Your photographs are made on your phone, and we cannot see any of them. Outside a shared roll, none of them leaves your phone except by your own export or your own iCloud backup. Inside one they travel locked, and only the people holding that roll's link can open them. Advertising involves Google: one video you choose to watch and, without Pro, a small advertisement at the foot of two pages of the darkroom. That part is described in full below.
GETFLSH has no accounts and no login. Your photographs and videos are made on your phone and written to the app's own folder there. Outside a shared roll, the app's own code sends no photograph anywhere.
A shared roll is the one place where the app sends photographs. Each one you shoot into a roll you have made a link for, or joined from one, is locked on your phone and kept for that roll in iCloud, in a store that belongs to this app and is run by Apple. The key is in the roll's link and on the phones in the roll, never in that store, so the people holding the link can open the photographs and we cannot. Each phone takes out what it sent the next time the app is opened after the roll ends. All of it is under SHARED ROLLS below.
Five things reach a network. Apple, which the app asks for its price list every time it opens, and again for purchases and for restoring them. iCloud, for a shared roll, as above. Google, from the moment you press a button to watch an advertisement or, without Pro, open one of the two darkroom pages that carry a small one, and not before. Your own phone's backup, if you have iCloud Backup switched on. And getflsh.com, which is ours, if you tap one of the links to this page, to the terms or to the support page from inside the app.
The controller of the personal data this page describes is the seller named on the GETFLSH listing in the App Store, where Apple shows that name for every app. Every question, request and complaint about your data goes to support@getflsh.com, and is answered by the seller.
Required. GETFLSH is a camera. Every effect is applied to the live image on your device as you shoot. The live image is never transmitted; a finished photograph leaves the phone only by the doors listed under WHAT IS STORED, AND WHERE. On the back, both of the phone's own lenses are used: the ordinary one, and the ultra wide when you pinch past it. Zoom beyond a lens is a crop of that lens.
The microphone is part of the camera only while VIDEO is selected: it joins when you switch to VIDEO and leaves when you switch back to PHOTO. So taking photographs never lights the microphone indicator, and iOS asks for it the first time you switch to VIDEO. While VIDEO is on, the indicator shows even before you record, because the microphone is connected. Sound is only ever written into a clip you record, is never analysed, and never leaves the phone by itself.
Turning Sound off under VIDEO in Settings removes the microphone from the session entirely: iOS shows no microphone indicator, records no microphone use against the app, and clips come out with no audio track.
A video records the voices of everyone near you, who have not agreed to anything. That is true of every phone camera, and of this one.
Optional, and asked for the first time you set a roll to develop later or join a shared roll; a row in Settings asks too. Every notification is scheduled on your phone and shown by iOS; none is sent to it from anywhere else. There are two kinds: one when a roll develops, and, for a shared roll with other people in it, one the day before it disappears, unless everything they shot is already in your photo library. The title is the roll's name, as whoever made the roll typed it, so it can be read on your lock screen.
GETFLSH does not look for faces. Its code never calls a face detector: Apple's Vision framework is not part of the build, and the detectors inside the image and camera frameworks, which the app uses for other things, are never called. The light sits at a fixed point in the frame, which is arithmetic and not sensing.
So there is no face data: nothing detected, nothing measured, nothing stored, nothing sent. No reshaping and no generative AI. Some looks soften the whole frame, the way glass in front of a lens does, and skin softens with it. The app also switches off iOS's own red-eye retouching, the one thing the system would otherwise do to a face on a flash photograph.
If you delete GETFLSH, everything it stored on the phone goes with it. Three things survive: anything you exported to your photo library; whatever is inside an iCloud backup taken before you deleted it, which you manage in iOS Settings under your name, iCloud, Manage Account Storage; and the locked copies of frames you shot into a shared roll, which only the app, signed in to the Apple Account that sent them, can take out of that roll. Leave the roll before you delete the app if you want them out at once; otherwise they stay there, locked, where nobody without the roll's link can open them, as described under SHARED ROLLS.
Exporting a photograph without the small GETFLSH mark is free in exchange for watching one short video, and the same trade lends you a Pro chapter for a night. Without Pro, two pages of the darkroom also carry a small advertisement at the foot of the page: REPRINTS, from the second photograph you bring in, and the list of shared rolls, once there is a roll on it. The camera, your own rolls, an open photograph and the inside of a shared roll never show one, and with Pro there is no advertising anywhere in the app. Both kinds are served by Google AdMob.
Nothing about advertising happens until you press a button to watch that video or, without Pro, open one of those two pages when it is due to show an advertisement. Google's code is present in the app from the start, but it is held back: the app sets Google's own delay app measurement switch, which stops the advertising code from measuring or reporting anything until the app starts it, and the app only starts it at one of those moments. With Pro, or if you never do either, no advertising session is ever opened for you.
One other thing happens without a button, and it is Apple's: if you install another app after seeing an advertisement for it inside GETFLSH, iOS itself sends that advertiser's network a signed confirmation that the install happened. The app carries the list of 50 advertising networks iOS is allowed to answer, as every app that shows advertising does. The report comes from your phone's operating system, is designed by Apple so that it cannot identify you, and GETFLSH neither sends it nor sees it.
When you do press a button, up to three things happen in order. Google asks for your consent on its own form, where the law where you are requires it and you have not already answered. Unless you refused there, iOS then asks Apple's tracking question, which is the one about following you across other companies' apps. Then the advertising code starts, if a darkroom page has not started it already, and requests a video.
The small advertisement on the two pages asks less. Where the law requires Google's consent form, the form appears the first time you open one of those pages, because no advertisement may be requested there before it is answered; everywhere else the advertisement simply loads. Apple's tracking question is never put at that moment: it waits for the first time you press a button to watch a video, and until you allow it iOS does not hand your device's advertising identifier to Google.
If you refuse consent, you are not asked the tracking question, and Google can still show a limited ad: it is not personalised and uses nothing stored on your phone to choose it. The ad still needs your IP address to reach you, as any ad does. If one plays, you get the same clean prints as anybody else; if Google has none to show, the frame can still go out with the mark.
What Google receives, according to its own declaration shipped inside the app: your device's advertising identifier, advertising data, how you interacted with the advertisement, and an approximate location, all linked to you; plus performance, crash and other diagnostic data that are not. That identifier is used for tracking in Apple's sense of the word. What Google does with it is governed by Google's privacy policy, not by this one.
Google is the only company that receives data about you through the app for its own purposes, and it is bound to protect that data at least as well as this policy and Apple's guidelines require: by its terms with the apps that show its advertising, and by the data protection law where you live. Apple runs iCloud, where a shared roll's locked frames are kept for us, and receives nothing there that it can open. As with anything a phone sends to iCloud, Apple sees the Apple Account and the network address it came from.
Saying no costs you nothing here. Refuse Google's consent or Apple's tracking question and the advertisement still plays and you still get what it was worth; after a refusal the small advertisement is a limited one too. If no advertisement loads, the frame can still be exported with the mark on it.
Changing your mind. Settings has a row called Advertising choices, under HELP, which reopens Google's own consent form so you can change or withdraw what you agreed to. It appears once Google's form has been shown to you; where the law asks for no form there is no consent to withdraw, and the row is not shown. Apple's tracking question is asked once, ever, so it is changed in iOS Settings under Privacy & Security, Tracking.
Subscriptions and the one-time purchase are handled entirely by Apple. No card details, no name and no address ever reach the app. What the app receives from Apple is the price list it shows you and, for a purchase you have made, which product it was and when it expires or was refunded: enough to know whether to unlock Pro, and nothing about you. The app asks Apple for its price list when it opens, a request carrying the product identifiers and your storefront, and it keeps a channel open to Apple so that renewals, refunds and purchases made on another device arrive. Apple's own privacy policy governs all of that.
A formula is a set of camera settings kept under a name: a chapter, the light, the shape of the frame, and the lens dials. You share one as a short code or a link, through your phone's own share sheet, and the settings travel inside the link: there is no server behind it, no account, and no database of ours holding it.
A formula link carries numbers and nothing else. No photograph, nothing identifying you or your phone, and not even the name you gave it, which stays on your device, so a formula arrives with no words attached and is named again by whoever keeps it. There is nothing in it for anyone to moderate. Receiving one changes nothing until you choose to keep it, and discarding it puts your camera back exactly as it was.
The app never sees that you sent one, and the code travels inside the link rather than through any database of ours. But when somebody opens a formula link in a browser, their browser asks getflsh.com for that page, and the web host's ordinary access log records the request: the formula code, the visitor's IP address, and their browser, the way any web page is logged.
The sender can be in that log too. When a link is pasted into a messaging app such as WhatsApp or iMessage, the sender's own phone usually fetches the page to draw the preview, before anybody opens it. So the log can hold the sender's IP address next to the code as well. We do not read it that way or connect it to anything, but it is there.
A shared roll is one night that several people shoot into, up to twelve of them. The invitation is a link. It carries the roll's identifier, the exact minute it develops, how many frames each person gets, the roll's name, and a key. Joining makes no account, and it works with no signal; sending photographs waits for one. Opening a roll's link in the app reads from the vault who is already in that roll, before you decide whether to join.
What is sent. Each photograph you shoot into a roll you have made a link for, or joined from one, is copied at 2048 pixels on its long edge, locked on your phone, and sent to that roll's vault as you shoot, or later if there was no signal. Locked with it go the chapter and the light it was shot with, its number in your part of the roll, the time it was taken, a random identifier made for you in that roll alone, and the name you typed when you joined, which is up to twelve letters and can be anything you like. If you picked one of the small drawings the app offers at the door to stand for you in that roll, the choice is locked and sent in the same way. Clips are not sent. The full-size photograph stays in your own darkroom. A roll you have never made a link for sends nothing. Making the link is what starts it: from the moment you press INVITE THE OTHERS, the photographs already in that roll are sent as well, whether or not anybody uses the link.
Where it is kept. The vault is a store in iCloud that belongs to this app and is run by Apple. Sending to it needs your phone to be signed in to iCloud; it asks nothing of you and uses none of your own iCloud storage. A phone that is not signed in can still fetch a roll it holds the link to.
Who can open it. Every photograph, every name and everything said about a frame is encrypted on the phone that sent it, with a key made on the phone that sends the roll's first invitation. The key travels in the last part of the link, after the #, which a browser keeps to itself: it is not sent to getflsh.com when the link is opened, and it never reaches us. The vault holds no key, so what is in it cannot be opened from the vault, by us or by Apple. The key exists in the link, wherever the link has been sent, and on the phones in the roll, where it is left out of the phone's backup. Anybody who has the link has the key, so send it to the people you mean: someone it is forwarded to can join until the roll develops, and holds the key afterwards.
What we can see. That a roll's records exist, how large they are, when they were made and last changed, how many of its twelve seats are taken, how many frames each seat has sent, and, for each record, an identifier that iCloud assigns to the account that made it. That identifier is specific to this app, is the same in every roll that account takes part in, and tells us neither your name nor your Apple Account. We cannot see a photograph or a name. We look at none of it except to remove a frame or a roll that has been reported.
What the others can do. When the roll develops, every phone in it fetches everybody's frames and shows them, with the names people gave. Everybody in the roll can then save any frame to their own photo library, and a copy somebody has saved is theirs: taking a frame back does not reach it. The person who started the roll can remove any frame for everybody, or remove a person: everything they shot leaves the roll, and their phone stops receiving it. They can also close the roll to new people, and open it again: that choice is kept, locked, with their list in the vault. Anybody else can hide another person's frames on their own phone, which nobody is told about. Anybody else can report a frame, and a reported frame leaves the roll for everybody. The report is written, locked like everything else, onto the reporter's own seat in the vault, which is how the other phones learn of it; it stays with that seat until the roll ends, and the app shows nobody who made it. Whoever shot the frame is told that one of theirs was taken out, and not by whom. No message goes to us. When the roll cannot take a report, because you started the roll, the phone has no seat in it, the vault could not be reached, or you have already reported three frames, the app opens an email for you to send us from your own mail instead, carrying a reference to the roll and the frame, and whatever you write. We cannot see the frame, so what such a message lets us do is remove that frame, or that roll, from the vault.
When it goes. A shared roll ends three days after it develops. On each phone, the roll and everybody's frames in it are deleted the next time GETFLSH is opened after that. From the vault, each phone removes what it sent, also the next time GETFLSH is opened after the roll has ended, because only the Apple Account that sent a frame, and we, are able to remove it. You can take a frame out sooner with TAKE THIS ONE BACK, or all of yours with LEAVE THIS ROLL. If a phone never opens GETFLSH again, or has signed in to a different Apple Account since, what it sent stays in the vault, still locked, where nobody without the link can open it.
One thing travels in a roll link that never travels in a formula link: its name. If you give the roll a name, it is written into the invitation, so it is read by everybody who receives the link and by anybody they forward it to. Call it what you would say out loud.
The same web log applies as for formulas: if somebody opens an invitation in a browser rather than in the app, getflsh.com's ordinary access log records that request, which includes the roll's code and its name, and not the key. The phone that sends the invitation usually fetches the page to draw the preview, so the sender's IP address can be in that log too. Nothing about it reaches the app.
getflsh.com sets no cookies, runs no analytics, and loads nothing from anyone else's servers; its typefaces are served from here. The home page keeps one flag in your browser's session storage so that its opening plays once per visit; it is sent nowhere and goes when the tab closes. The site is hosted by Netlify, which keeps ordinary server access logs. Netlify says it keeps them for less than 30 days, and we take no copy of them.
Because the site tracks nobody, a browser's Do Not Track signal has nothing to switch off here. In the app, tracking happens only if you allow it when Apple asks.
If you email support@getflsh.com, we receive your address and whatever you write, and use them to answer you and to do what you asked. The mailbox is hosted by Namecheap. When an email reports a frame in a shared roll, we keep one line of our own about it: the day it arrived, the day we acted, the roll's reference, what was removed and which kind of report it was, with no name, no address and none of your words. That line is kept for three years, so that we can show what was done about a report, and longer only where a law requires it or while a complaint, a claim or an investigation about that report is still open; then it is deleted. Nothing else from an email is added to anything. An email is kept for as long as it takes to deal with what you wrote, and is deleted when you ask, unless a law requires us to keep it or it is needed to answer a complaint or a legal claim; one that reports what may be a serious crime is kept for as long as an authority may need it.
GETFLSH is not directed at children and is not for anyone under 13. It shows advertising and presents Apple's tracking request, so it is intended for teenagers and adults, and it is rated accordingly; the advertisements it can show are limited to content rated for teenagers. We do not knowingly receive personal information from anyone under 13. If you believe a child has sent us something, write to support@getflsh.com and it will be deleted.
Data protection law asks that every use of personal data rest on a reason it accepts, and each one here does. Advertising rests on your consent, given on Google's form and withdrawable in Settings. A limited ad shown after a refusal rests on Google's legitimate interest in delivering an ad and counting that it was shown, which the same form lets you object to. Carrying a shared roll rests on its being what you asked for when you started one or joined one. The website's server log rests on a legitimate interest in keeping the site secure and working. An email to support rests on your having written, and on our interest in answering; the line kept about a report rests on our interest in being able to show what was done. Anything kept longer because a law requires it rests on that law.
Some of this leaves Europe. Google, Netlify and Namecheap are based in the United States, and each moves data out of Europe under the safeguards European law requires for that: the European Commission's standard contractual clauses, and for Google and Netlify the EU-US Data Privacy Framework as well. Apple runs iCloud and decides where its servers keep a shared roll's vault, under the same kind of safeguards.
Under the GDPR, the UK GDPR, Brazil's LGPD, California's privacy laws and similar laws elsewhere, you have the right to access, correct, export and delete the personal data a company holds about you, and to object to how it is used. We give those rights to everybody, wherever they live. Outside a shared roll and outside advertising, the app sends nothing about you anywhere, so there is nothing from it to retrieve or erase, and deleting the app removes everything it stored on your phone.
Four things can exist on our side. The locked contents of the shared rolls you shot into: we cannot open them, and nothing we can read in them says who you are, so we cannot find yours from your name or your email address, or hand them over. You remove them yourself, inside the app, with TAKE THIS ONE BACK or LEAVE THIS ROLL, and your phone removes them in any case the next time the app is opened after the roll ends. An email you send us. The line kept when an email reports a frame, which holds a roll's reference and two dates and nothing that says who wrote. And the website's log: visiting getflsh.com, including opening a formula link, leaves an entry in our host's ordinary server log with your IP address and browser, kept by the host for less than 30 days, for security and reliability. An IP address is personal data under the GDPR. We do not analyse those logs, connect them to anything, or use them to build a profile.
We take no automated decisions about anybody and build no profiles. Which advertisement Google shows you, once you have agreed to a personalised one, is Google's choice under its own policy.
Where other data exists it is held by others, and the route to it runs through them: Apple for purchases and for your iCloud backup, and Google for advertising. Consent given to Google can be withdrawn from Settings inside the app, as described above.
To ask what we hold, to have any of it deleted, or to have any of this confirmed in writing, write to support@getflsh.com and you will get a real answer. We delete what you ask us to, except what a law requires us to keep or what is needed to answer a complaint or a legal claim, and we tell you which it is.
If you think we have got any of this wrong, you can also complain to a data protection authority: in Spain the Agencia Española de Protección de Datos, or the one where you live.
If this policy changes, the date at the top changes with it, and any change that affects what leaves your device is said in the app's update notes on the App Store as well, rather than quietly published here.