This Privacy Policy explains how Flinzo ("we", "us", "the app") handles your information when you use the Flinzo iOS application and website. We built Flinzo to help you in real dating conversations, and we collect only what we need to run the service securely.
Account and sign-in
Flinzo requires an account so your sessions can be securely saved to your profile and synced across your devices. You can create an account or sign in using:
- Sign in with Apple
- Google Sign-In
- Email and password
When you sign in, we receive and store your account identifier and email address, and where you provide it, your display name. If you use Sign in with Apple with "Hide My Email," we only ever see Apple's private relay address. Authentication is handled by Google Firebase Authentication on our behalf.
Information we process
Flinzo generates replies, coaching, and voice responses using AI. Depending on the feature you choose to use, your inputs may include:
- Chat or dating profile screenshots you choose to upload for analysis or first-message openers.
- Text you type when asking for a reply or chatting with the coach.
- Voice recordings you make during Voice Practice, which are transcribed to text so the coach can respond.
- Generated replies, transcripts, and session history saved to your account so you can return to them.
If you opt in to recent screenshot suggestions, Flinzo checks locally on your device for a recent screenshot and does not transmit or upload it unless you explicitly confirm the screenshot and start AI analysis.
These inputs are sent through our secure backend (Firebase Cloud Functions) to OpenAI to generate a response for you, which is then returned to your device. We do not sell this content or use it for advertising or cross-app tracking.
How AI keys are handled. Our OpenAI API key is stored only on our secure server (Google Secret Manager) and is used by our backend to talk to OpenAI on your behalf. The key is never included in the app, shown to you, or sent to your device. Every AI request requires you to be signed in and is rate-limited per account to prevent abuse.
AI processing and third-party providers
When you use an AI feature, you choose to send that feature's input to our backend for processing. Our backend forwards only the content needed for that request to OpenAI. OpenAI may process and temporarily retain API data under its own API data controls and privacy terms. OpenAI states that API inputs and outputs are not used to train its models by default. You can read more at OpenAI's API data controls.
Voice recordings are temporary working files. The app records audio in its local cache, sends it to our backend for transcription, and then removes the local recording after transcription. The spoken coach reply is also stored as a temporary local audio file and removed after playback. We save the text transcript and coach reply in your session history unless you delete the session or your account.
Where your data is stored
Your sessions, generated replies, profile, streak state, reports, and subscription status are stored in your private area of Google Firebase (Cloud Firestore) under your account, and cached locally on your device for speed. Client access is restricted so authenticated users can access only their own records; authorized backend services process data as described in this policy. Some anti-abuse counters and league records are written only by our secure backend.
Data we collect
- Email address, name, account identifier, and any phone number your selected sign-in provider supplies for sign-in and account management. Flinzo does not ask you to add a phone number in the app.
- Your chat content, screenshots, voice audio, voice transcripts, and AI replies to generate and save your sessions.
- Subscription status to unlock Pro features.
- Usage counters and streak/league state to enforce limits, prevent abuse, and run app features.
- Technical service data such as device identifiers, product interactions, other usage data, diagnostics, the called backend function, and your IP address, which can indicate an approximate or coarse location. Firebase and Google process this data for authentication, app functionality, security, abuse prevention, analytics, and service reliability.
All of the above is linked to your account. We do not use any of it to track you across other companies' apps or websites.
What we do not do
- We do not request access to GPS or precise location. Our service providers may process your IP address and an approximate location derived from it as described above.
- We do not sell your personal data to third parties.
- We do not use your data for advertising or cross-app tracking.
Third-party services
Flinzo relies on:
- OpenAI to power AI features. See openai.com/policies/privacy-policy and OpenAI API data controls.
- Google Firebase (Authentication, Firestore, Cloud Functions) for sign-in, secure storage, and our backend. See firebase.google.com/support/privacy.
- Apple for subscriptions and payments through the App Store and StoreKit. We never see your payment details.
- Cloudflare Pages to host and securely deliver this website. Cloudflare may process request data such as your IP address, browser information, and security diagnostics when you visit the site. See Cloudflare's Privacy Policy.
Children's privacy
Flinzo is intended for adults and is not directed at children under 17. We do not knowingly collect personal information from children.
Data retention and deletion
You are in control of your data. Account-linked content is kept while your account remains active so the app can provide history and sync. Temporary voice files are removed as described above. Security and service logs are retained only as long as reasonably necessary for reliability, abuse prevention, legal compliance, and provider backup cycles.
You can delete individual sessions at any time. From Settings - Account - Delete Account, you can permanently erase your account along with sessions, profile data, reports, streak/league data, and usage counters from our active systems. You can also reach us at the email below to request access, correction, deletion, or export of your personal data. Depending on where you live, you may also have rights to restrict or object to processing and to complain to your local data-protection authority.
After account deletion, we retain only limited one-way account hashes and Apple subscription-chain ownership records when necessary to prevent subscription theft, support a legitimate App Store restore, resolve payment disputes, and meet security or legal obligations. These records do not contain your conversations, screenshots, voice recordings, profile, email address, or display name; they are not used for advertising or marketing and are kept only for as long as those security, restore, dispute, or legal purposes require.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page.
Contact
If you have questions about this Privacy Policy, contact us at [email protected].