%% TODO before publishing live: replace [YOUR LEGAL NAME OR ENTITY], [SUPPORT EMAIL], [BUSINESS ADDRESS]; confirm dates; have a lawyer review. %% # Privacy Policy **Effective date:** 2026-07-24 **Last updated:** 2026-07-24 This Privacy Policy explains what happens to personal data when you use **Phlip** (the "App"), published by us the developers. ## 1. The most important thing: Phlip is self-hosted Phlip is a **self-hosted** app. There are **no Developer servers** that store your messages, events, photos, or account data. Instead: - One person in a group runs the **Host** on their own Android phone. The Host's phone stores that group's data. - Everyone else connects to that Host as a client (through the App or a web browser). - **The Host (not the Developer) controls and is responsible for the data stored on their device.** In data-protection terms, the Host acts as the operator/controller for their group's data. See the [[Notices/Terms]] for the Host's responsibilities. We (the Developer) do not receive, store, or have access to your group content. We cannot read your messages, see your events, retrieve your data, or delete data from a Host's device on your behalf. If you want your data removed, you must ask the Host of that group (see Section 8). ## 2. Data processed, and where it lives ### On the Host's device When you join a group, the following is stored on the **Host's phone** (in the app's private storage, encrypted at rest), not on any Developer server: | Data | Notes | |---|---| | Display name | Stored in readable form. | | Login credentials | Your password is **never** sent or stored. The Host stores only a random salt, a one-way verifier (from which the password cannot be recovered), and your group key wrapped under your password. | | Device fingerprint | A one-way **hash** used to keep you signed in; the underlying device identifier never leaves your device. Up to 8 are kept per member. | | Message and event **content** | Stored **end-to-end encrypted**; the Host device cannot read the plaintext (see Section 4). | | Content **metadata** | Timestamps, RSVP responses, channel names, @-mentions, categories and saved locations are currently stored in **readable form** (see Section 4). | | Server/group picture and offline avatars | Stored on the Host if you set them. | ### Only on your own device (never uploaded) - **Live session photos** (e.g. a camera photo shown while you're online) are relayed live and are **never written to the Host's storage**. - **"Memories" photos** you pick for a memory card stay **only on your own device** and are never uploaded. - Your personal space, cached data, and a random local device id stay in your browser/app local storage. ### IP addresses - Member IP addresses are **not stored** on member records. An IP address may be seen transiently by the Host's software to rate-limit failed logins; it is not persisted. - For public guest ("Broadcast") links, a guest's IP may be held in memory during the live session and is discarded afterward. ### Payments If you make an optional in-app **Supporter** purchase, the transaction is processed by **Google Play Billing**. We do not receive your card or payment details. Supporter purchases unlock cosmetic items only. ### Analytics Phlip contains **no analytics, telemetry, advertising, or crash-reporting SDKs.** We do not track your usage. ## 3. Third parties (sub-processors) - **Cloudflare**: When a Host makes a group reachable over the public internet, traffic is relayed through a Cloudflare Tunnel. Cloudflare can see connection metadata and any traffic that is not encrypted (see Section 4). Cloudflare's handling of that data is governed by Cloudflare's own terms and privacy policy. - **Google Play**: App distribution and, if you choose, Supporter billing. We do not sell your personal data, and we do not share it with third parties for advertising. ## 4. What is and isn't encrypted We want to be honest about this, because encryption in Phlip is **an actively developing area** that we are continuing to improve. - **Encrypted end-to-end** (unreadable to the Host device, to Cloudflare, and to us): message text, event titles, locations and details, event notes, and Open Pitch card labels. - **Not encrypted** (currently readable to the Host, and over a public tunnel potentially to Cloudflare): display names, timestamps, RSVP responses, channel names, @-mentions, categories, saved locations, and connection/routing metadata. - **At rest on the Host:** the group secret and the per-server data file are sealed on the Host's device using the Android Keystore. - **Local networks:** on a local (LAN) connection, and for LAN guest Broadcast links, data may be transmitted **without encryption** because the connection is directly between trusted devices on the same network. - **Invite links** may carry the group's encryption key in the link fragment. Treat invite links as secrets and share them only with people you trust. We do not claim that all data is encrypted. Completing encryption of remaining metadata is work we are pursuing over time, see the [[FAQs]] and [[Roadmap]]. ## 5. Children and minimum age - Phlip is **not intended for anyone under 13.** You must be at least **13 years old** to use the App. Individual servers may set a higher minimum age, shown before you join. - To **host** a group you must be at least **18 years old**, because a Host takes on operator responsibilities for other people's data (see the [[Notices/Terms]]). - We do not knowingly collect personal data from children under 13. If you believe a child under 13 is using Phlip, contact the relevant group's Host. ## 6. Legal bases (where applicable, e.g. UK/EU GDPR) Where data-protection law applies, processing generally relies on: your **consent** (which you can withdraw), the **performance of the service** you asked for (running the group you joined), and our **legitimate interests** in operating and securing the App. Because groups are self-hosted, the **Host is the controller** for their group's data and determines the purposes of processing; we provide the software. Hosts and members should read Section 8 for how rights are exercised. ## 7. Data retention - Group data is retained on the **Host's device** for as long as the Host keeps that group. Deleting a group on the Host device deletes that group's data file. - Notifications are capped and older ones are dropped automatically. - Live photos and guest sessions are discarded when you go offline or the session ends. - Data you keep only on your own device stays until you clear it. - If you leave a server you can opt to have your data deleted from that server, this will not delete old events but will remove your attachment to them. - Sever settings allow for automatic removal of events and chat messages after a set time period. ## 8. Your rights and how to exercise them Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict processing. **Because Phlip is self-hosted, most of these rights are exercised through the Host of your group, not through us**, since the Host holds the data: - To have your data in a group **deleted or corrected**, ask that group's **Host**. In the app you can also use **Leave & delete my data**, which purges your RSVPs, reactions, notes, chat, pitch seats and reports from that server (events you created remain historically). - Data you keep only on your own device you can delete yourself by clearing the App/browser data. - For questions about the App itself, or if you cannot reach a Host, contact us at **[SUPPORT EMAIL]** and we will help where we are able. Note we cannot access or delete data held on a Host's device. ## 9. Security Phlip uses end-to-end encryption for content (Section 4), stores no plaintext passwords, and seals sensitive material (the group secret, server data files, and Cloudflare tokens) in the Android Keystore. However, no system is perfectly secure, the App is provided "as is" (see the [[Notices/Terms]]), and a Host's device security is outside our control. Do not use Phlip to store data you cannot afford to have exposed. ## 10. International use Phlip is published on the app store for UK use only at this time. Public traffic may transit Cloudflare's global network. ## 11. Changes to this policy We may update this policy. Material changes will be reflected by updating the "Last updated" date and, where appropriate, by notice in the App. ## 12. Contact Pending app release. --- **Quicklinks:** [[Why Phlip|Home]] · [[Features]] · [[FAQs]] · [[Roadmap]] · [[Notices/Legal]]