Privacy policy
Effective 2026-09-28
Flush ("Flush", "we", "us") is a photo clean-up app for iPhone and Mac. This policy explains what data the app collects, why, and how you can control it. Flush is built to need as little of your data as possible: there is no account, and your photos never leave your device.
Your photos never leave your device
Flush scans your photo library and analyses each photo entirely on your device, using Apple's built-in Vision framework, to find exact duplicates, similar shots, and photos that are blurry, dark, or otherwise low quality. This analysis never uploads a photo, a thumbnail, or any description of a photo anywhere — it runs locally and the results stay locally.
What's stored, and where
- Scan results — which photos are duplicates, blurry, dark, or low quality, and which you've reviewed — are stored in a local database on your device only. We cannot see this data, and it never leaves your device.
- No account — Flush doesn't ask you to sign up, sign in, or provide a name, email, or any other personal identifier to use the app.
Deleting photos
Flush never deletes anything without you reviewing and confirming it first. When you confirm a deletion, Flush removes the photo through Apple's Photos framework, which moves it to your device's "Recently Deleted" album — the same as deleting a photo directly in Photos. It stays there for the length of time Apple's Photos app keeps recently-deleted items (typically 30 days) before being permanently removed, and you can recover it from Recently Deleted at any time before then. Flush cannot bypass this or delete a photo permanently in one step.
Anonymous install ID and invite codes
Flush's invite-a-friend feature is run by a small server we operate. To make that work, the app generates a random identifier when you first install it (not derived from your name, Apple ID, device serial number, or any other personal information) and sends it to our server, along with:
- your invite code and how many friends have subscribed with it, so we can credit you with bonus cleanups;
- an invite code you enter, if you redeem a friend's code; and
- a derived random account token (a one-way hash of the install ID; we never receive or store your Apple ID, and the token only lets Apple tell us whether an invited friend's subscription was paid) that the app attaches to your subscription purchase.
An invite counts toward the inviter's reward only after the invited friend's first paid subscription charge. To verify that, Apple sends our server a signed App Store Server Notification when a subscription is charged. It carries the account token, so we can link the purchase to the invite code. We do not receive your Apple ID, name or email, and no payment details.
This, plus the Apple notification above, is the only data our server receives, and it's not linked to your name, email, Apple ID, or photos. We keep the anonymous install ID and invite data for as long as the invite feature needs it to track your invite credits, and delete it on request (see "Your rights" below). We do not sell this data or share it with third parties other than the infrastructure provider that hosts our server.
Anonymous usage analytics
Flush uses TelemetryDeck to understand how the app is used in aggregate, so we can improve it. What's sent is a fixed set of named events (for example, that a scan finished or that the paywall was shown), each with only a coarse range attached (such as "1-10" photos) rather than an exact count. Alongside these, TelemetryDeck automatically records your device model, OS and app version, your language/region and time zone, and a signal marking the start of each session. It also derives a per-install identifier, hashed on your device and hashed again on TelemetryDeck's servers, so none of this can be linked back to you. No photos, photo metadata, names, or exact counts are ever sent. You can turn this off at any time in Flush's Settings.
Purchases
Subscriptions are handled entirely by Apple through the App Store and StoreKit. Flush never sees or stores your payment details, billing address, or card information — Apple processes all payments and shares with us only what's needed to unlock your plan (which product you bought and whether it's active). See Apple's own privacy policy for how Apple handles your payment information.
Notifications
Any notifications Flush shows are local notifications generated and scheduled entirely on your device. We don't operate a push notification service and don't receive any data as a result of a notification being shown.
Legal basis (UK/EU GDPR)
For people in the UK or EU, the legal bases we rely on are:
- Legitimate interests — for the anonymous install ID, invite codes and anonymous usage analytics, which help us run the referral feature and improve the app, without identifying you and with minimal impact on your privacy (analytics can be switched off in Settings).
- Contract — for the limited purchase information Apple shares with us, which is necessary to provide the subscription you've bought.
Children
Flush is not directed at children and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us using the details below and we'll delete it.
Your rights
Because Flush holds so little data about you, and none of it is linked to your identity, most of the data-subject rights under GDPR/UK GDPR (access, correction, deletion, portability, objection) apply to a very small dataset — chiefly the anonymous install ID and referral status on our server. To request that we delete the data associated with your install ID, email us at [email protected] with your invite code (shown in Settings → Invite friends) so we can find the right record; we'll confirm once it's deleted. You can also simply uninstall the app, which removes all data stored on your device.
Data controller and contact
The data controller for the limited data described above is Vincent Opitz. For any privacy question or request, email [email protected].
Changes to this policy
We may update this policy as the app changes. We'll update the effective date above when we do, and for material changes we'll make that clear in the app.