LEGAL
PRIVACY POLICY
Last updated: September 6, 2026
Flit is a link-sharing service that lets you share files, links, and messages with automatic expiry. This policy sets out what data we collect, the purposes for which we use it, and how long we retain it.
In summary: flits created in the Flit web application or the Flit iOS application are end-to-end encrypted. We store them, we serve them, and we cannot read them.
This policy forms part of, and should be read together with, our Terms of Service.
Flits created in the Flit web application and the Flit iOS application are encrypted on your device before anything is uploaded. The key is generated on your device and placed in the part of the share link that follows the # character, a fragment that browsers never transmit to a server. We receive the encrypted content and never receive the key.
We do receive a one-way fingerprint of the key. It allows us to verify that a visitor's link is genuine before it consumes one of the flit's views, so that a broken or fabricated link cannot burn through them. A fingerprint cannot be reversed, cannot reconstruct the key, and cannot decrypt anything.
The following consequences follow from this design and should be understood before you rely on it:
- (i)Any person holding the full link can read the flit. The key is part of the link, so the whole link should be treated as the secret. A link forwarded to another person works for them too, until it expires.
- (ii)If you lose the link, the content is unrecoverable, by you and by us. There is no key on our side to fall back on, and we cannot restore, resend, or read a flit for you, including in response to a support request.
- (iii)Some information is not encrypted, because we require it to operate the service. For file and media flits this comprises the file type and file size, together with the file extension. The file name itself is encrypted with the content and is not stored: we retain only a placeholder carrying the extension. The unencrypted information also includes the expiry settings you selected, the time of creation, the number of times the flit has been opened, and the technical records described in Section 3.
- (iv)Encryption protects content in our storage and in transit. It does not protect content from the person you sent the link to, and it cannot prevent that person saving or forwarding what they see.
If you report a flit as abusive, the report includes the key from the link you already hold, so that our moderators can review the material you are reporting. That disclosure is yours to make: it occurs only when you submit a report, and only for the flit you reported.
Device identifier: a random identifier generated on your device, used to associate anonymous flits with that device. It is never tied to your name or email address unless you create an account.
Flit content: the link, message, or file you choose to share. For flits created in the Flit web application or the Flit iOS application this reaches us already encrypted, and we hold only the encrypted form. It is retained only until the flit expires or is revoked.
File details: for file and media flits, the file type, file size, and file extension are stored unencrypted so that we can enforce size limits and block prohibited file types. The file name is not stored. For flits created in the Flit web application or the Flit iOS application it is encrypted together with the content, and we retain only a placeholder of the form “file.pdf”. A flit may contain more than one file, in which case these details are stored for each file and the number of files in the flit is visible to us.
View counts: the number of times a flit link has been opened.
Viewer records: where a flit has a view limit, the device identifier or account of each person who opens it, together with the time they first did so. This is required in order to count views against the limit and to allow a viewer to reopen the flit briefly without consuming a further view. These records are held with the flit and deleted with it.
Last activity: the time at which a flit was most recently opened, used to delete flits that have been inactive for fifteen (15) days.
Key fingerprint: for encrypted flits, a one-way fingerprint of the flit's key, sent by the application that created it. We compare it against the link a visitor arrives with, so that only a genuine link consumes a view. It cannot be reversed and cannot decrypt anything.
Account data (optional): if you register, we store your email address, username, and a hashed password. We never store passwords in plaintext.
Subscription data (only if you buy Premium): which provider you bought from, the identifiers that provider uses for your customer and subscription record, the plan purchased, its renewal or expiry date, any promotional code you used, and the email address you gave that provider at checkout. We keep the address so we can reach you about your own subscription, such as a failed payment, if it differs from the one on your account. We keep the rest to know whether your account is entitled to Premium and to support the subscription. It contains no payment details.
Reports: if you report a flit, we store the reason given and your device identifier so that we can investigate.
IP address: captured when you create a flit and when you submit a report, and used solely to investigate abuse. It is not captured when you view a flit. Retention is set out in Section 5.
Bug reports (optional): if you use Report a Bug in the application, we send your description, the application version, and your operating-system version and device model to our support inbox via a third-party email provider. Bug reports are not linked to your account and are deleted from the inbox once resolved.
To deliver the service, by serving flit content to persons holding the link.
To enforce the expiry rules you set, being time limits and view counts. Incomplete or invalid links are turned away without consuming a view.
To review reports of abusive content and take appropriate action. For encrypted flits this is possible only by means of the key included in the report by the person reporting it; we cannot review content that nobody has reported.
To authenticate you, if you choose to create an account.
To send you account emails, if you choose to create an account. These are limited to confirming your email address, confirming a change of email address, and resetting your password, and each is sent only in response to an action you took.
We do not sell, rent, or trade your data, and we do not share it with third parties for any purpose other than operating the service as described in Section 7.
Flit content (files, media, messages, and links) is permanently deleted from our servers when a flit expires, reaches its view limit, or is revoked by you. File and media content is removed from cloud storage at the moment of expiry.
Reported content is an exception to the preceding clause. Where a flit has been reported to us, its content is retained beyond its ordinary expiry so that the report can be reviewed, and is deleted once the report is resolved. Where the flit was a file or media, such retention does not exceed thirty (30) days, after which ordinary deletion resumes whether or not the report has been resolved. Where the flit was a message or a link, its content is retained with the report record and does not exceed the period stated in Section 5.f.
Account data is retained until you delete your account. Upon deletion, all such data is permanently removed within twenty-four (24) hours.
Subscription data is retained for as long as your account holds or has held a subscription, and is deleted with the account. Records of the transaction itself are held by the payment provider under its own retention obligations, which we do not control and cannot shorten.
Deactivated accounts are retained for thirty (30) days to permit reactivation, and are permanently deleted thereafter.
Report records are retained for up to twelve (12) months to permit the investigation of abuse, and are then deleted automatically. Where a report concerned an encrypted flit, the key disclosed to us by the person reporting it is held with that record and deleted with it.
IP addresses attached to a flit are removed from our records when the flit expires, reaches its view limit, or has been inactive for fifteen (15) days; they follow the same lifecycle as the content they were captured with. IP addresses attached to a report are retained with the report record for the same twelve-month period.
We rely on a small number of cloud infrastructure, storage, and email providers to operate the service. We disclose to these providers only what is necessary to deliver Flit.
We have not integrated any third-party analytics, advertising, or tracking service into the application or the website.
Because flits are encrypted on your device, our storage and hosting providers hold only encrypted content and never receive the keys. File and media content is permanently deleted from our storage provider at the moment a flit expires or is revoked.
If you buy a Premium subscription on this website, payment is handled by Polar Software, Inc., which sells and processes those purchases as merchant of record and therefore as an independent controller of the payment data you give it. If you buy in the iOS app, payment is handled entirely by Apple. In either case your card details are submitted to that provider and are never sent to, seen by, or stored by us.
From a web purchase we receive only what is needed to attach a subscription to your account and to support it: an internal customer and subscription identifier, the plan purchased, its renewal or expiry date, any promotional code used, and the email address you entered at the provider's checkout. We do not receive your card number, billing address, or tax details.
Web checkout is a redirect to the payment provider's own hosted page. No payment script, frame, or widget is loaded on the Flit website, which is why the statement above that there are no third-party scripts on the site remains true.
Each provider operates under its own privacy and data-handling terms.
Access: you may export a copy of all data we hold about you at any time from the Account tab in the Flit application.
Correction: you may update your username and email address at any time from Account → Edit Profile. A change of email address takes effect only once you confirm it from a link sent to the new address; until then you continue to sign in with the old one.
Deletion: you may permanently delete your account and all associated data from Account → Delete Account.
Pause: you may deactivate your account from Account → Deactivate Account. This suspends your account for thirty (30) days without deleting it.
Portability: your exported data is provided in JSON format so that you may use it elsewhere. Encrypted flit content is exported in its encrypted form, that being the only form we hold; it remains readable with the share link you retained.
No marketing: we do not use your data for marketing or profiling.
To exercise any of these rights, or to ask a question, contact us at privacy@getflit.app. We will respond within thirty (30) days.
You must be at least sixteen (16) years of age to create an account. If you are under 16, you may use the service anonymously without registering.
If we become aware that an account belongs to a person under 16, we will delete it promptly.
Account data (email address, password): required in order to provide the account features for which you registered.
Flit content (encrypted) and file details: required in order to deliver the sharing service, enforce size and file-type limits, and apply the expiry rules you set.
Subscription data: required in order to perform the contract you entered into when you bought Premium, namely to grant the entitlement you paid for and to end it when the subscription does.
Server logs: processed for the purposes of security and abuse prevention.
Reports and IP addresses: processed in order to review and act upon reported content and to investigate patterns of abuse.
Questions about this policy may be directed to privacy@getflit.app.