Legal
Privacy Policy
Effective date: September 19, 2026
FlickFly helps you keep secrets on your devices and move them between devices you trust. This policy explains what information is handled when you use the FlickFly mobile apps and flickfly.app.
1. Who we are
FlickFly is operated by Magno (“we”, “us”). For privacy questions, contact help@flickfly.app.
2. Our privacy principles
- Your vault stays on your devices. Passwords and other secrets you store in FlickFly are kept in on-device secure storage. We do not host your vault on FlickFly servers.
- Transfers are end-to-end encrypted. When you flick a secret to a paired device, the payload is encrypted for that peer. FlickFly’s signaling service relays encrypted messages; it is not designed to read your secret values.
- No FlickFly account is required. You unlock the app locally (for example with a PIN or device biometrics). We do not run a traditional email/password account system for the vault.
3. Information stored on your device
Depending on how you use FlickFly, your device may store:
- Secret names, usernames, and secret values in platform secure storage
- App lock PIN / related unlock settings
- Local records of paired devices (names, session identifiers, public keys)
- Purchase / unlock entitlement state from the app stores
- Browser pairing identity when you use flickfly.app as a receive target
This information remains under your control on that device unless you choose optional cloud backup (see below) or delete the app / forget a pairing.
4. Information processed for pairing and delivery
To connect a phone, another phone, or the browser, FlickFly uses a
short-lived pairing and WebSocket signaling service (API endpoints
under api.flickfly.app).
That service may process:
- Temporary pairing session identifiers and short pairing codes
- Device display names and device identifiers you provide for pairing
- Public keys used for encrypted transfers
- WebSocket connection identifiers while a session is active
- Push notification tokens (for example Firebase Cloud Messaging) so a paired device can be notified of activity
Pairing sessions are time-limited. We do not use this channel to store the contents of your vault.
5. Push notifications
FlickFly may use Firebase Cloud Messaging (and related Google / Apple push infrastructure) to deliver pairing or transfer-related notifications. Push providers process device tokens and notification metadata according to their own terms and privacy policies.
6. Optional vault backup
If you use Vault backup, FlickFly encrypts a vault snapshot with your PIN and stores it in your iCloud container (iOS) or Google Drive App Data folder (Android)—not in a FlickFly-operated file store.
Apple or Google process that encrypted backup under their respective cloud terms. We cannot restore your backup without the PIN you used to protect it.
7. Purchases and unlock
Optional paid unlock is handled by Apple App Store and/or Google Play billing. We receive entitlement signals needed to unlock features (for example, whether unlock has been purchased). We do not receive your full payment card details; those are handled by Apple or Google.
8. Website (flickfly.app)
The website provides product information and a browser receive experience. When you pair the browser, local storage in that browser may keep pairing material needed to receive secrets. Standard web logs from hosting/CDN providers may include IP address, user agent, and request metadata for security and reliability.
We do not run advertising trackers on the FlickFly site for the purpose of selling personal data.
9. How we use information
We use the limited operational data above to:
- Provide pairing, signaling, and notification features
- Maintain security, prevent abuse, and debug reliability issues
- Honor in-app purchases / unlock entitlements
- Respond to support requests you send us
- Comply with law where required
We do not sell your personal information. We do not use your vault secrets for advertising.
10. Sharing
We share information only as needed to operate FlickFly, including:
- Infrastructure providers (for example AWS for signaling APIs and website hosting/CDN)
- Push providers (Firebase / Apple / Google push services)
- App stores for distribution and purchases
- Your chosen cloud account when you enable vault backup (iCloud or Google Drive App Data)
We may disclose information if required by law, or to protect the security and integrity of FlickFly and our users.
11. Retention
- On-device vault and settings: until you delete them, clear app data, uninstall, or otherwise remove them
- Pairing / signaling records: short-lived operational retention; expired or revoked sessions are removed or become unavailable
- Support emails you send: retained as needed to help you and keep basic records
12. Security
We use industry-standard protections for our services (including encrypted transport). Device secure storage, local app lock, and end-to-end encryption for transfers are core to the product. No method of transmission or storage is perfectly secure; please also protect your devices, PIN, and pairing QR/codes.
13. Children
FlickFly is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact help@flickfly.app.
14. Your choices
- Delete secrets or forget paired devices in the app / browser
- Disable biometrics or change your PIN in the app
- Remove optional cloud backups from iCloud or Google Drive
- Uninstall the app or clear browser site data
- Manage notification permissions in system settings
- Contact us to ask questions about operational data associated with support requests
Depending on where you live, you may have rights to access, correct, delete, or restrict certain personal data, or to object to certain processing. Email help@flickfly.app and we will help where applicable.
15. International processing
Our infrastructure may process operational data in regions where our providers operate (including Australia and other locations used by AWS, Apple, Google, or Firebase). If you use FlickFly from another country, you understand that operational data may be processed outside your home country with appropriate safeguards used by those providers.
16. Changes
We may update this policy as FlickFly evolves. We will post the revised version on this page and update the effective date. For material changes, we may also provide an in-app or site notice where appropriate.
17. Contact
Privacy requests: help@flickfly.app
This page is provided for transparency about how FlickFly works. It is not legal advice. If you need a jurisdiction-specific review (for example GDPR or CCPA counsel), have a qualified professional review this draft before store submission.