Privacy Policy
Version: 2026-04-25
Effective date: 2026-04-25
1. Who We Are
Flit ("we", "us") is operated by [INSERT FULL LEGAL NAME], a [INSERT LEGAL FORM] with registered address at [INSERT FULL REGISTERED ADDRESS]. For the purposes of the GDPR, [INSERT FULL LEGAL NAME] acts as the data controller for personal data processed in connection with the Service.
As of this version, Flit handles privacy matters through a designated privacy owner rather than a formally appointed Data Protection Officer. Privacy questions and data-subject requests should be sent to contact@flit.social.
2. Data We Collect
2.1 Account and Profile Data
2.2 Location Data
2.3 Social and Activity Data
2.4 Device and Technical Data
2.5 Consent and Audit Records
3. How We Use Your Data
| Purpose | Data categories | Lawful basis |
|---|---|---|
| Creating and authenticating your account | Email, profile | Contract (Art. 6(1)(b)) |
| Displaying your profile to other users | Username, gender, age, avatar, interests | Contract |
| Matching you with relevant plans and users | Last-known location snapshot, saved locations, date of birth-derived age, age range, gender filters | Contract |
| Sending push notifications about plans and social activity | Push token | Consent (Art. 6(1)(a)) |
| Analytics and product improvement | Pseudonymous usage events | Consent |
| Crash and error monitoring | Device and error data | Legitimate interests (Art. 6(1)(f)) limited to service reliability, with consent-gating in the mobile app |
| Safety and moderation | Reports, block records, moderation metadata | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal obligations | Any required data | Legal obligation (Art. 6(1)(c)) |
| Preventing abuse and securing the service | IP addresses, request metadata, security logs | Legitimate interests (Art. 6(1)(f)) |
4. Consent
Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Withdrawal of analytics consent stops future analytics collection. Withdrawal of push notification permission stops future push delivery but does not delete historical in-app notification records already associated with your account.
5. Data Sharing and Processors
We use third-party service providers only where needed to operate, secure, and improve Flit.
| Processor | Purpose | Data | Region | Transfer mechanism |
|---|---|---|---|---|
| Clerk | Authentication | Email, account metadata, auth/session metadata | US / global infrastructure | SCCs or other lawful transfer mechanism offered by vendor |
| Cloudflare R2 | Avatar and photo storage | Image files and object keys | EU-region preference where available | SCCs or other lawful transfer mechanism offered by vendor |
| PostHog (EU cloud) | Product analytics | Pseudonymous usage events | EU | EU hosting / vendor terms |
| Sentry | Error monitoring | Error traces and device/runtime metadata, with PII stripped on the backend | US | SCCs or other lawful transfer mechanism offered by vendor |
| Expo push service, APNS, FCM | Push delivery | Push token and notification payload | US / global infrastructure | SCCs or other lawful transfer mechanism offered by vendor |
| Hetzner Cloud / Coolify-managed Postgres | Application hosting and database infrastructure | Core application data | Germany | EEA processing |
| Google Places / Geoapify | Location search | Search query string and related request metadata | US / EU | SCCs or other lawful transfer mechanism offered by vendor |
| Discord | Moderation alert delivery | Report metadata included in webhook notifications | US | SCCs or other lawful transfer mechanism offered by vendor |
We do not sell your personal data.
6. Retention
| Data type | Retention period |
|---|---|
| Active account data | Until account deletion |
| Deactivated accounts | 30 days, then automatically purged |
| Plan and saved-location history | Deleted with account unless a shorter in-product deletion happens first |
| Analytics events | 12 months in PostHog |
| Crash reports | 90 days in Sentry |
| Server access and security logs | 30 days, unless a longer period is required for an active security investigation or legal claim |
| Consent and ToS audit records | Until account deletion, then removed through account deletion and purge flows |
7. Your Rights (GDPR Art. 15–22)
Subject to applicable law, you have the right to:
To exercise any right, contact contact@flit.social. We aim to respond within 30 days. We may ask for reasonable verification of identity before fulfilling a request.
You also have the right to lodge a complaint with your supervisory authority. For users in Greece, the competent authority is the Hellenic Data Protection Authority (HDPA): https://www.dpa.gr/en
8. Age Restriction
Flit is only for users 18 and older. We do not knowingly permit accounts for persons under 18. If you believe a minor has created an account, contact contact@flit.social and we will investigate and remove the account where appropriate.
9. International Transfers
Some of our processors operate outside the EEA, including vendors in the United States. Where this occurs, we rely on the transfer mechanisms made available by those vendors and required by applicable law, such as Standard Contractual Clauses, supplementary contractual commitments, or other lawful transfer mechanisms.
10. Security
We use technical and organisational measures designed to protect personal data, including:
No method of transmission or storage is perfectly secure, but we review and update our safeguards on an ongoing basis.
11. Automated Decision-Making
Flit uses automated filtering such as age range and gender visibility preferences to shape what a user sees in the product. These filters are based on settings provided by the user and do not produce legal or similarly significant effects within the meaning of GDPR Art. 22.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make a material change, we will provide notice in-app or by another reasonable channel before the updated version takes effect. The effective version is recorded when relevant consents or policy acceptances are collected.
13. Contact
Privacy questions, data-subject requests, or concerns:
**Email:** contact@flit.social
**Controller name:** [INSERT FULL LEGAL NAME]
**Registered address:** [INSERT FULL REGISTERED ADDRESS]
**VAT / Tax ID:** [INSERT VAT OR TAX ID]
**GEMI / Registry number:** [INSERT GEMI OR OTHER REGISTRY NUMBER, IF APPLICABLE]