FlockingVersion française

Privacy policy

DRAFT — to be reviewed by a lawyer before launch. This text was drafted from what the software does today and has not been reviewed. It is not yet the agreement between you and us.

Last updated: 2026-09-29

This policy explains what personal data Flocking keeps, why, for how long, who else receives it, and what you can do about it. It covers the website at https://flocking.app, the Flocking iPhone app and the Flocking Android app, which all use the same service.

1. Who we are

The controller of your personal data is [to be completed], [to be completed], [to be completed], registered under [to be completed].

You can reach us about anything in this policy at [not set].

[to be decided by the owner: whether a data protection officer is appointed, and if so their contact details]

2. What Flocking does, in one paragraph

Flocking helps a group of friends, each with a home airport, free days and a budget, find places they can all afford and agree on one. Planning is free. Real fares from third-party fare providers are fetched only when somebody presses the button to reveal them, and are paid for with a free search or with credit in a wallet. Flocking does not sell flights; you book with an airline or booking site yourself.

3. What we keep, and why

Your account

We keep this to provide the service you signed up for (performance of a contract, Article 6(1)(b) GDPR).

Your trips

Who can see what. Inside a trip, members see each other's names, airports, pictures, free days, votes and lock-ins; votes are not anonymous. Budgets are private by default: each person sees their own budget and fare in full, and other people's fares only rounded to about five euros, until a member turns budget sharing on for the trip, which every member is told about by email, with that member's name. A trip's link is an address, not a password: anyone who has it can see the trip's name, the names, airports and pictures of the people in it, the destinations and, once decided, the destination and dates. They never see anybody's budget, fare, free days, votes or lock-ins. When a trip link is shared in a messaging app, the preview shows the trip's name, how many people are in it and, once decided, the destination and dates. Please share trip links with care.

We keep this to provide the service (contract, Article 6(1)(b)).

Companions

When you send or accept a companion request, we keep who asked whom, and when. A pending request tells the other person only that you asked. Once accepted, each of you can see the other's home airport. If you ask somebody by email address and that address has an account, we email them and keep the request; we never tell you whether the address has an account.

Legal basis: contract (Article 6(1)(b)).

Destination likes and notes

You can like a destination and leave a note about a visit: a rating from 1 to 5, the month you went, the weather, and up to 600 characters of text. Notes are public. Anyone, signed in or not, can read them on the destination's page, with your first name beside them. Likes are only ever shown as a count. You can delete your note at any time.

Legal basis: contract (Article 6(1)(b)); you choose to publish.

The wallet and payments

Stripe, Apple and Google handle the payment itself. We never see or store your card details.

Legal bases: contract (Article 6(1)(b)) for the wallet and purchases; legal obligation (Article 6(1)(c)) for keeping accounting records; our legitimate interest (Article 6(1)(f)) in preventing abuse of the free search and of refunds, for the inbox hash and holds.

Emails

We send email through our email provider (see section 5). Emails we send:

Trip emails can be turned off with one click from the link at the foot of any of them, or in your profile. Account emails cannot be turned off, because they are how you get into and protect your account.

Emails waiting to be sent are stored encrypted, and deleted once sent. An email that cannot be delivered is erased, leaving only a record of the failure without the address or content, which is kept for 7 days.

Legal bases: contract (Article 6(1)(b)) for account and trip emails; legitimate interest (Article 6(1)(f)) for security notices and companion requests.

Reports of content

Next to a picture, a name, a destination note or a trip name that somebody else wrote there is a Report button. A report keeps: what was reported and where it was shown, a copy of the content as it was when reported (including a copy of a reported picture), the reason you chose, any details you write (up to 1,000 characters), and who reported it: your account if you are signed in, or an email address if you choose to leave one when you are not. We use the address only to acknowledge the report and tell you the outcome. The person whose content you reported is not told who reported it.

When we decide a report, we record the decision, who made it, and the reason. If we remove content, we email the person it belonged to a statement of reasons. The copy of the content, the details the reporter wrote and the address a reporter who was not signed in left are kept for 180 days after the report is decided, and then erased; what remains is that a report of that kind, for that reason, was made and what we decided. A report that has not been decided yet is kept until it is.

Legal bases: legal obligation (Article 6(1)(c)) under the EU Digital Services Act, and our legitimate interest (Article 6(1)(f)) in keeping the service free of illegal and abusive content.

Usage analytics

Our analytics are first-party: nothing is sent to an analytics company, and nothing records your screen, your keystrokes or what you type.

Legal basis: our legitimate interest (Article 6(1)(f)) in understanding how the service is used, and in keeping it working. [to be confirmed by the lawyer: whether the visit identifier kept in local storage requires prior consent under the ePrivacy rules as implemented in the relevant country, or falls within an exemption for first-party audience measurement; today analytics are on until switched off.]

Security records

For every request to our server we keep a line with the time, the route, the result, how long it took, your IP address, your browser's user agent (shortened), and your account id if you are signed in. We also record security events (refused requests, rejected payment notifications, addresses blocked and unblocked), which include the IP address. We use these to trace and stop attacks and abuse, and to keep the service running.

Legal basis: our legitimate interest (Article 6(1)(f)) in the security of the service.

The bot check

On sign-up, on the password reset page and on a first sign-in with Apple or Google, we use Cloudflare Turnstile to check that you are not an automated script. Your browser loads Cloudflare's script, and Cloudflare sees what it needs to run the check from your browser. Our server sends Cloudflare the resulting token and our secret key, nothing else: not your email address and not your IP address.

Legal basis: our legitimate interest (Article 6(1)(f)) in protecting sign-up from abuse.

Location on phones

When you choose your home airport in the iPhone or Android app, the app may ask for your approximate location to suggest the nearest airports. This is worked out on your phone, and your location is never sent to us or anyone else. You can decline and pick an airport yourself. The website does not ask for your location.

4. What we do not do

5. Who else receives data

We use the following service providers. Each receives only what it needs for its task.

Services that receive no personal data from us: the fare providers SerpAPI (which searches Google Flights for us) and Travelpayouts receive airports, dates and currencies, never names, budgets or anything else about the people in a trip. OpenSky Network, which supplies the aircraft positions on the globe, is asked by our server with no data about anyone.

We may also disclose data when the law requires it, for example to a court or authority with a valid order, and to our professional advisers under a duty of confidence.

6. Transfers outside the EU

Some of the providers above are established in, or may access data from, countries outside the European Economic Area, in particular the United States (Cloudflare, Resend, Stripe's group, Apple, Google, the Wikimedia Foundation). Where that is the case, the transfer relies on [to be confirmed for each provider: the EU–US Data Privacy Framework, the European Commission's standard contractual clauses, or another mechanism under Chapter V GDPR]. You can ask us for a copy of the relevant safeguards at [not set].

7. How long we keep it

8. Your rights

Under the GDPR you have the right to:

To exercise any of these, write to [not set] from the address on your account. We will answer within one month, and may ask you to confirm your identity.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work, or where you think the problem happened. [to be confirmed by the owner: the lead supervisory authority, e.g. the CNIL (Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr) if the business is established in France]

9. Age

Flocking is for people aged 18 and over. When an account is made we ask its holder to confirm they are 18 or older, and we keep the date and time they did, so we can show that we asked. We do not knowingly collect data from anyone younger. If you believe a child has an account, tell us at [not set] and we will close it.

10. Cookies and storage on your device

The Flocking server sets no cookies, for analytics or for anything else. The web app uses your browser's local storage, session storage and a service worker for the following, all of it first-party:

Third parties may set their own cookies or storage when your browser contacts them: Cloudflare, on the pages that show the bot check and as part of protecting the site; Stripe, on its checkout page; Apple or Google, on their sign-in pages; and Aviasales, if you follow a booking link. Their own policies apply.

[to be confirmed by the owner: while the site is in private access mode, the web server sets a cookie named flocking_gate, for three months, to let testers in; it is not used once the site is public.]

On the iPhone, the app keeps your sign-in token in the Keychain, on this device only, and your theme and a cache of place photographs in the app's own storage. On Android, the token is kept encrypted with a key held by the Android keystore, with the theme and a photograph cache in the app's private storage.

11. Security

We protect your data with, among other things: encrypted connections (HTTPS) for everything; passwords kept only as scrypt hashes; sign-in tokens, seat keys and codes kept only as digests; emails waiting to be sent kept encrypted; deleted database records overwritten rather than left on disk; budgets filtered on the server before they are sent to anybody who may not see them; limits on repeated attempts; and an administration dashboard reachable only over a private network, behind a password and a second factor. No system is perfectly secure; if a breach puts your rights at risk, we will tell you and the supervisory authority as the law requires.

12. Changes

If we change this policy, we will publish the new version here with a new date. If a change significantly affects how we use your data, we will tell you by email or in the app before it takes effect.

13. Contact

[to be completed], [to be completed]. Email: [not set].

See also our terms, our legal notice and how to report content.