Flash — Privacy Policy
Last updated: June 2026
Last updated: June 2026
Flash ("the App", "we", "us") is a mobile application that identifies movies and TV shows from short audio samples or typed dialogue. This Privacy Policy explains what information we process, why we process it, and the rights you have over that information.
By creating an account or using the App, you acknowledge that you have read and understood this Privacy Policy.
Account information: email address (required for authentication), and an optional display name and age that you choose to provide.
Content you create in the App: items you save to history or favorites, and text you type into the identification input.
Service analytics: aggregated, pseudonymous events about identification attempts, result outcomes, and feature engagement. These are used to monitor reliability and improve accuracy. You can disable analytics collection at any time from Settings.
Short audio samples: when you use audio identification, a brief sample (on the order of a few seconds) is transmitted to our backend for processing. Audio is used only to produce an identification result and is not retained, stored in a user-accessible form, played back, transcribed for review, or used to train third-party models on your behalf.
Approximate region: your country/region is derived from your device locale to tailor streaming availability. We do not collect precise location, GPS coordinates, IP-based geolocation, or street-level data.
Precise or background location, GPS coordinates, or Wi-Fi/Bluetooth-based location.
Contacts, photos, calendar entries, SMS, call logs, or files from your device.
Persistent device identifiers such as IMEI, MAC address, or advertising ID.
Microphone audio outside of an active identification request initiated by you.
Browsing history or any activity you perform in other apps.
To provide the core identification service and return results to you.
To maintain your account, authenticate you, and sync your history and favorites across sessions on the same account.
To send you a notification containing the result of an identification you requested.
To monitor service health, diagnose errors, prevent abuse, and improve identification quality in aggregate.
To comply with legal obligations and enforce our Terms of Use.
Performance of a contract: processing necessary to provide the service you have signed up for (e.g., authentication, returning identification results).
Consent: where you have opted in to analytics or other optional processing. You can withdraw consent at any time in Settings.
Legitimate interests: maintaining service security, preventing fraud and abuse, and improving the product in ways that do not override your rights.
Legal obligation: complying with applicable law and lawful requests from authorities.
We rely on reputable third-party infrastructure providers to deliver the service, including (without limitation) cloud hosting, managed authentication and database services, AI inference providers, push notification delivery, crash reporting, and public metadata catalogues for titles, posters, and ratings.
These providers process data only on our instructions and under their own contractual privacy commitments. We do not disclose the specific internal composition of our stack, which is part of our confidential operational design.
Some providers may process data outside your country of residence. Where applicable, transfers rely on lawful mechanisms such as standard contractual clauses.
We do not sell your personal information. We do not share your personal information for cross-context behavioural advertising.
Account information and user-created content (history, favorites) are retained for as long as your account exists. You may delete individual items at any time from the App.
When you delete your account, your personal data held in our systems is deleted or irreversibly anonymised without undue delay, subject to limited retention required for legal, accounting, fraud prevention, or dispute resolution purposes.
Audio samples submitted for identification are not retained after processing.
Aggregated or de-identified statistics that cannot reasonably be linked back to you may be retained indefinitely for analytical purposes.
All traffic between the App and our backend is transmitted over TLS/HTTPS.
Authentication sessions are stored in encrypted storage on your device, keyed to the device's secure hardware where available.
Server-side access controls restrict each account to its own data.
Passwords are never stored in plaintext; authentication is handled by our managed identity provider.
No system is perfectly secure. You are responsible for keeping your account credentials confidential and for using a strong, unique password.
Access & portability: you can view your data in-App and request an export of your account data from the Profile screen.
Rectification: you can edit your display name and age in Profile, and update your email and password from Profile/Settings.
Erasure: you can delete individual history or favorites items, or permanently delete your entire account from the Profile screen. Account deletion removes your authentication record and associated personal data from our systems.
Restriction & objection: you can disable optional analytics in Settings, or contact us to object to specific processing activities.
Withdraw consent: where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
Complaint: EU/UK users have the right to lodge a complaint with their local data protection authority.
The App is not directed to children under 13 (or the minimum age required by your jurisdiction, whichever is higher). We do not knowingly collect personal information from such users. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
Identification results are produced by automated systems using machine-learning models. These results are informational only and do not produce legal or similarly significant effects on you.
We may update this Privacy Policy to reflect changes to the App, to our practices, or to applicable law. Material changes will be notified in-App or by email where appropriate. Your continued use of the App after the effective date constitutes acceptance of the updated policy.
For privacy questions, data access requests, or data deletion requests, contact: flash.ai.support@gmail.com