Privacy Policy — Flock U
Effective date: August 9, 2026 · Last updated: August 17, 2026
Operator: Waterview Technologies LLC, a Missouri limited liability company
> Maintainers: this file is served publicly at /privacy by
> server/src/routes/site.ts and is the URL given to the app stores. It is a
> live legal document, not a draft — do not reintroduce a placeholder effective
> date or a "not yet published" banner into it. A published policy with a
> placeholder effective date fails CalOPPA §22575 on its face, which is exactly
> what this file did until 2026-08-09.
>
> Keep it in lockstep with the other three surfaces that state the same facts:
> the Settings → Privacy card, the Learn article "What Flock U itself collects,"
> and SECURITY.md. A change to one is a change to all four.
>
> Still pending: review by a licensed attorney.
Flock U is built so that we know as little about you as possible. This policy
describes everything the service collects, why, and what control you have. It
is written to be read; there is no fine print.
What we collect, by feature
Identity. Using Flock U requires no email, phone number, or name — your
first launch creates an anonymous account identified only by a random token.
If you choose to create a named account, we store a handle you invent and a
one-way cryptographic hash of your passphrase. There is deliberately no place
in our database for real-world identity.
Routes and address searches. Answered on demand and not stored. We do not
retain origins, destinations, searched addresses, route geometry, or the map
areas you look at, and none of them are ever written to logs with any
identifier. The only routing record we keep is an aggregate daily counter —
how many routes were planned and how many cameras were avoided, attached to no
account. Address searches are forwarded by our server to the OpenStreetMap
Nominatim geocoding service without your identity or IP.
Downloading the app. We count downloads of the Android build: two daily
totals, one for downloads begun and one for downloads that finished. That is
the whole record. No IP address, no device or browser identifier, and no row
per download are stored, so the counter cannot be turned back into a list of
who installed the app or when any particular person did.
Installing the app. The first time the app is launched after a fresh
install it tells our server "one install happened", along with which platform
(Android or iOS), which store it came from (our website or Google Play) and
the app version. Nothing else — no device identifier, no account, no IP is
recorded with it; the server adds one to a daily count. Updating an existing
install does not send this.
Visiting the website. We count page views on waterviewtechnologies.com and
an estimate of unique visitors, per page, per day. To tell repeat visits apart
within a day without keeping any identifier, our server hashes the connection
address together with the browser's User-Agent string using a random key that
exists only in the server's memory and is replaced each day (UTC) and whenever
the server restarts; only the resulting count is written down. No IP address,
no browser identifier and no page-by-page trail is stored in our database, and
there is no row per visit — only daily totals — so nothing we hold can be
turned back into who visited or what they read. (The operational request log
described under Server logs holds path and status only.) Crawlers and
monitors that identify themselves, including our own uptime monitor, are
excluded. We run no third-party analytics scripts and set no analytics
cookies. Note that Cloudflare, which fronts the site (see *Who else sees
anything*), sees each connection as any network provider does.
Camera reports. When you publish a camera to the map, we store the
camera's location — not yours. The camera record has no reporter field
(migration 0004 removed it), so a newly published camera is not linked to your
account. It becomes part of a public, openly licensed dataset (ODbL) and is
permanent by design.
One exception, stated because it is easy to miss: if your report lands within
25 metres of a camera we already have, we treat it as a **confirmation of that
camera rather than a new record** — and a confirmation is a vote, with
everything the next section says about votes. In a well-mapped area this is the
common outcome, not a rare one. If you do not want to leave a vote row, do not
re-report a camera that is already on the map.
Votes. Confirm/flag votes are recorded against your account. That is
deliberate: one vote per person per camera is what keeps a handful of
throwaway accounts from erasing real cameras. Stated plainly, because it is
the one place we hold data of this kind: a vote row is your account, a precise
camera location, and a timestamp — so your voting history is, in effect, a
list of places you have been near. Vote selectively if that matters to you.
Every vote is deleted with your account.
Maps on Android. The map view on Android is rendered by the Google Maps
SDK, so Google receives your device's map activity there as it would in any
app built on their maps. That exchange is between your device and Google; it
never passes through our server and we receive nothing from it. Moving to an
open map renderer is on our roadmap.
Watched areas. If you save an area to be alerted about, we store that area
(a bounding box) against your account. This is the one place we deliberately
hold a location attached to an identity, because we have to check it whenever
new camera data arrives. We store the area you chose to watch — not where you
are, and not where you have been. Deleting the area, or your account, deletes
it.
Usage counts. None. We previously stored a count of how many routes each
account had planned, in order to meter the free trial. The trial is now a
seven-day period administered by Stripe, so that counter has been removed from
our database and nothing has replaced it. We do not record how much you use the
app.
Subscriptions. Using the app requires a subscription. There is a seven-day
free trial, but a payment method is collected before it begins, and the
subscription renews automatically at $4.99 per month once the trial ends unless
you cancel first.
Payments are processed entirely by Stripe — we never see or store card details.
Our server stores Stripe's customer and subscription identifiers, your
subscription status, and your renewal date, which together are what keep your
access on.
Because payment is required to use the product at all, this is worth stating
plainly rather than leaving in the fine print: Stripe knows who you are. A
payment method carries a name, and often a billing address and an email. That
is inherent to taking money and is not something we add — but under our previous
model it applied only to users who chose to subscribe, and it now applies to
everyone. What crosses that boundary is an identifier and an amount: we never
transmit your routes, searches, watched areas, or any location to Stripe or to
any other payment processor.
Session activity. Each sign-in session records when it was last used. This
is a single timestamp per session — when, not what — kept so expired
sessions can be cleaned up and a stolen token does not live forever. It is never
joined to routes, searches, or locations, because those are not stored to join
it to.
Terms acceptance. The version of the Terms you accepted and when.
News. Headlines in the News tab are fetched by our server from public
feeds and cached; your device requests them only from us, and no reading
history is kept.
Server logs. Standard operational logs record request paths and status
codes for reliability and abuse response. They never include query strings or
request bodies — a map query is a location, so we structurally exclude it —
and they are not tied to accounts.
What we do NOT do
- No advertising, no analytics SDKs, no attribution or fingerprinting
libraries — the app's dependency list is short and contains none. (The
Android map SDK above is Google's and is disclosed rather than counted as an
exception.)
- We never sell, rent, or trade your personal information, and we do not
share it for cross-context behavioral advertising. We have never done either
and have no plans to. We do use a small number of service providers who
process data strictly on our instructions and for no purpose of their own —
they are named under "Who else sees anything," below. Notably, the free-text
label you give a watched area travels to the push services that deliver
the alert, so name areas accordingly.
- No route or search history — we never record where you went, where you
asked to go, what you typed into the address bar, or what part of the map you
looked at. We should not claim we hold no location data at all, though: we
hold two kinds, and we name them above rather than hide them behind this line
— your votes, and any watched areas you save.
- No reading of contacts, photos, or anything else beyond the location
permission you explicitly grant for map centering and navigation (used live,
never stored).
Who else sees anything
We use five external services. None is an advertiser, a data broker, or an
analytics vendor, and none receives data for its own purposes.
| Service | What it receives | Why |
| --- | --- | --- |
| Stripe / Google Play Billing | Your name, billing details and card — you give these to the payment provider directly. We send an account identifier and an amount. | To take payment. We never receive your card number and never send a location. |
| Google (Maps SDK for Android) | The map activity of your device — the tiles it requests and the area it displays. This is between your device and Google and never passes through our server. | To draw the map on Android. Replacing it with an open renderer is on the roadmap. |
| Expo push service, then Google FCM | Your device's push token and the text of each notification — which contains the label you gave a watched area. | To deliver watched-area alerts and trial-ending reminders. |
| OpenStreetMap Nominatim | The address text you type into search. Our server makes the request for you, so Nominatim never sees your IP address or any identifier for you. | To turn an address into coordinates. |
| Cloudflare | Every connection to our website and API passes through Cloudflare's network on its way to our server, so Cloudflare sees your IP address, browser and the URL requested — the same things any network provider on the path sees. Cloudflare provides its own aggregate traffic figures to us; we have not enabled its browser-side analytics script. | To reach our server over an encrypted tunnel, absorb abusive traffic, and cache the app download near you. |
How long we keep things
| What | How long |
| --- | --- |
| Your account record | Until you delete it |
| Session tokens (hashed) | 90 days, then deleted automatically; deleted immediately when you log out |
| Abuse-prevention counters | 48 hours |
| Confirm/flag votes | Until you delete your account |
| Watched areas and their labels | Until you delete the area, or your account |
| Push tokens | Until your device unregisters, you delete your account, or the push service reports the install is gone |
| Subscription status and identifiers | Until you delete your account |
| Terms-acceptance and renewal-consent records | Until you delete your account, and in any case at least 3 years — these are the record of what you agreed to and when |
| Camera locations you published | Permanent and public. They carry no link to you |
| Daily route, download, install and website-visit counters | Permanent. They are counters with no account column |
We state these plainly rather than saying "as long as necessary," which means
nothing. Where the table says "until you delete your account," that is a real
statement: no job expires it, and you are the one who ends it.
Your privacy rights
Some U.S. state privacy laws give residents specific rights, and whether a
given law formally applies to a company our size depends on thresholds we do
not currently meet. We would rather honor these rights for everyone than argue
about jurisdiction, so the following applies to every user regardless of where
you live.
- Know and access — ask for a copy of everything we hold about your
account. We will respond within 45 days.
- Delete — delete your account and its data at any time from Settings, or
ask us to do it.
- Correct — ask us to fix anything inaccurate. In practice the only
correctable fields are your handle and your watched-area labels, both of
which you can edit yourself.
- Opt out of sale, sharing, or targeted advertising — there is nothing to
opt out of. We do not sell personal information, we do not share it for
cross-context behavioral advertising, and we do not profile you. That is a
design decision, not a setting.
- Limit the use of sensitive personal information — the only sensitive
category we hold is precise geolocation, in your votes and watched areas. We
use it solely to run the features you asked for, never to infer
characteristics about you.
- Non-discrimination — exercising any of these rights will never change
your price, your access, or the quality of the service.
How to make a request. Email the address below with your account handle. We
verify a request by asking you to send it from the app while signed in, or to
confirm a detail only the account holder would know — we deliberately hold no
email address or phone number to verify against, which is a consequence of
collecting so little. If we say no, you may appeal by replying with the word
"appeal"; we will review and answer within 60 days with our reasons.
Your controls
- Delete your account in Settings at any time. This permanently removes,
from our systems: your account record, every session, every vote, every
watched area and its label, every push token, your terms-acceptance and
consent records, and your subscription record. Deleting your account **also
cancels your subscription** so you are not charged again. There is no
soft-delete and no recovery. Published camera locations remain on the public
map — they were never connected to you.
If we cannot reach the payment processor to cancel at that moment, the app
tells you so and asks you to email us; we will cancel it and refund anything
charged after the deletion. Your payment provider keeps its own record of you
as a customer for as long as its financial-recordkeeping obligations require;
that record is governed by their privacy policy, and we will pass a deletion
request on to them if you ask.
- Location permission can be denied or revoked in your OS settings; the
map and all data remain usable without it.
Disclosure
We disclose information only when compelled by valid legal process, or where
disclosure is necessary to protect our rights or someone's safety. We will not
disclose voluntarily, and we will notify you of a legal demand for your data
unless we are legally prohibited from doing so.
Because of the design above, what exists to disclose about an individual user
is: a handle and a passphrase hash; that account's **vote rows, each of which
is a precise camera location with a timestamp**; its watched areas and their
labels; its push tokens; its subscription status; and its terms-acceptance
dates. Payment and identity records live with the payment provider and would
have to be sought from them.
What does not exist, and cannot be produced under any order, is route history,
destination history, address-search history, or map-viewport history. None of
it is recorded, so there is nothing to compel.
Security, and what happens if we get it wrong
Passphrases are hashed with scrypt and never stored or transmitted in
plaintext. Session tokens exist on our servers only as SHA-256 hashes, so a
stolen database cannot be replayed as a live login. Traffic is encrypted in
transit. Our logs record the path of a request and nothing else — no query
strings, no bodies, no headers, no IP addresses — because a map query is a
location. Full technical detail, including our known gaps, is in
docs/SECURITY.md; we publish the gaps as well as the controls.
No system is perfectly secure. If we discover a breach affecting your data we
will notify you without unreasonable delay and within the time your state's law
requires, tell you what was taken, what we have done, and what you should do,
and notify the relevant Attorney General where required. We will not wait for a
finished investigation to tell you something happened.
Notice for California residents
Do Not Track. There is no common standard for honoring the signal, and we
do not track you across sites or services in the first place, so there is
nothing for it to change.
Third-party tracking. We allow no third party to collect personal
information about your activity across different websites or services through
our app. We use no advertising, analytics, or attribution SDKs.
Categories. In the twelve months before the date of this policy we
collected: identifiers (an account handle, an internal account id, a payment
customer id, a push token); commercial information (subscription status and
history); geolocation data (your votes and watched areas, plus live location
processed in-request and not retained); and other user-generated content (camera
reports and watched-area labels you write). We disclosed these to service
providers only, for the purposes in the table above. **We sold and shared none
of it.**
Children
The Service is for adults. Our Terms require you to be at least 18, or the age
of majority where you live, and a valid payment method is required to use the
Service at all. Flock U is not directed to children under 13, we do not
knowingly collect personal information from children under 13, and nothing in
the app is designed to appeal to children. If we learn that we hold information
from a child under 13 we will delete the account and its data promptly.
Changes
Material changes to this policy will be posted here with a new effective date,
and in-app claims will be updated in the same release.
Contact
Questions about this policy, or a request to delete data we hold about you:
If you find a place where our practice does not match this policy, tell us at
that address. We will correct the practice or the policy, whichever is wrong.
Flock U is operated by Waterview Technologies LLC (Missouri, USA).
*Maintainer note: the technical enforcement of each claim above is documented
in SECURITY.md (log serializer, schema minimalism, aggregate-only
route_metrics, hashed tokens, deletion cascade). If code changes make any
sentence here untrue, treat it as a release blocker — under this product's own
identity, a false privacy claim is a core product failure (ROADMAP §Product
identity, P0.A4).*