Privacy Policy

Last updated: August 2026

This policy sets out how Flint Apps (“we”, “us”, “our”) treats your information across the software we publish. We refer to each product as an “App” and to all of them collectively as the “Apps”. It governs every App we ship, except where an individual App publishes its own notice, in which case that notice controls anywhere the two disagree.

Using our Apps means you accept the practices set out below.


1. How we think about your data

Our starting position is to ask for as little as an App genuinely needs, and we do not sell personal data. A good number of our Apps run perfectly well without any account whatsoever. Where an App does require or offer one, perhaps to keep your data consistent across devices, we gather only what makes that work. Content you create is frequently processed on the device itself and never leaves it. Where an App does place your content or account details on cloud infrastructure, it is to deliver a specific feature such as sync or backup, and it is used for nothing else.


2. What we collect

a. Account details, where an App has accounts

For Apps built around an account, we hold what is necessary to create and maintain it: typically an email address, credentials, and whatever optional profile information you decide to supply. Should you sign in through a third-party provider such as Sign in with Apple, we receive only the narrow set of details that provider passes along. None of this applies to Apps that operate without accounts.

b. Content you enter

Certain Apps exist for you to write, capture, or keep things: notes, files, settings, and the like. Where that material stays local to your device, it is invisible to us. Where a feature deliberately moves it off-device, for backup or for syncing to your account, that transfer happens solely to power the feature you switched on.

c. Local preferences

Your settings generally sit on your own device in standard system storage. They do not reach us unless a feature you have enabled specifically requires it.

d. Messages to support

When you write to us, we hold onto the thread so we can actually help.

e. Data gathered automatically

f. Analytics and install attribution

We may rely on third-party services to see how an App is actually used and where it falls short. What those services receive is usage and event data, such as which screens are opened and which features are exercised, alongside anonymised technical context such as operating system version, device model, App version, and locale. This is recorded against a randomly generated identifier for your installation rather than against your name or email address, and we read it in aggregate to work out what to improve.

Most of our Apps stop there, and gauge marketing only through the aggregate reporting the app store hands us, which leans on no advertising identifier whatsoever. Certain Apps go further and measure which campaign an install came from. Those Apps present Apple's App Tracking Transparency (ATT) prompt on iOS, and only where you allow it may the Identifier for Advertisers (IDFA) be passed to our attribution provider for that purpose. On Android the Google Advertising ID fills the same role, governed by your device's ads settings. Decline, or reset or opt out of the identifier, and nothing is shared; attribution then falls back on signals that identify nobody. An App that never shows you the prompt is not using these identifiers at all.


3. Things we don't do


4. Device permissions

An App may request access to the camera, photo library, microphone, notifications, motion sensors, or the local network, but only in service of a feature you have chosen to use. We say why at the moment of asking, and declining simply means that one feature sits idle. Every permission can be granted or withdrawn later from your device Settings.


5. Storage and security

For data held on your device, security rests on your device's own defences: your passcode, biometric unlock, and disk encryption. Once a feature transmits data off the device, we apply reasonable technical and organisational safeguards to protect it both in transit and at rest. That said, no method of transmission or storage is completely secure, and we cannot offer an absolute guarantee.


6. Third-party services

A handful of outside services support the Apps operationally:

Each of these providers operates under its own privacy policy.


7. How long we keep things


8. Managing and deleting your data

To clear out what an App holds:


9. Children

Our Apps are intended for people aged 13 and over, and we do not knowingly gather personal data from anyone younger. If such data comes to our attention we delete it without delay. Parents and guardians who believe a child under 13 has provided us with information should contact us.


10. Users outside our home jurisdiction

Our Apps are built to function on your device wherever you happen to be. Where we do process limited personal data, support email being the main example, we do so consistently with applicable data-protection law, including the EU and UK General Data Protection Regulation and the California Consumer Privacy Act as amended by the California Privacy Rights Act.

a. Where your data is processed

Flint Apps operates from Singapore, and the providers described in section 6 may process data in the United States, within the European Economic Area, or in other countries where they or their own infrastructure providers operate. Personal data belonging to users in the EEA, the UK, or Switzerland may therefore be transferred outside those regions.

Where such a transfer takes place, we rely on the safeguards permitted under Chapter V of the GDPR and its UK equivalent. In practice that means one of the following, depending on the provider: the European Commission's Standard Contractual Clauses (together with the UK International Data Transfer Addendum where the UK GDPR applies), incorporated into our agreement with that provider; or the provider's certification under an adequacy decision covering its location, such as the EU to US Data Privacy Framework. We select providers that commit to a standard of protection equivalent to the one described in this policy. If you would like detail on the safeguards applying to a specific provider, ask us and we will tell you.

b. EU, UK, and EEA users (GDPR / UK GDPR)

We rely on the following legal bases:

You can withdraw consent whenever you like: revoke the relevant permission in your device Settings, change your tracking choice under Settings → Privacy & Security → Tracking on iOS, or reset or opt out of your advertising ID on Android. You are equally entitled to complain to your local supervisory authority. We have not appointed a Data Protection Officer, as we do not process personal data at a scale that triggers that requirement.

c. California residents (CCPA / CPRA)

We have not sold personal information within the meaning of the CCPA/CPRA. Where an App measures install attribution and you have allowed tracking at the ATT prompt, the IDFA and the app-event data accompanying it may be passed to our attribution provider, and the CPRA can treat that disclosure as “sharing” personal information for cross-context behavioural advertising. Apps that show no such prompt do none of this.

Opting out: decline the ATT prompt when it appears, or on Android switch off ad personalisation or reset your advertising ID. The decision can be revisited at any point under Settings → Privacy & Security → Tracking on iOS, or in your Android ads settings. With tracking disallowed, no advertising identifier is shared and attribution works only from non-identifying signals.

We neither use nor disclose sensitive personal information in ways that would create a separate CPRA opt-out right. You may ask what personal information we hold, request its deletion or correction, opt out of sharing as described, and expect no penalty for exercising any of these rights. To do so, email us from the address you would like us to verify.


11. Changes to this policy

This policy will be revised from time to time as our practices evolve or the law requires. The date at the top always reflects the current version. Anything material will be signalled in the App itself or on its store listing, and continuing to use an App after that point constitutes acceptance of the revised policy.


12. Get in touch

Flint Apps is the data controller responsible for the personal data described in this policy. Privacy questions, data requests, and anything else on this subject go to [email protected].