Privacy Policy
Last updated:
Last updated: 2026-09-30. This policy is written in English. If we publish it in other languages, in case of conflict between translations, the English version prevails. Users in Türkiye can also read our Turkish KVKK notice (KVKK Aydınlatma Metni) at /agreements/kvkk.html; that notice is a Turkish original.
Summary
- My Flirt is an Android app for adults (18+) built around chatting, flirting, fun and connection. It is operated by TATBIQAT ALEASR INFORMATION TECHNOLOGY L.L.C in Dubai, United Arab Emirates.
- When you delete your account, not everything is erased at once. Your profile is closed and no longer visible in the app, but after deletion we keep a copy of your member record, your messages (depending on your app version) and device and connection records, to prevent fraud and ban evasion and to be able to handle legal claims and complaints. We do not currently apply a fixed automatic deletion period to this data; it is deleted when it is no longer needed, and you can ask us to delete it at contact@androidapps.app. See How long we keep data.
- If you sign in with Google, we receive only your Google account ID, email address, whether that email is verified, and your first name. See Google Sign-In.
- We do not sell your personal data for money.
- For any privacy question or request, write to contact@androidapps.app.
Who we are and how to contact us
The data controller responsible for your personal data in the My Flirt app (package name com.flortumapp.date) and on this website (androidapps.app) is:
| Company | TATBIQAT ALEASR INFORMATION TECHNOLOGY L.L.C |
|---|---|
| Address | Office - D66, Building no. PR1005-OF708, Dubai, United Arab Emirates |
| TRN | 104487663700001 |
| D-U-N-S number | 85-008-7551 |
| Phone | +971554508228 |
| Privacy and general contact | contact@androidapps.app |
| App support | support@androidapps.app |
In this policy, “we”, “us” and “our” mean this company. “You” means a person who uses the app or this website.
Representatives and data protection contacts
- We have not appointed a data protection officer. Privacy questions and requests are handled by our team at contact@androidapps.app.
- We have not appointed a representative in the European Union or in the United Kingdom. You can contact us directly at contact@androidapps.app, wherever you live.
- We have not appointed a representative in Türkiye. Users in Türkiye can contact us directly as described in our KVKK Aydınlatma Metni.
What this policy covers
This policy covers the My Flirt Android app, the servers and services behind it, and this website. It does not cover Google Play, Google accounts, or other services that have their own privacy policies, even when the app links to them.
Information we collect
Information you give us
- Account data: email address, password (stored as a hash, not in plain text), name, age, gender, country, the language of your phone and the languages you speak.
- Profile data: biography, interests and up to three profile photos.
- Messages: the text of the messages you send and the photos you send in chats.
- Likes and feedback: likes (“kisses”) you send, ratings and feedback you give, and reports about calls in the app (these can include your age, gender and country).
- Messages to us: what you write when you contact us by email.
Sensitive information. Conversations in My Flirt can be flirtatious or sexual, and you may reveal information about your sex life, sexual orientation, health, beliefs or political views, or send intimate photos. That information is stored and processed like your other messages. Please think carefully before sharing it. The app does not currently ask for a separate consent before you share such information; if you do not want it processed in this way, do not share it in a chat, and you can ask us to delete it (see Your rights and choices).
Who can read conversations. Authorised members of our team can open conversations in our internal admin tools, for example to handle a support request, a report or a legal request.
Information collected automatically
- Precise location, only if you allow location access: latitude, longitude and accuracy. We turn these coordinates into a street address, city, district and neighbourhood using Google’s geocoding service, and we may match them to nearby roads using Google’s Roads service. We use this to sort the profiles we show you by distance.
- Device and network data: your device’s Android ID, IP address, the country your connection comes from, push notification tokens (Firebase and OneSignal), app session times and durations, and the language setting of your device.
- Install source: the Google Play install referrer value, which tells us which link or campaign led to your install.
- App usage events: for example which sign-in method you used, button taps, when a message was sent and when a premium offer was shown (collected through Firebase Analytics and AppsFlyer).
- Advertising ID: the app declares the Android advertising ID permission, and the AppsFlyer and Firebase Analytics libraries it includes can read your device’s advertising ID. We use it only to measure installs and campaigns, not to show ads in the app. You can reset or delete your advertising ID at any time in your Android settings (usually Settings → Privacy → Ads or Google → Ads).
- Experiments: which version of a feature you were shown when we test changes (A/B tests).
- Crash reports: crash reports from the app (Firebase Crashlytics), which include technical information about your device and the app.
Purchases
When you buy something in the app, payment is handled by Google Play. We never see or store your card or bank details. We receive and keep: the product, order number, price, currency, the country of the buyer, the Google Play purchase token, and Google Play’s response and signature. Google Play also receives your internal member ID in an obfuscated form so purchases can be linked to your account.
Device permissions the app asks for
| Permission | What it is used for |
|---|---|
| Location | Sorting profiles by distance. Optional; you can turn it off in your phone settings. |
| Camera | Taking profile or chat photos, and the camera preview on the call screen. The call preview stays on your device and is not sent to us; for calls we only receive the call type, duration and reason it ended. |
| Notifications | Sending you push notifications, for example about new messages. |
| Storage | Choosing photos from your device and saving photos taken with the camera, on older Android versions. |
| Calendar (read), display over other apps, biometric | The current app version declares these permissions, but none of the app's features uses them: the app does not read your calendar, does not draw over other apps and does not use your fingerprint or face. The biometric permission is added by a library the app includes. |
| Advertising ID, install referrer | Declared by the Google Play, Firebase and AppsFlyer libraries the app uses, for install and campaign measurement (see above). |
The app also hides phone numbers that appear in message text. This happens on your device.
Google Sign-In
You can create an account or sign in with your Google account. This section explains exactly what we receive from Google and what we do with it.
What we access. The app uses Google’s standard sign-in with the basic scopes openid, email and profile. The app sends us a signed Google ID token, and from it our server reads and keeps only:
- your Google account ID (the
subvalue), - your email address,
- whether Google has verified that email address (
email_verified), - your first name (
given_name).
We do not receive your Google password. We do not use your Google profile photo, your contacts, your calendar, your Drive files or any other Google API or Google data.
How we use it.
- Google account ID and email: to create your account, to sign you in, and to recognise your account the next time you sign in with Google.
- Email verification status: to check that the email address belongs to you.
- First name: only to fill in the name field of the sign-up form in advance. You can change it before you continue.
Your name after sign-up. If you keep the pre-filled first name, it is saved as your profile name. From then on it is handled like any profile name, in the same places a profile name goes: it is shown in the app, sent to OneSignal as a notification tag, and it can appear in internal alerts our team receives on Telegram (see Who we share data with).
Where we store it and for how long. Google data is stored with your account in our database on Amazon Web Services in the eu-central-1 (Frankfurt, Germany) region. We keep it while your account exists. When you delete your account, a copy of your member record, including your Google account ID and email address, is kept after deletion, as described in How long we keep data.
What we do not do with Google data. We do not use Google user data for advertising and we do not sell it. We do not share your Google account ID, email address or email verification status with third parties, except with the service providers that host and operate our systems (listed in Who we share data with) and where the law requires it.
Security. Data travels between the app and our servers over encrypted HTTPS connections (TLS). See also Security.
How to remove access. You can remove My Flirt’s access to your Google account at any time in your Google Account: go to myaccount.google.com, open Security, then Your connections to third-party apps & services, choose My Flirt and remove access. This stops future Google sign-ins; it does not delete your My Flirt account. To delete your account, see Your rights and choices.
How we use your information and our legal bases
Where a law such as the GDPR requires a legal basis, the table below shows the one we rely on.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating your account and signing you in (including with Google) | Account data, Google Sign-In data | Performance of our contract with you |
| Showing your profile and suggesting profiles to you | Profile data, onboarding answers, location | Contract; consent for location (device permission) |
| Messaging | Messages, chat photos | Contract; explicit consent for sensitive data and intimate photos |
| Keeping the member record, messages and device and connection records after account deletion, to prevent fraud and ban evasion, produce aggregate statistics and handle legal claims, complaints and disputes | Copy of the member record, messages, device and connection records | Legitimate interests; establishing, exercising or defending legal claims |
| Push notifications | Push tokens; name, country and gender as notification tags | Legitimate interests; you can turn notifications off in your phone settings |
| Purchases, virtual balance (Gold) and credits | Purchase data | Contract; legal obligations (tax and accounting) |
| Security, preventing fraud, abuse, repeat sign-ups by banned users, and protecting minors | Device ID, IP address, sessions, account data, deleted-account records | Legitimate interests; legal obligations |
| Measuring installs and marketing campaigns | Install referrer, AppsFlyer and Firebase events, advertising ID | Consent where the law requires it (for example in the EEA, the UK and Türkiye) |
| Analytics, testing changes and fixing crashes | Usage events, experiment assignments, crash and error reports | Legitimate interests |
| Answering your requests and complying with the law | Any data needed for the request | Legal obligations; legitimate interests |
Automated processing. Our systems automatically choose which profiles to show you, based on your profile and location. If you disagree with an automated outcome that affects you, you can write to contact@androidapps.app and ask for a person on our team to review it.
Who we share data with
We share personal data only with the service providers below, which process it for us, and with authorities when the law requires it. The full list, with what each provider receives, is on our Sub-processors page.
| Provider | What they do for us | Personal data they receive |
|---|---|---|
| Amazon Web Services | Hosting: database, file storage and servers, in the eu-central-1 (Frankfurt, Germany) region; content delivery | All data stored by the service |
| Google (Sign-In, Google Play Billing and Play Developer API) | Sign-in, payments, verifying purchases | Sign-in data; order number, purchase token, obfuscated member ID |
| Google (Firebase Analytics, Crashlytics, Cloud Messaging) | App analytics, crash reports, push delivery | Usage events, crash reports, device data, push token |
| Google Maps Platform (Geocoding, Roads, Maps) | Turning coordinates into an address; maps | Latitude and longitude |
| OneSignal | Push notifications | Subscription ID, name, country and gender tags, notification content |
| AppsFlyer | Install attribution and campaign measurement | Member ID, sign-up and sign-in events, purchase data and signature, advertising ID (see above) |
| Telegram | Internal alerts to our team's group chat | Member ID, product, amount and currency of subscriptions; member ID and name for boost alerts |
| Detect Language (detectlanguage.com) | Detecting message language; used only by our earlier server system, not by the new one | Text of messages with three or more words from members outside Türkiye |
| Cloudflare | DNS for the androidapps.app domain only | None of your app data |
Selling and “sharing”. We do not sell your personal data for money. Using AppsFlyer and Firebase to measure installs and campaigns may count as “sharing” for cross-context behavioural advertising under some US state laws. We do not show ads in the app. You can limit this by resetting or deleting your advertising ID in your Android settings, or by writing to contact@androidapps.app to opt out.
Legal requests and business changes. We may disclose data when the law requires it, to respond to valid requests from authorities, to protect the safety of users (including children) and to defend legal claims. If our business is sold or merged, personal data may be transferred to the new owner, who must keep protecting it as this policy describes.
International data transfers
Our database and files are stored by Amazon Web Services in Frankfurt, Germany (eu-central-1). We are based in the United Arab Emirates, and our team may access the data from outside the European Economic Area. Our service providers may process data in other countries, including the United States and other countries that do not have the same level of data protection as yours.
Where the law requires safeguards for these transfers, we rely on the transfer mechanisms available under that law, such as the standard contractual clauses that many of our providers include in their data processing terms. You can ask us which safeguard applies to a given provider at contact@androidapps.app.
How long we keep data
We keep your data while your account is active. Deleting your account does not erase all of your data at once. When you delete your account:
- your account and profile are closed and are no longer visible in the app;
- a copy of your member record is kept (email address, password hash, Google account ID, name, age, photo file references, device ID and the other account fields);
- depending on the app version you use, your messages and profile photos are either deleted straight away or kept.
We do not currently apply a fixed automatic deletion period to this data. It is deleted when it is no longer needed for the purposes below. We keep it only for these purposes:
- the member record and device and connection records: to prevent fraud and ban evasion (for example, a device that was banned cannot be used to sign up again) and to produce aggregate statistics;
- messages: so that we can look into legal requests, complaints and disputes about a conversation.
Nobody reads kept messages unless one of these reasons requires it. You can object to this, or ask us to delete this data or restrict its processing, by writing to contact@androidapps.app. We will do so unless the law requires us to keep it. See Your rights and choices.
| Data | How long we keep it |
|---|---|
| Account and profile data | While your account is active |
| Copy of the member record after account deletion | Kept after deletion; no fixed automatic deletion period, deleted when no longer needed |
| Messages | While your account is active; after account deletion (where they are kept), no fixed automatic deletion period, deleted when no longer needed |
| Temporary message records | 7 days |
| Likes ("kisses") | 6 months |
| Profile photos | While your account is active; after account deletion (where they are kept), no fixed automatic deletion period, deleted when no longer needed |
| Photos sent in chats | Deleted from our servers 180 days after they were sent, or earlier if the account is deleted with an app version that deletes messages |
| Location records, IP addresses, device IDs, device sessions, install referrer | While your account is active; after account deletion, no fixed automatic deletion period, deleted when no longer needed |
| Purchase and payment records | As long as required by applicable tax and accounting law |
| Analytics events and app sessions on our servers | While your account is active; after account deletion, no fixed automatic deletion period, deleted when no longer needed |
| Data held by providers (Firebase, AppsFlyer, OneSignal) | According to each provider's own retention settings and terms |
| Website server logs | For a limited period, to run and protect the website |
App versions. If you delete your account from an app version that still uses our earlier server system, your messages and your three profile photos are deleted straight away. In app versions that use our new account system, they are kept after deletion as described above. In both cases, a copy of your member record is kept after deletion.
Your rights and choices
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy,
- correct data that is wrong or incomplete,
- delete your data, including the data we keep after account deletion, such as your messages,
- restrict or object to certain processing, including processing based on our legitimate interests,
- port your data to another service in a machine-readable format,
- withdraw consent at any time, without affecting processing that happened before,
- complain to a data protection authority.
How to use your rights.
- Delete your account in the app: Profile, then Delete My Account. More details are on our Account deletion page.
- Anything else, or if you cannot use the app: email contact@androidapps.app from the email address linked to your account, and tell us what you want. We may ask for information to confirm that the account is yours. We reply within the time the law gives us (for example one month under the GDPR, 30 days under KVKK, 45 days under the CCPA).
- Location and notifications: you can turn these off at any time in your phone settings.
- Google access: see How to remove access.
- Data kept after account deletion: to object to it being kept, or to ask us to delete it or restrict its processing, write to contact@androidapps.app.
We will not treat you differently for using your privacy rights. Some requests can be refused or limited where the law allows, for example when we must keep purchase records for tax reasons; if so, we will tell you why.
Additional information for your region
European Economic Area and United Kingdom
- The controller is listed in Who we are. We have not appointed a representative in the EU or the UK; you can contact us directly at contact@androidapps.app. Legal bases are listed in How we use your information.
- You have the rights listed above under Articles 15 to 22 of the GDPR and UK GDPR.
- Where we rely on consent, you can withdraw it at any time. Where we rely on legitimate interests, you can object.
- You can complain to the data protection authority in the country where you live or work, or where you think the law was broken. In the UK this is the Information Commissioner’s Office (ICO).
United States: California and other states
Notice at collection. In the last 12 months we collected these categories of personal information: identifiers (email, member ID, Google account ID, device ID, IP address, advertising ID); personal characteristics (age, gender); commercial information (purchases); internet and app activity (usage events, sessions); precise geolocation; audio-visual information (photos); and sensitive personal information (account login data, precise geolocation, and information about sex life or sexual orientation that you may share in chats). Sources, purposes, recipients and retention are described in the sections above.
- Sale and sharing: see Selling and “sharing”.
- Sensitive personal information: we use it only to provide the service as described in this policy.
- Your rights: to know, access, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information. Send requests to contact@androidapps.app or use the in-app account deletion. An authorised agent can make a request for you with your signed permission; we may verify your identity with you directly.
- No discrimination: we will not deny you the service, charge you a different price or give you a different quality of service because you used these rights.
Brazil (LGPD)
You have the rights in Article 18 of the LGPD, including confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary data, portability, information about who we share data with, and withdrawal of consent. We have not appointed a named data protection officer (encarregado); our contact point for data protection matters is contact@androidapps.app. You can also complain to the Autoridade Nacional de Proteção de Dados (ANPD).
India (DPDP Act)
You can access information about your data, ask for correction, completion, updating and erasure, withdraw consent as easily as you gave it, and nominate another person to use your rights if you die or become unable to. Our grievance contact is contact@androidapps.app. If you are not satisfied with our answer, you can complain to the Data Protection Board of India.
Nigeria (NDPA)
You have the rights in the Nigeria Data Protection Act 2023, including access, correction, erasure, objection, portability and withdrawal of consent. You can contact us at contact@androidapps.app and complain to the Nigeria Data Protection Commission (NDPC).
South Africa (POPIA)
You have the rights in the Protection of Personal Information Act, including access, correction, deletion and objection. Our contact point for information requests is contact@androidapps.app. You can complain to the Information Regulator of South Africa.
Türkiye (KVKK)
We have not appointed a representative in Türkiye. Our notice under Law No. 6698 on the Protection of Personal Data (KVKK Aydınlatma Metni) and our separate explicit consent text are available in Turkish at /agreements/kvkk.html and /agreements/acik-riza.html.
Children
My Flirt is only for adults aged 18 or over. We do not knowingly collect data from anyone under 18. Every member declares their age at sign-up, and the app does not accept an age under 18. If we learn that a user is under 18, we close the account. If you believe a child is using My Flirt, write to contact@androidapps.app. Read our Child Safety Standards.
Security
Data travels between the app and our servers over encrypted HTTPS connections (TLS). Passwords are stored as hashes, not in plain text. Access to our database and servers is limited to authorised members of our team. No system is completely secure; if a breach affects your data, we will inform you and the authorities as the law requires.
This website
This website does not use cookies, analytics or advertising trackers, and it loads no third-party scripts or fonts. If you pick a language in the footer, your browser remembers that choice in its local storage. Our servers may record technical data such as your IP address when you visit. See our Cookie Policy.
Changes to this policy
We update this policy when our practices change. The “Last updated” date at the top shows the current version. If we make an important change, we will tell you in the app or by email before it takes effect, and we will ask for your consent again where the law requires it.
This version: 2026-09-30.
Contact
For questions or requests about this policy or your data:
- Email: contact@androidapps.app (privacy and general), support@androidapps.app (app support)
- Post: TATBIQAT ALEASR INFORMATION TECHNOLOGY L.L.C, Office - D66, Building no. PR1005-OF708, Dubai, United Arab Emirates
- Phone: +971554508228