Flock U

Privacy Policy — Flock U

Effective date: August 9, 2026 · Last updated: August 17, 2026

Operator: Waterview Technologies LLC, a Missouri limited liability company

> Maintainers: this file is served publicly at /privacy by

> server/src/routes/site.ts and is the URL given to the app stores. It is a

> live legal document, not a draft — do not reintroduce a placeholder effective

> date or a "not yet published" banner into it. A published policy with a

> placeholder effective date fails CalOPPA §22575 on its face, which is exactly

> what this file did until 2026-08-09.

>

> Keep it in lockstep with the other three surfaces that state the same facts:

> the Settings → Privacy card, the Learn article "What Flock U itself collects,"

> and SECURITY.md. A change to one is a change to all four.

>

> Still pending: review by a licensed attorney.


Flock U is built so that we know as little about you as possible. This policy

describes everything the service collects, why, and what control you have. It

is written to be read; there is no fine print.

What we collect, by feature

Identity. Using Flock U requires no email, phone number, or name — your

first launch creates an anonymous account identified only by a random token.

If you choose to create a named account, we store a handle you invent and a

one-way cryptographic hash of your passphrase. There is deliberately no place

in our database for real-world identity.

Routes and address searches. Answered on demand and not stored. We do not

retain origins, destinations, searched addresses, route geometry, or the map

areas you look at, and none of them are ever written to logs with any

identifier. The only routing record we keep is an aggregate daily counter —

how many routes were planned and how many cameras were avoided, attached to no

account. Address searches are forwarded by our server to the OpenStreetMap

Nominatim geocoding service without your identity or IP.

Downloading the app. We count downloads of the Android build: two daily

totals, one for downloads begun and one for downloads that finished. That is

the whole record. No IP address, no device or browser identifier, and no row

per download are stored, so the counter cannot be turned back into a list of

who installed the app or when any particular person did.

Installing the app. The first time the app is launched after a fresh

install it tells our server "one install happened", along with which platform

(Android or iOS), which store it came from (our website or Google Play) and

the app version. Nothing else — no device identifier, no account, no IP is

recorded with it; the server adds one to a daily count. Updating an existing

install does not send this.

Visiting the website. We count page views on waterviewtechnologies.com and

an estimate of unique visitors, per page, per day. To tell repeat visits apart

within a day without keeping any identifier, our server hashes the connection

address together with the browser's User-Agent string using a random key that

exists only in the server's memory and is replaced each day (UTC) and whenever

the server restarts; only the resulting count is written down. No IP address,

no browser identifier and no page-by-page trail is stored in our database, and

there is no row per visit — only daily totals — so nothing we hold can be

turned back into who visited or what they read. (The operational request log

described under Server logs holds path and status only.) Crawlers and

monitors that identify themselves, including our own uptime monitor, are

excluded. We run no third-party analytics scripts and set no analytics

cookies. Note that Cloudflare, which fronts the site (see *Who else sees

anything*), sees each connection as any network provider does.

Camera reports. When you publish a camera to the map, we store the

camera's location — not yours. The camera record has no reporter field

(migration 0004 removed it), so a newly published camera is not linked to your

account. It becomes part of a public, openly licensed dataset (ODbL) and is

permanent by design.

One exception, stated because it is easy to miss: if your report lands within

25 metres of a camera we already have, we treat it as a **confirmation of that

camera rather than a new record** — and a confirmation is a vote, with

everything the next section says about votes. In a well-mapped area this is the

common outcome, not a rare one. If you do not want to leave a vote row, do not

re-report a camera that is already on the map.

Votes. Confirm/flag votes are recorded against your account. That is

deliberate: one vote per person per camera is what keeps a handful of

throwaway accounts from erasing real cameras. Stated plainly, because it is

the one place we hold data of this kind: a vote row is your account, a precise

camera location, and a timestamp — so your voting history is, in effect, a

list of places you have been near. Vote selectively if that matters to you.

Every vote is deleted with your account.

Maps on Android. The map view on Android is rendered by the Google Maps

SDK, so Google receives your device's map activity there as it would in any

app built on their maps. That exchange is between your device and Google; it

never passes through our server and we receive nothing from it. Moving to an

open map renderer is on our roadmap.

Watched areas. If you save an area to be alerted about, we store that area

(a bounding box) against your account. This is the one place we deliberately

hold a location attached to an identity, because we have to check it whenever

new camera data arrives. We store the area you chose to watch — not where you

are, and not where you have been. Deleting the area, or your account, deletes

it.

Usage counts. None. We previously stored a count of how many routes each

account had planned, in order to meter the free trial. The trial is now a

seven-day period administered by Stripe, so that counter has been removed from

our database and nothing has replaced it. We do not record how much you use the

app.

Subscriptions. Using the app requires a subscription. There is a seven-day

free trial, but a payment method is collected before it begins, and the

subscription renews automatically at $4.99 per month once the trial ends unless

you cancel first.

Payments are processed entirely by Stripe — we never see or store card details.

Our server stores Stripe's customer and subscription identifiers, your

subscription status, and your renewal date, which together are what keep your

access on.

Because payment is required to use the product at all, this is worth stating

plainly rather than leaving in the fine print: Stripe knows who you are. A

payment method carries a name, and often a billing address and an email. That

is inherent to taking money and is not something we add — but under our previous

model it applied only to users who chose to subscribe, and it now applies to

everyone. What crosses that boundary is an identifier and an amount: we never

transmit your routes, searches, watched areas, or any location to Stripe or to

any other payment processor.

Session activity. Each sign-in session records when it was last used. This

is a single timestamp per session — when, not what — kept so expired

sessions can be cleaned up and a stolen token does not live forever. It is never

joined to routes, searches, or locations, because those are not stored to join

it to.

Terms acceptance. The version of the Terms you accepted and when.

News. Headlines in the News tab are fetched by our server from public

feeds and cached; your device requests them only from us, and no reading

history is kept.

Server logs. Standard operational logs record request paths and status

codes for reliability and abuse response. They never include query strings or

request bodies — a map query is a location, so we structurally exclude it —

and they are not tied to accounts.

What we do NOT do

libraries — the app's dependency list is short and contains none. (The

Android map SDK above is Google's and is disclosed rather than counted as an

exception.)

share it for cross-context behavioral advertising. We have never done either

and have no plans to. We do use a small number of service providers who

process data strictly on our instructions and for no purpose of their own —

they are named under "Who else sees anything," below. Notably, the free-text

label you give a watched area travels to the push services that deliver

the alert, so name areas accordingly.

asked to go, what you typed into the address bar, or what part of the map you

looked at. We should not claim we hold no location data at all, though: we

hold two kinds, and we name them above rather than hide them behind this line

— your votes, and any watched areas you save.

permission you explicitly grant for map centering and navigation (used live,

never stored).

Who else sees anything

We use five external services. None is an advertiser, a data broker, or an

analytics vendor, and none receives data for its own purposes.

| Service | What it receives | Why |

| --- | --- | --- |

| Stripe / Google Play Billing | Your name, billing details and card — you give these to the payment provider directly. We send an account identifier and an amount. | To take payment. We never receive your card number and never send a location. |

| Google (Maps SDK for Android) | The map activity of your device — the tiles it requests and the area it displays. This is between your device and Google and never passes through our server. | To draw the map on Android. Replacing it with an open renderer is on the roadmap. |

| Expo push service, then Google FCM | Your device's push token and the text of each notification — which contains the label you gave a watched area. | To deliver watched-area alerts and trial-ending reminders. |

| OpenStreetMap Nominatim | The address text you type into search. Our server makes the request for you, so Nominatim never sees your IP address or any identifier for you. | To turn an address into coordinates. |

| Cloudflare | Every connection to our website and API passes through Cloudflare's network on its way to our server, so Cloudflare sees your IP address, browser and the URL requested — the same things any network provider on the path sees. Cloudflare provides its own aggregate traffic figures to us; we have not enabled its browser-side analytics script. | To reach our server over an encrypted tunnel, absorb abusive traffic, and cache the app download near you. |

How long we keep things

| What | How long |

| --- | --- |

| Your account record | Until you delete it |

| Session tokens (hashed) | 90 days, then deleted automatically; deleted immediately when you log out |

| Abuse-prevention counters | 48 hours |

| Confirm/flag votes | Until you delete your account |

| Watched areas and their labels | Until you delete the area, or your account |

| Push tokens | Until your device unregisters, you delete your account, or the push service reports the install is gone |

| Subscription status and identifiers | Until you delete your account |

| Terms-acceptance and renewal-consent records | Until you delete your account, and in any case at least 3 years — these are the record of what you agreed to and when |

| Camera locations you published | Permanent and public. They carry no link to you |

| Daily route, download, install and website-visit counters | Permanent. They are counters with no account column |

We state these plainly rather than saying "as long as necessary," which means

nothing. Where the table says "until you delete your account," that is a real

statement: no job expires it, and you are the one who ends it.

Your privacy rights

Some U.S. state privacy laws give residents specific rights, and whether a

given law formally applies to a company our size depends on thresholds we do

not currently meet. We would rather honor these rights for everyone than argue

about jurisdiction, so the following applies to every user regardless of where

you live.

account. We will respond within 45 days.

ask us to do it.

correctable fields are your handle and your watched-area labels, both of

which you can edit yourself.

opt out of. We do not sell personal information, we do not share it for

cross-context behavioral advertising, and we do not profile you. That is a

design decision, not a setting.

category we hold is precise geolocation, in your votes and watched areas. We

use it solely to run the features you asked for, never to infer

characteristics about you.

your price, your access, or the quality of the service.

How to make a request. Email the address below with your account handle. We

verify a request by asking you to send it from the app while signed in, or to

confirm a detail only the account holder would know — we deliberately hold no

email address or phone number to verify against, which is a consequence of

collecting so little. If we say no, you may appeal by replying with the word

"appeal"; we will review and answer within 60 days with our reasons.

Your controls

from our systems: your account record, every session, every vote, every

watched area and its label, every push token, your terms-acceptance and

consent records, and your subscription record. Deleting your account **also

cancels your subscription** so you are not charged again. There is no

soft-delete and no recovery. Published camera locations remain on the public

map — they were never connected to you.

If we cannot reach the payment processor to cancel at that moment, the app

tells you so and asks you to email us; we will cancel it and refund anything

charged after the deletion. Your payment provider keeps its own record of you

as a customer for as long as its financial-recordkeeping obligations require;

that record is governed by their privacy policy, and we will pass a deletion

request on to them if you ask.

map and all data remain usable without it.

Disclosure

We disclose information only when compelled by valid legal process, or where

disclosure is necessary to protect our rights or someone's safety. We will not

disclose voluntarily, and we will notify you of a legal demand for your data

unless we are legally prohibited from doing so.

Because of the design above, what exists to disclose about an individual user

is: a handle and a passphrase hash; that account's **vote rows, each of which

is a precise camera location with a timestamp**; its watched areas and their

labels; its push tokens; its subscription status; and its terms-acceptance

dates. Payment and identity records live with the payment provider and would

have to be sought from them.

What does not exist, and cannot be produced under any order, is route history,

destination history, address-search history, or map-viewport history. None of

it is recorded, so there is nothing to compel.

Security, and what happens if we get it wrong

Passphrases are hashed with scrypt and never stored or transmitted in

plaintext. Session tokens exist on our servers only as SHA-256 hashes, so a

stolen database cannot be replayed as a live login. Traffic is encrypted in

transit. Our logs record the path of a request and nothing else — no query

strings, no bodies, no headers, no IP addresses — because a map query is a

location. Full technical detail, including our known gaps, is in

docs/SECURITY.md; we publish the gaps as well as the controls.

No system is perfectly secure. If we discover a breach affecting your data we

will notify you without unreasonable delay and within the time your state's law

requires, tell you what was taken, what we have done, and what you should do,

and notify the relevant Attorney General where required. We will not wait for a

finished investigation to tell you something happened.

Notice for California residents

Do Not Track. There is no common standard for honoring the signal, and we

do not track you across sites or services in the first place, so there is

nothing for it to change.

Third-party tracking. We allow no third party to collect personal

information about your activity across different websites or services through

our app. We use no advertising, analytics, or attribution SDKs.

Categories. In the twelve months before the date of this policy we

collected: identifiers (an account handle, an internal account id, a payment

customer id, a push token); commercial information (subscription status and

history); geolocation data (your votes and watched areas, plus live location

processed in-request and not retained); and other user-generated content (camera

reports and watched-area labels you write). We disclosed these to service

providers only, for the purposes in the table above. **We sold and shared none

of it.**

Children

The Service is for adults. Our Terms require you to be at least 18, or the age

of majority where you live, and a valid payment method is required to use the

Service at all. Flock U is not directed to children under 13, we do not

knowingly collect personal information from children under 13, and nothing in

the app is designed to appeal to children. If we learn that we hold information

from a child under 13 we will delete the account and its data promptly.

Changes

Material changes to this policy will be posted here with a new effective date,

and in-app claims will be updated in the same release.

Contact

Questions about this policy, or a request to delete data we hold about you:

[email protected]

If you find a place where our practice does not match this policy, tell us at

that address. We will correct the practice or the policy, whichever is wrong.

Flock U is operated by Waterview Technologies LLC (Missouri, USA).


*Maintainer note: the technical enforcement of each claim above is documented

in SECURITY.md (log serializer, schema minimalism, aggregate-only

route_metrics, hashed tokens, deletion cascade). If code changes make any

sentence here untrue, treat it as a release blocker — under this product's own

identity, a false privacy claim is a core product failure (ROADMAP §Product

identity, P0.A4).*