CirclesMM Privacy Policy

Effective date: August 21, 2026

CirclesMM is a small messaging app for staying in touch with people you actually know. This policy describes what data the app collects, who it goes to, and how to reach us if you want it removed. It is written in plain language. There is no fine print.

What we collect

We do not collect your location. We do not collect your contacts. We do not run analytics or tracking SDKs inside the app. We do not use advertising identifiers.

The Cloudflare bot check on the sign-up screen, described below, is not analytics and does not follow you around the app.

Bot protection at sign-up

When you tap Send Code, the app runs a bot check from Cloudflare called Turnstile before we send your verification text. Fake sign-ups cost us real money in text messages and eat the hourly limit that real people need, so we check that a real device is asking.

The check runs in a small web view inside the app. It runs on the sign-up screen and on Resend code, and nowhere else. It does not run when you submit your code, and it does not run once you are signed in.

Cloudflare's own privacy notice says Turnstile processes signals “such as client IP address, TLS Fingerprint, User-Agent Header and Sitekey and associated origin.” On top of that, the check runs small tests inside the web view — reading browser characteristics, calling browser APIs, and asking your device to solve lightweight puzzles — which Cloudflare describes as detecting “browser-quirks and human behavior.” Cloudflare does not publish a complete list of those in-browser signals. We would rather tell you that than pretend we have the full list.

Usually you will see nothing but a brief “Verifying…” on the button. Sometimes Cloudflare decides it needs more and shows you a checkbox to tick. That is Cloudflare's decision, made on their side; we do not control when it happens.

We never see any of it. Your device sends those signals to Cloudflare directly. Cloudflare tells our server only whether the check passed. We do not store the signals, and we cannot connect them to your account.

Cloudflare says it “does not have the ability to directly identify any individuals from any of the Signals Turnstile collects, including IP addresses,” and that its business is “protecting websites, not selling ads.” Cloudflare uses these signals for two things. The first is blocking bots for us, which it does on our instructions. The second is improving Turnstile's bot detection for all of its customers — and for that one, Cloudflare says it is acting for itself, not for us. That is Cloudflare's own use of the data, not ours, and you should know it happens.

Cloudflare does not publish how long it keeps these signals. We are not going to make up a number. If Cloudflare publishes one, we will put it here.

Turnstile can set a cookie called cf_clearance, but only on sites that switch on a feature called pre-clearance. We have not switched it on.

You can read Cloudflare's own notice at cloudflare.com/turnstile-privacy-policy.

Who we share it with

We do not sell your data. We do not share it with advertisers. We share data only with the service providers we need to operate the app:

These providers are bound by their own terms. They are not permitted to use your information for their own marketing.

We do not sell, rent, or share mobile opt-in information or SMS consent data with any third parties or affiliates for their marketing or promotional purposes. No mobile information collected through SMS sign-in is shared with third parties for marketing. See our SMS Terms & Conditions for the full text-message program terms.

Your choices

Children

CirclesMM is not directed to children under 13, and we do not knowingly collect data from anyone under 13. If you believe a child has signed up, email us at contact@circlesmm.com.

Data retention

We keep your data while your account exists. When you ask us to delete it, we remove it from our active systems. Backups may retain copies for a short period before they roll off.

Our backend host keeps sign-in logs, which include your IP address, for up to 24 hours.

One exception is set by law, not by us: if content is part of a report of suspected child sexual abuse material that we file with the National Center for Missing & Exploited Children, federal law requires us to preserve it — separately from the rest of the app — for at least a year (18 U.S.C. § 2258A(h)), and longer if law enforcement asks. A deletion request cannot reach that material while the matter is open.

Security

Communications between your device and our backend are encrypted in transit using HTTPS (TLS). Data stored on our backend is encrypted at rest with AES-256, including backups. On your phone, your sign-in session is stored in the device's secure hardware-backed storage (Keychain on iOS, Keystore on Android), not in plain app data.

We do not encrypt messages end-to-end in this version of the app; that means we (and our backend provider) can technically read message contents on the server. We do not access them as a matter of practice, but you should treat the service accordingly.

Changes

If we change this policy in a meaningful way, we will update the effective date at the top of this page.

Contact

Questions, requests, or concerns: contact@circlesmm.com

SMS terms

The full terms for the CirclesMM text-message (SMS) verification program are published separately. See our SMS Terms & Conditions.