Privacy Policy

Last updated: Jul 10, 2026

1. Data Collected

The following personal data may be collected when using the Flompt application:

  • Email address and username
  • Profile information (name, bio, profile picture)
  • Content you create and share (prompts, comments, messages)
  • App usage data and interactions (likes, bookmarks, follows)
  • Device information (model, operating system, unique identifiers)
  • IP address and approximate location (country/city level)
  • Advertising identifiers (IDFA on iOS, GAID on Android) - only with your consent

2. Data Usage

Collected data is used for the following purposes:

  • Account creation, authentication, and session management
  • Providing personalized content recommendations in your feed
  • Enabling social features (following, messaging, notifications)
  • Improving application performance and user experience
  • Providing customer support and responding to inquiries
  • Security, fraud prevention, and abuse detection
  • Displaying advertisements (personalized or non-personalized based on your preference)
  • Analytics and statistical analysis to improve our services

3. Feed Personalization

Your "For You" feed is ranked by our recommendation algorithm using only your in-app activity. Personalization is a core part of the Flompt service and is enabled by default; the legal basis for this processing is the performance of our contract with you and our legitimate interest in providing a relevant, useful feed (GDPR Art. 6(1)(b) and (f); KVKK Art. 5(2)(c) and (f)). Signals used include:

  • Content you interact with (likes, bookmarks, comments, copies, shares)
  • Creators and topics you engage with or follow
  • How long you view content in the feed (dwell time)
  • Negative feedback you give ("see less", mute, block, report)

No third-party or cross-app tracking data is used for feed ranking. You can turn personalization off at any time in the app under Settings → Consent Preferences → Personalization (your right to object); you will then see a non-personalized feed ranked by overall popularity and freshness.

4. Data Security

The security of your personal data is our priority. We implement industry-standard security measures including: SSL/TLS encryption for all data in transit, server-side encryption for stored media, passwords hashed using Argon2 algorithm (never stored as plain text), regular security audits and vulnerability assessments, access controls and authentication mechanisms, and secure cloud infrastructure hosted in the EU (DigitalOcean, Frankfurt).

5. Third Party Services

We use the following third-party services to provide and improve our application. These services may collect and process data according to their own privacy policies:

  • RevenueCat (RevenueCat Inc., USA): Manages subscription and credit purchases made through the App Store / Google Play, processing purchase receipts and an app user identifier. Privacy Policy: https://www.revenuecat.com/privacy
  • Google AdMob (Google LLC, USA): Advertising platform that may collect advertising identifiers (IDFA/GAID), device information, and approximate location to show relevant ads. You can control personalized ads in Settings > Privacy. Privacy Policy: https://policies.google.com/privacy
  • Expo Push Notifications (650 Industries Inc., USA): Delivers push notifications using device push tokens, via Apple and Google notification services. Privacy Policy: https://expo.dev/privacy
  • Sentry (Functional Software Inc., USA): Error tracking service that collects crash reports, device information, and anonymized usage data to help us fix bugs. Privacy Policy: https://sentry.io/privacy/
  • PostHog (PostHog, Inc.; data is processed in the EU region — Frankfurt, Germany): Product analytics. While you are signed in it is active only if you enable the Analytics consent. If you browse the app without an account, devices outside the European Economic Area and the United Kingdom are measured anonymously, with no link to any account; in the EEA and the UK no such measurement takes place. If you then create an account and accept the Analytics consent, that device's earlier anonymous records are linked to your account; if you decline, they are not. Data processed: the path of screens you open, sign-up steps, sign-in and sign-out, views of the subscription or credit screen and the outcome of a purchase attempt, content publishing and AI image generation events; plus device model, operating system, app version, language, time zone, location derived from your IP address, and your subscription tier and account creation date. For signed-in users these events are linked to your account's internal identifier; while browsing without an account only a temporary per-device identifier is used. Prompt text, message content, search terms, your email address, and your username are not sent. You can turn this off in the app under Settings > Consent Preferences > Analytics. Privacy Policy: https://posthog.com/privacy
  • Resend (Resend Inc., USA): Transactional email delivery such as verification codes and account emails, processing your email address. Privacy Policy: https://resend.com/legal/privacy-policy
  • OpenAI (OpenAI, L.L.C., USA): Automated content moderation; the text of submitted prompts and comments, together with the public URLs of their images, is sent to the OpenAI moderation API before publication. These inputs are not used to train OpenAI's models. Privacy Policy: https://openai.com/policies/privacy-policy
  • Google Gemini API (Google LLC, USA): The engine behind our AI features. It is used to: (a) generate vector representations from the text of shared prompts (title, summary, body, tags) for semantic search and similar-content suggestions, and to process the search term you type in real time when you search; (b) assign invisible automatic topic labels to shared content — this step processes the content's text and up to four of its images, and content rejected in moderation is never sent; (c) generate and edit images in AI Studio — this processes the image prompt you write along with any source and mask images you upload; (d) the optional prompt improvement feature. Your user identifier, email address, and IP address are not included in these requests. Because we use the paid tier, Google does not use this content to train its models; it retains it for a limited period solely to detect abuse. Privacy Policy: https://policies.google.com/privacy — API terms: https://ai.google.dev/gemini-api/terms
  • Replicate (Replicate, Inc., USA): Runs some of the image generation and editing models in AI Studio; it processes the image prompt you write along with any source and mask images you upload, and your user identifier is not sent. Privacy Policy: https://replicate.com/privacy
  • DigitalOcean (DigitalOcean LLC): Cloud hosting and storage of user-uploaded media; data is stored in Frankfurt, Germany. Privacy Policy: https://www.digitalocean.com/legal/privacy-policy
  • Cloudflare (Cloudflare Inc., USA): Content delivery network and security; publicly visible media is cached at edge locations. Privacy Policy: https://www.cloudflare.com/privacypolicy/

We do not sell your personal data. Apart from personalized advertising via AdMob (which you can turn off in Settings > Privacy, and which may qualify as 'sharing' under some US state laws — see our Do Not Sell page), we do not share your personal data for advertising purposes. If our practices ever change, we will update this Policy in advance and ask for your consent where the law requires it. Your personal data will not be shared with other third parties except when required by law.

6. Cookies and Tracking

Our mobile application uses the following tracking technologies:

  • Local Storage: To save your preferences, authentication tokens, and app settings
  • Analytics: Product usage events to improve our service — collected only if you enable the Analytics consent, and linked to your account's internal identifier; see the Third Party Services section above for details
  • Advertising Identifiers: IDFA (iOS) and GAID (Android) for ad personalization - only with your explicit consent via App Tracking Transparency on iOS or in-app settings

You can reset your advertising identifier or opt out of personalized ads in your device settings or within the Flompt app (Settings > Privacy).

7. Data Retention

We retain your personal data for as long as necessary to provide our services:

  • Account data: Retained while your account is active and for 30 days after deletion request
  • Content you create: Retained while your account is active, permanently deleted upon account deletion
  • Messages: Retained for 1 year after last activity or until you delete them
  • Log data and analytics: Retained for 90 days for security and debugging purposes
  • Images you create with AI Studio: Kept on our servers for 7 days after they are downloaded to your device, for content-safety review, then deleted; if never downloaded, kept for at most 30 days
  • AI Studio prompts: Retained after the image is deleted, for abuse review and cost reporting
  • Backup data: Retained for 30 days before permanent deletion

You can request immediate deletion of your data by contacting us at [email protected].

8. Children's Privacy

Flompt is not intended for children under the age of 13; in the European Economic Area, if your country's digital consent age (13-16 depending on the country, per GDPR Art. 8) is higher, that age applies. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at [email protected]. We will take steps to delete such information from our servers.

9. International Data Transfers

Our primary infrastructure is hosted in the EU (Frankfurt, Germany). Some of the service providers listed in Section 5 process data in the United States. Where data leaves your jurisdiction, we ensure appropriate safeguards are in place:

  • Appropriate safeguards under applicable EU data protection law (GDPR Chapter V) for transfers from the EU/EEA
  • Appropriate safeguards under KVKK Article 9 for transfers from Turkey
  • Data Processing Agreements with all third-party service providers

These transfers rely on the safeguards above rather than on your consent. You can request more information about the safeguards we use by contacting [email protected].

10. Account and Data Deletion

You can delete your account and all associated data at any time. Here's how:

  1. Open the Flompt app on your device
  2. Go to your Profile tab (bottom right)
  3. Tap the Settings icon (gear icon in the top right)
  4. Scroll down to the 'Danger Zone' section
  5. Tap 'Delete Account'
  6. Confirm your decision by entering your password
  7. Your account and all data will be permanently deleted

When you delete your account, the following data will be permanently removed:

  • Your profile information (username, email, bio, profile picture)
  • All prompts you have created and shared
  • All comments and likes you have made
  • All messages and conversations
  • Your followers and following lists
  • All bookmarks and saved content

Data retention after deletion:

  • Account data is retained for 30 days after deletion request (for recovery purposes)
  • After 30 days, all data is permanently and irreversibly deleted
  • Backup data is purged within 30 days of account deletion

If you cannot access the app, you can also request account deletion by emailing [email protected] with your registered email address.

11. Your Rights

Under GDPR, KVKK, and applicable data protection laws, you have the following rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ('right to be forgotten')
  • Right to Restrict Processing: Request limitation of how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests or for marketing
  • Right to Withdraw Consent: Withdraw consent at any time for processing based on consent

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

12. Machine Learning and Service Improvement

When you give explicit, separate consent (Settings > Data & ML Consent), the following may be used to train and improve our recommendation and content moderation models:

  • The text and tags of prompts you publish as PUBLIC (private prompts are never used)
  • Pseudonymized interaction signals such as likes, copies, saves and dwell time
  • Pseudonymized session-level behavioral patterns (foreground sessions, app version, locale)

How we pseudonymize

Before any data reaches the ML training pipeline we replace your user ID with a pseudoId derived as HMAC-SHA256(userId, daily_salt). The salt rotates daily, which means if the salt store is breached today, prior days' pseudoIds cannot be re-derived. Pseudonymized data still counts as personal data under KVKK / GDPR — it is not anonymous — but it is significantly safer than raw identifiers.

We commit to the following:

  • Output filtering — models do not emit user prompts verbatim as their own output
  • No sale or licensing of training data to third parties
  • If we add a third-party ML subprocessor (e.g. fine-tuning provider), this Policy will be updated and your consent re-requested
  • Withdrawing consent in Settings stops all future training inclusion. Already-trained models are not retrained, but no new rows from you enter the pipeline

ML training consent is separate from feed personalization (Section 3): declining it does not affect your personalized feed — it only keeps your data out of model training. If you decline, the service still works fully for you.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page, updating the 'Last updated' date, and sending you a notification through the app. We encourage you to review this policy periodically.

14. Contact Us

If you have questions about this Privacy Policy or want to exercise your rights, contact us:

[email protected]

For Turkish users (KVKK): You may also submit requests via registered mail with a wet signature or through the e-Government portal.