Privacy Policy

Privacy Policy for FlowClip

Last Updated: August 22, 2026  ·  Developer: Melibyte Apps  ·  Package: com.melibyte.flowclip

Overview

FlowClip ("the app", "we") is a video editing application that prioritizes your privacy while providing powerful creative tools. This policy explains what data we collect, why, and how we protect it.


Data Collection

What We Collect

1. Account Information (Optional — Only if you sign in)

If you choose to use the Community Workshop feature, you may sign in with your Google Account. When you do, we collect:

  • Display Name & Email: Used solely to create your private user profile. Your email is never shown to other users.
  • Username: A public nickname you choose, visible to other users in the Community Workshop.
  • User ID (UID): A unique identifier tied to your Google account, used to associate your data with your account.
Important: Signing in is entirely optional. All core video editing features work without an account. We do not send your Google account information to FlowClip unless you choose to sign in. When you sign in, your Google ID token is exchanged with FlowClip's authenticated backend to establish an authenticated session. We store the account identifier, email address, and username needed to provide your profile and account features. See "Service & Security Data" below for details.

2. Community Workshop Content (Optional — Only if you publish)

If you publish a custom shader effect to the Community Workshop, the following is stored:

  • Shader Code (GLSL): The source code of your custom effect, stored in Cloudflare object storage.
  • Effect Metadata: Name, description, and parameter definitions of your effect, stored in a Cloudflare database.
  • Author Attribution: Your chosen username and User ID, so the community knows who created the effect.

  • Community Interactions: When you report a shader/effect or a user, like an effect, or download one, we record the information needed for that action. Reports may include your UID, the report type and target, your selected reason, optional details, and a timestamp. When you block a user, we store the active block relationship (your UID and the blocked user's UID) so we can hide that user's Workshop content from your views. These records support moderation, abuse prevention, personalization, and feature functionality.

3. Service & Security Data (Always Collected)

When the app connects to the Community Workshop, Cloud Sync, authentication, model-delivery, or billing services, the relevant service provider receives standard request metadata:

  • HTTP Request Metadata: Standard request metadata, such as your IP address, timestamp, and requested resource, may be visible to Cloudflare when you use those online features. This is required to deliver, operate, rate-limit, and secure the service.

What We DO NOT Collect

  • Precise Location (GPS)
  • Advertising ID (We do not show ads)
  • Your Unencrypted Media for ordinary editing: Your photos, videos, and audio are not uploaded for ordinary editing, browsing, or on-device AI features. If you explicitly use Pro Cloud Sync, an encrypted project archive may include media contained in that project. Cloudflare stores the encrypted archive, not the unencrypted media contents.
  • Your Audio/Speech Data for AI processing: AI Auto-Captions are processed entirely on your device using a locally downloaded AI model. No audio is sent to a server for AI processing. Audio included in an optional Cloud Sync project may be transmitted as part of that encrypted archive.
  • Your Media for Other On-Device AI Features: Voice AI text-to-speech, audio separation, background removal, tracking, and quality enhancement process data locally on your device. These features do not upload your source media for AI processing.
  • Optional AI Output Reports: If you choose Report AI output or Report caption issue, FlowClip submits the report through its authenticated in-app reporting system. The report can contain the feature, your selected reason, optional details, platform information, and source text only if you explicitly choose to include it. Generated audio, video, and other media are not uploaded automatically.
  • Payment or Financial Information: We never process, see, or store your payment card details. Payments are handled entirely by our payment providers — Google Play (Android) and Paddle (Windows).
  • Contacts, Call Logs, or Messages

Third-Party Services

We use the following third-party services:

1. Google Sign-In

Purpose: To allow optional sign-in for the Community Workshop.

  • Data Collected: Google account name, email address, and a unique user ID, processed by Google on your device and verified by FlowClip's authenticated backend.

Privacy Policy: Google Privacy Policy

2. Cloudflare Services

Purpose: To host the FlowClip backend — provide authenticated services, a database, object storage, and the Workshop and Cloud Sync features.

  • Data Stored: User ID, username, email (for your private profile), effect metadata, shader code, optional PNG assets, billing reconciliation records, and encrypted cloud sync project archives. Cloud sync data is encrypted on-device before transmission; Cloudflare does not receive the unencrypted project contents.
  • Authentication Exchange: When you sign in or refresh your authenticated session, your Google ID token is sent to FlowClip's authenticated backend, which verifies it and returns a signed session token to the app. The Google ID token is used for verification and is not stored as your session credential.
  • Data Processing: FlowClip's authenticated backend validates authentication before accepting or serving data. Standard HTTP request metadata (IP, timestamp, URL path) is visible to Cloudflare during Community Workshop and cloud feature use.

Privacy Policy: Cloudflare Privacy Policy

3. Google Play Billing (Pro Subscription — Android)

Purpose: To process Pro subscription payments and verify purchase status.

  • Payment Processing: All payment transactions are handled entirely by Google Play Store. Your credit card, billing address, and other payment details are never transmitted to or stored by FlowClip's servers.
  • Purchase Verification: When you purchase a Pro subscription, a non-reversible purchase token is sent to FlowClip's authenticated backend. The backend verifies this token with Google Play's API. To match renewals, refunds, voids, and account ownership, we store an opaque purchase identifier, your User ID, the product identifier when available, entitlement status, expiry time, and relevant event timestamps. These records do not contain your payment card details.
  • Data Stored: Your account record contains the current derived Pro status and expiry, while billing records contain the reconciliation information described above. This data is used to grant or deny Pro features (120 FPS export, cloud storage, and higher shader limits).
  • Refund & Cancellation: Google Play manages all payments, cancellations, and refunds. Cancelling normally stops the next renewal while Pro access continues through the already-paid period. A refund, chargeback, or other provider revocation can end access earlier; provider events update the relevant entitlement records.

Privacy Policy: Google Play Data Safety

4. Paddle Billing (Pro Subscription — Windows)

Purpose: To process Pro subscription payments and verify purchase status on Windows.

  • Merchant of Record: Paddle Inc. is the merchant of record for Windows purchases. All payment transactions (card details, billing address, and payment processing) are handled entirely by Paddle. FlowClip never receives or stores your payment card details.
  • Purchase Flow: When you subscribe, the app creates a checkout session with Paddle and opens Paddle's hosted checkout page in your browser. Payment completes on Paddle's secure, PCI-compliant checkout.
  • Data Shared with Paddle: To process your transaction and issue a tax invoice, Paddle receives your email address and billing details. As merchant of record, Paddle is responsible for payment processing, tax compliance, and the refund relationship with you.
  • Purchase Verification: Paddle sends signed notifications to FlowClip's authenticated backend when your subscription starts, renews, is cancelled, refunded, or otherwise changes. The notifications are verified before any change is applied. To reconcile checkout recovery, subscription ownership, renewals, refunds, and cancellations, we store opaque subscription or transaction identifiers, your User ID, price/product identifiers when available, entitlement status, expiry time, webhook event identifiers, and relevant timestamps. These records do not contain your payment card details.
  • Data Stored: Your account record contains the current derived Pro status and expiry, while billing records contain the reconciliation information described above. This data is used to grant or deny Pro features.
  • Refund & Cancellation: Paddle manages all billing, cancellations, and refunds as merchant of record. You can manage or cancel your subscription through Paddle's customer portal via the app's "Manage Subscription" button. Cancelling normally stops the next renewal while Pro access continues through the already-paid period. A refund or chargeback can end access earlier.

Privacy Policy: Paddle Privacy Policy

5. FFmpeg

Purpose: Video processing engine.

  • Data Sent: None (Runs securely on-device).

6. On-Device AI Models

Purpose: To download on-device AI speech recognition models for the Auto-Caption feature.

  • Data Sent: None. Only the model file is downloaded to your device from Cloudflare's delivery infrastructure.
  • Data Processed Locally: Your audio is processed entirely on your device using the downloaded model. No audio is sent to a server for AI processing. If you use Cloud Sync, audio included in a project may be transmitted as part of the encrypted project archive.

Privacy Policy: Cloudflare Privacy Policy


Data Storage & Security

  • Local Media: For ordinary local editing, your projects, media files, and exported videos remain on your device. If you choose Cloud Sync, media included in the selected project is also stored in an encrypted cloud archive.
  • Account Data: Stored securely in a Cloudflare-hosted database with access controlled by your authenticated session. Your private profile (including email) is not publicly visible and is protected by authenticated access controls.
  • Community Data: Published shader code and optional PNG assets are stored in Cloudflare object storage, while effect metadata and your public username are stored in the associated database. Published Workshop content is visible to users of the Community Workshop.
  • Reports and Block Preferences: Reports about users or effects are stored as moderation records in a Cloudflare-hosted database. They can include the reporter account ID, reported target, selected reason, optional report details, and timestamp, and may be reviewed by Melibyte Apps to enforce our Terms and community policies. Your active block preferences are also stored in that database, are private to your account, and are used to filter blocked users' Workshop content. We retain moderation records as needed for safety, abuse prevention, and enforcement.
  • AI Output Reports: Reports about locally generated speech or captions are stored in the same authenticated moderation system used for Workshop reports, only when you choose to submit them in the app. They may include the feature, selected reason, optional details, platform information, and source text if you opt in. Generated media remains on your device and is not uploaded automatically.
  • Cloud Sync Projects (Pro): When you choose Cloud Sync, your project is packaged into an archive that may contain project edits, imported media, audio, thumbnails, and related project files. The archive is encrypted on your device before being uploaded to Cloudflare object storage, so media included in the project leaves your device only inside the encrypted archive. You may optionally set a PIN for an extra layer of privacy. With a PIN: your projects receive additional protection, but forgetting the PIN may prevent recovery. Without a PIN: account recovery remains possible if you ever get locked out. Cloudflare may still process service metadata such as your account ID, project name, size, timestamps, and request metadata needed to operate cloud sync.
  • Transmission: All data is transmitted securely via HTTPS encryption.
  • Retention: Published Workshop content remains available while it is published. When you delete a published effect, its public catalog entry and hosted effect files are removed where technically available; copies already downloaded by other users remain on their devices. Reports, billing reconciliation records, and other security or moderation records may be retained as needed for safety, fraud prevention, dispute handling, legal compliance, and enforcement. Cloud Sync project data is retained for 30 days after your Pro subscription expires, during which you can download your projects from the cloud.
  • No Absolute Guarantee: While we implement encryption, authentication, and access controls, we cannot guarantee that backend services (including Cloudflare services and Google) will be immune to security breaches, unauthorized access, or data loss. By using cloud features, you acknowledge this risk. We will notify affected users as required by applicable law in the event of a confirmed data breach involving personal information.

International Data Transfers

FlowClip uses third-party services that may process your data in countries outside your own, including the United States. When data is transferred from the European Economic Area (EEA), Switzerland, or the United Kingdom, we ensure adequate safeguards are in place:

  • Cloudflare: Cloudflare is certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, and also offers Standard Contractual Clauses (SCCs) as an additional safeguard (cloudflare.com/trust-hub/gdpr).
  • Google: Google relies on Standard Contractual Clauses (SCCs) approved by the European Commission and is certified under the EU-U.S. Data Privacy Framework (policies.google.com/privacy).
  • Paddle: Paddle may process Windows purchase information as merchant of record under its own privacy and transfer safeguards (Paddle Privacy Policy).

By using FlowClip, you acknowledge that your data may be transferred to and processed in the United States and other countries where our service providers operate, under the safeguards described above.


Permissions

FlowClip requests permissions strictly for functionality:

Android

PermissionPurpose
READ_MEDIA_VIDEOTo select videos for editing.
READ_MEDIA_AUDIOTo select music/audio for your project.
READ_MEDIA_IMAGESTo browse and select photos from your gallery for editing.
READ_MEDIA_VISUAL_USER_SELECTEDTo support Android 13+'s partial media access ("Selected Photos"), allowing you to grant access to only specific photos/videos rather than your entire gallery.
CAMERATo record video directly from your device camera for importing into the timeline. Recordings stay on your device unless you choose Cloud Sync for a project containing them.
RECORD_AUDIOTo record voice/audio directly from your device microphone for importing into the timeline. Recordings stay on your device unless you choose Cloud Sync for a project containing them.
INTERNETRequired by the Community Workshop and cloud features (Cloudflare, Google sign-in, Play). Ordinary editing does not send media over the internet; Cloud Sync may transmit an encrypted project archive containing selected project media.

Windows (Microsoft Store)

CapabilityPurpose
Internet accessRequired by the Community Workshop and cloud features (Cloudflare, Google sign-in). Ordinary editing does not send media over the internet; Cloud Sync may transmit an encrypted project archive containing selected project media.
Videos libraryTo access and import video files from your Videos folder and other locations.
Music libraryTo access and import audio files from your Music folder.
Pictures libraryTo access and import image files from your Pictures folder.
Removable storageTo import media files from USB drives and SD cards.
MicrophoneTo record voice/audio directly from your device microphone for importing into the timeline. Recordings stay on your device unless you choose Cloud Sync for a project containing them.

Your Rights & Control

You have full control over your data:

  • Don't Sign In: All core editing features work without an account. Your name, email, and public username are never collected. Using the Community Workshop or cloud features requires signing in, and your account is never created without your consent.
  • Delete Your Account Data: You can request deletion of your account and all associated data by emailing us at melibyteapps@outlook.com. Once requested, your personal profile data (email, display name, and record) will be permanently deleted. Any of your shaders that remain active in the system to preserve other users' project integrity will have their author attribution permanently anonymized (e.g., changed to "Anonymous" or "Deleted Creator") in accordance with GDPR regulations.
  • Delete Published Shaders: You can delete your own published shaders at any time from your in-app Profile tab, which immediately removes them from the public community index.
  • Block Users: You can block or unblock users from their public profiles. Blocking filters that user's published Workshop content from your Workshop views; it does not delete copies of content you previously downloaded to your device.
  • Report Users or Effects: You can report a user or effect from the relevant in-app profile or effect page. Reports are sent to our moderation system for review and may be retained as safety and enforcement records.
  • Report AI Output: You can report unexpected, inappropriate, or incorrect locally generated speech or captions from the relevant AI result. The report is submitted through the same in-app moderation system used for Workshop reports.
  • Sign Out: You can sign out at any time from the Profile tab, which stops all account-related data syncing.
  • Uninstall: Uninstalling the app stops all data collection. Local data is removed from your device.
  • Android Settings: You can revoke file permissions at any time.
  • Windows Settings: You can manage app permissions in Windows Settings > Privacy & Security.

Children's Privacy

FlowClip does not knowingly contact or collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us so we can verify and delete it.


Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.


Contact

For questions about this Privacy Policy or to request data deletion:

Developer: Melibyte Apps
Email: melibyteapps@outlook.com
App: FlowClip


Summary

FlowClip is a local-first video editor. Your original media files remain on your device unless you explicitly use Cloud Sync. Cloud Sync may upload an encrypted project archive containing the selected project's media and edits; unencrypted project media is not sent to the backend. If you choose to sign in for the Community Workshop, we store your username and published shader effects securely. We do not collect analytics or crash reports. We never sell your personal data.