Last updated: 2026-05-26

Privacy Policy

This Privacy Policy describes how Flicker ("we", "us") collects, uses, and shares information when you use flickercloud.com and related services.

Information we collect

  • Account information: name, email address, organization name.
  • Authentication data: hashed password, session tokens, API keys.
  • Billing information: handled by Stripe; we store only customer and subscription identifiers, never card numbers.
  • Usage and operational logs: requests, branch and database events, error traces, IP addresses.
  • Customer data: the contents of databases you create in Flicker.

How we use information

  • To operate, secure, and improve the service.
  • To bill for the service and handle support requests.
  • To detect abuse and enforce our Acceptable Use Policy.
  • To send transactional email (account, billing, security, incident notifications).

We do not sell personal information. We do not use customer database contents to train models or for any purpose other than running the service you asked us to run.

Subprocessors

We rely on a small number of vendors to deliver Flicker. The current list is maintained in our Security FAQ. We will provide reasonable notice before adding a new subprocessor that processes customer data.

Data retention

We retain account data while your account is active. After account closure, customer data and its backups are deleted within 30 days, except where retention is required by law. Operational logs are retained for up to 90 days.

Data location

Customer databases are hosted in the United States (Vint Hill, Virginia). Account and operational metadata (organizations, apps, secrets, and deployment records) is stored in a managed Postgres database (Supabase, US-East) and served by our control plane on Fly.io (US-East). Backups are stored in Tigris S3-compatible storage. Transactional email is sent from Flicker's own in-cluster mail service (DKIM-signed); DNS by Cloudflare.

Your rights

You may request access to, correction of, or deletion of your personal information by emailing johnorlando@me.com. EU and UK customers have additional rights described in our Data Processing Addendum.

Children

Flicker is not directed to children under 18 and we do not knowingly collect personal information from them.

Changes

We will notify customers of material changes to this Policy by email and update the "Last updated" date above.

Contact

Privacy questions: johnorlando@me.com.