Giffy

Privacy policy

Last updated 23 September 2026.

This policy explains what Giffy collects, why it collects it, and what you can ask us to do about it. It covers the Giffy app and this website.

01 / Who we are

Giffy is run by Tehidea Ltd, a company registered in England and Wales under number 05902165, with its registered office at 86-90 Paul Street, London, England, EC2A 4NE. Tehidea Ltd decides why and how your personal data is used, which makes it the controller.

Giffy is offered worldwide. Write to [email protected] about anything on this page.

02 / Your phone number and sign-in codes

You sign in with your phone number. There are no passwords and no social login. We store your number and whether you have confirmed it. Our sign-in software needs an email address on every account, so we make one up from your number; nothing is ever sent to it.

To confirm your number we send a six-digit code by SMS through Telnyx, which receives your number and the text of the message. A code works once, expires after five minutes, and stops working after three wrong attempts.

To stop abuse we count how often a number asks for a code and how often it gets one wrong. Those counters are keyed by a one-way hash of the number, not by the number itself. We also count requests from each network address.

Each sign-in creates a session that records the network address you connected from, the user agent your device sends, a session token and an expiry. A session renews when you use it, at most once a day, and expires 90 days after its last renewal. Signing out ends it.

We need your number to open your account and let you sign in, so we process it to perform our contract with you. The counters rest on our legitimate interest in keeping accounts secure.

03 / Your profile

Your profile holds your phone number, a username, a display name, a profile picture if you add one, any badge you have earned, your early adopter number if you have one, and your subscription tier.

Your public profile is your username, display name, profile picture and badge. Other people see it; they never see your phone number from us.

04 / Contacts lookup

If you allow it, the app reads the names and phone numbers in your address book. The names stay on your device. The numbers are sent to us as they are, not hashed, so we can tell you which of your contacts have an account.

We compare the numbers with the numbers of existing accounts and send back the public profile of each match. We do not store the numbers you send or keep a copy of your address book.

This works the other way too. Anyone who has your phone number in their address book can learn that it has an account and see your username, display name and profile picture.

If you invite someone by phone number, the invite keeps that number. It is deleted when you delete your account.

The people in your address book have not agreed to any of this, so we use their numbers only to answer your question. We rely on our legitimate interest, and yours, in finding people you already know. You can refuse or withdraw the contacts permission in your device settings at any time.

05 / Content you send and receive

We store the content you send and receive, or a link to where it is hosted, with who sent it, the conversation it belongs to and when.

We also store the conversations you take part in, their names, who else is in them and what role each person has, the things you choose to save, and the settings you choose, such as the people you block.

The people in a conversation can see what is sent to it. We process all of this to perform our contract with you: delivering it is the service.

You can delete anything you sent. A conversation's owner can delete the conversation, which deletes everything in it. Everything else stays until you delete your account.

06 / Profile pictures

A profile picture is a JPEG, PNG or WebP file of up to 5 MB that you upload. We store it in object storage on our own servers, and other people see it through links that expire.

When you upload a new picture or delete your account, we delete the old file. If that deletion fails, the file stays in storage until we find it and remove it.

07 / Push notifications

If you allow notifications, the app gets a push token from Expo and we store it with your profile. When someone sends you something, we send your token, the sender's display name, the conversation's name if it has one, and a fixed line of text to the Expo push service, which passes the notification to Apple or Google to deliver. A notification never carries the content itself.

We remove the token when you sign out, if your device can reach us at that moment, and when you delete your account. You can turn notifications off in your device settings at any time.

08 / Purchases

Subscriptions are sold through the Apple App Store or Google Play and managed by RevenueCat. Apple or Google take the payment, so your card details never reach us.

The app identifies you to RevenueCat by your account id. When a subscription starts, renews or ends, RevenueCat tells us, and we store your tier on your profile and a record of each event: its id, its type, when it happened and your account id. Those event records are not deleted with your account.

We process this to perform our contract with you. Apple, Google and RevenueCat keep their own purchase records under their own privacy policies.

09 / Search

Search in the app uses a third-party search provider. What you search for goes from your device straight to that provider, with the network details of your device; it does not pass through us. The provider handles it under its own privacy policy.

10 / This website

We set no cookies on this website. Cloudflare, which carries every request to it, may set a strictly necessary security cookie if it decides to challenge your traffic.

We count page views with Umami, which runs on our own servers, so the numbers go to no analytics company. Umami sets no cookies and stores nothing on your device.

It records the page you read, its title, the site that sent you, and the screen size and language your device reports. From each request it also works out your browser, operating system, device type and approximate location. It drops the query string and the fragment from every address before recording it, it runs only on our own domains, and it honours your browser's Do Not Track setting.

It builds no profile of you and feeds no advertising network. We rely on our legitimate interest in knowing which pages are read. The app runs no analytics.

11 / Reports

You can report a person, or something they sent you. A report holds who filed it, who it is about, what was reported, a copy of the reported content, the reason chosen, and up to 500 characters the reporter wrote. We log only a report's id, its reason and what kind of thing it is about.

A report stays when an account it refers to is deleted. When the account that filed it is deleted, the report no longer says who filed it; when the account it is about is deleted, it no longer says who it was about. It keeps the reason, the details and the copied content.

Otherwise deleting your account would be how you erase the evidence against it. Both app stores require a way to report abuse and expect someone to act on a report within 24 hours; a report that vanishes when its subject leaves cannot be acted on. What survives names nobody.

That holds for the accounts: a report keeps no link to a deleted account. It still names whoever has not deleted theirs, and the copied content or the details the reporter wrote may themselves name or identify someone.

Once a report has been reviewed or dismissed, we delete it 90 days later. A report that is still open is kept until someone decides it.

We rely on our legitimate interest in keeping people safe, and on the duty the app stores place on us to act on abuse.

12 / Deleting your account

You can delete your account in the app. It happens at once and cannot be undone.

It deletes your account, your profile and profile picture, your sessions, everything you sent, your place in every conversation, the things you saved, your settings, the invites you sent, and your push token. Conversations you started stay with the people in them.

Three things stay: reports, as section 11 describes; the subscription event records in section 08; and any invite someone else sent to your phone number, which keeps your number until that person deletes their account.

13 / Who else handles your data

Every request to this website and to our servers passes through Cloudflare, which provides our DNS and a proxy in front of them and sees your IP address.

Our servers run at Hetzner in Nuremberg, Germany, managed with Dokploy. The database, the object storage and the website analytics all run on those servers, and Tehidea administers them.

Telnyx delivers sign-in codes. Expo, Apple and Google deliver push notifications. RevenueCat manages subscriptions, and Apple and Google sell them. A third-party search provider answers searches made in the app.

We do not sell your data and share none of it for advertising.

14 / Why we are allowed to use it

Most of what this page describes is how the service works, so we process it to perform our contract with you: your number, your sessions, your profile, the content you send and receive, push notifications and purchases.

Security counters, contacts lookup, reports and website statistics rest on our legitimate interest, and you can object to any of them. Reading your address book and sending you notifications also need your permission on the device, which you can withdraw in its settings.

15 / Moving data between countries

Tehidea Ltd is established in the United Kingdom. Our servers are in Germany, and Cloudflare, Telnyx, Expo and RevenueCat are United States companies, so your personal data is handled outside the country you live in.

Where a provider processes data outside the UK or the EEA, we rely on the safeguards the law requires.

Ask at [email protected] which safeguard covers a particular transfer and we will tell you.

16 / Your rights

Under the UK GDPR, and the EU GDPR if you are in the EU or the EEA, you can ask for a copy of your data, take it elsewhere in a machine-readable form, ask us to correct it, ask us to delete it, ask us to pause a particular use, object to anything we base on legitimate interest, and withdraw any consent you gave. Withdrawing consent does not undo processing that was lawful before you withdrew it.

Email [email protected] and we will answer within one month.

You can complain at any time to the Information Commissioner's Office, at ico.org.uk. If you are in the EU or the EEA, you can also complain to the data protection supervisory authority where you live or work.

17 / Children

You must be at least 13 to use Giffy. If the law where you live sets a higher age for agreeing to online services yourself, up to 16 in the European Union, you need the consent of a parent or guardian until you reach it.

We do not knowingly collect data from anyone under 13, and we delete it if we find that we have.

18 / Changes to this policy

When what we do changes, we change this page and the date at the top of it. If a change matters to you, we will say so rather than leave you to spot it.

Questions go to [email protected].