Funkle Fone Privacy Policy & Children's Privacy Notice
Version 2026-08-20 · Operator: Sean Ahrens · Contact: 
Mailing address & telephone (the operator's postal and phone contact under COPPA §312.4(d)(1)):

This policy explains what we collect and how we use it. It supplements the Tester Agreement (section 6)
and serves as our direct notice under the Children's Online Privacy Protection Act (COPPA), because
a Funkle Fone device may be set up for a child under 13. Whenever a child uses a device, COPPA applies
in full and this notice governs.
What we collect, and why
- Voice messages sent and received — the recording is stored only to deliver it (voice is
treated as sensitive/biometric-class data) and is deleted about 30 days after it is sent. We keep a
delivery record with no audio — sender, recipient, time, duration, and which app or device sent and
played it — for up to about a year to understand and improve the Product. We run no transcription and no
content analysis; the only processing of audio is acoustic (loudness normalization and the waveform display).
- A first name — the display identity contacts see. Connecting uses a code that is minted on the
spot, works once, and expires; we keep no permanent "add me" code for an account.
- The contact list and connection controls — who each account may exchange messages with. Only an
account's own contacts can message it; connecting takes a single-use code that expires, and a parent can
remove any contact at any time — so strangers cannot message a device.
- Device identifiers and diagnostics (hardware id, firmware version, last check-in, connection
health) — to run the service, deliver updates, and fix problems.
- Diagnostic information (error reports from the device and the apps) — the kind of error, the
device and software version, network status codes, the account and device it happened on, and, for a
failed message, which contact it was being sent to. It carries no message audio and no message
content, is kept up to 90 days, and is used only to find and fix problems.
- Order information (buyer name, email, shipping addresses, family-contact emails/phones you
enter) — to fulfill and communicate about your order (adults only).
- An adult's sign-in (name, email address, and a password) — so a grown-up can sign in to their
account and to their Console from any phone or computer. Passwords are never stored in readable
form (they are salted and hashed, and are never logged or shown back to anyone). Children never get a
sign-in: a child's account exists only on their device.
We collect no precise location, no advertising identifiers, show no ads, and never sell
or share personal information. Wi-Fi credentials stay on the device; the server sees only an anonymous
network fingerprint. We collect no more than is reasonably necessary for a child to use the service, and a
child's participation is never conditioned on collecting more.
Children: parental consent, review, and deletion (COPPA)
A device used by a child activates only after their parent or legal guardian completes verifiable
parental consent at first setup (via our parental-verification partner). The parent then holds a
Console, which they open with their own email and password, where they can: review what is collected;
approve or remove every contact; report a problem; ask us for (and withdraw) time-boxed support access;
revoke consent and delete the child's account and all its data at any time. Consent can also be exercised, reviewed,
or revoked by emailing
. If consent is not given, the device does not activate and no
child data is collected. The companion apps and website are for adults only.
Who can listen
Messages travel encrypted in transit (HTTPS) and are stored encrypted at rest (AES-256) on
our infrastructure. They are readable server-side for delivery (not end-to-end encrypted), but no person
at Funkle Fone accesses or listens to messages unless (a) the account holder or parent grants
time-boxed (72-hour), logged support access by asking us for it, or (b) a
specific safety/abuse report or legal obligation requires review — each such access is recorded in an audit
log.
Processors we use
Cloudflare (hosting, storage, and the database that holds messages and order records),
Stripe (payment processing — card details never reach us), Expo push services / Apple / Google
(delivery of new-message notifications to companion apps), and our parental-verification partner
(Kids Web Services) for the consent step. Each receives only what its function requires.
Retention schedule & deletion
- Voice recordings: deleted automatically ~30 days after they are sent, listened to or not.
This window is fixed. Deleted immediately when an account is deleted.
- Message delivery records (no audio): the record of each message — sender, recipient, time,
duration, and which app or device sent and played it — is kept up to about a year to understand and
improve the Product, then deleted. It contains no recording and no message content, and is deleted
immediately when an account is deleted.
- Keepsakes (opt-in): a parent may choose, per conversation, to keep those messages as
keepsakes past the normal window. This is a deliberate, disclosed, revocable choice (it takes
effect only when both parties opt in); turning it off, or deleting the account, lets the messages be
deleted. It is never the default.
- Diagnostic information (error reports — error kind, device and software version, network status
codes): deleted automatically after 90 days. It contains no recording and no message content.
- Account data (name, codes, contacts): kept while the account is active; deleted on account
deletion (self-serve in the Console, or by email).
- Consent records and audit logs: retained as legal proof of the consent lifecycle.
- Order records: retained as required for tax/commercial obligations.
Nothing is retained indefinitely by default. You may request deletion of any of your (or your child's)
data at any time at
; we will delete it within a reasonable period except where retention
is legally required.
Your responsibility
Because the Product records voice, you are responsible for obtaining the consent of everyone whose voice
may be captured, including people at any address you order for (see Tester Agreement section 6). If you buy
for a child in another household, that child's own parent/guardian completes the consent step at setup.