Our Privacy Commitment
At GLOBIZS, your privacy is our top priority. This Privacy Policy explains exactly what data Flozo collects, why we collect it, how it is used and protected, and the rights you have over your information. We are committed to full compliance with Apple App Store Review Guidelines (including 5.1.1(v)), the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and all applicable privacy laws.Information We Collect
We collect only the minimum data necessary to provide a secure, reliable messaging experience. Below is a complete description of every category of data we process.
| Category | Examples | How Collected | Required? |
|---|---|---|---|
| Account & Identity | Name, phone number, email address, profile photo, bio | Provided by you during registration / profile setup | Required |
| Messages & Content | Text messages, images, videos, voice recordings, files, location shares | Created by you when you use the app | Required |
| Contacts | Contact names and phone numbers on your device | Read from device address book only when you grant permission | Optional |
| Location | Approximate or precise geographic coordinates | Read from device GPS only when you choose to share your location in a chat | Optional |
| Media & Files | Photos, videos, documents you choose to send | Selected by you from your photo library or camera | Optional |
| Device & Technical Data | Device model, OS version, app version, FCM push token, IP address, language | Collected automatically at app launch | Required for core |
| Usage & Diagnostics | Crash reports, error logs, feature usage patterns | Collected automatically via Firebase | Required for stability |
| Authentication Tokens | Session tokens, JWT | Generated and stored securely on your device upon login | Required |
Device Permissions We Request
Flozo requests the following device permissions. You can deny any optional permission without losing core messaging functionality. Each permission is requested only at the moment the relevant feature is first used.
| Permission | Platform | Why We Need It | Optional? |
|---|---|---|---|
| Camera | iOS & Android | To take photos/videos and scan QR codes for contact linking | Optional |
| Photo Library | iOS & Android | To pick photos and videos to send in chats | Optional |
| Microphone | iOS & Android | To record voice messages and audio notes | Optional |
| Contacts | iOS & Android | To identify which of your contacts already use Flozo | Optional |
| Location (When In Use) | iOS & Android | To share your current location inside a chat conversation | Optional |
| Notifications | iOS & Android | To deliver push notifications for new messages | Optional (recommended) |
| Storage / Files | Android | To read and save files and documents shared in chats | Optional |
How We Use Your Information
We use the data we collect only for the following legitimate purposes:
Creating your account, displaying your profile, and routing messages to the correct recipients.
Transmitting messages, media, and files between users securely via our servers.
Alerting you to new messages and events using your device's notification system (Firebase Cloud Messaging / APNs).
Verifying your identity via OTP, issuing session tokens, and detecting suspicious activity.
Analysing anonymised crash and performance data to fix bugs and improve reliability.
Fulfilling our obligations under applicable laws and responding to lawful requests from authorities.
How We Store & Protect Your Data
- Secure Enclaves: Authentication tokens and user credentials are stored in encrypted secure storage (iOS Keychain / Android Keystore).
- Encrypted Database: Message history and media metadata are stored locally in an encrypted Hive database.
- Local Directory: Media files (photos, videos, audio) are stored in your device's local protected app directory.
- Transit Encryption: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
- Encrypted at Rest: Server databases are access-controlled and encrypted at rest using AES-256.
- Access Governance: We conduct regular security reviews, vulnerability assessments, and strictly log role-based staff access.
Data Sharing & Third-Party Services
We do not sell, rent, or trade your personal information. We share data only with trusted service providers who help us operate Flozo, and only to the extent necessary for them to perform their essential services.
| Service | Provider | Purpose | Privacy Policy |
|---|---|---|---|
| Firebase Cloud Messaging (FCM) | Google LLC | Deliver push notifications to Android & iOS devices | firebase.google.com |
| Firebase Analytics & Crashlytics | Google LLC | App performance monitoring and crash reporting | firebase.google.com |
| Apple Push Notification service (APNs) | Apple Inc. | Deliver push notifications on iOS devices | apple.com/legal |
We may also disclose your information if required by law, valid court order, or to protect the vital rights, property, or safety of Flozo, our users, or the public.
Push Notifications
Flozo uses Firebase Cloud Messaging (FCM) and Apple Push Notification service (APNs) to send real-time notifications when you receive a new message.
- Your device push token (a randomly generated identifier) is stored on our servers and used exclusively to route notifications to your device.
- Notification content may include the sender's name and a message preview, which can be disabled in Settings → Notifications → Show Preview.
- Your push token is deleted from our servers when you log out or uninstall the app.
- You can disable all push notifications at any time in your device's native Settings.
Data Retention
| Data Type | Retention Period | Deletion Trigger |
|---|---|---|
| Account information | Duration of account + 30 days | Account deletion request |
| Messages & media (server) | Delivered + 30 days | User deletion or account closure |
| Messages & media (device) | Until app uninstall or manual deletion | Logout clears local cache; uninstall removes all |
| FCM push token | Until logout / uninstall | Automatically removed on logout |
| Crash & analytics logs | 90 days | Automatic rolling deletion |
| Authentication tokens | Session duration | Cleared on logout |
You may request immediate deletion of all your data at any time by contacting us. See Section 09 below.
Children's Privacy
Flozo is intended for users aged 13 and older (or the minimum digital age of consent in your country, if higher). We do not knowingly collect personal information from children under 13 years of age.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at contact@globizs.com. We will promptly delete any such information from our systems.
Your Rights & Choices
Depending on your location, you may have the following rights regarding your personal data. We honour all valid requests within 30 days.
How to Delete Your Account (In-App Deletion Steps)
Compliant with Apple App Store Review Guideline 5.1.1(v)In accordance with Apple App Store Review Guideline 5.1.1(v) and applicable data protection laws, Flozo provides a direct, self-service way to permanently delete your account and all associated personal data from within the app:
- Permanent & Irreversible: Once confirmed, your account and credentials are permanently purged and cannot be recovered or restored.
- No Re-login: You will not be able to log back into Flozo with this phone number. Any subsequent login attempt will indicate that the user does not exist.
- Server Data Erased: Your profile (name, phone number, bio, avatar), group memberships, authentication tokens, and push notification tokens (APNs / FCM) are immediately deleted from our active databases.
- Local Device Data Cleared: All cached chat history, pending actions, downloaded media, and credentials stored on your device will be wiped clean.
You have the right to know, delete, and opt out of the sale of your personal information. Flozo does not sell personal information.
Our lawful bases for processing are contract performance (delivering the messaging service), legitimate interests (security and fraud prevention), and consent (optional features like location sharing).
International Data Transfers
Flozo is operated by GLOBIZS and your data may be processed on servers located outside your country of residence. Where data is transferred across borders, we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your information in line with this policy and applicable law.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the “Last Updated” date at the top of this page.
- Send you an in-app notification before the new policy takes effect.
- For significant changes, request your explicit acceptance before continuing to use Flozo.
Your continued use of Flozo after the effective date of a revised policy constitutes your acceptance of those changes.
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact our Data Privacy team:
We respond to all privacy inquiries within 72 hours.
