Flick AI
Last updated 12 September 2026
This describes what the Flick AI iOS app collects, who receives it, and what you can do about it. It is written from the app's actual behaviour: where it names a service, a data type or a limit, that is what the code does.
Flick AI is operated by Kasparas Sasnauskas, an individual developer based in Lithuania, who is the data controller for everything described here. Contact: [email protected].
Flick AI is for people aged 16 and over. The app asks your age before it asks anything else, and will not create an account for anyone younger. We do not knowingly collect data from under-16s; if you believe we have, write to us and we will delete it.
Scroll Mode uses Apple's Screen Time frameworks. The identifiers iOS gives us for the apps you choose are opaque, encrypted tokens — we cannot read which apps they refer to, and we never transmit them. We also do not transmit the apps' names, and we never receive how long you spend in them: iOS tells our code only that a usage threshold was reached, never any duration.
Your selection, and everything Screen Time knows about your usage, stays on your iPhone.
Your email address and an account identifier. If you sign in with Apple or Google, we also receive the name on that account. If you use Sign in with Apple's private relay, we only ever see the relay address.
Your education level, year or grade, subject area, preferred explanation style, and the language of your material. These are sent with requests to our AI provider so the questions match your level and language.
PDFs, photos, slides and text you add to build an exam, together with the filename, file type and page count. The file itself is stored so your deck can keep generating from it. Verbatim excerpts of it are stored alongside the facts we extract, because a question has to be checkable against its source.
The decks, cards and questions generated for you, which you have seen, which you answered correctly, and your progress through each deck. This is the app working — without it there is nothing to show you next.
Whether you are subscribed, which product, whether it will renew, and when it expires. We never see your card details. Payment is handled entirely by Apple.
If you use Send feedback, we store your message with your account identifier, your app version, build number, iOS version and the screen you sent it from. The text of your message is never sent to our analytics provider.
We record which screens you open and a set of specific events — signing in and out, deleting an account, viewing the paywall, starting, completing, failing or restoring a purchase, submitting feedback, a deck failing to generate, an error you were shown, and whether the Scroll Mode shield fired. These carry your account identifier and technical context such as device model, OS version, app version and locale.
They do not carry your email address, your study material, your cards, your answers, your feedback text, or the names of the apps you block. We do not use analytics for advertising and we do not sell them.
We log how many AI requests you have made in the last hour, to enforce fair-use limits, and the cost and token count of each request. When you ask for a sign-in link we record a one-way cryptographic hash of your email address and of your IP address, to stop the link being used to flood an inbox. The IP address itself is not stored.
Flick AI uses OpenAI and no other AI provider. Your questions
are generated by their gpt-4o, gpt-4o-mini and
gpt-4.1-mini models.
What we send: the text extracted from your material; the facts and verbatim excerpts drawn from it; your study profile fields listed above; and, when you use Ask AI, your question, the answer you picked and the earlier turns of that conversation. If a document is a scan or a photo with no text layer, we send the page images so they can be read.
What we never send: your name, your email address, or your account identifier. None of them appear in anything we send to OpenAI.
Training: we do not use your material to train any model. OpenAI states that data submitted through its API is not used to train its models unless the customer opts in, which we have not. OpenAI retains API content for up to 30 days for abuse monitoring. We ask for your explicit agreement before sending anything to OpenAI for the first time.
We use a small number of providers. Each acts on our instructions and only to provide the function described. Each is bound by terms requiring protection of your data equivalent to that described in this policy.
| Provider | What it receives | Why |
|---|---|---|
| Supabase | Everything listed above | Accounts, database, file storage (EU, Ireland) |
| OpenAI | Material, excerpts, profile fields, Ask AI messages, page images | Generating your questions (United States) |
| PostHog | The analytics described above | Product analytics (EU Cloud) |
| RevenueCat | Your account identifier and Apple's purchase data | Subscription status. No email, no study content |
| Apple | Sign-in, payments, and push notifications | Live Activity notifications carry no app name |
| Sign-in only, if you use it | Authentication | |
| Upstash | Your account identifier and a deck identifier | Scheduling background generation |
| Resend | Your email address and the sign-in link | Delivering sign-in emails |
| Vercel | Requests to our API pass through it | API hosting |
Transfers outside the EEA are made under the European Commission's Standard Contractual Clauses.
Your account data, uploaded material and study history are kept for as long as your account exists.
Deleting your account in the app removes your profile, decks, cards, concepts, study progress, feedback, subscription record and every file you uploaded. There is no undo and no recovery period.
Being straight about what deletion cannot reach:
If you are in the EEA or the UK you have the right to access your data, correct it, have it erased, receive a portable copy, restrict or object to processing, and withdraw consent where we relied on it. Write to [email protected] and we will respond within one month.
You may also complain to a supervisory authority. In Lithuania that is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt.
Data is encrypted in transit. Access to your rows is enforced at the database level, so one account cannot read another's data, and uploaded files are stored in a private bucket scoped to your account. No system is perfectly secure and we will not claim otherwise.
If we change this policy we will update the date above, and anything material will be announced in the app. Where a change affects what we send to a third party, we will ask for your agreement again rather than relying on the old one.