Courtesy translation: only the French version is legally binding.
Version 2026-07-24 — in force from 2026-07-24
This policy explains which personal data FLICK processes, why, on what legal basis, with whom it is shared, how long it is retained and which rights you may exercise. It is written in plain language, in accordance with Articles 12 and 13 of the General Data Protection Regulation (GDPR).
FLICK is designed on the principle of minimisation: the service has been architected to see as little of your data as possible. Your messages are end-to-end encrypted and we cannot read them; your exact location is never stored; there is no advertising network and no third-party audience-measurement tool.
1. Data controller
The controller of your data is:
[À COMPLÉTER — dénomination du responsable de traitement] ([À COMPLÉTER — forme juridique])
[À COMPLÉTER — adresse postale]
Privacy contact: [À COMPLÉTER — e-mail de contact vie privée]
Data protection officer: [À COMPLÉTER — contact du DPO, ou « non applicable »]
For any question relating to your data or to exercise your rights, write to [À COMPLÉTER — e-mail de contact vie privée].
2. A special category of data: your sexual orientation
FLICK is aimed at the LGBTQ+ community. The mere fact of holding an account, together with certain profile fields you choose to complete (orientation, "position", type of relationship sought), constitutes data revealing your sexual orientation and your sex life. This is sensitive data within the meaning of Article 9 GDPR, which enjoys enhanced protection.
We process this data only on the basis of your explicit consent, obtained when the account is created via a dedicated tick-box, separate from acceptance of the general terms of use. This consent is set out in detail in the document "Consent to the processing of sensitive data".
You may withdraw this consent at any time: by removing the relevant tags from your profile, or by deleting your account. Withdrawal does not affect the lawfulness of processing carried out before it.
3. What data do we process?
Data you provide to us
- Account: email address, password (stored only in a hashed and irreversible form — we never know your password in plaintext), username.
- Age: you state your age (18 minimum). We do not keep your real date of birth: an approximate date is derived from the age you declare, for the sole purpose of keeping your displayed age accurate over time.
- Profile: display name, biography, photos, and tags (orientation, body type, what you are looking for, etc.) — all optional, except those required at sign-up.
- Content: messages and media (end-to-end encrypted — see section 4), posts and comments in communities, reports you submit.
Data generated by your use of the service
- Approximate location: the app degrades your location directly on your phone (to about 100 metres) before any transmission, then our servers reduce it further to a grid of about 500 metres. Your exact location is never transmitted or stored. Location is read only when the app is open (never in the background); if you disable location, your position is erased from our servers.
- Notification token provided by the Google notifications service (Firebase), to wake your device when a message arrives.
- Technical operating metadata: connection timestamps, message delivery statuses (sent, delivered, read), and technical security logs containing your IP address (see section 7).
- Anonymous error reports, unless you have disabled them (see section 6).
Data we do NOT process
Exact GPS position; the content of your private messages and media (technically unreadable to us); health data; your phone's contacts; advertising identifiers. No data is transmitted to advertising networks, data brokers or third-party audience-analysis tools.
4. End-to-end encryption
Your private messages and media are encrypted on your device using the Signal protocol and can be decrypted only by their recipient. Our servers relay only unreadable content; they retain only routing metadata (sender, recipient, timestamps, delivery status), deleted no later than 30 days after sending. Encrypted ephemeral media are deleted no later than 24 hours after being uploaded.
As a result, we can neither read, restore nor export the content of your conversations: it exists only on the correspondents' devices.
5. Why and on what legal bases?
- Providing the service (account, profile, discovery by proximity, messaging, communities) — performance of the contract between us (Article 6(1)(b)).
- Processing data revealing your orientation or your sex life — your explicit consent (Article 9(2)(a)).
- Sending you operating notifications (new messages) — performance of the contract and permission from your operating system.
- Sending you service news ("FLICK News") — your consent (an option disabled by default, which can be enabled in the settings).
- Producing anonymous error reports — our legitimate interest in improving the reliability of the app (can be disabled at any time).
- Ensuring moderation, the prevention of abuse and fraud, and security (logs, rate limiting, protection against location triangulation) — our legitimate interest in protecting users and the service.
- Complying with our legal obligations (handling reports, responding to valid legal requests) — legal obligation (Article 6(1)(c)).
6. Anonymous error reports
In the event of a malfunction, the app may send us a technical report containing: a random installation identifier (never linked to your account), the model and system of your device, the version of the app, the network type, and the technical detail of the error automatically redacted (email addresses, tokens and contact details are removed before sending). No IP address or account identifier is associated with it. These reports are retained for 90 days. You can disable them at any time in Settings → Privacy.
7. Technical logs and security
To operate and secure the service (abuse detection, fault diagnosis, defence against attacks), our servers log incoming requests (timestamp, path, response code, IP address, account identifier). These logs never contain the content of the requests, are retained for at most 90 days, and are used for no other purpose.
8. How long do we keep your data?
- Account and profile — for as long as your account exists.
- Sign-up never completed — automatically deleted after 7 days.
- Encrypted messages (content and server metadata) — 30 days maximum.
- Encrypted ephemeral media — 24 hours maximum.
- Notification token — deleted on log-out, and automatically after 270 days without use of the app.
- Anonymous error reports — 90 days.
- Media reports — 90 days.
- Community moderation logs — 12 months maximum.
- Technical logs (IP address) — 90 days maximum.
On the deletion of your account, your profile, your photos, your encryption keys, your messages (in both directions), your posts, your community memberships and your tokens are deleted immediately from our servers. Technical logs (for at most 90 days) and certain moderation log entries may remain temporarily, without allowing you to be directly identified.
9. Who has access to your data?
- Other users: your public profile (display name, age, photos, tags, biography, approximate distance in bands, recent presence) is visible to logged-in users nearby and via search. Your messages are visible only to their recipients.
- Our team: restricted administrative access enables moderation and support (profiles, public community content, reports). It gives access neither to the content of your messages nor to your individual location.
- Our processors:
- SERVERD SAS, which hosts our servers in France.
- Google (Firebase Cloud Messaging), for the delivery of notifications: it receives your device token and wake signals with no message content. Google is certified under the EU–United States Data Privacy Framework and bound by contractual data-protection clauses; some processing takes place in the United States.
- No one else. We do not sell or rent your data. No advertising network, no data broker, no third-party analytics tool. We disclose data only where legally required (valid legal request).
10. Your rights
You have the rights of access, rectification, erasure, portability, restriction and objection, as well as the right to withdraw your consent at any time.
How to exercise them:
- Rectification: directly in the app (profile, tags, photos, password).
- Erasure: Settings → Account → Delete my account (immediate effect, see section 8); or by email if you no longer have access to the app.
- Access and portability: send a request to [À COMPLÉTER — e-mail de contact vie privée]; we will provide you with a copy of your data in a machine-readable format within one month at most.
- Withdrawal of consent to sensitive data: by removing the relevant tags from your profile, or by deleting your account.
- Objection, restriction, other requests: write to [À COMPLÉTER — e-mail de contact vie privée].
We may ask you to confirm your identity (for example from within the app, or from the email address associated with the account) before acting. Exercising these rights is free of charge, except for a manifestly unfounded or excessive request.
If you consider that your rights are not being respected, you may lodge a complaint with your data protection authority: [À COMPLÉTER — autorité de contrôle compétente], or the authority of your country of residence.
11. Security
We implement: end-to-end encryption (Signal protocol) of your conversations; TLS encryption of all communications; password hashing (Argon2); a local encrypted message database on your device; the blurring of your location from your phone onwards; the compartmentalisation and logging of administrative access; the detection of session theft. As no system is infallible, we will inform you in accordance with the law in the event of a data breach likely to result in a high risk to your rights.
12. Minimum age
FLICK is strictly reserved for people aged 18 and over. Age is declared at sign-up and checked by our servers; any account detected as belonging to a minor is deleted.
13. Transfers outside the European Union
Our servers are located in France. The only transfer outside the European Union concerns the delivery of notifications by Google (United States), governed by the Data Privacy Framework and standard contractual clauses (see section 9).
14. Storage on your device
The app stores on your device, strictly as necessary for its operation: your login tokens, your encryption keys, your encrypted message database, and your preferences (theme, language, notifications). These items are not advertising cookies and serve no tracking purpose. They are deleted when you log out or uninstall the app.
15. Changes to this policy
Any substantial change will be notified to you in the app before it comes into force, with the option to delete your account if you refuse it. The version and effective date appear at the top of this document.