Flickback Privacy Policy
Effective August 20, 2026 · Renewal Ventures, LLC
Before you read this
Questions about this policy?Email
[email protected]. This policy may be updated as Flickback evolves; material changes will be announced in the app.
The short version
Flickback turns photos you pick into a music video with a song written and performed by AI. To do that we have to send your photos to other companies. That is the single most important thing on this page, so it is first.
- **We send your photos to our AI vision and language provider** so it can work out what is in them and write words about them.
- **We send your photos to our cloud infrastructure provider** so it can find where the faces are, which is how we avoid cropping somebody out of the frame.
- **Every photo you upload is automatically scanned** for illegal and unsafe content.
- **Your photos, songs and videos are stored on servers in the United States**, run by our database and authentication provider and Amazon.
- **We do not send your photos to the company that makes the music.** It only ever receives the words of the song.
- We do not sell your information. We do not use it for advertising. We do not track you across other apps.
- You can delete everything from inside the app: Settings, then Delete Account.
- If you are going to upload photos of your children, please read the Children section below before you do.
Who we are
Flickback is made by Renewal Ventures, LLC, at 5966 South Dixie Hwy, Suite 300, Miami, FL 33143. If you have a question about anything on this page, or you want a copy of your information, or you want it deleted, write to [email protected].
This policy takes effect on August 20, 2026 and covers the Flickback iOS app and the Flickback service behind it.
What we collect
- The photos you choose. Only the ones you select in the photo picker — up to 50 for a project. We never look at the rest of your library. Before a photo leaves your phone the app re-saves it as a JPEG no larger than 2048 pixels on its longest side. That re-save drops the EXIF metadata block, so the camera settings and any GPS coordinates stored inside the file do not leave your phone.
- What we work out from your photos. For each photo we store a written description (several hundred words), a short summary, the things and activities in it, the mood of the scene, how many people are in it, a guess at where it was taken based only on what is visible, and rectangles marking where faces are. From all of that we generate a title for your video and the words of the song.
- Titles and lyrics count as personal information. They are written from your photos, so they routinely contain real first names, place names and family events. We treat them the same way we treat the photos themselves.
- Your account. When you first open Flickback we create an anonymous account for you automatically — a random identifier, no email, no password, nothing you typed. If you later choose to add an email address and password so you can sign in on another device, we store the email address. our database and authentication provider handles the password and we never see it. We never ask for your name, phone number, postal address, date of birth or payment details.
- Your device. If you allow notifications, we store a push token for your device and whether it is an iPhone or an Android phone. When your phone renders the video itself rather than our servers doing it, we also record the device model (for example "iPhone15,2") so we can tell how fast it was.
- Diagnostics. When the app or our server hits an error, a crash report goes to our crash-reporting service. It contains the technical detail of the fault and, on the app side, basic device and session information. On the server we delete request bodies and blank out the access tokens inside file links before the report is sent, because those links would otherwise let somebody open the file.
- Usage counts. We keep a count of how many videos you generated on each day, which is how the daily limit is enforced.
**Product analytics are currently switched off.** The app contains our analytics service, an analytics tool, but no key is configured for it, so it is inert and sends nothing anywhere. If we turn it on we will update this page first. If it were on it would record events like "app opened", "generation started" and "video shared", along with your account identifier and whether you are a guest — never photos, lyrics or titles.
Things we deliberately do not collect:
- Your location. The app never asks for location permission and does not read GPS data from your photos.
- Your microphone. Microphone access is explicitly disabled in the app.
- Your contacts, calendar, health data or messages.
- An advertising identifier. There is no ad SDK in the app and we do no cross-app tracking.
Where your photos go
Making a music video out of a photo needs software we did not write. Here is every company that receives something of yours, what it receives, and why. All of them are in the United States.
- our AI vision and language provider — receives your photos. A shrunk copy of each photo (JPEG, at most 1024 pixels on the longest side) is sent to our AI vision and language provider up to three times: once to describe what is in it, once again when the song lyrics are written, and once to be checked for unsafe content. our AI vision and language provider also receives the finished song audio so it can transcribe the words and line them up with the pictures for the on-screen captions. our AI vision and language provider does not receive your email address or your account identifier.
- our cloud infrastructure provider (Rekognition) — receives your photos. A shrunk copy of each photo is sent to Amazon's face detection service, which answers with rectangles showing where faces are. There is a whole section about this below, because it deserves one.
- our cloud infrastructure provider (S3, CloudFront, Fargate) — stores your photos and videos. Our server runs on Amazon. Before a video is rendered, a copy of each of your photos is placed in an Amazon storage bucket so the renderer can fetch it quickly, and the finished video is stored there too.
- our cloud rendering infrastructure — receives your photos. our cloud rendering infrastructure runs the machines that assemble the video. It is given the web addresses of your photos and your song, and it downloads them to draw the frames.
- our database and authentication provider — stores everything. our database and authentication provider hosts our database and file storage. Your photos, your song, your video, your account and every piece of text we generated about your photos live there.
- our music-generation partners (the our music-generation partners music model) — receive the words, never the pictures. The music is made by the our music-generation partners model, reached through our music-generation partners, with our music-generation partners as a backup if our music-generation partners is unavailable. They receive the lyrics, a short description of the musical style, and the title. They do not receive your photos, your email address or your account identifier.
- our speech-transcription provider — receives the song audio only. If our AI vision and language provider fails to transcribe the song, we send the song audio to our speech-transcription provider instead. This is audio the AI sang, not anything you recorded. our speech-transcription provider never receives your photos.
- our app-platform tooling, Apple and Google — receive your notifications. Push notifications go out through our app-platform tooling, which hands them to Apple (and Google on Android) to deliver. The notification contains the title of your video, which was written from your photos.
- our crash-reporting service — receives error reports. When something breaks, the technical details go to our crash-reporting service. We strip request bodies and redact file-access tokens on the server before sending. our crash-reporting service is live in the app and on the server.
**Anthropic is configured but not switched on.** The code can fall back to Anthropic for photo descriptions if our AI vision and language provider refuses service, but no Anthropic key is configured on our production servers, so no photo is sent there today. If that changes we will update this page.
None of these companies receives your information for their own advertising, and we do not sell it to anyone.
Faces
This one needs saying carefully, because "the app looks at faces" can mean two very different things and only one of them is true here.
A Flickback video is tall and narrow. Most photos are not. So for every photo something has to decide how to fit a wide picture into a tall frame, and getting that wrong means cutting somebody out of their own family video. To decide it, we send a shrunk copy of each photo to Amazon's face detection service and ask one question: **where in this picture are there faces?**
It answers with rectangles. For each face: a position and a size, written as fractions of the picture. We ask for the basic response only, so we do not receive — and could not store — Amazon's guesses about anyone's age, gender, emotion or facial landmarks. We store the rectangles alongside the photo, and we also keep them in a small lookup table keyed by a fingerprint of the photo file so that re-uploading the same photo does not cost us a second look. If two people are far apart in a photo we show the whole picture on a blurred background instead of cropping. That is the entire purpose.
What this is **not**:
- We do not create a faceprint, face template, or any other mathematical description of what a particular face looks like.
- We do not try to work out who anybody is.
- We do not compare faces between photos, between projects, or between users.
- We do not match faces against any database, ours or anyone else's.
- We do not tag, name, or group people.
- The rectangles record that a face is **here**. Nothing we keep can say **whose** face it is.
One honest detail: the lookup table is keyed by a fingerprint of the photo file rather than by your account, so it has no user or project attached to it. That means those rectangles survive after you delete your account. They are rectangles and a picture size — no photo, no name, no account, nothing that points back to you. It is written down here because it is true, not because it is comfortable.
Your photos are automatically scanned
Every photo you upload is sent to our AI vision and language provider's moderation service and checked against a list of categories that includes sexual content, sexual content involving minors, graphic violence and self-harm. The words of your song are checked the same way before they are sent to be sung.
If something is flagged we record which photo it was, which category it matched, the score the service returned, and the raw response, in a table we can review. Some categories stop the video from being generated at all. If a scan cannot be completed we record that too, rather than assume the photo was fine.
What this means for you in practice: this is an automated system making a numerical judgement, and automated systems get ordinary family photographs wrong. A picture of a baby in the bath or a toddler at the beach can be flagged. A flag is a machine's score. It is not an accusation, and it is not a conclusion anyone has reached about you.
Where your files live, and who can open them
Your photos, your song and your finished video are stored in file storage run by our database and authentication provider and Amazon, both in the United States.
Read this bit
Those files sit at web addresses that contain long random identifiers. **Anyone who has the exact address can open the file without signing in.** We never publish those addresses and they are far too long to guess, but they are not password-protected. Treat a Flickback file link the way you would treat a link to an unlisted video.
When you share a video, we create a public web page for it. Anyone with that link can watch the video and see the cover photo, without signing in — that is the point of sharing — and we count how many times it has been viewed. The page stays up until you delete the project. Once you have sent somebody a link, you cannot take it back from them.
Our servers, database, file storage and content delivery network are all in the United States. If you use Flickback from somewhere else, your information is transferred to and stored in the United States.
Children
Flickback is for family photos. In practice that means people will upload pictures of children, including babies. Rather than tell you that we take this seriously, here is exactly what happens to a photograph of your child:
- A shrunk copy is sent to our AI vision and language provider, which writes a description of it — including a description of the people in it, their expressions and what they are doing.
- A shrunk copy is sent to our AI vision and language provider a second time when the song lyrics are written.
- A shrunk copy is sent to our AI vision and language provider's moderation service to be checked for unsafe content.
- A shrunk copy is sent to our cloud infrastructure provider, which returns rectangles marking where the faces are.
- A copy is placed in Amazon storage so the video can be rendered from it.
- The photo, the description, the rectangles and the finished video are stored on servers in the United States until you delete them.
Flickback is not designed for children to use, and it is not aimed at them. We expect the person holding the account to be an adult who owns the photographs. You must be at least 13 to use it.
**If you are a parent deciding whether to use this:** that list above is the decision. Your child's photographs will be sent to other companies' computers for automated analysis, stored in the United States, and scanned by an automated safety system. You can delete all of it from inside the app. If you are not comfortable with that, do not upload those photographs — and please do not upload photographs of somebody else's children without asking their parent first.
How long we keep things, and how to delete them
You can delete a single project, or your whole account, from inside the app. Account deletion is under Settings. It is immediate and it is not reversible.
Deleting your account removes:
- The photos you uploaded, and every file we generated from them, from our file storage.
- The rendered videos from our video storage.
- Every database record for your projects — the photo descriptions, the creative brief, the lyrics, the storyboard, the moderation records and the job history.
- Your push notification tokens, so notifications stop.
- Your sign-in account itself, which ends every session on every device.
Being honest about what may survive:
- The face rectangles described above, in the lookup table keyed by a fingerprint of the photo file. No account, no project, no photo.
- A count of how many videos you generated on each day, kept for abuse limits.
- Copies held by the companies listed above, for as long as their own retention periods say. We cannot reach into our AI vision and language provider, Amazon, our cloud rendering infrastructure, our music-generation partners, our speech-transcription provider, our app-platform tooling or our crash-reporting service and delete their records.
- Server logs and error reports, which age out on their own schedule.
- Cached copies at our content delivery network, for up to about a day.
- Anything already out of our hands: a video you saved to your camera roll, a link you sent somebody, or a copy they made.
- Routine backups, until they are rotated out.
For projects you do not delete, we keep them for while your account is active; deleted within 30 days of account deletion. There is no automatic clean-up today: your projects stay until you remove them or your account is deleted.
Your choices
- You choose which photos to upload. The app cannot see any others.
- You can decline the photo permission, the notification permission, or both. Declining notifications only means we cannot tell you when a video is ready.
- You can delete any project, or your whole account, at any time, from Settings.
- You can write to [email protected] to ask for a copy of your information, to correct it, or to have it deleted.
One practical warning about guest accounts
If you never add an email address, your account is anonymous — we genuinely do not know who you are. That is good for your privacy and bad for your recovery: if you sign out, delete the app, or lose your phone, there is no way for us to identify your account, restore your videos, or connect a support email to your data. Add an email address in Settings if that matters to you.
Security
Everything travels over encrypted connections. Passwords are handled by our database and authentication provider and we never see them. Your sign-in token is kept in the iOS Keychain on your device. Only our server holds the key that can reach the database directly. Before an error report leaves our server we delete the request body and black out the access tokens inside any file links, because those tokens would otherwise let somebody open the file.
The honest caveat is the one in the storage section above: files are protected by the secrecy of a very long address, not by a password. And no system is perfectly secure. If information is exposed in a way that affects you, we will tell you, and we will tell any regulator we are required to tell.
Changes to this policy
If we change what we do with your information, we will change this page, and we will change the date at the top. For a change that materially affects you, we will tell you in the app before it takes effect.
Contact
Questions, requests, or complaints: [email protected]. Support: https://flickback.app/support. Postal address: Renewal Ventures, LLC, 5966 South Dixie Hwy, Suite 300, Miami, FL 33143.