Privacy Policy
Last updated: 28 September 2026 — Version 3.6
This Privacy Policy explains how Flirty collects, uses, shares and protects personal data when you use the Flirty mobile app, website and related services. It is written to match the app as it operates today. If a feature is not described here, you should not assume we collect data for it.
Flirty is for adults only. You must be 18 or older to use the Service.
1. Who We Are
In this Policy, “Flirty”, “we”, “us” and “our” means FLIRTY LTD, a company registered in England and Wales under company number 14409571, which operates the Flirty app and flirtyapp.com. Where UK or EU data protection law applies, we are the controller of personal data we process for the Service.
Our address is Unit 82A, James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE, United Kingdom.
Privacy requests: privacy@flirtyapp.com. Account security (for example, a sign-in or email change you did not make):security@flirtyapp.com. Everything else, including safety concerns: support@flirtyapp.com.
We have not listed a Data Protection Officer or EU representative in this Policy. If applicable law requires us to appoint one, we will publish those details before relying on them.
2. Information We Collect
We collect the information needed to create accounts, run a dating and social app, provide paid features, keep users safe, comply with law, and keep the app working.
- Account data: Email address, the sign-in method you use (email link, Google, Apple or Facebook) and its identifier, user ID and date of birth. Used to create and secure your account, check that you are 18 or over, send you service emails and prevent abuse. We do not ask for or store a phone number.
- Profile content: Display name, photos, videos, stories, bio, gender, who you want to see, what you are looking for, interests, current vibe, prompts (including recorded voice answers), This-or-That answers, and the optional “About me” details you choose to add: height, drinking, smoking, vaping, children, relationship style, exercise, sleep, pets, tattoos, piercings, education, job title, workplace, hometown, languages and star sign. Sexual orientation is optional and covered in section 3. Used to show your profile, help people discover you and moderate content.
- Messages and interactions: Messages, photos, videos and voice notes you send in chat, reactions, read receipts, typing indicators, flirts and Super Flirts, likes, skips, “see less often” choices, follows, blocks, mutes and reports. Also: which profiles you view and who views yours, who views your posts and stories and for how long, replies to prompts, and monthly activity totals (such as counts of profile views, flirts and conversations). Used to deliver conversations, show you your activity, rank discovery, prevent spam and abuse, and investigate reports.
- Location data: With your permission, your device location. We keep it privately, rounded to about 1 km, and derive a town, country and a coarse area code (a geohash covering roughly 5 km) from it. If you use Travel Mode, we store the place you choose instead. Used for nearby discovery, distance, local content and fraud prevention.
- Device, session and security data: Device type, brand and model, operating system, app version, push token, App Check token, IP address, an approximate city and country looked up from your IP address, a one-way hash of your IP address, a device fingerprint (a hash that lets us recognise a device you have used before), and session records. We keep your IP address itself in security logs of sensitive account actions, such as account deletion, data export and appeals. Crash and performance data is collected where enabled (see section 6). Used to operate the app, show you your active sessions, keep your account secure, diagnose problems and stop automated abuse.
- Purchases: Product, subscription tier, renewal and entitlement status, and purchase tokens from Apple, Google and RevenueCat, plus your use of monthly allowances such as Super Flirts and Rewinds. Used to provide paid features, apply limits and respond to support requests.
- Email delivery data: When we email you, our email provider tells us whether the email was delivered, bounced or marked as spam, and whether it was opened or a link was clicked. We store these events against a one-way hash of your address and a masked copy (for example, a***@example.com). If an address permanently fails, we stop sending to it.
- Advertising and analytics data: Advertising identifiers where allowed, ad interactions, usage events, screen views and your consent choices. Used to show ads to free users, measure performance and respect your consent settings.
- Safety and moderation data: Reports you make or that are made about you, evidence attached to reports, automated moderation results for uploads, moderation decisions, warnings, strikes, suspensions, bans and appeals, and safety signals such as how often an account is reported and how reliable a reporter's past reports have been. Used to enforce our rules, prioritise reports and protect users.
- Support and feedback: Messages you send us, and feedback you give in the app.
Things we do not do:
- We do not receive your payment card number, CVV or bank details. Apple and Google handle payment.
- We do not perform background, identity or criminal-record checks on users.
- We do not use face recognition or age estimation. Age is checked against the date of birth you give us. If we introduce stronger age assurance, we will update this Policy.
- We do not access your contacts.
- We remove location and other embedded metadata from photos and videos before they are uploaded. We use your camera, microphone and photo library only when you choose to take, record or pick media.
- Messages are not end-to-end encrypted. They are protected in transit and at rest by our infrastructure providers, but authorised Flirty systems and staff can access them where needed for delivery, support, safety, abuse prevention, legal compliance or troubleshooting.
3. Sensitive Information
Sexual orientation is “special category” data under UK and EU law, and sensitive personal information under some US state laws. On Flirty it is optional. You do not need to give it to use the app. If you do, we ask for your explicit consent first and record that consent. Your orientation is shown on your profile. It isnot used for matching or to decide who you are shown. Discovery uses your gender and who you want to see.
You can hide your orientation at any time with the “Show on profile” setting, or withdraw consent in Privacy Settings. Either one deletes the stored value, not just hides it. We keep the record of your consent choices so we can show we had consent while we used the data.
Your gender and who you want to see are published on your profile because discovery needs them to work. Someone could infer your orientation from those two fields together. If you are not comfortable with that, you can use Incognito Mode (section 5) or choose “Everyone”. Relationship style (for example, open or non-monogamous) is optional and shown on your profile only if you add it.
4. How We Use Information
- Provide the app: Account, profile, discovery, flirts, chat, media, subscriptions, support and settings. UK/EU legal basis: contract.
- Discovery and ranking: We rank profiles using things like distance, shared interests, how complete a profile is, how recently someone was active and how people have interacted. UK/EU legal basis: contract and legitimate interests.
- Safety and security: Automated scanning of uploads, report handling, fraud prevention, rate limits, account integrity and security logs. UK/EU legal basis: legitimate interests, or legal obligation where the law requires us to act.
- Sexual orientation: Shown on your profile only. UK/EU legal basis: your explicit consent.
- Service messages: Sign-in links, security alerts, account and subscription notices, enforcement notices and replies to requests, by email, push and in-app message. These are part of running your account. UK/EU legal basis: contract, legal obligation and legitimate interests.
- Reminders and news: Push notifications and in-app messages such as “we miss you” reminders, profile tips, monthly insights, birthday messages and occasional announcements about Flirty. You can turn off reminder pushes with the Reminders setting in Notification settings. UK/EU legal basis: legitimate interests.
- Marketing email: We do not currently send marketing email. If we start, we will send it only to people who have turned on “Marketing emails” in Privacy Settings, and every email will include an unsubscribe link. UK/EU legal basis: consent.
- Analytics, crash reporting and ads: See section 6. UK/EU legal basis: consent in the UK and EEA; legitimate interests elsewhere.
- Legal and business administration: Tax, accounting, legal requests, disputes and enforcing our terms. UK/EU legal basis: legal obligation and legitimate interests.
Automated decisions
Most moderation decisions are made by people. Automated tools scan uploads and help us rank reports, but a flagged post is held for a person to review before any action is taken against your account. Three things happen automatically, without a person reviewing them first:
- Under-18 check: if the date of birth on an account shows the person is under 18, the account is banned.
- Re-registration check: if someone who was banned, suspended or had active strikes deletes their account and signs up again with the same email address or sign-in account, the same restriction or strikes apply to the new account.
- Profile photos: if our moderation provider rejects a new profile photo, it is removed and your previous photo is restored.
For the two account checks, the notice we send you says the decision was automated. You can appeal from the app, and a person will review your appeal. You can also ask for human review by emailing privacy@flirtyapp.com.
5. What Other Users Can See
Your public profile. Any Flirty user can see your display name, age, photos, videos, bio, gender, who you want to see, what you are looking for, interests, current vibe, prompts and voice answers, This-or-That answers, the “About me” details you add, your star sign if you add it, your town and country (or your Travel Mode location), roughly how far away you are, and when you joined. If you choose to show your sexual orientation, it is shown too.
We never publish your date of birth, email address, precise location, sign-in details or payment details.
Activity status. Other users are not shown whether you are online or when you were last active. We use when you were last active to rank discovery.
Profile and content views. When you view someone's profile, post or story, we record it. Flirty Elite and Diamond members can see who viewed their profile, posts and stories. All users see a monthly count of profile viewers.
In a chat. The person you are chatting with can see when you are typing. Your messages are marked as read when you read them, and senders with a paid plan can see this.
Stories are shown to people you have an accepted flirt with, for 24 hours.
Incognito Mode (Flirty Diamond) removes your profile from discovery and search, and stops your profile and content views being recorded. People you already have an active flirt with can still see you.
Messages are visible to you, the recipient, and to Flirty only as needed to operate, secure, moderate and support the Service. A recipient can screenshot or otherwise keep copies of what you send them.
6. Advertising, Analytics and Tracking
Free users see ads through Google AdMob, as native ads in the Discover feed and the story viewer. Every paid plan removes ads. We use Google's User Messaging Platform (UMP) to ask for consent where the law requires it. How ads are requested depends on your region. In the UK and the EEA, ads are personalised only if you accept personalisation in the UMP consent form; otherwise they are non-personalised. Everywhere else, every ad request is non-personalised and uses Google's Restricted Data Processing signal (“rdp=1”), so Google must not treat it as a sale or share of personal data under US state privacy laws. Google Consent Mode v2 ad signals follow the same rules.
We use Firebase Analytics, Crashlytics and Performance Monitoring to understand how the app is used and to fix crashes. In the UK and the EEA they are off by default and only collect data after you opt in through the controls in Privacy Settings. Elsewhere they are on by default and you can turn them off with the same controls. If we cannot tell your region, we treat you as if UK/EU rules apply and collect nothing until you opt in. Analytics identifies you by a hashed user ID. It receives your age group and approximate area, not your exact date of birth or location. Some Firebase processing (authentication, database, messaging, App Check) is needed for the app to work and is not optional.
We do not sell personal data. Because ads outside the UK and EEA are always non-personalised and use Restricted Data Processing, we do not consider our advertising a “sale”, “share” or targeted advertising under US state privacy laws such as the CCPA. For this reason, the app has no “Do Not Sell or Share” toggle. If we change this, we will update this Policy and add the required opt-out first. You can also use device controls such as iOS App Tracking Transparency or Android's ad settings.
7. Who We Share Information With
Other users, as described in section 5.
Service providers who run parts of Flirty for us, and may only use the data to provide that service:
- Google (Firebase and Google Cloud): hosting, database, file storage, sign-in, push notifications, App Check, Remote Config, analytics, crash reporting and performance monitoring.
- Google Maps Platform: turns your location into a town name (we send your device coordinates to do this), searches places for Travel Mode, and shows the Travel Mode map.
- Bunny.net: a content delivery network that serves public profile and feed photos quickly, so it sees the IP address of people viewing them. Chat media never goes through it.
- api.video: stores, processes and streams videos, including chat videos, which are private.
- Sightengine: scans photos and videos uploaded to your profile, posts and stories for content that breaks our rules. It does not scan chat messages or chat media.
- Maileroo: sends our emails. It receives your email address and the content of the email, and tells us whether the email was delivered, opened or clicked.
- RevenueCat: manages subscriptions. It receives your user ID, email address, display name and purchase history.
- ipapi.co and ipwho.is: receive your IP address to look up an approximate city and country for your session list and security checks.
- Google AdMob and UMP: ads and consent, as described in section 6.
- Connectivity checks: to tell whether you are online, the app briefly contacts public servers run by Cloudflare, Google, Apple and icanhazip.com. They receive your IP address and nothing else.
Apple and Google handle app downloads and payments under their own privacy policies, as independent controllers.
Sign-in providers. If you sign in with Google, Apple or Facebook (Meta), that provider handles the sign-in under its own privacy policy. The Facebook SDK is included in the app for this. Automatic event logging and advertiser ID collection are turned off in it.
Legal, safety and business. Professional advisers where needed. Law enforcement, regulators or courts where the law requires it, or where it is needed to prevent harm, fraud or illegal activity. A buyer or successor if the business is sold or reorganised.
8. How Long We Keep Data
While your account is active, we keep your data for as long as it is needed to provide the Service, unless a shorter period is listed below.
- Chats: when a flirt ends (the timer runs out, or either person unmatches, declines or blocks), the whole conversation and its photos, videos and voice notes are deleted for both people.
- Unanswered flirt requests: 14 days.
- Stories: shown for 24 hours, then deleted within the following 24 hours.
- Notifications: 60 days.
- Prompt replies: 30 days.
- Who viewed your profile: until the end of the month, plus a few days.Who viewed your posts and stories: 90 days.
- Sessions: 30 days after the session was last used.
- Email delivery events: 90 days.
- Undeliverable email addresses: a hash of an address that permanently failed is kept so we never send to it again.
- Strikes: stop counting after 90 days, and stay on your account history until your account is deleted.
- Unfinished sign-ups: deleted after 7 days.
- Data export files: 7 days.
- Reports and evidence: while the accounts involved exist. When you report a message, a copy of it is kept with the report, even if the chat is later deleted. If a reported person deletes their account, reports about them from the previous 90 days are kept for 90 days after the deletion (see below).
Deleting your account
- When you ask to delete your account, it is deactivated straight away and deleted after48 hours. We email you when you make the request. If you sign back in within those 48 hours, the deletion is cancelled. The exception is a permanently banned account: its deletion cannot be cancelled.
- If you want a break instead, use Take a Break. It hides your profile without deleting anything.
- After 48 hours, we delete your account, profile, photos, videos and other content. This includes videos held by api.video and cached copies of photos held by our content delivery network. Messages you sent in chats that are still active stay in the other person's chat, shown as from “Deleted User”.
- Reports you made are deleted, and so are reports about you and their evidence, with one exception: reports about you from the 90 days before deletion, and their evidence, are kept for 90 days after it, so deleting an account cannot erase a case that is still being handled. They are then deleted automatically. We keep a limited set of records where we need to: consent records (linked to a hashed identifier), security logs, records of moderation decisions, the ban record described below, and records needed for tax, accounting, chargebacks or legal claims.
- Backups are overwritten on a rolling schedule. We do not restore deleted data from backups except for disaster recovery, security or legal needs.
Ban records
If an account that is banned, suspended or has active strikes is deleted, we keep a small record so the restriction cannot be avoided by signing up again. It contains only one-way hashes of the email address and sign-in accounts, the rule involved, the relevant dates and any strikes still in force. Nothing else about the person is kept for this purpose. The record is deleted automatically when the suspension and strikes would have expired. A permanent ban is kept for as long as the ban stands.
9. Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict or object to the use of your personal data, withdraw consent, opt out of sale/share or targeted advertising, limit use of sensitive personal information, and appeal or complain to a regulator. We will not discriminate against you for exercising privacy rights.
In the app you can edit your profile, change privacy, ad and analytics choices, block and report, pause or delete your account, and download your data.
The self-service download covers:
- your profile and preferences;
- photos, videos and stories;
- messages you sent;
- flirts and matches;
- likes, profiles you viewed and prompt replies;
- people you blocked or muted;
- reports you made and your appeals;
- warnings, strikes and restrictions;
- notifications and post alerts;
- devices and sign-ins;
- consent records;
- your subscription status;
- settings.
It does not include:
- messages other people sent you;
- other people's names or photos;
- who viewed you;
- IP addresses;
- who reported you.
If you ask for a download while deleting your account, it covers the main categories (profile, media, messages, flirts, blocks, reports you made, subscription status and settings). Anything not covered can be requested fromprivacy@flirtyapp.com. We may need to verify your identity, and we may refuse or limit a request where the law allows, for example to protect another user's privacy, keep safety records or prevent fraud.
If you think we have got something wrong with your data, tell us first — we would rather put it right. You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113. If you are in the EEA, you can go to your local data protection authority instead.
10. Where Your Data Is Stored and Transferred
Our main database and file storage are in the European Union (Google Cloud EU multi-region locations), and our servers run in London. Some of the providers in section 7 process data in the United States and other countries. Our content delivery network serves images from locations around the world. Where UK or EU transfer rules apply, we rely on adequacy decisions (including the UK–US and EU–US data bridge and framework, where the provider is certified), Standard Contractual Clauses and the UK International Data Transfer Addendum.
11. Security
We protect personal data with encryption in transit, access controls, App Check, rate limits, monitoring, restricted and audited administrative access, and deletion workflows. No online service is perfectly secure, so take care when sharing sensitive content with other users. If you think your account has been accessed without your permission, email security@flirtyapp.com.
12. Children
Flirty is not for anyone under 18. We do not knowingly allow minors to create accounts. If you believe a minor is using Flirty, report the account in the app or email support@flirtyapp.com. If we reasonably determine an account belongs to a minor, we remove it.
13. Changes
We may update this Policy when the app, the law or our providers change. If changes are material, we will tell you in the app, by email or on the website where required. The date at the top shows when this version took effect.
Questions? support@flirtyapp.com