FixedTime

Privacy Policy

Effective date: September 12, 2026
Last updated: September 28, 2026
Published by: FLX Create LLC, Los Angeles, California, USA
What changed recently

September 28, 2026: the app is now called FixedTime. It runs at app.fixedtime.app, with its home page at fixedtime.app. Nothing about what we collect has changed. The old address keeps working; see section 3 for what that means for data already on your device. FLX Create LLC remains the company behind it.

September 20, 2026: an optional email newsletter you can join and leave at any time (section 9); one-step Delete my account and all data in Settings (section 13); a plain statement that FixedTime sets no cookies (section 15). Corrected: integration links are stored on your device, not in the Keychain, and we no longer describe an age question that the app does not ask.

Rate limiting (added 16 September): our server now counts requests per hour to stop abuse. Doing that means briefly storing an hourly, irreversible 8-byte hash derived from your IP — never the address itself — which is deleted within the hour. It is the only thing our relay stores, and section 7 sets out exactly how it works.

Photos and scanned documents (added 14 September) stay on your device and are never uploaded — see section 4. Assignment reminders (also 14 September) are composed and shown by your own device, with no push service involved — see section 5.

The AI assistant has been removed from FixedTime. Nothing in the app is sent to Anthropic or to any AI provider any more, and the sections describing that have been deleted rather than left standing. Canvas now connects by read-only calendar link instead of an access token — see section 10. Optional cloud backup (added 12 September) is unchanged: encrypted on your device, unreadable by us, and off unless you switch it on.

01The short version

FixedTime stores your habits and schedule on your device. We do not sell your data, we do not run ads, and we do not track you across other apps or websites.

Data leaves your device in only four situations, and each one is something you turn on yourself:

  • You turn on cloud backup, which sends an encrypted copy of your data to our server. It is encrypted on your device first, with a key that never leaves your device, so we hold something we cannot read.
  • You connect an optional integration such as Canvas, and your device requests data from that service directly.
  • You buy a subscription, which is processed by Apple, not by us.
  • You join the optional newsletter, which sends us the email address you type in. See section 9.

We never ask for your name or a password. We only ask for your email address if you choose to join the newsletter, and creating a backup account never requires it.

This summary is here to be useful, not to replace the detail below. Where the summary and the full sections differ, the full sections govern.

02Who we are

FixedTime is published by FLX Create LLC, a limited liability company organized in the State of California, United States. In this policy, "we," "us," and "our" mean FLX Create LLC. "You" means the person using the app. "The app" means FixedTime on any platform we publish it for, including the web app, iPhone, iPad, Apple Watch, and Mac.

For the purposes of the EU and UK General Data Protection Regulation, FLX Create LLC is the controller of the limited personal data described in this policy.

Our contact details are in section 20.

03What stays on your device

The core of FixedTime works entirely on your device. The following is created by you and stored in the app's own storage on your device:

  • Your habits, their targets, and the days you log them
  • Your schedule: blocks, their titles, times, categories, and notes
  • Your checklists and the steps inside each block
  • Your completion history, day scores, and streaks
  • Your alarm times and app settings
  • Your answers to the setup questions, including the goal you wrote in your own words
  • Any custom trackers or metrics you create
  • Any nutrition file you import, and the values read from it
  • Photos you take in the app, and the folder, name and note you file them under
One address at a time

The app is served from app.fixedtime.app, and also from time.flxcreate.com, which is where it used to live. Your browser keeps a site's on-device storage separate for each address, so the data listed above belongs to whichever address you created it on and is not visible from the other. It is not lost, and we never see it either way — but opening the other address shows an app with nothing in it.

You can carry it across yourself with Settings → Data → Export backup, or turn cloud backup on, in which case signing in at either address restores it. The iPhone app keeps its own storage and is unaffected by any of this.

If cloud backup is off, none of this is transmitted to us, we have no copy of it, and we cannot recover it for you if you lose it.

If you turn cloud backup on, a copy of this data is encrypted on your device and then sent to our server. We still cannot read it, for the reasons set out in section 8 — but a copy does exist outside your device, and we would rather say so plainly than hide it in a clause.

Why this matters

With backup off, this data is processed only on your device, is not "collected" as Apple defines that term for App Store privacy labels, and is not disclosed in them. With backup on, an encrypted copy is transmitted to us, so we do disclose it — as data that is not linked to your identity, because we hold no identifier that could link it to you.

04Photos and scanned documents

FixedTime can take a photo of a worksheet, a receipt, a form, a meal — anything — clean it up so it reads like a document, and file it under a folder or attach it to an assignment.

Those images never leave your device. They are stored in a separate database in the app's own storage on your phone, and they are deliberately excluded from cloud backup. We have no copy of them and no way to obtain one. This is not a promise about our intentions; the images are not sent anywhere, so there is nothing for us to hold.

Two consequences we would rather state than bury:

  • They are not backed up. If you lose the phone, delete the app, or clear its storage, the photos are gone. Export a folder to PDF if you need a copy somewhere safe.
  • They can be removed at any time. Deleting a photo in the app deletes the image itself, not just its entry in a list.

FixedTime asks your device for camera access only when you tap to take a photo, and only for that purpose. No image analysis, face detection, or text recognition is performed by us or by any third party. The clean-up step is arithmetic on the pixels, carried out on your device.

05Reminders and notifications

If you allow notifications, FixedTime can remind you about assignment due dates and your morning alarm. The reminder is composed on your device from data already on your device, and is shown by your device. Nothing is sent to us or through a push service — FixedTime has no push server, holds no push subscription, and cannot message you when the app is closed.

A record of which reminders have already been shown is kept on that device so the same one does not repeat. It stays on the device and is not included in cloud backup.

You can turn reminders off in Settings, and you can revoke notification permission in your device's own settings at any time.

06What leaves your device, and when

This table is the complete list. Nothing else is transmitted.

WhatWhenGoes to
An encrypted copy of your app data, plus a one-way account identifier Only after you create a backup account, and only when a backup runs Our sync server, hosted on Cloudflare
Your Canvas calendar feed link, so the feed can be fetched on your behalf Only when you press Sync, and only if you connected Canvas Our relay on Cloudflare, then your school's Canvas server. Neither the link nor the calendar is logged or stored. See abuse prevention for the one thing that is briefly counted.
Purchase and subscription information When you subscribe, restore, or renew Apple
Your email address and a record of your consent Only if you join the newsletter Our server, hosted on Cloudflare. See section 9.

Photos and scans are not on this list, and that is the point. They are never transmitted — not to us, not to a backup, not to anyone.

We do not embed advertising networks, analytics SDKs, or third-party trackers in the app. If that ever changes, we will update this policy and describe what is collected before the change takes effect.

Anonymous usage counts (off unless you turn them on)

FixedTime sends nothing about how you use it unless you switch this on yourself. It is off when you install the app and it stays off until you go to Settings → Anonymous usage and turn it on. There is no prompt nagging you to, and nothing about the app works differently either way.

If you do turn it on, three things are sent to our own server, and only these three:

  • A random number the app generates for itself the first time it runs. It is not your device’s identifier, not an advertising identifier, and not connected to your account. It exists so that “did this installation open the app again a week later” has an answer. Turning the setting off deletes it.
  • The word “ios” or “web”.
  • Counts of events from a fixed, published list — for example “3 blocks completed” or “1 week planned”. The list is built into the app and the server rejects any name that is not on it. There is no field anywhere in the message that can carry free text, so the title of a block, the name of a class, a note, a photo or a file name cannot travel on this channel even by accident.

How it is stored matters as much as what is sent. The event counts are written to a table that has no identifier column at all — it records that something happened that day and how many times, and there is nowhere in it to record who. The return-visit record is written to a separate table holding only the random number and a date. The two tables cannot be joined, because there is no column they share. This is a property of how the database is built, not a policy we are promising to follow.

No advertising identifier, no cookie, no IP address and no third-party analytics company is involved at any point. Nothing is sent before you have accepted the terms, and nothing is sent at all while the setting is off.

07Abuse prevention

Our server limits how many requests one caller can make in an hour. Without it, anyone could fill our database or use our Canvas relay as a free bandwidth pipe, and the cost of that lands on us.

To count requests we need to tell callers apart. We do it like this:

  • Your IP address arrives with every request, as it does with every request to every website. We never write it down.
  • We combine it with the current hour and a fixed internal string, run that through a one-way hash, and keep only the first 8 bytes of the result.
  • That short hash and a counter are stored — nothing else. No IP address, no account id, no request contents.
  • Every row expires within the hour and is deleted.

Because the hash changes every hour and cannot be reversed, these rows cannot be used to follow anyone over time or to link requests back to a person. They exist to answer one question — “has this caller made more than N requests this hour?” — and then they are gone.

Why we are telling you about 8 bytes

We could have called this “standard security measures” and left it out. But this policy says elsewhere that our relay stores nothing, and after this change that would not have been strictly true. So here is the exception, stated plainly.

08Cloud backup and sync

Phones get lost, broken, and replaced. Cloud backup exists so that your history survives that. It is off until you create a backup account, and the app is fully functional with it off.

Your account, and what your password actually does

An account lets your history follow you to a new phone, and is how a subscription knows it is you. Creating one is optional; the app works without it.

  • Your password never reaches us. Your phone stretches it 600,000 times (PBKDF2-HMAC-SHA-256) and sends only the result. We salt that result again with 16 random bytes and a secret held outside the database, and store the hash of that. We never hold your password, not even for the instant before hashing it.
  • What we store about you: your email address, the optional first name you give us, that password hash and its salt, whether you have confirmed your address, whether two-step sign-in is on, whether you asked for our newsletter, which plan you are on, and when the account was made.
  • Your backup key is wrapped, not held. Your history is encrypted with a key your phone generates. We keep two locked copies of that key — one locked by your password, one by each recovery code — so a new phone can get your history back. Both are ciphertext to us. We cannot open either.
  • Recovery codes are made on your phone, shown once, and never sent to us in a form we can read. If you lose both your password and every recovery code, your old backup cannot be recovered by anyone, including us. That is the honest cost of encrypting it properly.
  • Sessions. When you sign in, your device holds a random token. We store only a hash of it, along with the device name you see in Settings, so you can sign out everywhere. Changing your password signs out every other device.

We do not ask for your phone number, your address, your date of birth, or any payment details. Apple handles payment; we never see a card.

Using the app without an account

Everything except cloud backup and a subscription works with no account at all. If you never make one, we hold nothing about you beyond what section 7 describes.

Your data is encrypted before it leaves your device

The backup is encrypted on your device, using AES-256-GCM with a key derived from your sync key by PBKDF2-HMAC-SHA-256 at 210,000 iterations with a random salt, and a fresh random initialization vector for every backup. Only then is it sent to us.

This is end-to-end encryption, and we mean the literal thing: we do not hold your sync key, so we cannot derive the decryption key, so we cannot read your backup. Neither can anyone who compromises our server, and neither can anyone who compels us to hand it over.

Exactly what our server stores

One row per account, containing four values and nothing else:

ValueWhat it is
Account identifierA 64-character hash of your sync key. Opaque; not reversible; not linked to any personal detail.
Encrypted blobYour app data, already encrypted. Unreadable to us.
Updated timestampWhen the most recent backup arrived, so the app can tell you.
Size in bytesThe length of the blob, used to enforce a size limit.

There is no column for a name, an email address, a device identifier, an advertising identifier, or an IP address. Each backup replaces the previous one; we do not keep a history of versions.

Where it is hosted, and what our host can see

The sync server runs on infrastructure operated by Cloudflare, Inc., which acts as our processor and service provider. Cloudflare does not receive the contents of your data in readable form — what passes through it is the same ciphertext described above.

As with every service reached over the internet, the network connection itself carries your IP address to the host handling the request. Cloudflare processes connection-level information of this kind for security and delivery purposes under its own terms; we do not store IP addresses, and we do not join any connection information to your account identifier.

If you lose your key

This part is not recoverable, and we want you to read it before you rely on it

Because we do not hold your sync key, we cannot reset it, recover it, or decrypt your backup without it. If you lose the key, the encrypted copy on our server is permanently unreadable — by us and by you. There is no support request that can undo this. That is the honest cost of the app not being able to read your data, and the app states it before it lets you continue past the key screen.

Turning it off and deleting the copy

  • Settings → Sign out removes the key from that device and stops it backing up. Your data stays on the device. The encrypted copy on our server remains until you delete it.
  • Settings → Delete my cloud account permanently deletes the row from our database. Nothing of yours remains on our server afterwards. This is immediate and cannot be undone.

09Email newsletter (optional)

FixedTime has an optional newsletter with product news and tips. It is off unless you join it, and nothing in the app depends on it.

How you join

In Settings → Newsletter you type your email address and tick a box that starts unticked. The box reads: “Email me product news and tips about FixedTime from FLX Create LLC. I can unsubscribe at any time.” The Subscribe button stays disabled until you tick it. We never pre-tick it, and we never add anyone to the list any other way — not from a backup, not from a support email, not from a purchase.

Then we email that address to check it is really yours. Typing an address into a box is not proof that it belongs to the person typing, so nothing is sent to it until someone opens that email and taps Yes, subscribe me. Until then the address sits on our server marked unconfirmed and receives nothing. If nobody ever taps it, it never joins the list. This also means that if a stranger types your address into that box, all that reaches you is the one question — and ignoring it is the answer.

What we store

ItemWhy
Your email addressTo send you the newsletter
The exact wording you agreed to, and whenOur record that you consented
Where you signed up (for example, “app settings”)To know which consent screen you saw
A random unsubscribe tokenSo an unsubscribe link works for you and can’t be forged by anyone who only knows your address
Whether you confirmed, and whenNothing is sent to an address that has not confirmed

If your address is already on our list and it gets entered again — by you on another phone, or by someone else — we leave the existing record exactly as it is. We do not overwrite the consent we already recorded, and we do not issue a new unsubscribe token, because that would quietly break the unsubscribe link in every email we have already sent you.

That is all. Your newsletter address is not connected to your backup or to anything inside the app. Your backup is identified only by an opaque hash, so we could not link the two even if we wanted to.

How to leave

  • Every newsletter email has an unsubscribe link, and supports the one-click “Unsubscribe” button built into most mail apps.
  • In the app: Settings → Newsletter → Unsubscribe.
  • Or email [email protected].

Unsubscribing deletes your address from our list immediately — we do not keep a list of people who left. It takes effect at once online; if you email us, we act within 10 business days, as U.S. law (CAN-SPAM) requires, and usually the same day.

What our emails will always do

Every email identifies FLX Create LLC as the sender, includes our postal address, has an honest subject line, and carries a working unsubscribe link. We will not sell, rent or share your address, and we will not use it for anything other than the newsletter and replies to messages you send us.

We store the list on Cloudflare (see section 12). Before the first newsletter is sent, we will name the email delivery provider we use in this section.

If you are in the EEA or UK, our legal basis is your consent, which you can withdraw at any time as described above.

10Optional integrations

FixedTime can connect to services you already use, so that your own information appears alongside your schedule. Every integration is off until you turn it on, each is a separate decision, and none is required to use the app.

Canvas

We never ask for your Canvas username, your password, or an API access token. Instructure's own API Policy prohibits an app used by multiple people from asking them to generate access tokens, and we do not intend to hold student credentials under any circumstances.

Instead, Canvas gives every user a personal, read-only calendar feed link (in Canvas: Calendar → Calendar Feed). If you choose to connect Canvas, you paste that link into FixedTime. It returns your assignments, their due dates, and your class events. It is read-only: FixedTime cannot submit work, change grades, post, or alter anything in your Canvas account.

Where the link is kept. On your device. It is never included in your encrypted backup and never shared with anyone.

How the request is made. Canvas does not permit browsers to read the feed directly, so the request passes through a relay we run on Cloudflare. That relay fetches the feed and hands the text back to your device. It accepts only Canvas calendar-feed addresses, and it does not log or store the link or the calendar contents. We do not keep a copy of your assignments on our servers. The relay does keep a short-lived request count to stop abuse — see section 7 for exactly what that involves.

How to cut it off. Disconnect in Settings, which deletes the link from your device. You can also reset the feed inside Canvas, which invalidates the old link everywhere it has ever been used.

Treat the feed link like a password

Anyone who has that link can read your Canvas calendar, without logging in. Do not post it or share it. If you think it has been exposed, reset the feed in Canvas immediately.

Nutrition file import

If you export a data file from a nutrition-tracking service and import it into FixedTime, the file is read entirely on your device. It is never sent to any third party. If cloud backup is on, values you have saved into the app are included in the encrypted backup like the rest of your data. Because this is health-related information, it is also covered by our separate Consumer Health Data Privacy Policy.

Services governed by their own terms

When you connect a third-party service, your use of that service continues to be governed by that service's own terms and privacy policy. We do not control those services and are not responsible for how they handle your information on their side.

11Purchases and subscriptions

All purchases made through an Apple platform are processed by Apple, which is the seller of record. We never see or receive your payment card number, your billing address, or your Apple Account credentials. Apple provides us with anonymized, aggregated sales reporting, which does not identify individual customers.

Your subscription status is checked on your device against Apple's records. Manage or cancel your subscription in your device's Settings, or at apps.apple.com/account/subscriptions.

12Who we share data with

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have never done so.

The only parties who receive any data in connection with the app are:

PartyWhat they receiveWhy
Cloudflare, Inc.Your encrypted backup and its opaque account identifier, in ciphertext they cannot read; and, only if you join the newsletter, your email address and consent recordTo host the sync server, store the backup, and store the newsletter list
An email delivery provider (to be named in section 9 before the first newsletter)Newsletter subscribers’ email addresses onlyTo deliver the newsletter
Apple Inc.Purchase and subscription recordsTo process purchases and manage subscriptions
Services you connectAn authorization token and data requests, sent directly from your deviceTo retrieve the data you asked for

We require that any third party with whom the app shares user data provides the same or equal protection of that data as is stated in this policy.

We may also disclose information if we are legally compelled to do so by valid legal process, or where necessary to protect our rights or the safety of others. Given the architecture described above, what we could produce in response to such a request is an opaque identifier and a block of ciphertext we cannot decrypt.

13How long we keep data, and how to delete it

Data on your device

Data stored on your device is kept until you delete it. You have two ways to do so:

  • Settings → Delete my account and all data in the app. In one step it permanently deletes your cloud backup (if you have one), removes your email address from the newsletter (if you joined), and erases your habits, schedule, history, photos, settings and imported data from the device. If our server can’t be reached, it stops and tells you before erasing anything, so you are never left with a copy on our server that you can no longer reach.
  • Deleting the app, which removes its storage container along with it.

Both are immediate and irreversible on that device.

Photos and scans can also be deleted one at a time, in the app, which removes the image itself and not merely its listing. Because they are never uploaded, deleting them on the device deletes them everywhere they exist.

Your encrypted backup

If cloud backup is on, the encrypted copy is kept until you delete it, because its entire purpose is to still be there when you need it. Each backup replaces the previous one, so we hold one copy, not a history.

Settings → Delete my cloud account deletes only the backup, permanently. Settings → Delete my account and all data deletes the backup and everything else. Simply deleting the app does not delete the backup — that is deliberate, so that reinstalling on a new phone still works.

If an account is untouched for 24 months, we may delete the backup. We cannot notify you first, because we have no way to contact you.

Data held by others

Apple retains purchase records under its own policies. Data held by a service you connected is retained by that service under its own policy; disconnecting in FixedTime revokes our access but does not delete your account with them.

Data held by us

If you email us, we keep that correspondence for as long as needed to handle your request and for a reasonable period afterwards, and no longer than two years unless a longer period is legally required. We do not add you to any mailing list unless you separately join the newsletter yourself.

Your newsletter address

Kept until you unsubscribe or delete your account, then deleted. See section 9.

14How to withdraw consent

Every transmission described in this policy is switched off by a control inside the app:

  • Cloud backup: Settings → Sign out stops it. Settings → Delete my cloud account also erases the copy we hold.
  • Canvas: Settings → Integrations → Disconnect, which deletes the feed link from your device. Resetting the feed inside Canvas revokes it everywhere.
  • Newsletter: the unsubscribe link in any email, or Settings → Newsletter → Unsubscribe. Your address is deleted.
  • Everything: Settings → Delete my account and all data.

Withdrawing consent does not affect processing that already took place, and it does not disable the rest of the app. FixedTime is fully usable with every optional feature turned off.

15Do Not Track

California law requires us to state how we respond to "Do Not Track" signals. FixedTime does not respond to Do Not Track signals, because it does not perform the tracking those signals are designed to stop. The app does not monitor your activity across other apps or websites, does not build an advertising profile, and contains no third-party advertising or analytics networks. The optional usage counting described in section 6 is confined to this app, is off by default, and cannot follow you anywhere.

We also do not permit other parties to collect personally identifiable information about your online activities over time and across different sites or services through the app.

Cookies

FixedTime sets no cookies — none of our own and none from third parties — which is why it shows no cookie banner. The app does keep your data in your device’s own storage (browser local storage and IndexedDB, or the app container on iOS). That storage is strictly necessary for the app to work, is never read by us, and is never used to track you. You can clear it at any time with Settings → Delete my account and all data.

16Children

FixedTime is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. You must be 13 or older to use the app, and you confirm this when you accept the Terms on first launch. It is not submitted to the App Store Kids Category and is not designed for or marketed to children.

If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you are a parent or guardian and believe this has happened, contact us at the address in section 20. Because a backup is identified only by an opaque hash, we will need the sync key in order to identify and delete the corresponding backup.

17Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or port your personal information, to object to processing, and to withdraw consent.

For the data stored on your device, these rights are self-service and immediate. You hold the data. You can view all of it in the app, edit any of it, export it, and erase it, without asking us and without waiting for us. We think that is a better answer than a request form.

For your encrypted backup, the same is true. You can read it by pulling it into the app with your key, replace it by backing up again, and delete it outright from Settings. We cannot exercise these rights on your behalf even if you ask us to, because we cannot decrypt the backup and cannot identify which row is yours without your key.

For anything else described in this policy, or to ask a question about how we handle information, write to us at the address in section 20. We will respond within 45 days, and will tell you if we need longer.

If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your national data protection supervisory authority. Where we transfer personal data outside your region — for example, to Cloudflare in the United States — we rely on appropriate safeguards, including standard contractual clauses where applicable.

If you are in Washington State or Nevada, additional rights apply to health-related information. See our Consumer Health Data Privacy Policy.

We will not discriminate against you for exercising any of these rights.

California residents

If you live in California, the California Consumer Privacy Act as amended gives you the right to know what personal information we collect and why, to correct it, to delete it, and to opt out of its sale or sharing. For completeness:

  • We do not sell or share your personal information, in the CCPA's sense of those words or any other. We have never done so and have no plans to.
  • We serve no advertising and use no third-party analytics or tracking software. There is no advertising profile of you to opt out of. Our own anonymous usage counting is off unless you switch it on, collects no personal information, and is described in section 6.
  • The categories we collect are identifiers (your email address, and a first name if you give one) and, if you turn on backup, commercial-ish records in the form of ciphertext we cannot read. That is the whole list.
  • Where it comes from: you, directly. We buy no data and receive none from brokers.
  • Who we disclose it to: only the service providers named in section 12, under contracts that forbid them from using it for their own purposes.
  • How long we keep it: see section 13. Deleting your account deletes it.
  • How to ask: email the address in section 20, or simply use Settings → Delete my account and all data, which does the whole thing immediately and without asking anyone.

If there is ever a breach

If personal information of yours is ever exposed, we will tell the people affected within 30 days of discovering it, as California law now requires, and sooner if we can. We will say what happened, what was exposed, what we have done, and what you should do. We would rather send an embarrassing email than a quiet one.

18Security

We take reasonable measures appropriate to the nature of the data and the size of our operation:

  • Your backup is encrypted on your device with AES-256-GCM before transmission, under a key we do not hold. A breach of our server exposes ciphertext and an opaque hash, not your data.
  • Your password is stretched 600,000 times on your device and never sent to us. What we store is a salted hash of that result, with the extra secret needed to test a guess kept outside the database. A copy of the database alone is not enough to attack it.
  • Sign-ins, sign-ups, password resets and confirmation emails are rate limited per address and capped across the whole service, so neither one machine nor a network of them can guess its way in or run up our bill.
  • Your sync key is held in its own storage slot on your device, is never placed in app state, and is never included in the backup payload.
  • Your Canvas calendar link is stored only on your device. When you sync, our relay passes it to Canvas and discards it; it is never logged or stored by us.
  • Our server sends strict security headers, including a Content Security Policy that blocks injected scripts, and rate-limits every endpoint to prevent abuse.
  • All network requests use encrypted connections.
  • With cloud backup off, your habits and history never leave your device at all, and are protected by your device's own encryption and passcode.

No method of storage or transmission is completely secure, and we cannot guarantee absolute security. Keeping your device locked, updated, and under your control — and keeping your sync key somewhere safe and private — is an important part of protecting your information.

19Changes to this policy

If we make a material change to this policy, we will update the effective date at the top, and we will notify you inside the app before the change takes effect, with a summary of what changed. For changes that expand what data is transmitted or who receives it, we will ask for your consent again rather than assuming it.

Non-material changes — clarified wording, corrected typos, updated contact details — will be reflected by a revised "last updated" date.

The September 12, 2026 revision added cloud backup, which is a material change. It is off by default and requires you to switch it on, so no data of yours was transmitted under it before you chose to.

20Contact us

Questions, complaints, and requests about privacy can be sent to:

FLX Create LLC
Attn: Privacy
[BUSINESS ADDRESS — see note below]
Los Angeles, California, USA

Email: [email protected]
Phone: [BUSINESS PHONE — see note below]

We aim to reply within five business days, and in any case within the timeframes required by applicable law.