Privacy policy
DRAFT — to be reviewed by a lawyer before launch. This text was drafted from what the software does today and has not been reviewed. It is not yet the agreement between you and us.
Last updated: 2026-09-29
This policy explains what personal data Flocking keeps, why, for how long, who else receives it, and what you can do about it. It covers the website at https://flocking.app, the Flocking iPhone app and the Flocking Android app, which all use the same service.
1. Who we are
The controller of your personal data is [to be completed], [to be completed], [to be completed], registered under [to be completed].
You can reach us about anything in this policy at [not set].
[to be decided by the owner: whether a data protection officer is appointed, and if so their contact details]
2. What Flocking does, in one paragraph
Flocking helps a group of friends, each with a home airport, free days and a budget, find places they can all afford and agree on one. Planning is free. Real fares from third-party fare providers are fetched only when somebody presses the button to reveal them, and are paid for with a free search or with credit in a wallet. Flocking does not sell flights; you book with an airline or booking site yourself.
3. What we keep, and why
Your account
- Email address. To sign you in, to send you the codes and emails you ask for, and to reach you about your account. It is stored in lower case. Other people cannot search for you by email address.
- Password. We never store your password. We store a one-way scrypt hash of it, which is enough to check a password you type and not enough to recover it.
- Name. Shown to the people you share trips with, to your companions, and, in first-name form, beside any destination note you publish (see below).
- Username (handle). Chosen at sign-up. It is the one thing about you another person can search for, so that they can send you a companion request.
- Profile picture, if you add one. Stored as a JPEG, PNG or WebP image of up to the size the app allows, and shown to people who see your name in the app. Anyone who has the picture's address can load it.
- Home airport and currency. Learned from the first airport you give, and changeable. Your home airport is shown to companions who have accepted your request.
- Trip email setting. Whether a trip may email you (on by default).
- Sign in with Apple or Google, if you use them. We keep the account identifier the provider gives us, the email address it gave us when the link was made, and which of our app registrations the sign-in came through. For Apple only, we also keep a refresh token, encrypted, for one purpose: to ask Apple to end the link when you close your account.
- Sign-in sessions. When you sign in we give your browser or phone a token and keep only a digest of it. A session lasts up to 90 days, or until you sign out or change your password.
- Sign-up codes and reset links. Kept as digests. A pending sign-up also holds the name, username and home airport you entered until the code is used or expires.
We keep this to provide the service you signed up for (performance of a contract, Article 6(1)(b) GDPR).
Your trips
- Trip details: the trip's name, its length, its currency, and the names written on seats before a person takes them.
- What you say about yourself in a trip: your name as you give it, the airport or airports you would leave from, your budget, and the days you are free, free at a push, or not free.
- What you do in a trip: when you joined, your likes and dislikes of each destination, your lock-in, whether you have marked your flight as booked, and when you were last active.
- Search rounds: the fares a search found, which seats they were for, and what they cost.
Who can see what. Inside a trip, members see each other's names, airports, pictures, free days, votes and lock-ins; votes are not anonymous. Budgets are private by default: each person sees their own budget and fare in full, and other people's fares only rounded to about five euros, until a member turns budget sharing on for the trip, which every member is told about by email, with that member's name. A trip's link is an address, not a password: anyone who has it can see the trip's name, the names, airports and pictures of the people in it, the destinations and, once decided, the destination and dates. They never see anybody's budget, fare, free days, votes or lock-ins. When a trip link is shared in a messaging app, the preview shows the trip's name, how many people are in it and, once decided, the destination and dates. Please share trip links with care.
We keep this to provide the service (contract, Article 6(1)(b)).
Companions
When you send or accept a companion request, we keep who asked whom, and when. A pending request tells the other person only that you asked. Once accepted, each of you can see the other's home airport. If you ask somebody by email address and that address has an account, we email them and keep the request; we never tell you whether the address has an account.
Legal basis: contract (Article 6(1)(b)).
Destination likes and notes
You can like a destination and leave a note about a visit: a rating from 1 to 5, the month you went, the weather, and up to 600 characters of text. Notes are public. Anyone, signed in or not, can read them on the destination's page, with your first name beside them. Likes are only ever shown as a count. You can delete your note at any time.
Legal basis: contract (Article 6(1)(b)); you choose to publish.
The wallet and payments
- Free searches. Each email inbox gets 1 free search for life. To enforce that, we keep a keyed hash (HMAC) of your address, normalised so that a plus-tag or dots in a Gmail address count as the same inbox. The hash is not your address and cannot be read back as one, but it lets us recognise the same inbox if it signs up again, including after an account is closed.
- The wallet: a ledger, in euros, of every top-up, every search charge and every refund.
- Purchases: for each top-up, the amount, currency, which store sold it (Stripe, the App Store or Google Play), the store's reference for the payment, and any refund or dispute.
- Holds: if a refund or chargeback takes back credit that had already been spent, we put a hold on paid searches and web top-ups for that account until we have looked at it.
Stripe, Apple and Google handle the payment itself. We never see or store your card details.
Legal bases: contract (Article 6(1)(b)) for the wallet and purchases; legal obligation (Article 6(1)(c)) for keeping accounting records; our legitimate interest (Article 6(1)(f)) in preventing abuse of the free search and of refunds, for the inbox hash and holds.
Emails
We send email through our email provider (see section 5). Emails we send:
- About your account, because you asked or because it concerns your security: sign-up codes, codes to link an Apple or Google sign-in, codes to confirm closing your account, password reset links, a notice when someone tries to sign up with your address, a notice when your password is changed, and a confirmation when your account is closed.
- About your trips: an invitation to a seat, the trip launching, being dropped from a trip you did not join in time, somebody taking their seat, the vote's ranking, the lock-in opening, the trip being decided or put back, budget sharing being turned on, and a daily reminder, for up to a week after a decision, to those who have not marked their flight booked.
- Companion requests sent to your address, no more than one a week from the same person.
- About reports (see below).
Trip emails can be turned off with one click from the link at the foot of any of them, or in your profile. Account emails cannot be turned off, because they are how you get into and protect your account.
Emails waiting to be sent are stored encrypted, and deleted once sent. An email that cannot be delivered is erased, leaving only a record of the failure without the address or content, which is kept for 7 days.
Legal bases: contract (Article 6(1)(b)) for account and trip emails; legitimate interest (Article 6(1)(f)) for security notices and companion requests.
Reports of content
Next to a picture, a name, a destination note or a trip name that somebody else wrote there is a Report button. A report keeps: what was reported and where it was shown, a copy of the content as it was when reported (including a copy of a reported picture), the reason you chose, any details you write (up to 1,000 characters), and who reported it: your account if you are signed in, or an email address if you choose to leave one when you are not. We use the address only to acknowledge the report and tell you the outcome. The person whose content you reported is not told who reported it.
When we decide a report, we record the decision, who made it, and the reason. If we remove content, we email the person it belonged to a statement of reasons. The copy of the content, the details the reporter wrote and the address a reporter who was not signed in left are kept for 180 days after the report is decided, and then erased; what remains is that a report of that kind, for that reason, was made and what we decided. A report that has not been decided yet is kept until it is.
Legal bases: legal obligation (Article 6(1)(c)) under the EU Digital Services Act, and our legitimate interest (Article 6(1)(f)) in keeping the service free of illegal and abusive content.
Usage analytics
Our analytics are first-party: nothing is sent to an analytics company, and nothing records your screen, your keystrokes or what you type.
- In the web app, your browser keeps a random visit identifier in local storage and sends us small events: which page (as a route template, without trip ids or codes), which named button was pressed, the category of an error, and page speed measurements. If you are signed in, events are filed under your account.
- You can turn this off on the landing page ("Privacy & analytics") or in your profile. Turning it off stops the events, deletes the visit identifier from your browser and stops it being sent. It applies to that browser.
- The iPhone and Android apps do not send these events.
- Separately, and whatever that setting, the server records its own events when you do things that matter to the service (signing up, signing in, creating a trip, voting, searching, topping up, and so on), with your account id and trip ids, never your email, your words or your budget. These are kept 180 days.
Legal basis: our legitimate interest (Article 6(1)(f)) in understanding how the service is used, and in keeping it working. [to be confirmed by the lawyer: whether the visit identifier kept in local storage requires prior consent under the ePrivacy rules as implemented in the relevant country, or falls within an exemption for first-party audience measurement; today analytics are on until switched off.]
Security records
For every request to our server we keep a line with the time, the route, the result, how long it took, your IP address, your browser's user agent (shortened), and your account id if you are signed in. We also record security events (refused requests, rejected payment notifications, addresses blocked and unblocked), which include the IP address. We use these to trace and stop attacks and abuse, and to keep the service running.
- The request log is deleted after 30 days.
- IP addresses are removed from security events after 30 days.
- An address we block stays on the block list for as long as the block lasts, never more than 30 days.
- Limits on how often an address may do something are counted in memory and never written down.
Legal basis: our legitimate interest (Article 6(1)(f)) in the security of the service.
The bot check
On sign-up, on the password reset page and on a first sign-in with Apple or Google, we use Cloudflare Turnstile to check that you are not an automated script. Your browser loads Cloudflare's script, and Cloudflare sees what it needs to run the check from your browser. Our server sends Cloudflare the resulting token and our secret key, nothing else: not your email address and not your IP address.
Legal basis: our legitimate interest (Article 6(1)(f)) in protecting sign-up from abuse.
Location on phones
When you choose your home airport in the iPhone or Android app, the app may ask for your approximate location to suggest the nearest airports. This is worked out on your phone, and your location is never sent to us or anyone else. You can decline and pick an airport yourself. The website does not ask for your location.
4. What we do not do
- We do not sell your personal data, and we do not share it with advertisers.
- We do not use third-party analytics or advertising trackers.
- We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. The ranking of destinations and the decision of a trip follow the group's own votes and budgets, under rules that are the same for everyone.
5. Who else receives data
We use the following service providers. Each receives only what it needs for its task.
- Hostinger (Hostinger International Ltd., Cyprus): hosts the server on which the whole service and its database run. Every category above is stored there. [to be confirmed by the owner: the data centre location of the server]
- Cloudflare (Cloudflare, Inc.): our website traffic passes through Cloudflare's network, which protects it from attacks. Cloudflare therefore handles your IP address and the requests your browser makes. Cloudflare Turnstile runs the bot check described above. [to be confirmed by the owner: that the Cloudflare proxy is switched on, and which Cloudflare entity is the contracting party]
- Off-site backup storage: a continuously updated copy of the database, including all account and trip data, is kept with an S3-compatible storage provider. [to be confirmed by the owner: the provider (for example Cloudflare R2) and that the bucket is in the EU jurisdiction]
- Resend (Resend, Inc.): sends our emails. It receives your email address, your name and the content of each email. Our sending is configured in Resend's EU region.
- Stripe (Stripe Payments Europe, Ltd. [to be confirmed]): processes web top-ups. When you top up on the web we send Stripe your account id, your email address and the top-up amount; Stripe collects your card details directly, and a billing address if tax is calculated at checkout. Stripe tells us whether the payment succeeded and about any refund or dispute. Stripe is also a controller of the data it collects for its own legal obligations; see its privacy policy.
- Apple: if you sign in with Apple, Apple tells us your account identifier and email address (which may be an Apple relay address). When you close your account we ask Apple to revoke the link. If you top up in the iPhone app, Apple processes the payment; each purchase carries an opaque identifier derived from your account id, never your email address. If you ask Apple for a refund, Apple asks us whether the credit was delivered and used, and we answer with that identifier, whether the credit was delivered, how much of it is still in your wallet, whether your account is still open, and whether we think a refund should be granted.
- Google: if you sign in with Google, Google tells us your account identifier and email address. If you top up in the Android app, Google Play processes the payment, and we ask Google about the purchase to credit it; the purchase carries the same opaque identifier, never your email address.
- Wikipedia and Wikimedia (Wikimedia Foundation, Inc.) and Open-Meteo: the descriptions, photographs and past weather shown beside a destination come from Wikipedia, Wikimedia Commons and Open-Meteo's historical weather service. Our server fetches them and passes them on; your browser or phone never contacts these services itself, so they receive no information about you — only our server's address and the name, coordinates and dates of the place being looked at. If you follow a link to one of them (a photograph's credit, for example), your device then visits it like any other website.
- Booking sites: a real fare links to the same search on Aviasales. When you follow it, you leave Flocking and Aviasales' own privacy policy applies. The link carries the route, dates, currency and, when set, our partner marker (see our terms); it carries nothing about you.
Services that receive no personal data from us: the fare providers SerpAPI (which searches Google Flights for us) and Travelpayouts receive airports, dates and currencies, never names, budgets or anything else about the people in a trip. OpenSky Network, which supplies the aircraft positions on the globe, is asked by our server with no data about anyone.
We may also disclose data when the law requires it, for example to a court or authority with a valid order, and to our professional advisers under a duty of confidence.
6. Transfers outside the EU
Some of the providers above are established in, or may access data from, countries outside the European Economic Area, in particular the United States (Cloudflare, Resend, Stripe's group, Apple, Google, the Wikimedia Foundation). Where that is the case, the transfer relies on [to be confirmed for each provider: the EU–US Data Privacy Framework, the European Commission's standard contractual clauses, or another mechanism under Chapter V GDPR]. You can ask us for a copy of the relevant safeguards at [not set].
7. How long we keep it
- Your account, profile, companions, likes, notes and Apple or Google links: until you close your account.
- Sessions: up to 90 days, or until you sign out.
- Sign-up codes and reset links: until used or expired, then one more day.
- Your part of a trip (your name, airports, budget, free days, votes, lock-in): until you leave the trip or close your account. A trip is deleted when its last member leaves. Seats nobody took when the joining clock ran out are dropped.
- Wallet, purchases and search charges: kept after you close your account, as the business's accounting records, under a random reference that no longer says whose they were. [to be decided by the owner, with the lawyer: the retention period for these records, e.g. the statutory period for accounting documents; the software currently keeps them without a limit]
- The free-search record (the keyed hash of your inbox) and any hold after a refund or chargeback (kept with the same kind of hash): kept after your account is closed, so that closing and reopening an account does not create a new free search or clear a hold. [to be decided by the owner: a retention limit; none is set today]
- Emails waiting to be sent: until sent; failure records without address or content, 7 days.
- Reports: the copy of the content, the reporter's words and a reporter's address, 180 days after the report is decided; the record that a report was made and how it was decided, [to be decided by the owner: how long].
- Request log and IP addresses: 30 days.
- Server and analytics events: 180 days. They are not deleted when an account is closed, but they carry only ids, never your email address or anything you wrote.
- Backups: copies of the database are kept for about 14 days and then replaced. They are used only to recover the service after a failure, never to bring back an account that was closed.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectification of data that is wrong (most of it you can change yourself in your profile and your trips);
- erasure: you can close your account yourself, on the web in your profile and in the apps under You, Delete account. This removes your account, sessions, companions, profile picture, likes, notes, Apple or Google links, and your seat, name, airports, budget, free days and votes in every trip. What is kept is described in section 7;
- restriction of processing in certain cases;
- portability: to receive the data you gave us in a structured, machine-readable format. There is no export button yet; ask us at [not set];
- object to processing based on our legitimate interests, including the analytics (which you can also switch off yourself);
- withdraw consent at any time, where we rely on consent, without affecting what was done before.
To exercise any of these, write to [not set] from the address on your account. We will answer within one month, and may ask you to confirm your identity.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work, or where you think the problem happened. [to be confirmed by the owner: the lead supervisory authority, e.g. the CNIL (Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr) if the business is established in France]
9. Age
Flocking is for people aged 18 and over. When an account is made we ask its holder to confirm they are 18 or older, and we keep the date and time they did, so we can show that we asked. We do not knowingly collect data from anyone younger. If you believe a child has an account, tell us at [not set] and we will close it.
10. Cookies and storage on your device
The Flocking server sets no cookies, for analytics or for anything else. The web app uses your browser's local storage, session storage and a service worker for the following, all of it first-party:
- flocking.session.v1 (local storage): your sign-in token. Necessary to keep you signed in.
- flocking.seats.v1 (local storage): seat keys for trips joined before accounts existed. Necessary.
- flocking.invite.v1 (session storage): an invitation you arrived with, held for the next few minutes while you sign up. Necessary.
- flocking.social.v1 (session storage): a sign-in with Apple or Google in progress. Necessary.
- flocking.dash.theme (local storage): your choice of light or dark theme. Preference.
- flocking.stamps.seen.v1 (local storage): that you have seen the explanation of the free search. Preference.
- flocking.photos.v3… (local storage): a cache of place descriptions and the addresses of their photographs on our own server, so they are not fetched again. Performance.
- flocking.visit.v1 (local storage): the random visit identifier for analytics. Removed when you turn analytics off.
- flocking.telemetry.v1 (local storage): remembers that you turned analytics off.
- The service worker's caches (flocking-pages and flocking-assets): copies of the app's pages and files so it can open without a connection. Pages with a code, a token or a query in their address are never kept.
Third parties may set their own cookies or storage when your browser contacts them: Cloudflare, on the pages that show the bot check and as part of protecting the site; Stripe, on its checkout page; Apple or Google, on their sign-in pages; and Aviasales, if you follow a booking link. Their own policies apply.
[to be confirmed by the owner: while the site is in private access mode, the web server sets a cookie named flocking_gate, for three months, to let testers in; it is not used once the site is public.]
On the iPhone, the app keeps your sign-in token in the Keychain, on this device only, and your theme and a cache of place photographs in the app's own storage. On Android, the token is kept encrypted with a key held by the Android keystore, with the theme and a photograph cache in the app's private storage.
11. Security
We protect your data with, among other things: encrypted connections (HTTPS) for everything; passwords kept only as scrypt hashes; sign-in tokens, seat keys and codes kept only as digests; emails waiting to be sent kept encrypted; deleted database records overwritten rather than left on disk; budgets filtered on the server before they are sent to anybody who may not see them; limits on repeated attempts; and an administration dashboard reachable only over a private network, behind a password and a second factor. No system is perfectly secure; if a breach puts your rights at risk, we will tell you and the supervisory authority as the law requires.
12. Changes
If we change this policy, we will publish the new version here with a new date. If a change significantly affects how we use your data, we will tell you by email or in the app before it takes effect.
13. Contact
[to be completed], [to be completed]. Email: [not set].
See also our terms, our legal notice and how to report content.