Privacy policy
Effective 22 September 2026
FlickerTalk does not store conversations, address books, private keys or communication histories on its servers. Messages that cannot be delivered directly are kept encrypted end to end, so that we cannot read them, only until they are delivered or expire. The service keeps only the minimum technical information needed to route notifications and deliver those pending messages.
1. Who is responsible
The controller of your data is ERPLORA CLOUD SL, NIF B27593136, Avda. de Lisboa, 17, Pta. C, 28822 Coslada (Madrid), Spain. Contact: info@flickertalk.com.
2. Data that never leaves your phone
Your messages, files, call history, contacts and the names you give them, your private keys and, if the app ever needs it for the price, whether you are under 18. FlickerTalk does not read your phone's address book and never asks for your date of birth.
3. Data our servers process
| Data | Purpose and legal basis | Kept |
|---|---|---|
| Device ID, public key and a hash of your routing code | Authenticate your phone's requests and let only your contacts reach you. Performance of the contract (GDPR art. 6.1.b). | Until you use “Erase this phone” |
| Push token and provider, encrypted | Wake your phone when a message or call arrives. Art. 6.1.b. | Until you erase the phone, turn notifications off, or the provider says the token expired |
| Undelivered messages, end-to-end encrypted, without sender | Deliver them when your phone comes back. Art. 6.1.b. | Until picked up, at most 7 days; never in backups |
| IP address of an open connection | Route it and limit abuse. Legitimate interest in the security of the service (art. 6.1.f). | Not stored; the abuse limits use a salted hash held in memory for one minute |
| IP addresses seen by our relay and STUN servers | Connect two phones that cannot reach each other directly. Art. 6.1.b. | Not logged |
| Reports and emails you send us | Handle abuse reports and answer you. Art. 6.1.f. | As long as needed to handle them |
A report is an email you send from your own mail app to info@flickertalk.com, with only the evidence you choose to include.
4. Who else takes part
- Hetzner Online GmbH (Germany) hosts our servers in its data centre in Falkenstein, Germany.
- Google (Firebase Cloud Messaging) delivers the wake-up notifications on Android, and Apple (Apple Push Notification service) on iPhone. They receive your push token and the time of each notification, never its content or sender.
- OVH (France) hosts the mailbox of info@flickertalk.com.
- Google Play and the App Store distribute the app and handle payments under their own privacy policies. We receive no payment data: your phone checks the subscription locally.
Google and Apple may process data outside the European Economic Area, under the safeguards they provide (the EU-US Data Privacy Framework or standard contractual clauses).
5. No tracking
No analytics, advertising or crash-reporting services in the app. This website sets no cookies, loads nothing from other sites and keeps no access logs.
6. Your rights
You can ask for access to, rectification or erasure of your data, restrict or object to its processing, and ask for its portability (GDPR arts. 15 to 22). You can delete everything yourself in the app with Settings → “Erase this phone”. Because we do not know who you are, we will need your FlickerTalk ID (shown in the app) to find your record. Write to info@flickertalk.com.
You can also complain to the Spanish Data Protection Agency (AEPD), www.aepd.es.
7. Children
If you are under 14, you need your parent or guardian's permission to use FlickerTalk.
8. Security
End-to-end encryption, keys sealed by the phone's secure key store, signed requests, encrypted push tokens and no logs of content, identifiers or IP addresses. See Security.
9. Changes
If this policy changes, the new version will be published here with its date.