Legal
Privacy Policy
Last updated 7 September 2026
This policy explains what personal data Phriend collects, why, who sees it and how long we keep it. It is written to comply with the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules.
1. Who is responsible
Phriend is the personal information controller for data processed through phriend.app and web.phriend.app. Our Data Protection Officer can be reached at support@phriend.app.
2. What we collect
- Account data: the name, email address and profile photo of the Google account you sign in with, or the name, email address and password you register with (the password is stored only as a scrypt hash), plus the display name, gender, birth date and avatar you set.
- Phriend profile data: name or nickname, age, gender, city and area, languages, activities and sub-activities, non-negotiables, hourly rate, services and their prices, working hours, weekly availability and lockout dates, bio, and up to 8 photos you upload.
- Bookings, reviews, favorites, gigs and notes: the date, time, hours, place, note and status of each booking request; the reviews you write, with up to 4 photos; the profiles you favorite; the gigs you post; and your private notes, which only you can read.
- Chat messages: the messages, images and payment account details you exchange with other members. Chat is delivered through Ably, our real-time messaging provider. A message that contains listed offensive words is refused and recorded, with the matched words, for moderation.
- Identity verification data: if you verify, you submit a government ID and a selfie to Didit, our verification partner. Didit checks them and keeps the images. Phriend receives and stores Didit's decision record: the result, a session reference and the details Didit read from your ID, not the ID or selfie images.
- Device and usage data: IP address, browser and device type, pages viewed, approximate location derived from IP, crash and performance logs.
- Reports and support: the reason and up to 4 photos you attach when you report a profile or a gig, and anything you send support.
3. Why we use it
We process your data to:
- run your account and show your Phriend profile to other members (performance of our contract with you);
- deliver chat and booking requests between members;
- verify age and identity, prevent fraud, and keep minors off the Service (legal obligation and legitimate interest);
- review reports, profiles and gigs, including an automated first pass, enforce the terms and community guidelines, and cooperate with lawful requests;
- keep the Service secure and working, limit abusive request rates, and fix bugs;
- send you service emails (a welcome on first sign-in, verification results and booking updates) and in-app notifications for bookings and reviews, and announce policy changes.
We do not sell personal data and we do not use it for third-party advertising.
4. Who we share it with
We share data only with processors that help us run the Service, under contracts that limit what they can do with it:
- Google: sign-in. We receive your name, email address and profile photo from your Google account.
- Ably: real-time chat delivery.
- Didit: identity and age verification.
- OpenAI: the automated first-pass review of reports, Phriend profiles and gigs run by our moderation team.
- Upstash: request rate limiting, which keeps short-lived counters keyed by your account or IP address.
- Cloudflare R2: storage of uploaded photos.
- Neon: database hosting.
- Our email provider: delivery of account and service emails.
Other members see your profile, your Phriend profile and the messages you send them. We may also disclose data when Philippine law, a court order or a lawful law-enforcement request requires it, or to protect members' safety. Some processors store data outside the Philippines under contractual safeguards consistent with the Data Privacy Act.
5. How long we keep it
- Phriend profiles leave the feed after 30 days unless you save them again; the profile stays on your account until you delete it or your account.
- Verification data is retained only as long as needed to confirm the result and handle disputes, then deleted by Didit on our instruction.
- Account data is kept while your account is active. When you delete your account, your account, Phriend profile, photos, favorites, reviews, bookings, notes, gigs and reports are removed right away, except the moderation log, which keeps a record of any action taken on the account. Chat messages are delivered and stored by Ably under its message retention; deleting your account does not itself erase them.
- Logs are kept for up to 90 days.
6. Your rights
Under the Data Privacy Act you have the right to:
- be informed about how your data is processed;
- access the personal data we hold about you;
- correct inaccurate or outdated data;
- erase or block data that is unlawfully obtained, no longer necessary, or being misused;
- object to processing, including for direct marketing or profiling;
- data portability: obtain a copy of your data in a commonly used electronic format;
- be indemnified for damages caused by inaccurate, incomplete or unlawfully obtained data;
- file a complaint with the National Privacy Commission (privacy.gov.ph).
To exercise any of these, email support@phriend.app from the address on your account; we respond within 15 working days. You can also delete your account from your profile screen by typing DELETE.
7. Cookies
We use essential cookies (a session cookie that keeps you signed in and one that remembers your preferences) and Google Analytics 4 to count visits and see which pages are used. Analytics sets first-party _ga cookies, uses no advertising or cross-site tracking cookies, and Google does not store IP addresses. You can block it in your browser or with an extension without affecting the site.
8. Children
Phriend is for adults only. We do not knowingly allow anyone under 18 to use the Service. If you believe a minor has an account, email support@phriend.app and we will remove it.
9. Security
Data is encrypted in transit, Google sign-in never gives us a password and email passwords are stored only as scrypt hashes, production access is limited to the people who need it, and ID documents never pass through our own servers. If a breach affects you we will notify you and the National Privacy Commission as the law requires.
10. Changes and contact
We will update this policy when our practices change and show the new date at the top. Material changes are announced in the app or by email. Questions: support@phriend.app. See also our Terms of Use.