t track you across other apps.
    • What we can see is limited to what running the service requires (technical metadata, anonymous usage counts, and crash reports) plus the things you choose to send us, like a suggestion or an abuse report.
    • You can delete your account in the app at any time.

    The rest of this policy is the detail behind that list.

  2. What your group shares stays between you

    Everything you and your group create in Fellowing is end-to-end encrypted: group names, messages, reactions, commitments, check-ins, events and RSVPs, profile names, and profile photos.

    End-to-end encrypted means the data is encrypted on your device before it leaves, and only members of your group hold the keys to read it. Our servers store and deliver it as ciphertext. We can’t read any of it, even if we wanted to (we don’t), and neither can the companies that host our servers. Our encryption page explains how this works.

    One consequence to know: what you share with a group becomes part of that group’s shared record. If you leave a group, are removed from one, or delete your account, the messages, check-ins, and other content you already shared stay with the group, without your name attached.

  3. Your passkey or recovery phrase

    When you sign up, the only thing we ask for is the name you’ll go by. There’s no password. Instead, you protect your account with a passkey or a recovery phrase, and you can set up both.

    A passkey is created by your device, protected with Face ID, your fingerprint, or your device PIN, and synced through iCloud Keychain or your password manager if you use one. A recovery phrase is 24 words the app shows you on screen. You keep them wherever you like, and we don’t keep a copy. Both the passkey and the phrase contain the secret that unlocks your account.

    Since we never have that secret, we can’t reset it for you. If you lose your passkey and your recovery phrase, nobody, including us, can get your account or your data back.

  4. What we don’t collect

    • No email address or phone number.
    • No contacts, no location, no advertising identifiers.
    • No identity records: there is no record on our servers connecting your account to your name or any contact detail.
    • No ads, no data sales, no tracking across other apps or websites.
  5. What our servers can see

    Running a sync service requires some technical metadata. Here’s what our servers handle in readable form:

    • Random account and record identifiers (machine-generated strings, not names). We can see that an account exists and which encrypted records it syncs, and when.
    • Which account identifiers belong to which group identifiers, so we can route notifications. Not group names, and not member names.
    • Device push tokens: the address Apple and Google use to deliver notifications to your phone.
    • Connection data: your IP address when your device connects, used for rate limiting and abuse protection, and short-lived operational logs kept for a few days.
    • App version and platform (iOS or Android).

    None of this tells us who you are or what your group is about.

  6. Push notifications

    Notification content is encrypted too. The notification our servers send through Apple and Google is generic (it says "Fellowing" and "New activity") plus an encrypted preview. Your phone decrypts the real preview, like the sender’s name and a summary, locally, just before showing it to you.

    Apple, Google, and Expo (the delivery service we use) see your device’s push token and a group identifier, never the content or the group’s name. You can turn notifications off in your device settings at any time.

  7. Usage analytics

    We count how features get used so we can tell what’s working. These events are counts and categories only. When you check in, for example, we record that a check-in happened and whether it included a note; never the note or the content of the check-in itself.

    Each event is tagged with random identifiers for the account and group it came from. Nothing on our servers ties those identifiers to you, and we additionally scramble them with a secret key before the event is stored. The stored data has no IP address or device identifiers either, and there is no third-party analytics code in the app.

  8. Roadmap votes and suggestions

    The app has a roadmap where you can vote on what we build next and send us feature ideas. Votes and suggestions are tied to your account identifier so each person counts once, and they’re sent directly to Fellowing. They are never visible to other users, in your groups or anywhere else. The board shows only totals, and the totals carry no record of who voted.

    Suggestion text is content you’re choosing to send us, so write it accordingly. We keep suggestions and votes while we plan the roadmap; your own suggestions also stay in your account, where the app shows you what you’ve sent.

  9. Abuse reports

    You can report a member or a message from inside the app. A report to your group’s admin stays inside your group’s encryption; we never see it.

    A report to Fellowing is content you choose to send us: the reason you pick, the random identifiers of the accounts and group involved, and the reported message if you include it. Reports arrive as email, and we keep them only as long as we need to handle them, unless the law requires us to preserve one longer.

  10. Crash and performance reports

    When the app crashes or something breaks, a report goes to Sentry, a crash-reporting service. We’ve configured it not to collect personal information: your IP address is replaced with zeroes, and reports contain technical details (device model, OS version, what the app was doing) rather than anything you wrote. A small sample of sessions also sends performance timings, like how long screens take to load.

    Reports can include internal record identifiers; they never include your content. Sentry keeps reports for about 90 days.

  11. Invite links

    Groups are invite-only and aren’t listed or discoverable anywhere. Invite links are unguessable. Anyone who has a group’s invite link can see the group’s name and how many members it has, and can ask to join; a group admin has to approve them before they see anything else. Treat an invite link like a key: share it only with people you’d welcome into the group.

  12. Who helps us run Fellowing

    A few companies process data on our behalf, each bound by contract to handle it only to provide its service to us:

    • Cloudflare hosts our servers, stores your group’s encrypted data (as ciphertext it cannot read), and stores our pseudonymized usage analytics.
    • Expo relays push notifications to Apple and Google and delivers app updates.
    • Apple and Google carry push notifications the last mile to your device. They also help us check that connections come from a genuine Fellowing app on a real device; that check shares standard device signals and your IP address, never who you are or anything you’ve written.
    • RevenueCat manages in-app purchases. If you pay for Fellowing, it receives the purchase record from Apple or Google, tied to a random identifier we generate for purchases only. Apple or Google handles the payment itself; your payment details never reach RevenueCat or us.
    • Sentry receives crash and performance reports, as described above.

    That’s the whole list. No data brokers, no ad networks.

  13. Where your data lives

    Our providers are US companies, and our servers run on Cloudflare’s global network. Wherever you use Fellowing from, the protections in this policy apply. If you’re in the EEA, the UK, or another region with data-transfer rules, we rely on our providers’ standard contractual protections for any transfer.

  14. How long we keep things

    • Group content: as long as the group exists. It’s the group’s shared record.
    • Encrypted backups: our storage keeps encrypted point-in-time backups for up to 30 days.
    • Push tokens: removed when you delete your account, and pruned automatically when they go stale.
    • Purchase records: Apple or Google keeps its own payment records; RevenueCat keeps the purchase record tied to your random purchase identifier.
    • Usage analytics: kept as aggregate statistics that aren’t tied to your identity.
    • Roadmap suggestions and votes: while we plan the roadmap.
    • Abuse reports: only as long as we need to handle them, unless the law requires us to preserve one longer.
    • Crash reports: about 90 days, at Sentry.
    • Operational logs: a few days.
  15. Deleting your account

    You can delete your account in the app: Account settings, then Delete account. Deleting your account erases your profile (your name and photo), removes your commitments, removes you from all of your groups, removes your push tokens, and deletes the random purchase identifier from your account. It can’t be undone.

    Messages, check-ins, and other content you already shared stay in your groups, without your name on them. If you made a passkey, it stays in your device’s password settings; you can remove it there. A recovery phrase you kept opens an account with nothing in it. Apple or Google keeps its own record of any purchases you made. There is no account record on our side to delete, because we never had one.

  16. Your rights

    You can ask us what information we have about you, ask us to correct or delete it, or ask for a copy. For most of Fellowing, the honest answer is that your data lives on your device and sits encrypted on our servers, so we couldn’t produce a readable copy even if you asked. Viewing and deleting your data is self-serve in the app. For the little we can read, like the metadata and crash reports above, email legal@fellowing.com and we’ll respond within 30 days.

    If you’re in the EEA, the UK, California, or another place with data-protection laws, these are your legal rights there. We honor them regardless of where you live, and we’ll never treat you differently for exercising them. We don’t sell personal information, and we don’t share it for cross-context behavioral advertising.

    Where the GDPR applies: Fellowing PBC is the data controller. We process the data described here to provide the service you signed up for, and, for analytics and crash reports, in our legitimate interest to keep Fellowing working and improving.

  17. Children

    Fellowing isn’t directed at children under 13, or under the higher age some countries set for consenting to data processing (16 in parts of Europe), and we don’t knowingly collect information from anyone below those ages. If you believe a child is using Fellowing, email legal@fellowing.com and we’ll look into it.

  18. If we’re required to disclose data

    If a legal request compels us to hand over data, what we hold is encrypted content we cannot decrypt, plus the limited metadata described above. Where the law allows, we’ll tell you about a request for your data.

  19. If there’s a breach

    If someone breaks into our systems, the most they can read is the metadata described above. Your group’s content stays encrypted and unreadable. If a breach happens, we’ll post a notice in the app and on this site telling you plainly what happened and what we’re doing about it, and we’ll notify regulators where the law requires it.

  20. Security

    Fellowing’s encryption is built on our fork of Jazz, an open-source sync engine that uses proven cryptographic primitives. Our encryption page explains the architecture. If you find a vulnerability, email security@fellowing.com.

  21. This website

    fellowing.com is served by Cloudflare. The site has no accounts, sets no cookies of its own, and runs no trackers. We use Cloudflare Web Analytics, which is cookieless and doesn’t use fingerprinting, to count page visits. Nothing you do on this site is tied to an app account.

    Before launch, the site linked to a waitlist form to ask for access, hosted by Tally, where you could give us your name, email, and a few short answers. Tally stores those responses for us; we don’t sell or share them. We keep them until you ask us to delete them, or until we close the waitlist. To delete yours sooner, email legal@fellowing.com.

  22. Changes to this policy

    We’ll update this policy as Fellowing evolves. When we do, we’ll post the new version here and change the date at the top. If a change meaningfully reduces your privacy, we’ll say so in the app before it takes effect. This page lives at fellowing.com/privacy.

  23. Contact us

    For any privacy questions or requests, email legal@fellowing.com. By postal mail: Fellowing PBC, 251 Little Falls Drive, Wilmington, DE 19808.