Privacy · effective May 12, 2026

What we collect, why, and how to get it back.

Short answer: as little as we can; only what the product needs; never sold; never used to train ad targeting outside Coeta. Long answer below.

What we collect

Account basics (email, age verification result), what you make on Coeta (profile, photos, posts, messages, audience choices), and the device telemetry we need to keep the app running — none of which includes your email, phone, coordinates, display name, or photo URLs. The deny-list at the foundation strips those before they leave your device.

Where it lives

Server-side data sits in Postgres and Firestore in US data centers. Device-side data is encrypted at rest with a hardware-backed key — on iOS via the Secure Enclave, on Android via the Keystore. Signing out regenerates the device key.

Who we share it with

Crash reporting (Crashlytics) — opaque IDs only. Push notification delivery (APNs, FCM). Stripe for paid features. We do not share your data with advertisers, brokers, or "partners" of any kind.

Your choices

Export your data at any time from Me · settings · data. Delete your account from the same screen. Adjust audience defaults, opt out of presence, and mute per-community / per-chat / per-event from the same settings screen.

Children

Coeta is 18 and over. We use age verification at signup and do not knowingly retain data on minors. If you believe a minor is using Coeta, write privacy@coeta.io and we will act.
Placeholder copy · final wording lands before launch
Get in touch

Questions? Email legal@coeta.io — a person will reply.

About CoetaSafety + privacy