Privacy Policy

Effective September 27, 2026

The short version

The full detail is below. It's written in plain language on purpose. If anything is unclear, email social@flockcorp.com.

Who we are

Flock is a social coordination app that helps you plan nights out with friends. Flock ("we", "us", "our") is operated by Flock Social LLC, a Pennsylvania limited liability company. We are the data controller for personal information processed through the Flock app, flockcorp.com, the venue dashboard, and the venue sensors described in section 3.

This policy covers all of those. It applies whether you use Flock in the iOS app or in a browser, whether you have an account or answer an invite link as a guest, and whether you use Flock to make plans or to run a venue. Write to us at social@flockcorp.com. Our postal address is 2610 Long Ridge Dr, Hellertown, PA 18055.

What we collect

You provide directly

Photos, and what is hidden inside them

A photo from a phone carries more than the picture. The file can hold the exact spot it was taken, accurate to a few metres, the make and model of the camera, the moment of capture, and on many cameras a small copy of the original frame from before you cropped it. None of that shows up in any app, so nobody knows they sent it.

Before we store an image you upload, our server strips that hidden data out. It covers avatars, chat photos and direct message photos, in JPEG, PNG and WebP, which is what phones produce. What comes off is the EXIF, XMP and IPTC blocks: GPS position, device identifiers, capture times, embedded thumbnails, and free-text comments. What stays is the colour profile, because dropping that changes how the picture looks. The picture itself is not re-encoded, so nothing about its quality changes. If a file does not parse the way its format says it should, we store it unchanged rather than risk corrupting it, and we do not claim to have cleaned it.

Every image is also screened against our content rules before anyone can see it. That check is described under Who we share with and in our Community Guidelines.

We collect automatically

Location

Anonymous budget data

Budget submissions are stored on our servers but the system is designed so individual amounts are never returned to other flock members. Until the budget settles, the only things other members see are counts: how many have answered, how many are in the flock, and whether it is ready. No number at all. The budget settles when every member who has accepted the plan and every guest who said they are in from an invite link has answered, and at least three members have shared an amount (a guest's amount goes into the figure but does not count toward the three). The person who created the plan can settle it sooner by locking it, which also needs three members' amounts and closes it to anyone who has not answered yet. Only when it settles is a single group figure published, and what is published is a rounded-down band rather than anyone's actual figure. It is published once and never moves, because a ceiling is a minimum and a number that moved when the fourth person answered would name whoever has the least. This is a core product guarantee enforced in code.

Venue occupancy sensors

A venue can install a small Flock sensor near its entrance. It is the only part of Flock that is hardware, and it measures the room rather than the people in it. This section applies to everyone who walks into a venue that has one, whether or not you use Flock.

What the sensor sends us

Every 30 seconds it sends these numbers, and nothing else:

What it does not do

A reading is filed against the venue and the sensor that sent it, and it holds nothing else: no name, no account, no phone or device belonging to anyone in the room, nothing that separates one person from the next. So there is nothing in one to trace back to you.

What we do with the readings

They produce the "Live Occupancy" figure and the 12-hour chart on that venue's page in the app, and the same figures in that venue owner's dashboard. We keep them as a record of how busy the venue has been over time. Because they contain no identifiers, deleting your Flock account does not touch them and there is nothing in them belonging to you to delete. We do not currently delete them on a schedule.

The occupancy card also shows how many Flock accounts checked in at that venue in the last hour. That is a count of separate accounts. No names go with it.

If we ever put anything in this device that can tell one person from another, this section is rewritten before the device goes in.

How we use your information

We do not sell your personal information. We do not share it for cross-context behavioural advertising. We do not run ads, and we do not use your messages or your content to train advertising models, ours or anybody else's.

Our legal bases

If you are in the EEA or the UK, the law wants us to say why each kind of processing is lawful. Here it is, plainly.

Where we rely on legitimate interests, you can object. See If you are in the EEA or the UK.

Birdie and Roost

Flock has two features that send text to a large language model. Both use Google's Gemini API. They are separate features with separate audiences and separate payloads, so they get separate paragraphs. Neither one has any ability to write to your account, post on your behalf, or change anything. They read and they answer.

Birdie, the assistant in the app

When you chat with Birdie, what goes to Google to produce the reply is your first name, your age bracket (under 18, under 21, or adult, never your birthday), your messages in that conversation, and, only if you have allowed location, your approximate position rounded to about a kilometer.

Every message also carries where you are in the app, because otherwise Birdie cannot answer "is this place busy". That means the screen and tab you are on and, when you have one open, the name of the flock you are looking at with its venue and status, and the name of the venue you are looking at with its Google place identifier. This goes with every message, not only when you ask about a plan.

On top of that, if you ask Birdie about your plans or your friends, the names, venues and times of your flocks and your friends' display names are included so it can answer. When Birdie looks up a venue, the venue and the crowd numbers we hold for it go with the question.

What is not sent: we don't send your email, exact coordinates, or messages from your flocks or your direct messages. The roster of who is in a flock is replaced by a count. Birdie conversations are not used by us for advertising and we do not use them to train any model of our own. What Google may do with the text it receives is governed by Google's own terms for the Gemini API.

Birdie's answers are generated. They can be wrong. Nothing Birdie says is advice about your safety, your health, your money, or the law.

Roost, the advisor for venue owners

Roost is the product venue owners will pay for, and it works two ways. You can tap one of the suggested questions, or you can type your own question about your business.

When you tap a suggested question, what goes to Google is the identifier of that question and a block of facts our server has already computed about your venue: things like your projected peak hour, your own recent occupancy readings, the operating facts you gave us at intake, the weather, the ticketed events listed near you, and where your venue sits inside its cohort. The model's only job there is wording. Every number in the answer is put back in by our server afterwards, and an answer that contains a number the model wrote is thrown away unread.

When you type your own question, the question itself goes to Google as well, inside the same request. It is capped at 280 characters and stripped of control characters first. It is used to route your question and, where the answer is general trade advice rather than a reading of your own numbers, to write that advice.

What Roost does not send: nothing about any Flock user. No consumer's name, account, message, budget, or position. No other venue's identity or figures. The cohort comparison your answer may draw on is an aggregate, and it is only computed once two floors are cleared: five reporting owners besides you, and three of their readings landing on the number itself. See Venue owners and business data.

What Roost stores: not your question. We keep counts, how many questions your venue asked today and how many tokens they cost, so we can meter the feature. The text of a typed question is not written to our database.

Roost is an analyst, not an oracle. Every figure it quotes carries its source and its date. Where our data cannot answer, it refuses instead of guessing. Predictions are estimates. Nothing Roost says is a guarantee about how your business will do, and nothing it says is legal, tax, employment or financial advice.

Venue owners and business data

Venues appear on Flock whether or not anybody claims them, because listings are built from public sources such as Google Places and from what Flock users post. Claiming a venue does not create the listing; it gives you tools to manage your side of it. This section is about what we collect from the person and the business behind a claimed venue.

A venue account is an ordinary Flock account, so everything above applies to it too. On top of that we store:

What we do with what you submit

Your occupancy readings do three things. They set the live number users see at your venue while they are fresh. They become training labels for the crowd model, which serves every venue, not only yours. And once enough venues in one city and category are reporting, they contribute to a cohort figure that answers the question every operator asks: was it just us, or was everyone slow.

That cohort figure is built so that no venue's own number can be read out of it, and it has to clear two floors before it is published at all. First, at least five reporting owners other than the one asking must have posted into the same city, category, night and hour band. We count owners rather than venues so that one company with five rooms cannot become five voices. Second, at least three of those owners' readings must round to the very number we are about to print, so the number describes several businesses rather than sitting on top of one. Both are higher floors than we use anywhere else, because a venue is a pin on a public map with a name and an address and the set of them is short enough to count.

The asking venue is inside the group its own figure is drawn from. Leaving it out would make the number change depending on who asked, which is its own way of leaking. The figure itself is the middle reading of that group, rounded to the nearest ten, so it is not read off any single venue exactly: we pick the middle reading rather than averaging the two either side of it, precisely so that no arithmetic connects the published number back to one reading. The most anyone can learn about another venue's reading is which rounded step it fell near. When either floor is missed we say so and give no number, and we do not say which floor it was, because that would itself describe who reported.

Readings are accountable in the other direction too. When three or more verified users in the room contradict a live owner reading by a wide margin, we mark it, and repeated divergence suspends the override for that venue so users see our own estimate again.

What venue owners see, and do not see

The dashboard shows counts and curves built from Flock activity: how many groups considered the venue, check-in counts, predicted busyness, review text that is already public. It never shows individual users' identities, their budgets, their positions, their messages, or who voted for what. The advisor that reads this data is structurally forbidden from touching budgets at all.

Roost, the paid venue plan, is bought on flockcorp.com. Stripe takes the payment, and we never see or store the card. What it costs, and when a venue can be charged, is under Venue fees in our Terms of Service.

Who we share with

We share information only with the companies that help us run Flock, and only as much as the job needs. This is the whole list, taken from the dependency inventory the codebase keeps of every outside service Flock touches. Each entry says what that company receives.

They run Flock itself

They receive something about you

They receive a place or a search, not a person

They receive nothing about anyone

The people around you

Other members of a flock see what you share inside it: your messages, your RSVP, your vote, your reliability score, and your live location while you have it turned on. The person you are in a direct message with sees what you send them. Your friends see your availability status while it is set. When you press SOS, your trusted contacts receive an email, and people who, like you, have accepted a confirmed plan starting within twelve hours of the alert get an alert in the app, unless they are banned or one of you has blocked the other. Both carry your location when your phone can find one. A venue owner sees the reviews written about their venue, including yours.

Everyone else

We may disclose information to comply with a valid legal process, to protect people from imminent harm, to report apparent child sexual abuse material as the law requires, or in connection with a merger or sale of the business, in which case we will tell you before your information becomes subject to a different policy.

We do not sell personal information, and we do not share it with anyone for advertising.

Analytics, error reports, and email

Product analytics, with PostHog

We use PostHog to understand how Flock is used: pages viewed, and a short list of events we write by hand, such as signing up, logging in, creating a flock, sharing an invite link, and submitting a crowd report. Events are tied to your account number, never to your name or your email, and only signed-in people get a profile at all. Like any web request, the one that carries an event also carries your IP address to PostHog's servers.

None of this happens until you agree to it. Before you answer, and after you decline, PostHog is never started, nothing is written to your device for it, and no event is sent. If you agreed and then change your mind, declining also clears the identifier PostHog stored.

The youngest person allowed on Flock is 13, so the settings are written to collect as little as they can, in code rather than in a dashboard where a toggle could widen them later:

Birdie has one extra measurement. Every call to the model records how many tokens it used and how long it took, against your account number. The words are deliberately left out: PostHog is where we measure cost and speed, not where conversations go.

Crash and error reporting, with Sentry

Sentry is wired into both the app and the server and it is not switched on. With no connection string configured, the code never starts it and the software is not even downloaded to your device, so no crash report is being sent anywhere today.

If we turn it on, this is what it will do. Sentry will receive unhandled errors and a sample of performance traces: the error, where in our code it happened, the page or request it happened on, and the recent steps that led to it. Before any of that leaves your device, invite tokens and anything shaped like a coordinate are replaced with the word "redacted", in the address, in the referrer, in breadcrumbs, in the trace name, and in the individual spans. We do not attach your name or your email to a Sentry event. We will update the effective date on this page when it is switched on.

Email, and how to stop it

Flock sends two kinds of email. Transactional email keeps your account working: the verification link at sign-up, a password reset you asked for, and SOS alerts to your trusted contacts. Those cannot be turned off while your account is active, because turning them off would break the account.

Everything else is optional and every message carries an unsubscribe link that works without signing in. The waitlist confirmation and the Monday venue digest both do, and the two links work differently because the lists are different. Unsubscribing from the waitlist writes your address to a do-not-mail list. Turning off the Monday digest switches off a setting on your venue account instead, so it stops that one email and writes nothing about your address. The digest is off by default and only sends if a venue owner switches weekly reports on. An address that hard-bounces or is reported as spam is added to the do-not-mail list automatically.

The do-not-mail list is checked inside the one function every outgoing message in Flock passes through, rather than in each sender, so there is nothing to forget. One honest limit: if that check cannot reach our database it lets the message go rather than holding it. We would rather send a message we should not have than swallow a password reset or an emergency alert because of a database blip.

Two deliberate exceptions. Unsubscribing from a list does not stop a password reset or an SOS alert, because those are not lists you are on. And an SOS alert is sent even to an address that has hard-bounced or reported us as spam. A bounce says a message failed, not that the person refuses to hear from you, and a complaint about a marketing email is not a refusal of an emergency from the person who named that contact. Because nothing on our side stops that send any more, the Safety screen marks a trusted contact whose address has been failing, so you can fix the address rather than find out later.

How long we keep it

Deleting your account

You can delete your account from inside the app (You → scroll to the bottom → Delete account) or from our account deletion page. It is a real delete, not a deactivation, and it cannot be undone. To protect your account, deleting it asks you to confirm your password, or to sign in again if you use Apple or Google.

What is erased

What survives, and why

If you would rather have a copy of your data before you delete it, you can get one yourself in the app, under You and then Get a copy of my data. You can save it or copy it out, depending on your device. If you would rather we sent it, ask us at social@flockcorp.com.

Your choices and rights

If you are in the EEA or the UK

Flock Social LLC is the controller for the processing described here, and Our legal bases says which basis covers what. You have the following rights, and you exercise all of them the same way, by writing to social@flockcorp.com:

We answer within one month. We will not charge you and we will not make the service worse for asking. If we cannot identify you from what you send us, we will ask for enough to be sure we are not handing your data to somebody else.

We do not make decisions about you by automated means that produce legal effects or anything similarly significant. The crowd model predicts how busy a building is; it does not decide anything about a person.

If you are in California

Under the California Consumer Privacy Act, as amended by the CPRA, these are the categories of personal information Flock has collected in the last twelve months, why, and who it goes to. Every one of them is described in more detail earlier in this policy.

Sensitive personal information, in the CPRA's sense, means your precise geolocation and your account credentials. We use them only to deliver the features you asked for and to secure your account, which is a use the law does not require us to offer a limit on. We do not use or disclose sensitive personal information for any other purpose, and we do not sell or share it.

We have not sold personal information, and we have not shared it for cross-context behavioural advertising. We do not have an advertising business, we run no advertising software, and there is no "Do Not Sell or Share My Personal Information" link on Flock because there is nothing for it to switch off.

You have the right to know what we collect and why, to get a copy, to correct it, to delete it, and not to be discriminated against for asking. Email social@flockcorp.com and say which one you want. An authorised agent may ask on your behalf with written permission we can verify. We verify a request by checking that it comes from the address on the account, or by asking you to confirm from inside the app.

Children

Flock is for people 13 and older. Sign-up asks for a year of birth and our server works the age out from it rather than trusting the app, so an under-13 account is refused rather than merely discouraged. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, write to social@flockcorp.com and we will delete it.

Several countries in the EEA set the age at which a young person can consent to an online service above 13, most often at 16. Flock has no way to collect and verify a parent's consent. So if you are between 13 and the age of digital consent where you live, you need your parent or guardian's permission to use Flock, and by using it you are telling us you have it. A parent or guardian who wants an account closed can write to social@flockcorp.com and we will close it.

Flock has zero tolerance for child sexual abuse and exploitation. Our Community Guidelines describe what we do about it, including reporting apparent material to the National Center for Missing and Exploited Children.

We do not build advertising profiles of anyone, so we do not build them of minors either. The analytics settings under Analytics, error reports, and email were written with the 13-year-old in mind.

Security

These are the protections that are actually in place, not a list of aspirations:

No system is perfectly secure. If you find a problem, write to social@flockcorp.com and we will take it seriously.

If something goes wrong

If personal information is exposed by a breach, we will investigate it, fix what caused it, and tell the people affected without undue delay, describing what happened, what was involved, and what we are doing about it. Where the law sets a deadline, we will meet it: for people in the EEA or the UK that means notifying the relevant supervisory authority within 72 hours of becoming aware of a reportable breach, and telling you directly when the risk to you is high. We will not wait for certainty about every detail before telling you something happened.

International transfers

Our servers are in the United States, and the companies listed under Who we share with are United States companies or process there. If you use Flock from outside the United States, your information is transferred to and processed in the United States, which may not give it the same legal protection as your own country.

We want to be straight about the mechanism, including about what we do not know. Flock has not separately negotiated a transfer agreement with any of the companies listed above. Several of them apply their own data processing terms, including Standard Contractual Clauses, to every account by default, so those may well cover some of these transfers without our having signed anything bespoke. We have not audited each vendor's terms to tell you which, and we will not claim a protection we have not checked. For people in the EEA or the UK, the transfer happens because it is necessary to provide the service you asked us for, and because you agree to it by using Flock. If we put a specific agreement in place, this section changes with it.

What Flock does not do

A privacy policy that only lists what a company takes is half a document. Here is the other half. None of the following happens, anywhere in Flock, today:

If any of that ever stops being true, it changes on this page before it changes in the product.

Changes to this policy

We may update this policy. We will post the new effective date at the top and, for material changes, give in-app notice before the change takes effect. If a change means we need your consent for something, we will ask.

Contact

Questions, requests, or concerns? A human reads this inbox:

social@flockcorp.com