The short version
Flintly has no accounts and no server. Your routines, to-dos, streaks, notes and timer history are stored only in the app's database on your phone. We cannot see them. There is no analytics SDK, no crash reporting, no advertising and nothing to sell. Data leaves your device only when you deliberately export a file or turn on backup to your own Google Drive.
This policy applies to the Flintly mobile app (Android), this website, and any support email you send us.
Who we are
Flintly is developed and published by Artem Kovalov, an independent developer (“Flintly”, “we”, “us”), contactable at [postal address]. Because the app keeps your data on your own device, there is very little personal data for which we act as controller — where there is (a support email you send us, a request to this website), it is described below.
- Support and privacy requests: kovaloff1@gmail.com
What the app stores on your device
All of the following is written to a local SQLite database and a local key–value store inside the app's private storage area. None of it is transmitted to us, at any point, in any form.
- Routines — name, icon, color, kind (build or quit), schedule and repeat cycle, daily target, timer settings, reminder times, and paused/vacation ranges.
- Completion history — for each day, whether a routine was done, the partial count, skipped days, and any note you attach.
- To-dos — title, category, priority, due date, notes, subtasks, reminders and completion state.
- Timer sessions — start time, planned duration and elapsed time per session, used for the Time analytics screen.
- App preferences — theme (system, light, dark, color-blind-safe), start of week, language, home layout, notification and silent-hours settings, and your Pro status.
- The display name you optionally type during onboarding, which is only used to greet you on the home screen.
Uninstalling the app deletes all of it. On Android this data may be included in the operating system's own device backup (Google One) if you have that enabled — that backup belongs to you and Google, and we have no access to it.
When data leaves your device
Only in these four cases, and the first two only ever because you asked for them:
1. Google Drive backup (optional, off by default)
- If you sign in with Google in Settings → Sync & Data, Google returns your name, email address, profile picture URL and Google account ID to the app. These are stored on your device so the app can show which account is connected, and are cleared when you sign out.
- The app requests only the
drive.appdatascope. That scope can read and write a hidden, app-specific folder in your own Google Drive and nothing else — Flintly cannot see, list or touch any of your other Drive files. - “Back up to Drive” writes a single JSON file containing your routines, entries, to-dos, categories, reminders and app settings into that hidden folder. It goes from your phone to your Drive over HTTPS. It does not pass through any server of ours — we have none.
- You can revoke Flintly's access at any time from your Google account's security settings, and delete the file by removing the app's hidden app data from Google Drive.
Limited Use disclosure. Flintly's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: Google user data is used only to provide the Drive backup feature you switched on; it is not transferred or sold to third parties; it is never used for advertising or to build profiles; and no human reads it — the backup is written by your device directly to your own Drive and never reaches a server of ours.
2. Manual export and import
Settings → Sync & Data → Export data produces a JSON or CSV file of your data and hands it to your device's share sheet. Where it goes next — email, a messaging app, cloud storage, another device — is entirely your choice, and that destination's own privacy policy then applies. Import data reads such a file back from a document you pick. Neither step involves us.
3. App update checks
The app can fetch over-the-air JavaScript updates from Expo's update service (u.expo.dev). Those requests reveal the usual technical details of any network request — IP address, platform, app and runtime version — to Expo, so a fixed version can be delivered to the right devices. No habit data is included.
4. This website
This site serves static files, sets no cookies, and runs no advertising or analytics scripts. It loads a web font from Google Fonts, which means your browser's IP address and user agent are visible to Google when that request is made. Standard server access logs (IP address, user agent, requested URL) may be retained briefly by the host for security and abuse prevention.
What we never collect
- Your habit content. We have no server that could receive it and no account system that could identify you.
- Precise location, contacts, photos, microphone, camera or health-record data.
- Advertising identifiers. Flintly contains no ad SDKs and shows no ads.
- Analytics or telemetry. There is no usage tracking, no event logging and no crash-reporting SDK in the app. The “Insights” and “Time analytics” screens are computed on your device from your own data and stay there.
- Push notification tokens. Reminders are scheduled locally by your operating system; nothing is sent from a server, so no device token exists.
- Anything used to train machine-learning models or sold to data brokers.
Why we process it, and on what legal basis
Since your habit data stays on your device, there is nothing for us to process. The table below covers the narrow remainder.
| Activity | Data | Who receives it | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Running the app: routines, streaks, reminders, stats | Everything listed above | Nobody — stays on your device | Not processed by us |
| Backing up to your Drive | Backup file, Google profile basics | Google, under your own Google account | Consent (Art. 6(1)(a)) — you sign in and press the button |
| Delivering app updates | IP address, platform, app version | Expo | Legitimate interests (Art. 6(1)(f)) — shipping fixes |
| Serving this website | Access-log data | Our web host | Legitimate interests — security and abuse prevention |
| Answering your support email | Your email address and message | Us | Legitimate interests — replying to you |
Where we rely on consent you may withdraw it at any time — sign out of Google in Settings, and revoke the app in your Google account. Withdrawal does not affect processing already carried out.
Third parties
We do not sell personal data and we do not “share” it for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA. We have no hosting provider, database or analytics vendor holding your data, because we hold none. The only third parties involved at all are:
| Party | Role | When |
|---|---|---|
| Google (Sign-In & Drive API) | Stores your backup file in the hidden app-data folder of your own Drive | Only if you sign in and back up |
| Expo | Delivers over-the-air app updates | On update checks |
| Google Play | App distribution and, if paid features are offered, payment processing | Install and update |
| Our web host | Serves this static website | When you visit this page |
Flintly does not currently sell anything inside the app. If paid Pro features launch later, Google will process the payment and we would receive only an entitlement status — never your card details — and this policy will be updated before that happens.
Data sent to Google or Expo may be processed outside your country, including in the United States, under those companies' own safeguards and privacy policies. We may disclose data where legally compelled, or to protect our rights or the safety of users — in which case we will inform you unless prohibited from doing so.
How long data is kept
- On-device data — until you delete it in the app, or until you uninstall Flintly. We set no expiry and delete nothing on our own initiative.
- Google Drive backup — a single rolling file that is overwritten each time you back up. It stays in your Drive until you delete it or revoke the app.
- Exported files — for as long as you keep them, wherever you put them.
- Website access logs — a short period set by our host, typically no more than 30 days.
- Support emails — up to 24 months, then deleted.
Your rights over your data
Depending on where you live, you have some or all of the following rights: access, rectification, erasure, restriction, objection, portability, and the right not to be subject to solely automated decisions with legal effect (we make none). California residents additionally have the rights to know, delete, correct, opt out of sale/sharing (we do neither) and to non-discrimination for exercising them.
In practice you exercise most of these yourself, because you hold the data:
- Access and portability: Settings → Sync & Data → Export data gives you the whole dataset as JSON or CSV.
- Rectification: edit or delete any routine, entry or to-do directly in the app.
- Erasure: delete items in the app, or uninstall Flintly to remove the database entirely. If you used Drive backup, also delete the app's hidden app data and revoke Flintly's access in your Google account settings.
- Ask us: email kovaloff1@gmail.com. We answer within 30 days. Note that we usually cannot fulfil an access or deletion request for habit data — we do not hold it and have no way to identify you.
If you believe we have handled your data poorly, please tell us first — but you may also complain to your local supervisory authority (in the EU, the DPA of your member state; in the UK, the ICO).
How your data is protected
- Your data sits in the app's private storage, protected by your operating system's app sandbox and by your device passcode or biometric lock.
- All network requests the app makes — Drive backup, update checks — use HTTPS/TLS.
- Google sign-in uses the platform OAuth flow; Flintly never sees or stores a password, and holds only short-lived access tokens managed by the Google Sign-In library.
- The Drive scope is the narrowest one available (
drive.appdata), so a compromise of the app could not expose the rest of your Drive. - Dependencies are updated regularly.
No system is perfectly secure. Because your habit data lives on your device rather than on a server, keeping your device passcode-locked and your OS updated is the single biggest protection for it. If we ever become aware of a security incident affecting data we control, we will notify affected users and the relevant authority as required by law, within 72 hours where the GDPR applies.
Children's privacy
Flintly is not directed at children under 13 (or under 16 where local law sets a higher digital-consent age), and we do not knowingly collect their personal data. As the app collects no data from anyone, there is nothing for us to delete — but if you are a parent with a concern, please contact us.
Device permissions we ask for
- Notifications — to deliver the reminders you schedule. They are generated locally on your device. Declining only disables reminders; everything else keeps working.
- Google sign-in — only when you choose to set up Drive backup.
- File access — the system share sheet and document picker, used only at the moment you export or import a backup file.
Every permission is requested in context, with an explanation, and the app remains fully usable if you decline all of them.
Changes to this policy
When we change this policy we update the “Last updated” date above and keep the previous version available on request. If a future version of the app starts collecting something new, we will say so here and in the app before it takes effect, and ask for fresh consent where the law requires it.
Contact
Questions, privacy requests or corrections — one person reads this inbox, so please be specific:
- Email: kovaloff1@gmail.com