Legal

PRIVACY POLICY

Last updated: July 18, 2026
Effective date: June 7, 2026
Compliant with: India DPDP Act 2023
🔒
Our promise to you: We built Flick to be a community for photographers — not an advertising platform. We collect only what we need to operate the Service, we never sell your personal data to anyone, and we give you full control over what you share.
Table of Contents
  1. Who We Are
  2. Data We Collect
  3. Legal Basis for Processing
  4. How We Use Your Data
  5. Advertising
  6. How We Share Data
  7. Private Messages
  8. Content Deletion Controls
  9. Mystery Gift Shipping Addresses
  10. Local Storage & Device Data
  11. Cross-Border Data Transfers
  12. Sensitive Personal Data
  13. Children's Privacy
  14. Data Security
  15. Data Retention
  16. Your Rights & Choices
  17. Google Play Data Safety
  18. Third-Party Services
  19. Changes to This Policy
  20. Contact Us
Section 01

Who We Are

This Privacy Policy is published by Alpha Labs ("we", "us", or "our"), the developer of the Flick photography contest application ("Flick" or "the Service").

Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), Alpha Labs acts as the Data Fiduciary — the entity that determines the purpose and means of processing your personal data. This Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have under applicable law.

Contact for privacy matters: support@joinflick.in

Section 02

Data We Collect

Data you provide directly:

  • Account registration: full name, username, email address, password (stored encrypted via Firebase Authentication)
  • Profile information: profile photo, biography/about me
  • Optional profile fields: birthday, gender, location, mobile number — each independently controlled via Privacy Settings
  • Photos, captions, and hashtags you submit to contests or duels
  • Private messages you send to other users
  • Referral codes you use during registration or share with others
  • Contest theme suggestions you submit through the app
  • Support messages or feedback you send to us

Data collected automatically:

  • Device information: device type, manufacturer, model, operating system version, app version
  • Usage data: contests entered, votes cast, duels initiated, features used, session duration, screens visited
  • Engagement data: login streak count, last login date, last streak date, total submissions, total wins, total votes cast and received
  • Profile view count — the number of times your profile has been viewed (we do not store the identities of individual viewers)
  • Firebase Cloud Messaging (FCM) token — used exclusively to deliver push notifications to your device
  • Crash reports and performance diagnostics via Firebase Crashlytics
  • Anonymised aggregate usage analytics via Firebase Analytics

Data from third parties:

  • If you sign in with Google, we receive your name, email address, and profile photo from Google as part of the OAuth 2.0 authentication flow
Note on photo EXIF data: Photos you upload may contain embedded metadata (EXIF data) such as GPS location, camera model, and capture time. We do not actively read, extract, or store EXIF metadata. However, EXIF data may be preserved within the photo file itself when stored on Firebase Storage. We recommend stripping EXIF data from photos before uploading if location privacy is a concern.
Section 03

Legal Basis for Processing

Under India's DPDP Act, 2023, and applicable privacy law, we process your personal data on the following legal bases:

  • Consent: You provide explicit, informed consent when you register for an account, accept these Terms and this Privacy Policy, and optionally provide sensitive personal data (birthday, gender, mobile number). You may withdraw consent at any time.
  • Contract performance: Processing necessary to provide the Service you have requested — running contests, calculating XP, delivering push notifications, enabling messaging.
  • Legal obligation: Where we are required to retain or disclose data by applicable Indian or international law, court order, or governmental authority.
  • Legitimate interests: For fraud detection, abuse prevention, security, and improving Service quality — where these interests are proportionate and do not override your privacy rights.
Important — DPDP Act compliance: Under India's DPDP Act, 2023, there is no "legitimate interests" basis for processing sensitive personal data or for tracking/profiling users. All sensitive personal data processing is based solely on your explicit consent. You may withdraw consent at any time by deleting the relevant data from your profile or deleting your account.
Section 04

How We Use Your Data

PurposeData usedLegal basis
Create and manage your accountName, email, username, passwordContract
Display your public profileUsername, avatar, bio, level, badges, public stats, location (if enabled)Contract / Consent
Run photo contests and duelsSubmitted photos, username, avatar, captions, hashtagsContract
Calculate XP, levels, streaks, and leaderboardsContest activity, votes, wins, login history, streak datesContract
Send push notificationsFCM token, notification preferencesConsent
Send birthday notificationsBirthday (only if provided by you)Consent
Enable private messagingMessages, username, avatarContract
Process referral rewardsReferral code, user ID, XP balanceContract / Consent
Detect fraud, abuse, and ban evasionAccount activity, device info, user reportsLegitimate interests / Legal obligation
Improve the ServiceAnonymised aggregate analytics, crash reportsLegitimate interests
Respond to support requestsEmail, username, message contentContract / Legal obligation
Display advertisementsDevice identifiers via Google AdMob (see Section 5)Consent

We do not use your personal data for targeted advertising based on your profile content, photos, or in-app behaviour. We do not sell your data to any third party.

Section 05

Advertising

Flick displays in-app advertisements served by Google AdMob. AdMob may collect device identifiers (such as the Android Advertising ID) and app usage signals to serve contextual and personalised advertisements. This data collection is governed by Google's Privacy Policy.

You can opt out of personalised advertising at any time:

  • Android: Settings → Google → Ads → Delete advertising ID (Android 12+) or Opt out of Ads Personalisation (older Android)

Opting out does not remove ads from the app — it means the ads shown will be less relevant to you. We do not share your name, email address, photos, or any personal profile information with advertisers.

Section 06

How We Share Your Data

We share your data only in the following limited circumstances:

  • Public information visible to all users: Username, profile photo, submitted contest photos, contest rankings, XP level, badges, total votes received, total wins, total submissions, following/follower count
  • Private information never shown to other users: Email address, password, birthday, mobile number, gender
  • Location: Only shown to other users if you explicitly enable "Show Location" in Privacy Settings
  • Private profiles: If your account is set to private, your photos and activity are visible only to approved followers
  • Firebase (Google): All app data is stored and processed on Google Firebase infrastructure. Firebase acts as our data processor under a data processing agreement with Google and is bound by appropriate technical and legal safeguards
  • Google AdMob: Device identifiers for advertising purposes as described in Section 5
  • Legal compliance: We may disclose data if required by applicable Indian law, court order, governmental authority, or to protect the rights, safety, or property of Alpha Labs, our users, or the public
  • Business transfer: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity, subject to equivalent privacy protections and prior notice to you

We never sell, rent, or trade your personal data to any third party for their own marketing or commercial purposes.

Section 07

Private Messages

Private messages between users are stored on Google Firebase servers. Messages are accessible only to the sender and recipient. We do not read, analyse, or use the content of private messages for any purpose other than delivering them to the intended recipient, except in the following circumstances:

  • A message is reported by a user for violating our Terms of Service, in which case our moderation team may review the reported content to assess the report
  • We are legally required to disclose message content by applicable law or valid court order

We do not use message content for advertising, analytics, AI training, or any other commercial purpose.

Section 08

Content Deletion Controls

Flick gives you direct, in-app control over deleting the content you create. This section explains exactly what you can delete, what cannot be deleted, and why — so you always know the status of your data.

What you can delete at any time:

  • Individual photo submissions: You may delete a photo you have submitted, provided the associated contest is no longer active and the submission has not won or placed in that contest (see conditions below)
  • Private messages: You may delete individual messages you have sent from within a conversation. Deleting a message removes it from your view; see Section 7 for how message data is handled between sender and recipient
  • Your entire account: You may delete your account at any time from Settings → Account → Delete Account, which permanently removes all associated data as described below and in Section 15

When a submission cannot be deleted:

  • While its contest is active: Submissions cannot be deleted while the associated contest is still running. This is because contest standings, vote counts, and leaderboard rankings are calculated live from active submissions, and removing an entry mid-contest would compromise the fairness and integrity of the results for all participants
  • If the submission has won or placed: Submissions that have won or placed in a contest are retained even after the contest ends, because contest results, leaderboard history, and season records depend on preserving this data permanently. This ensures the accuracy of Flick's Hall of Fame, season history, and public contest archives

Outside of these two conditions, once a contest has ended and a submission did not place, you are free to delete it from your profile at any time.

Full account deletion: Deleting your account removes all of your associated data — including your profile, submissions, messages, and activity history — subject to the retention periods and legal-hold exceptions described in Section 15 (Data Retention). Anonymised contest leaderboard records that contain no personal identifiers may be retained to preserve historical contest integrity, consistent with Section 15.

Section 09

Mystery Gift Shipping Addresses

Some contests on Flick award a Mystery Gift instead of a voucher. If you win a Mystery Gift, we ask you to submit a shipping address so we can send your prize.

What we collect: Full name, phone number, address lines, city, state, pincode, and an optional landmark.

How this data is used and protected:

  • Used solely to ship your physical prize — not used for marketing, analytics, or any other purpose
  • Never visible to other users and never shown on your public profile
  • Accessible only to authorised Flick administrators handling prize fulfilment
  • Automatically deleted from our systems within 60 days of your prize being shipped. We retain a record that you won and received a prize, but not the address itself, beyond that period

Submitting a shipping address is optional. If you win a Mystery Gift and choose not to submit an address before the claim window closes, the prize goes unclaimed and no address data is collected.

Section 10

Local Storage & Device Data

Flick stores limited data locally on your device to improve performance and enable certain features:

  • SharedPreferences: App preferences such as theme mode (dark/light), onboarding completion status, and local settings
  • Hive (local database): Local caching of app data to improve load times and offline usability
  • Temporary photo cache: Photos are temporarily cached during upload and automatically removed after the upload completes

This locally stored data is not transmitted to our servers except as described in this Policy. Uninstalling the app removes all locally stored data from your device.

Section 11

Cross-Border Data Transfers

Flick uses Google Firebase, which stores and processes data on Google's global server infrastructure. This means your personal data may be transferred to, stored in, and processed in countries outside India, including the United States, where Google operates data centres.

Under India's DPDP Act, 2023, cross-border data transfers are permitted unless the Indian government specifically restricts transfers to a particular country. As of the date of this Policy, no restricted jurisdictions list has been published by the Indian government.

By using the Service and providing your consent to this Privacy Policy, you explicitly consent to this cross-border transfer of your data. Google Firebase maintains appropriate technical and organisational safeguards for international data transfers, including applicable data processing agreements.

Section 12

Sensitive Personal Data

Under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and India's DPDP Act, 2023, the following data we may collect is classified as sensitive personal data:

  • Password: Stored in encrypted form via Firebase Authentication. We never store or access your password in plain text.
  • Mobile number: Optional. Never shared with other users or third parties for marketing purposes.
  • Birthday: Optional. Used only to send you a birthday notification and never displayed publicly.

You provide explicit consent to our collection of this sensitive data by voluntarily entering it into the app. You may delete any sensitive data at any time from Settings → Edit Profile or by deleting your account.

We implement reasonable security practices as required by Rule 8 of the IT SPDI Rules, 2011, to protect sensitive personal data from unauthorised access, use, or disclosure.

DPDP Act — Children: Under India's DPDP Act, 2023, users under 18 are classified as children. We do not engage in tracking, behavioural monitoring, targeted advertising, or profiling of users under 18. Any processing of data of users under 18 requires verifiable parental or guardian consent.
Section 13

Children's Privacy

Flick is not directed at children under the age of 13. Under India's DPDP Act, 2023, users under the age of 18 are classified as children and their data must be processed with verifiable parental or guardian consent.

Users aged 13–17: Must have obtained verifiable parental or guardian consent before using the Service. By using the Service if under 18, you represent that your parent or guardian has reviewed and consented to this Privacy Policy and the Terms of Service on your behalf.

Restrictions for users under 18: We do not engage in targeted advertising, behavioural profiling, tracking, or monitoring of users under 18.

Data deletion: If we become aware that a child under 13 has provided personal data without verifiable parental consent, we will delete that data within 7 days and terminate the account, in compliance with the DPDP Act's erasure obligations. If you are a parent or guardian and believe your child under 13 has used Flick without consent, please contact us immediately at support@joinflick.in.

Prohibition of Child Sexual Abuse and Exploitation (CSAE): Flick strictly prohibits any content or behaviour that sexually exploits, abuses, or endangers children, including but not limited to child sexual abuse material (CSAM), grooming, sextortion, or trafficking of a minor. Violation of this policy results in immediate content removal and account termination.

Reporting: Every profile, photo, and message in the app includes a built-in "Report" option, which you can use to flag any content or user that violates this policy. Reports are reviewed by our moderation team, and confirmed violations are removed immediately. Where required by applicable law, we report confirmed CSAM to the National Center for Missing & Exploited Children (NCMEC) or the appropriate authority.

Child safety point of contact: For reports or concerns specifically related to child safety on Flick, contact support@joinflick.in.

Section 14

Data Security

We implement appropriate technical and organisational measures to protect your personal data:

  • Encryption in transit: All data transmitted between the app and our servers uses TLS/SSL encryption
  • Encryption at rest: Data stored on Firebase is encrypted at rest
  • Access controls: Firestore Security Rules ensure users can only access data they are authorised to access
  • Firebase App Check: Prevents unauthorised API access to our backend
  • Firebase Crashlytics: Monitors for crashes that could indicate security issues
  • Infrastructure compliance: Google Firebase is ISO 27001 certified and SOC 2/3 compliant

Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data. In the event of a data breach that affects your rights and freedoms, we will notify affected users and the relevant authorities as required by applicable law.

Section 15

Data Retention

Data typeRetention period
Account and profile informationFor the duration of your account. Deleted within 30 days of account deletion request (7 days for children's data under DPDP Act)
Submitted contest photosFor the duration of your account. After deletion, photos are removed from Firebase Storage within 30 days. Contest leaderboard records may retain anonymised submission data (no personal identifiers) to preserve contest integrity
Private messagesDeleted within 30 days of account deletion
Push notification token (FCM)Deleted immediately upon account deletion or device token refresh
Crash reports and analyticsRetained in anonymised, aggregated form for up to 14 months per Firebase's default retention policy
Support correspondenceRetained for up to 3 years for legal and dispute resolution purposes
Legal hold dataRetained as required by applicable law, even after account deletion
Section 16

Your Rights & Choices

Under India's DPDP Act, 2023, and applicable privacy law, you have the following rights regarding your personal data:

📋 Right to Access
View your profile information and activity within the app at any time.
✏️ Right to Correction
Edit your profile information from Settings → Edit Profile at any time.
🗑️ Right to Erasure
Delete your account from Settings → Account → Delete Account. Data deleted within 30 days (7 days for children's data).
🚫 Right to Withdraw Consent
Remove optional sensitive data from your profile or delete your account to withdraw consent.
🔒 Right to Privacy Controls
Toggle private account, location visibility, and notification preferences from Settings → Privacy.
📦 Right to Data Portability
Request a copy of your personal data in a portable format by emailing support@joinflick.in.
🙈 Right to Restrict Processing
Contact us to request restriction of processing in specific circumstances permitted by law.
📢 Right to Grievance Redressal
Under the DPDP Act, you have the right to raise a grievance with us and to approach the Data Protection Board of India if unresolved.

To exercise any right that cannot be performed in-app, contact us at support@joinflick.in. We will respond within 30 days as required by applicable law, or within 7 days for children's data erasure requests.

Section 17

Google Play Data Safety

Google Play requires app developers to declare their data collection and sharing practices in the Data Safety section of the app's Play Store listing. The information declared in that section is consistent with this Privacy Policy. The following is a summary for reference:

  • Data collected: Name, email address, user ID, photos, device ID, app activity, crash logs
  • Data shared with third parties: Device identifiers with Google AdMob for advertising; crash data with Firebase Crashlytics
  • Data encrypted in transit: Yes
  • Data deletion option: Yes — via Settings → Account → Delete Account
  • Required app functionality: Account registration data is required; all other fields are optional

If you believe there is any discrepancy between the Data Safety section and this Policy, please contact us at support@joinflick.in.

Section 18

Third-Party Services

Flick integrates the following third-party services. Each processes data according to its own privacy policy:

ServicePurposePrivacy Policy
Firebase AuthenticationUser login, account management, Google Sign-Infirebase.google.com/support/privacy
Firebase FirestoreDatabase — stores all app and user datafirebase.google.com/support/privacy
Firebase StorageStores uploaded photosfirebase.google.com/support/privacy
Firebase Cloud FunctionsServer-side logic — contest results, notifications, XPfirebase.google.com/support/privacy
Firebase Cloud MessagingPush notifications deliveryfirebase.google.com/support/privacy
Firebase CrashlyticsCrash reporting and performance diagnosticsfirebase.google.com/support/privacy
Firebase AnalyticsAnonymised aggregate usage analyticspolicies.google.com/privacy
Firebase App CheckSecurity — prevents unauthorised API accessfirebase.google.com/support/privacy
Google AdMobIn-app advertisingpolicies.google.com/privacy
Google Sign-InOAuth authentication optionpolicies.google.com/privacy
Section 19

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, new features, or legal requirements. We will notify you of material changes through an in-app notification or push notification, and by updating the "Last updated" date at the top of this page.

Your continued use of the Service after changes are posted constitutes your acceptance of the updated Policy. If you do not agree to the updated Policy, you must stop using the Service. We recommend reviewing this Policy periodically.

Section 20

Contact Us

For any questions, concerns, data requests, or complaints regarding this Privacy Policy or your personal data, please contact us:

We aim to respond to all privacy-related requests within 30 days as required by applicable law, or within 7 days for urgent matters.

Data Protection Board of India: Under the DPDP Act, 2023, if you are not satisfied with our response to a privacy complaint, you have the right to approach the Data Protection Board of India once it is fully operational (expected May 2027 per current DPDP Act implementation timelines).