The short version
Recording stays on your PC unless you explicitly upload a clip. Flashback does not sell personal information, build advertising profiles, or scan your local library. Cloud needs enough account, file, and security data to host the clips you choose.
Local app data
Replay segments, clips, screenshots, clip metadata, custom sounds, preferences, and diagnostic logs are stored on your device. Flashback accesses them to provide the features you use. They are not sent to Cloud merely because the app is running.
The optional participation count uses a daily rotating anonymous token for an approximate number of devices seen within 30 minutes. It is not an account total. The token does not include a clip, game name, hardware profile, account, setting, or feature history and can be disabled in Settings.
Cloud account data
Before Discord sign-in, the Cloud page asks for a date of birth to perform a neutral age-eligibility check. The date is processed only for that decision and is not stored. We retain that the age gate passed, the agreement versions, and the time. When you continue, we receive your Discord user ID, display name, and avatar reference; security token records; plan and storage usage; and account lifecycle timestamps. Discord authentication tokens are used briefly to retrieve that profile and are then revoked.
Uploaded content
For each chosen upload, we store the MP4, poster image, title, size, duration, dimensions, frame rate, codec details, random share identifier, and upload state. We also record when a share link was last viewed and count total and privacy-preserving daily unique views.
Flashback does not use uploaded clips to train an AI model or target advertising.
Network and security data
Cloudflare processes connection information such as an IP address to deliver and protect the service. Flashback turns the address into a secret-keyed, rotating value for rate limits and short-lived unique-view counting instead of storing the raw address in its application database. Operational logs use random request IDs and are normally retained for no more than 30 days unless needed for a documented security, abuse, or legal matter.
Billing
Stripe handles checkout, payment details, billing addresses, tax calculation, receipts, and its own fraud controls. Flashback stores Stripe customer and subscription identifiers, plan, subscription status, and paid-through dates. Flashback does not store full card numbers.
Why we use data
We use data to provide requested features, authenticate accounts, enforce quotas, process billing, keep links working, prevent abuse, measure service health and cost, answer support and legal requests, and comply with law. Depending on where you live, the legal basis may be performance of a contract, legitimate interests in security and operation, consent, or legal obligation.
Service providers
Cloudflare provides application delivery, database, security, and object storage. Discord provides sign-in. Stripe provides billing and tax tooling. These providers process data under their own terms and privacy notices. We may disclose information when legally required, to protect people or the service, or as part of a properly structured business transfer.
Retention
Ready clips remain until you delete them or the account is deleted. Abandoned upload reservations expire within hours. Sign-in handoffs expire within minutes. Refresh sessions normally expire after 30 days and rotate when used. Short-lived unique-view records are removed after about eight days; aggregated counts can remain. If a future free-plan retention limit is introduced, affected users will receive clear advance notice and a chance to keep their local originals.
An account-deletion request disables sharing immediately and normally purges active content within seven days. Provider recovery copies roll off under bounded backup schedules and are not returned to active use. Billing, dispute, safety, and legal records may be retained as required.
Your choices and rights
You can avoid Cloud entirely, disable the anonymous active-user count, rename or delete a shared clip, export Cloud account data, sign out, or request Cloud account deletion in the app. Depending on where you live, you may also have rights to access, correct, delete, restrict, object, or appeal.
Send a privacy request to [email protected]. We may need to verify account ownership before acting.
Children
Flashback Cloud is not available to children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 created an account, contact [email protected] so we can investigate and remove it.
Security and international use
We use short-lived upload permissions, encrypted transport, Windows-protected desktop tokens, hashed server tokens, rate limits, access-controlled administration, and recovery procedures. No service can guarantee perfect security.
Cloud infrastructure may process information in the United States and other locations where providers operate. Public availability by country will be limited until the corresponding privacy, consumer, and tax requirements are ready.
Changes and contact
We will post changes here with a new version date and request renewed acceptance when a material Cloud change requires it.
Privacy and legal questions can be sent to [email protected].