Fluck Privacy Policy

Effective date: 2026-04-15 Last updated: 2026-04-15

This policy explains what information Fluck collects when you use our mobile app, website, and related services, what we do with it, and the rights you have over it. We've tried to keep it in plain English. If something isn't clear, email us at privacy@fluckai.com and we'll explain.


1. Who we are

Fluck is a social expense-sharing app operated by Fluck AI Ltd ("Fluck", "we", "us"), a company registered in England and Wales, United Kingdom at Innovation Centre, Knowledge Gateway, Boundary Road, Colchester, Essex, CO4 3ZQ, United Kingdom.

For users in the EU/EEA and UK, Fluck AI Ltd is the data controller for the personal data described below.


2. What data we collect

We only collect what we need to make the app work. The table below lists every category.

2.1 You give us

CategoryExamplesWhen
IdentityName, date of birthOn signup and profile edit
ContactEmail address, phone numberOn signup
CredentialsPassword (hashed — we never see it in plaintext), OTP codesOn signup / login
Financial activityBill amounts, payment references, split details, IOUsWhen you create or join a bill split
User-generated contentGroup names, messages, notes, calendar events, receipt photosWhen you use these features
Contacts (optional)Names and phone numbers from your device contact bookOnly if you grant contacts permission to invite friends
Calendar (optional)Events you create in Fluck that we sync to your device calendarOnly if you grant calendar permission
Photos (optional)Receipt images from your camera or photo libraryOnly if you grant camera/photo permission

2.2 Collected automatically

CategoryExamples
DeviceDevice model, OS version, app version, language, timezone
IdentifiersFirebase installation ID (for push notifications), app-scoped user ID
UsageScreens viewed, features used, approximate session duration
DiagnosticsCrash reports, performance traces, error logs (scrubbed of personal content)
NetworkIP address (used transiently for request routing and abuse prevention)

2.3 What we don't collect


3. How we use your data and why (legal bases)

Under GDPR Art. 6, every use of your data needs a lawful basis. Here's ours:

What we doWhyLawful basis (GDPR Art. 6)
Create and maintain your accountSo you can log in and use FluckContract (6(1)(b))
Let you split bills, message groups, share calendarsCore productContract (6(1)(b))
Send OTP + password-reset emailsAccount securityContract + legitimate interest (6(1)(f))
Send push notifications about your activityYou asked us to via opt-inConsent (6(1)(a)) — revocable in settings
Detect fraud and abuseKeep the platform safeLegitimate interest (6(1)(f))
Improve the app (aggregated analytics)Build better featuresLegitimate interest (6(1)(f))
Comply with the lawTax, accounting, legal requestsLegal obligation (6(1)(c))

4. Who we share your data with

We use the following processors. Each is bound by a Data Processing Agreement.

ProcessorPurposeLocationPolicy
Google Firebase (Firebase Cloud Messaging)Push notificationsUS / EUhttps://firebase.google.com/support/privacy
Brevo (formerly Sendinblue)Transactional email (OTP, password reset)EUhttps://www.brevo.com/legal/privacypolicy/
DigitalOcean (Spaces + Droplets)Object storage for receipts; application hostingEU regionhttps://www.digitalocean.com/legal/privacy-policy
Apple (App Store, APNs)App distribution, iOS push deliveryGlobalhttps://www.apple.com/legal/privacy/
Google (Play Store)App distribution on AndroidGlobalhttps://policies.google.com/privacy

We do not share your data with advertisers. We do not sell your data.

We may disclose data if legally compelled (court order, valid subpoena) or to protect life, property, or the security of the service.


5. International transfers

Your data is processed primarily in the EU region of DigitalOcean (Frankfurt). Some processors (Firebase, Apple, Google) may process data in the United States. For transfers outside the EU/EEA/UK, we rely on:


6. How long we keep your data

DataRetention
Active account dataFor as long as your account is open
Deleted account — personal dataPurged or anonymised within 30 days of deletion request
Financial / bill-split records (required for tax and dispute)Up to 7 years after deletion, anonymised where possible
Crash / diagnostic logs90 days
OTP codes10 minutes then permanently deleted
BackupsRotated out within 35 days

7. Your rights

7.1 If you're in the EU/EEA/UK (GDPR)

You have the right to:

7.2 If you're in California (CCPA/CPRA)

You have the right to:

7.3 How to exercise your rights

The fastest way: Profile → Delete account in the app (for erasure) or Profile → Export my data (for access).

Alternatively, email privacy@fluckai.com with your registered email address. We respond within 30 days.


8. Children

Fluck is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe a child has signed up, contact privacy@fluckai.com and we will delete the account.


9. Cookies and similar technologies

The Fluck mobile app does not use cookies. Our website (www.fluckai.com) uses only strictly necessary cookies for session handling and CSRF protection. We do not use analytics or advertising cookies without your consent.


10. Security

We take security seriously:

No system is perfectly secure. If you believe you've found a vulnerability, email security@fluckai.com.


11. Changes to this policy

If we make material changes, we will notify you in-app and by email at least 30 days before they take effect. The "Last updated" date at the top of this policy always reflects the most recent revision.


12. Contact


<a id="deletion"></a>

How to delete your account

  1. Open the Fluck mobile app
  2. Tap the profile menu (top-right) → Delete account
  3. Confirm the deletion warning and enter your password to proceed

Your account is soft-deleted immediately (your data becomes invisible to other users) and permanently erased after a 30-day grace period. To cancel during the grace period, simply log back in with the same credentials and confirm reactivation.

If you cannot access the app, email privacy@fluckai.com from your registered email address and we will process the deletion manually within 30 days.


Publication status

All placeholders filled with Fluck AI Ltd's registered details (Companies House 15723506). Effective date 2026-04-15. Ready for publication at https://www.fluckai.com/privacy.

Mailboxes required on the domain before go-live:

Effective date: 2026-04-15. Questions? Email privacy@fluckai.com.

Fluck LogoFluck

Fluck helps you simplify your life—from calendars and budgets to documents and loyalty cards. Everything you need, finally in one place.


Company

  • About
  • Contact us
  • Careers
  • Culture

Contact

  • support@fluckai.com
  • +44 7897423374
  • Fluck Ai LTD.
    Innovation Centre, Knowledge Gateway, Boundary Road, Colchester, Essex, United Kingdom, CO4 3ZQ

Subscribe to our newsletter

Stay ahead with the latest features, offers, and productivity tips from Fluck.

Copyright © 2025 Fluck | All Rights Reserved