fliklist — Privacy Policy

Lucid Studios LLC · Effective 19 August 2026

The short version

Every line here is a plain-English restatement of a section below — nothing extra, nothing softened.

Who this is about

fliklist is how two people decide what to watch: you each swipe through the same films and shows, and fliklist tells you what you both said yes to. It is published by Lucid Studios LLC. Questions go to developer@lucidstudios.io.

This one policy covers all three ways you can use fliklist — the iPhone app, the Android app, and the website at flicker.joeyshub.com. They are the same product talking to the same server and the same database, so splitting this into separate policies would only mean two pages saying the same thing and drifting apart. Where the app and the website genuinely differ, this policy says so on the spot rather than hiding it.

fliklist is rated for adults and is not directed at children. We do not knowingly collect anything from anyone under 18.

Your account

Unlike a timer or a notepad, fliklist cannot work without an account — the whole point is that your swipes meet someone else's. Creating one stores:

There is no self-service password reset yet. If you are locked out, write to developer@lucidstudios.io.

What you do in fliklist

This is the part that lives on our server, because it has to be compared against another person's. Everything here is tied to your account:

Trailers are the one thing fliklist plays that it does not hold itself. Tapping play opens an embedded YouTube player — Google's privacy-enhanced youtube-nocookie.com one — which means your device connects straight to Google for that video. What they can see is the ordinary shape of a video request: your IP address, your browser or app's identification line, and which trailer you asked for. Nothing about your account, your swipes or your partner goes with it, and nothing happens at all until you tap play.

The films and shows themselves are not about you. fliklist keeps its own catalogue — names, posters, blurbs, scores, cast, and which services carry what — refreshed from Watchmode. That catalogue is the same for everybody.

What your partner sees

Your display name and your email address, and everything the two of you share: what you matched on, what either of you added or marked watched, and the activity feed for your pairing. That is what a shared list is.

The email address is worth spelling out, because it is the one people assume is hidden. It is printed under your name on the Partners screen, and it is what "Added by …" says beside anything you put on a shared list yourself. Somebody you ask to pair with sees it too — they have to know who is asking. An invitation emailed to a stranger does not: that message carries your display name only, and your address reaches them once they have an account and the pairing exists. Your display name is a label on top of it, not a mask over it.

Your partner also sees, in the home feed, how many titles you swiped through on each day you used the deck and when the last of those was — a number and a time, not which titles. It is what tells them you have been keeping up, so neither of you is waiting on the other without knowing it.

Your swipes are never published to your partner as a list. Two of them show through anyway, and it is fairer to say so than to claim otherwise. The Alone list shows each of you the titles you said yes to that every active partner has said no to — so with one partner, their Alone list tells them, title by title, which of the things they liked you passed on. And when a title stops being a match because one of you changed a yes into a no, the other is told which title it was. Everything else — the titles neither of you flagged, and every no on something they never said yes to — stays yours.

Your partner never sees your password, and never sees anything from a different pairing. You can hold more than one pairing at a time, and they are entirely separate from each other.

Either of you can unpair at any time, from the partners screen.

Inviting somebody

To invite a partner you type their email address. We store that address so the invitation can be tracked and resent, and we mail it — through Resend, our email provider — a message saying who invited them and carrying a link. If it did not arrive you can send it again, and each resend is another message carrying a fresh link, so there may be more than one.

fliklist never reads your contacts. There is no address book access on either phone: the only email address involved is the one you type.

You can cancel a pending invitation from inside the app. That kills the link immediately — it stops working there and then. The record of the invitation is not thrown away, though: it is what tells whoever you invited that the link was cancelled rather than simply broken, and it still holds the address you typed. It stays until you delete your account.

Notifications

Notifications are optional, off until you turn them on, and can be turned off again — in fliklist's Settings, or in your phone's or browser's own settings.

In the app, turning them on stores a Firebase Cloud Messaging device token and which platform it came from — iPhone or Android. The token is a delivery address for this one device. Google delivers the message for us (and Apple's push service carries it the last leg on an iPhone); a notification says who did what, for example that a partner matched with you.

On the website, turning them on stores a Web Push subscription: the endpoint URL your browser issues and the two keys that let us encrypt a message to it. Your browser's push service delivers it.

Our Firebase project exists only to route notifications. Google Analytics is switched off in it, and fliklist contains no analytics SDK of any kind.

What sits on your device

Not much, and this is the one place the app and the website genuinely differ. Both keep a signed-in session; they just keep it in different places.

Signing out clears the session on that device. On the website, clearing your browser's site data clears the rest.

Feedback you send from the app

The account menu › Send feedback sends exactly five things: whether it is a bug or an idea, what you typed, your fliklist version, your OS version, and the email address on your account.

There is no email box on the form, and nothing to leave blank: feedback from fliklist is never anonymous. You are already signed in, so our server attaches your account's own address rather than asking you to type one. That is a deliberate choice — a bug report we cannot ask a follow-up question about is usually a bug we cannot fix — and the form says so before you send.

Your report passes through our server, then through a small relay service we run, and becomes an issue in our private GitHub repository for fliklist. GitHub stores and holds that issue on our behalf, so your description and your email address rest with GitHub. The relay keeps nothing itself.

Your device never contacts the relay directly, so your IP address is never seen by it. The relay counts a short-lived, one-way salted hash of whoever called it to stop abuse — which, for fliklist, is our own server rather than you.

Please don't put anything in a report you would rather keep private. Type what happened, not your passwords.

Who else touches your data

A handful of companies, each doing one job for us. None of them is allowed to use your data for their own purposes, and none of them pays us for it:

What fliklist never does

How long we keep it

For as long as your account exists, and no longer. Nothing in fliklist expires on a timer: your swipes, matches, watch history, added titles, daily picks and the activity feed for each pairing stay while the account does — a shared list that quietly forgot last month would not be a shared list, and "have we seen this?" is a question about years, not weeks.

Three things do carry a clock. An invitation link expires after seven days. The website session cookie lasts 90 days from your last visit. A notification token is dropped as soon as the delivery service tells us it is dead, or when you switch notifications off.

Deleting your account is what ends the rest, and it is not a scheduled job — it happens at the moment you confirm. There is no backup copy of our database for anything to linger in afterwards, and no archive we keep on the side.

Deleting your account

Open fliklist, go to Settings › Delete account, and confirm. It happens immediately and it is permanent — there is no waiting period, no recovery window, and nothing kept behind as a ghost.

Everything in the sections above goes: your account and display name, your password hash, every swipe, every pairing you were in, your matches, your watch history, the titles you added, your daily picks, the activity feed for those pairings, your invitations, and any notification address for your devices.

Your partner keeps their own swipes and their own account, and simply sees themselves as unpaired. They are not told that you deleted your account, because that is not theirs to know.

We send one last email to the address on the account, saying it has been deleted — so that if it was not you who did it, you find out.

Three things deliberately survive, because they are not ours to delete on your behalf:

Ask us at developer@lucidstudios.io and we will delete the issue, including your address on it, and any invitation still holding your address.

If you would rather not use the in-app button, or you want a copy of what we hold about you first, write to the same address and we will take care of it.

Changes to this policy

If fliklist's data practices change, this page changes with them and the effective date at the top moves. The current version is always the one you are reading.

Contact

Lucid Studios LLC — developer@lucidstudios.io