How It WorksGamesSafety
← Back to Home

Privacy Policy

Last Updated: July 28, 2026

Effective Date: July 28, 2026

This Privacy Policy (“Policy”) describes how Flame (“Company,” “we,” “us,” or “our”) collects, uses, processes, stores, shares, and protects information obtained from users (“you,” “your,” or “User”) of the Flame mobile application and website (collectively, the “Service”). This Policy applies to all Users of the Service, regardless of how you access or use it.

By creating an account, accessing, or using the Service in any manner, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with any provision of this Policy, you must immediately discontinue all use of the Service and delete your account. Your continued use of the Service following any modifications to this Policy constitutes your acceptance of such modifications.

This Policy should be read in conjunction with our Terms of Service, which govern your use of the Service.

1. Definitions

For the purposes of this Privacy Policy:

1.1 “Personal Data” means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

1.2 “Processing” means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, including but not limited to collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

1.3 “Service” means the Flame mobile application (available on Apple App Store and Google Play Store), associated website(s), and all related features, functionalities, content, and services.

1.4 “Data Fiduciary” means the Company, which alone or in conjunction with other persons determines the purpose and means of Processing of Personal Data, as defined under the Digital Personal Data Protection Act, 2023 (India).

1.5 “Data Principal” means the User whose Personal Data is processed by the Data Fiduciary.

1.6 “Sub-Processor” means any third-party vendor, partner, or contractor engaged by the Company to process Personal Data on behalf of the Company, subject to contractual obligations regarding data protection and confidentiality.

1.7 “End-to-End Encryption” or “E2EE” means a method of secure communication where messages are encrypted on the sender's device and can only be decrypted on the recipient's device, such that the Company and any intermediaries cannot access the plaintext content of the communication.

1.8 “CSAM” means Child Sexual Abuse Material as defined under applicable law, including but not limited to 18 U.S.C. § 2256.

1.9 “CSAE” means Child Sexual Exploitation and Abuse.

2. Information We Collect

We collect and process information that is necessary to provide a safe, functional, and engaging social experience. The categories of information we collect are described below.

2.1 Information You Provide Directly

  1. Account and Authentication Data. When you register for an account, we collect your phone number for the purpose of OTP-based (One-Time Password) authentication via Firebase Authentication. Your phone number serves as your primary account identifier.
  2. Profile Information. You may provide the following information to create and customise your user profile: display name, date of birth (or age), gender, biographical text, profile photographs, personal interests, zodiac sign, and occupation. This information is used to display your profile to other Users and to facilitate discovery and matchmaking features.
  3. Preferences and Lifestyle Data. You may optionally provide information about your relationship status, relationship intent (for example, seeking friends, dating, or networking), lifestyle preferences (such as drinking and smoking habits), and responses to in-app vibe check questionnaires. This information is used for compatibility matching and profile enrichment.
  4. User-Provided Location. You may voluntarily enter text-based location information, including your hometown and current city. We do not collect precise GPS coordinates, nor do we engage in real-time location tracking.
  5. Campus and College Verification Data. If you choose to participate in campus verification, we collect your college or university email address, institution name, course of study, and academic year. A verification code is sent to your college email address to confirm your affiliation.
  6. Selfie Verification Photograph. If you choose to undergo selfie verification, we collect a front-facing camera photograph. This photograph is uploaded to secure cloud storage and is used solely for the purpose of visual identity verification to reduce impersonation and catfishing. We do not extract biometric templates, facial geometry data, or any biometric identifiers from selfie verification photographs.
  7. Communications and Content. We facilitate and process messages, media (including photographs, videos, view-once media, GIFs, and stickers), game invitations, game results (including FLAMES results and vibe check results), reactions, and other communications exchanged between Users through the Service. Certain categories of communications are end-to-end encrypted as described in Section 4.
  8. Music and Entertainment Preferences. You may search for and add favourite songs (via Spotify's search API) and favourite movies (via The Movie Database search API) to your profile. The search queries you enter are transmitted to these third-party services as described in Section 5. We store only the selected song or movie metadata (title, artist, album art URL) on your profile.
  9. Collaborative Profile Data. If you create a collaborative profile with another User, we collect and store shared milestones, captions, photographs, pinned moments, and other content contributed by both Users within that collaborative context.
  10. Reports, Blocks, and Feedback. When you report another User, block a User, or submit moderation-related feedback, we collect the details of your report or action, including supporting context and any evidence you provide, for the purpose of safety enforcement and content moderation.

2.2 Information Collected Automatically

  1. Device Information. We automatically collect certain technical information about your device, including device type, operating system name and version, and unique device identifiers. Device identifiers are used solely for the purpose of delivering push notifications and are not used for advertising, tracking, or cross-device identification.
  2. App Usage and Analytics Data. We collect anonymised and pseudonymised data about how you use the Service, including which features you access, interaction timestamps, onboarding step completion events, and session-level data. This data is collected through Firebase Analytics and is used for product improvement and performance monitoring.
  3. Push Notification Tokens. We collect Firebase Cloud Messaging (FCM) device tokens for the sole purpose of delivering push notifications to your device. You may disable push notifications at any time through your device's settings.
  4. Local Device Storage. The Service stores certain data locally on your device using platform-standard storage mechanisms (AsyncStorage for non-sensitive data such as onboarding flags, cached user profiles, and session preferences; and SecureStore/Keychain for sensitive data such as cryptographic keys). This data does not leave your device unless explicitly transmitted as part of the Service's functionality.
  5. Crash and Error Diagnostics. We may collect crash logs, error reports, and technical stack traces for the purpose of debugging, diagnosing, and improving the stability and performance of the Service.

2.3 Information We Do Not Collect

To avoid ambiguity, we expressly state that we do not collect the following categories of information:

  1. Precise geolocation data or real-time GPS coordinates;
  2. Contact lists or phone book data from your device;
  3. Financial information, payment card details, or banking credentials;
  4. Government-issued identification documents (such as Aadhaar, PAN, passport, or driver's licence);
  5. Biometric identifiers or biometric templates (selfie photographs are used for visual comparison only and are not processed through facial recognition, facial geometry extraction, or biometric template creation systems);
  6. Browsing history, web activity, or data from other applications on your device;
  7. Health, medical, or genetic data;
  8. Caste, race, ethnic origin, political opinion, religious or philosophical belief, trade union membership, or sexual orientation data, except to the extent that a User voluntarily includes such information in their free-text profile biography.

3. Purposes and Legal Bases for Processing

3.1 We process your Personal Data for the following purposes:

  1. Account Creation and Management. To create, authenticate, maintain, and administer your user account. Legal Basis: Performance of contract (Terms of Service); Consent.
  2. Profile Display and User Discovery. To display your profile information to other Users and to enable social discovery and matchmaking features. Legal Basis: Performance of contract; Legitimate interest in providing core Service functionality.
  3. Messaging and Social Interactions. To facilitate and deliver chat messages, media, game invitations, game results, collaborative content, and other communications between Users. Legal Basis: Performance of contract.
  4. Campus and Selfie Verification. To verify your college or university affiliation and to verify your identity through visual selfie comparison. Legal Basis: Legitimate interest in preventing fraud, impersonation, and catfishing; Trust and safety.
  5. Push Notifications. To send you notifications about new messages, game invitations, connection requests, and other relevant Service updates. Legal Basis: Consent (you may disable notifications at any time).
  6. Content Moderation and Safety. To review reported content, investigate violations of our Terms of Service, enforce our community guidelines, and take action against abusive, harmful, or illegal conduct. Legal Basis: Legitimate interest in maintaining platform safety; Legal obligation.
  7. Child Safety and CSAM Detection. To detect, investigate, report, and prevent Child Sexual Abuse Material (CSAM) and Child Sexual Exploitation and Abuse (CSAE) on the Service. Legal Basis: Legal obligation under applicable law, including 18 U.S.C. § 2258A and the Protection of Children from Sexual Offences Act, 2012 (India).
  8. Analytics and Product Improvement. To analyse anonymised and aggregated usage patterns for the purpose of improving the Service, understanding User preferences, and optimising performance. Legal Basis: Legitimate interest in product development and improvement.
  9. Legal Compliance. To comply with applicable laws, regulations, legal processes, or enforceable governmental requests. Legal Basis: Legal obligation.
  10. Security and Fraud Prevention. To detect, prevent, and address fraud, abuse, security vulnerabilities, and technical issues affecting the Service. Legal Basis: Legitimate interest; Legal obligation.
  11. Enforcement. To enforce our Terms of Service and this Privacy Policy. Legal Basis: Legitimate interest.

3.2 We do not process your Personal Data for any of the following purposes:

  1. Selling, renting, leasing, or otherwise commercially transferring your Personal Data to third parties for their own marketing or commercial purposes;
  2. Serving personalised or targeted advertising;
  3. Automated decision-making that produces legal effects or similarly significant effects concerning you without human review;
  4. Profiling for purposes unrelated to the provision of the Service.

4. End-to-End Encryption

4.1 Flame implements end-to-end encryption for direct messages between Users using industry-standard cryptographic protocols.

4.2 Key Exchange. Public-key cryptography based on the X25519 elliptic curve (via the NaCl/libsodium cryptographic library) is used to negotiate shared secrets between communicating Users.

4.3 Message Encryption. Text messages are encrypted using authenticated encryption with the XSalsa20-Poly1305 cipher before leaving the sender's device.

4.4 Media Encryption. View-once photographs and videos are encrypted using symmetric encryption (AES-256-GCM or XSalsa20-Poly1305) with per-media random keys before being uploaded to cloud storage.

4.5 Key Storage. Private cryptographic keys are generated and stored exclusively on the User's device using platform-native secure storage mechanisms (iOS Keychain via Secure Enclave; Android Keystore via Expo SecureStore). Private keys are never transmitted to or stored on our servers.

4.6 Implications. As a result of our end-to-end encryption implementation:

  1. The Company cannot access, read, or decrypt the plaintext content of end-to-end encrypted messages or media.
  2. In response to a lawful request from a court or law enforcement authority, we can only provide the encrypted ciphertext of E2EE-protected communications, not the plaintext content.
  3. Message metadata — including sender identifier, recipient identifier, timestamp, and message type — is not end-to-end encrypted and is accessible to the Company for the purposes described in this Policy.

4.7 Non-E2EE Content. Profile information, system-generated messages, game results, collaborative profile content, and media shared outside of end-to-end encrypted contexts are stored in standard form on our servers, protected by encryption at rest (AES-256, provided by Google Cloud Platform) and encryption in transit (TLS 1.2 or higher).

5. Third-Party Sub-Processors

5.1 We engage a limited number of Sub-Processors to operate and maintain the Service. Each Sub-Processor is bound by contractual obligations to process Personal Data only for the specific purposes we designate and to maintain appropriate technical and organisational security measures.

5.2 Infrastructure and Backend Services

  1. Google Firebase. We use Google Firebase for our core backend infrastructure, including: Cloud Firestore (database), Firebase Authentication (phone number authentication), Cloud Functions (serverless backend logic), Cloud Storage for Firebase (file storage for media and verification photographs), and Firebase Cloud Messaging (push notification delivery). Data shared with Firebase includes account data, profile data, encrypted messages, media files, and push notification tokens. Google's processing of this data is governed by the Google Cloud Terms of Service and Google's Privacy Policy.
  2. Google Firebase Analytics. We use Firebase Analytics for collecting anonymised app usage events, including feature usage, device type, and operating system information. No personally identifiable information is sent to Firebase Analytics. Google's processing of analytics data is governed by the Google Analytics for Firebase Terms.
  3. Expo / Expo Application Services (EAS). We use Expo for app build infrastructure, over-the-air updates, and notification services. Data shared with Expo includes push notification tokens and basic device information. Expo's processing is governed by Expo's Privacy Policy.

5.3 Content and Media Services

  1. Giphy. We integrate Giphy's API to enable Users to search for and send GIFs within the Service. Only search query text is transmitted to Giphy; no User identifiers, account data, or Personal Data is shared. Giphy's processing is governed by Giphy's Privacy Policy.
  2. Google Tenor. We integrate Google's Tenor API to enable Users to search for and send GIFs and stickers. Only search query text is transmitted to Tenor; no User identifiers are shared. Tenor's processing is governed by Google's Privacy Policy.
  3. The Movie Database (TMDB). We integrate the TMDB API to enable Users to search for movies to add to their profile. Only movie search queries are transmitted to TMDB; no User identifiers are shared. TMDB's processing is governed by TMDB's Privacy Policy.
  4. Spotify Web API. We integrate Spotify's Web API to enable Users to search for songs to add to their profile. Only song and artist search queries are transmitted to Spotify; no User identifiers or Spotify account credentials are shared. Spotify's processing is governed by Spotify's Privacy Policy.

5.4 We do not sell, rent, lease, or otherwise make your Personal Data available to any third party for their independent use, marketing, or commercial purposes.

6. Data Sharing and Disclosure

6.1 Sharing with Other Users. As part of the core functionality of the Service, certain information you provide is made visible to other Users. This includes your profile information (display name, photographs, biography, interests, age, and other profile details you choose to share), messages you send to other Users, and collaborative profile content created with another User. You acknowledge and consent to this sharing as a necessary aspect of the Service.

6.2 Sharing with Sub-Processors. We share Personal Data with the Sub-Processors identified in Section 5, strictly for the purposes of operating, maintaining, and improving the Service.

6.3 Legal and Regulatory Disclosure. We may disclose your Personal Data if we determine, in good faith, that such disclosure is reasonably necessary to:

  1. Comply with applicable law, regulation, legal process, or enforceable governmental request, including but not limited to a subpoena, court order, search warrant, or national security or law enforcement request;
  2. Protect the safety, rights, or property of the Company, our Users, or any third party;
  3. Detect, prevent, investigate, or address fraud, security vulnerabilities, or technical issues;
  4. Respond to an emergency involving danger of death or serious physical injury to any person;
  5. Enforce our Terms of Service or this Privacy Policy.

6.4 Child Safety Disclosures. In accordance with applicable law — including 18 U.S.C. § 2258A (United States), the Protection of Children from Sexual Offences Act, 2012 (India), and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (India) — we will report confirmed or suspected CSAM and CSAE to the National Center for Missing & Exploited Children (NCMEC), relevant law enforcement authorities, and other applicable regulatory bodies. Such reports will include all information required by law, which may include User account data, communications content, and associated metadata.

6.5 Business Transfers. In the event of a merger, acquisition, reorganisation, bankruptcy, dissolution, asset sale, or similar corporate transaction involving all or a portion of the Company's assets, your Personal Data may be among the assets transferred or acquired. In such an event, we will provide notice to you — via the Service, email, or other reasonable means — before your Personal Data is transferred to the acquiring entity and becomes subject to a different privacy policy. You will have the opportunity to request deletion of your data before the transfer, to the extent technically and legally feasible.

6.6 With Your Consent. We may share your Personal Data for purposes not described in this Policy only after obtaining your explicit, informed, and freely given consent.

7. Data Storage and Security

7.1 Storage Infrastructure. Your Personal Data is stored on infrastructure provided by Google Firebase and Google Cloud Platform. Data may be stored and processed in data centres located in the United States, the European Economic Area, or other jurisdictions where Google Cloud operates. For information regarding international data transfers, please refer to Section 15.

7.2 Security Measures. We implement a multi-layered approach to data security, including:

  1. Encryption in Transit. All data transmitted between your device and our servers is encrypted using Transport Layer Security (TLS) version 1.2 or higher.
  2. Encryption at Rest. Data stored on our servers is encrypted at rest using AES-256 encryption, as provided by Google Cloud Platform.
  3. End-to-End Encryption. Direct messages and view-once media are encrypted end-to-end as described in Section 4.
  4. Secure Credential Storage. Cryptographic keys and sensitive authentication tokens are stored on your device using platform-native secure storage mechanisms (iOS Keychain / Android Keystore), which leverage hardware-backed security where available.
  5. Server-Side Access Controls. Access to backend data is restricted through Firebase Security Rules, role-based access controls on Cloud Functions, and the principle of least privilege.
  6. Authentication Security. User authentication is performed via phone number-based OTP verification through Firebase Authentication, with session tokens managed securely.

7.3 Limitation of Liability for Security. While we implement commercially reasonable and industry-standard security measures, no method of electronic transmission or storage is completely secure. We cannot and do not guarantee the absolute security of your Personal Data against all threats, including but not limited to unauthorised access, disclosure, alteration, or destruction resulting from a security breach, cyberattack, or unforeseen vulnerability. You acknowledge this inherent risk and agree that the Company shall not be liable for any unauthorised access to or disclosure of your Personal Data except to the extent caused by our gross negligence or wilful misconduct. You are responsible for maintaining the confidentiality and security of your device and account credentials.

8. Data Retention

8.1 General Retention Principle. We retain your Personal Data only for as long as is reasonably necessary to fulfil the purposes for which it was collected, as described in this Policy, or as required or permitted by applicable law.

8.2 Specific Retention Periods

  1. Active Account Data. Personal Data associated with your account is retained for the duration of your account's existence and active use of the Service.
  2. Messages and Communications. Encrypted messages are retained on our servers for the duration of the associated chat relationship. View-once media is permanently deleted from our servers after it has been viewed by the recipient or upon expiration of the viewing window, whichever occurs first.
  3. Deleted Account Data. Upon receipt of an account deletion request (submitted via the in-app deletion feature or by emailing us), we will initiate deletion of your Personal Data. Account data, profile information, and associated content will be deleted within thirty (30) calendar days of the deletion request, except where retention is required by law or is necessary for the purposes described in paragraph (d) below.
  4. Moderation, Safety, and Legal Records. Records related to content moderation actions (including reports received, investigations conducted, and enforcement actions taken), safety incidents, and legal proceedings are retained for a period of up to three (3) years following the date of the incident or account deletion, whichever is later. This extended retention is necessary for pattern detection, preventing re-registration by banned Users, cooperation with law enforcement, and legal compliance.
  5. CSAM/CSAE Reporting Records. Records and evidence related to CSAM and CSAE reports submitted to NCMEC or law enforcement are retained for the period required by applicable law, as directed by the receiving authority, or for a minimum of five (5) years, whichever is longer.
  6. Analytics Data. Analytics data is collected in anonymised and aggregated form and is retained indefinitely. Individual-level analytics events are not associated with identifiable Users.
  7. Local Device Data. Data stored locally on your device (via AsyncStorage or SecureStore) remains on your device until you uninstall the application, clear the application's data through your device settings, or delete your account (which triggers a local data clearance upon next app launch). We do not have the ability to remotely delete data stored locally on your device.

9. Your Rights as a Data Principal

9.1 Subject to applicable law and the exceptions and limitations described herein, you may exercise the following rights with respect to your Personal Data:

  1. Right of Access. You have the right to request confirmation of whether we process your Personal Data, and if so, to obtain a copy of the Personal Data we hold about you.
  2. Right to Correction. You have the right to request correction or update of any inaccurate or incomplete Personal Data we hold about you. You may correct most profile information directly through the Service's profile editing features.
  3. Right to Erasure. You have the right to request the deletion of your account and all associated Personal Data. You may exercise this right through the in-app account deletion feature or by contacting us as described below. Deletion is subject to the retention periods and exceptions described in Section 8.
  4. Right to Restriction. You have the right to request that we restrict the processing of your Personal Data in certain circumstances, including where you contest the accuracy of the data, where you believe the processing is unlawful, or where you have objected to the processing and a determination is pending.
  5. Right to Data Portability. You have the right to receive the Personal Data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us, where technically feasible.
  6. Right to Withdraw Consent. Where our processing of your Personal Data is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent prior to its withdrawal. You may withdraw consent by adjusting your in-app settings (for example, disabling push notifications) or by contacting us.
  7. Right to Object. You have the right to object to the processing of your Personal Data where such processing is based on our legitimate interests, on grounds relating to your particular situation.
  8. Right to Lodge a Complaint. You have the right to lodge a complaint with a competent data protection authority or supervisory authority in your jurisdiction if you believe our processing of your Personal Data violates applicable data protection law.

9.2 Exercising Your Rights. To exercise any of the rights described above, you may:

  1. Use the relevant in-app features (for example, profile editing, account deletion, notification settings);
  2. Send an email to hello@flameapp.in with the subject line “Data Subject Request” and a description of the right(s) you wish to exercise.

9.3 Identity Verification. To protect your privacy and prevent unauthorised requests, we may require you to verify your identity before processing your request. Verification will typically involve confirming the phone number associated with your account via OTP.

9.4 Response Timeline. We will acknowledge receipt of your request within seventy-two (72) hours and will fulfil your request within thirty (30) days of receipt. If the complexity or volume of requests necessitates an extension, we will notify you within the initial thirty-day period and provide an estimated completion date, which shall not exceed an additional sixty (60) days.

9.5 Exceptions. We may decline to process requests that are manifestly unfounded, excessive, or repetitive, or where we are required by law to retain certain data. If we decline a request, we will inform you of the reasons for the denial.

10. Children's Privacy

10.1 Age Restriction. The Service is not intended for, and must not be used by, individuals under the age of sixteen (16) years, or under the minimum age required by applicable law in your jurisdiction (for example, sixteen (16) years of age in the European Economic Area under the General Data Protection Regulation). By creating an account, you represent and warrant that you meet the applicable minimum age requirement.

10.2 Age Gate. During the account registration and onboarding process, Users are required to provide their date of birth. The Service will not permit the creation of an account by any individual who does not meet the applicable minimum age requirement based on the date of birth provided.

10.3 Discovery and Remediation. If we learn or have reason to believe that we have collected or processed Personal Data from an individual below the applicable minimum age without valid parental or guardian consent:

  1. We will immediately suspend the account in question to prevent further access;
  2. We will delete all Personal Data associated with the account as promptly as technically feasible, and in no event later than seventy-two (72) hours from the date of discovery;
  3. We will report the matter to the appropriate authorities if required by applicable law.

10.4 Parental and Guardian Contact. If you are a parent or legal guardian and believe that your child has created an account on or provided Personal Data to the Service, please contact us immediately at support@flameapp.in. We will take prompt steps to investigate and, where confirmed, to delete the child's account and associated data.

11. Child Safety and Protection Standards

11.1 Zero-Tolerance Policy. Flame maintains a strict, zero-tolerance policy towards any content, conduct, communication, or material that constitutes, promotes, facilitates, or is related to:

  1. Child Sexual Abuse Material (CSAM);
  2. Child Sexual Exploitation and Abuse (CSAE);
  3. Online grooming, sexual solicitation, or sextortion of minors;
  4. Any other form of child exploitation or endangerment.

11.2 Reporting Mechanisms

  1. In-App Reporting. Users may report concerning content, profiles, or messages by tapping the “Report” button available on any User's profile page or within chat settings. Reports are reviewed by our safety team.
  2. Email Reporting. Users and non-Users may report concerns by sending a detailed description of the concern to our dedicated safety team at support@flameapp.in.
  3. Anonymous Reporting. We accept anonymous reports where local law permits. However, providing contact information may be necessary for follow-up and resolution.

11.3 Investigation and Enforcement

Upon receiving a report:

  1. Our safety team will initiate an investigation within twenty-four (24) hours of receipt;
  2. Users found to have engaged in conduct described in Section 11.1 will be subject to immediate and permanent account termination, device-level bans to prevent re-registration, and any other available enforcement measures;
  3. We will preserve all relevant evidence, including account data, communications, media, and metadata, for the purpose of reporting to authorities and supporting law enforcement investigations;
  4. We will file a report with the National Center for Missing & Exploited Children (NCMEC) through the CyberTipline, as required under 18 U.S.C. § 2258A and applicable international frameworks;
  5. We will notify and cooperate with local and national law enforcement authorities in the relevant jurisdiction, including in India under the Protection of Children from Sexual Offences Act, 2012 (POCSO) and the Information Technology Act, 2000;
  6. We will cooperate fully and promptly with any subsequent law enforcement investigation or legal proceedings.

11.4 Proactive Measures. We employ and continuously improve proactive measures to detect and prevent child exploitation on the Service, including but not limited to content moderation practices, user behaviour monitoring for indicators of grooming or exploitation, maintaining audit logs to assist investigations, and participation in industry initiatives and working groups dedicated to child safety.

12. Device Permissions

12.1 The Service may request access to certain features and capabilities of your device. You are not required to grant any permission except Internet access, which is essential for the Service to function. All other permissions are optional and are requested only when you attempt to use a feature that requires them.

12.2 Camera. Access to your device's camera is requested when you choose to undergo selfie verification, record view-once videos, or capture photographs for sharing in chat or for collaborative profile milestones. Camera access is not used for surveillance, background capture, or any purpose other than the specific action you initiate.

12.3 Photo Library and Media Storage. Access to your device's photo library is requested when you choose to upload profile photographs, share images in chat, or add photographs to collaborative milestones. We access only the specific files you select; we do not scan, index, or access your full photo library.

12.4 Microphone. Access to your device's microphone is requested when you choose to record view-once videos with audio. Microphone access is not used for ambient listening, background recording, or any purpose other than the specific recording you initiate.

12.5 Push Notifications. Permission to deliver push notifications is requested during onboarding. Granting this permission enables us to notify you of new messages, game invitations, connection requests, and other relevant Service events. You may revoke this permission at any time through your device's notification settings.

12.6 Internet Access. Internet access is required for the Service to function and cannot be disabled while using the Service.

12.7 Revoking Permissions. You may revoke any device permission at any time through your device's settings application. Revoking a permission may limit or disable certain features of the Service that depend on that permission, but will not affect the core functionality of the Service or the security of your account.

13. Cookies and Local Storage Technologies

13.1 Mobile Application

The Flame mobile application does not use HTTP cookies. The application utilises the following local storage technologies:

  1. AsyncStorage (React Native). Used for storing non-sensitive local data, including onboarding completion flags, cached user profile data, session preferences, and other non-confidential data that improves app performance and reduces network requests. This data is stored locally on your device and is not transmitted to third parties.
  2. SecureStore (Expo SecureStore). Used for storing sensitive data, including cryptographic private keys, encryption key identifiers, and authentication tokens. SecureStore leverages platform-native secure storage (iOS Keychain with Secure Enclave; Android Keystore with hardware-backed security where available), providing the highest level of on-device security.
  3. SQLite (Local Database). Used for caching message data locally on your device to enable offline access and improve performance. The local SQLite database is stored on your device and is not transmitted to third parties.

13.2 Website

Our website may use strictly necessary cookies for core functionality such as session management and security. We do not use advertising cookies, tracking cookies, or cross-site tracking technologies on our website. Where applicable law requires it, we will provide a cookie notice or consent mechanism before placing any non-essential cookies.

14. Do Not Track

14.1 The Service does not currently respond to “Do Not Track” (DNT) signals transmitted by web browsers, as there is no universally accepted standard for how online services should respond to such signals.

14.2 Notwithstanding the foregoing, the Company does not engage in cross-site tracking, does not serve targeted advertisements, and does not sell or share Personal Data with advertising networks.

15. International Data Transfers

15.1 If you access the Service from a jurisdiction outside India, your Personal Data may be transferred to, stored in, and processed in India, the United States, and other jurisdictions where our Service infrastructure and Sub-Processors operate. These jurisdictions may have data protection and privacy laws that differ from the laws of your country of residence.

15.2 Where we transfer Personal Data internationally, we implement appropriate safeguards to ensure that your data receives an adequate level of protection, including:

  1. Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable;
  2. Reliance on adequacy decisions issued by relevant data protection authorities, where available;
  3. Contractual data processing agreements with Sub-Processors that impose confidentiality, security, and data protection obligations;
  4. Your informed consent to the transfer of data as a condition of using the Service, where other legal mechanisms are not available.

15.3 By using the Service, you acknowledge and consent to the transfer, storage, and processing of your Personal Data in jurisdictions outside your country of residence, subject to the safeguards described in this Section.

16. Changes to This Privacy Policy

16.1 We reserve the right to modify, amend, or update this Privacy Policy at any time, at our sole discretion.

16.2 Material Changes. If we make material changes to this Policy — including changes that affect the categories of Personal Data collected, the purposes of processing, or your rights — we will provide you with prominent notice at least fifteen (15) days before the changes take effect. Notice may be provided through an in-app notification, a prominent banner within the Service, an email to the address associated with your account (if available), or a combination of these methods.

16.3 Non-Material Changes. Minor changes, including typographical corrections, formatting adjustments, and clarifications that do not substantively alter the meaning or scope of the Policy, may be made without prior notice.

16.4 Effective Date. The “Last Updated” date at the top of this Policy will reflect the date of the most recent revision. Changes will take effect on the date specified in the notification or, in the absence of a specific date, fifteen (15) days after the notification is provided.

16.5 Continued Use. Your continued use of the Service after the effective date of any changes to this Policy constitutes your acceptance of the revised Policy. If you do not agree with the revised Policy, you must discontinue use of the Service and delete your account before the effective date of the changes.

17. Governing Law and Jurisdiction

17.1 This Privacy Policy and any dispute, claim, or controversy arising out of or relating to this Policy (including its existence, validity, interpretation, performance, breach, or termination) shall be governed by and construed in accordance with the substantive laws of the Republic of India, without regard to its conflict-of-law principles.

17.2 Subject to Section 17.3, any dispute arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts located in Bangalore, India.

17.3 For Users located in the European Economic Area, the United Kingdom, or other jurisdictions where mandatory consumer protection laws apply, this Section does not deprive you of any mandatory legal protections or the right to bring proceedings in the courts of your country of residence as provided by applicable law.

18. Severability

If any provision of this Privacy Policy is found to be invalid, illegal, or unenforceable by a court of competent jurisdiction, such finding shall not affect the validity, legality, or enforceability of the remaining provisions of this Policy. The invalid, illegal, or unenforceable provision shall be modified to the minimum extent necessary to make it valid, legal, and enforceable while preserving the original intent of the parties, or, if such modification is not possible, shall be deemed severed from this Policy.

19. Contact Information

For privacy-related inquiries, data subject requests, or concerns regarding this Policy, please contact us using the following channels:

Privacy and Data Protection Inquiries:
Email: hello@flameapp.in

General Support:
Email: support@flameapp.in

Safety and Child Protection Reports:
Email: support@flameapp.in

General Correspondence:
Email: hello@flameapp.in

We endeavour to acknowledge all privacy-related inquiries within seventy-two (72) hours and to provide a substantive response within thirty (30) calendar days.

20. Regulatory Compliance Framework

This Privacy Policy is designed to comply with the requirements of the following laws, regulations, and platform policies, to the extent applicable:

  1. Information Technology Act, 2000 (India), including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
  2. Digital Personal Data Protection Act, 2023 (India), and any rules, regulations, or guidelines issued thereunder;
  3. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (India);
  4. General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), to the extent applicable to Users located in the European Economic Area and the United Kingdom;
  5. Children's Online Privacy Protection Act (COPPA) (United States), 15 U.S.C. §§ 6501–6506;
  6. Protection of Children from Sexual Offences Act, 2012 (POCSO) (India);
  7. 18 U.S.C. § 2258A (United States), regarding mandatory reporting of apparent violations involving CSAM to the National Center for Missing & Exploited Children (NCMEC);
  8. Google Play Developer Program Policies, including the User Data Policy, Permissions Policy, and Families Policy;
  9. Apple App Store Review Guidelines, including Section 5.1 (Privacy) and the Apple Developer Program License Agreement.

The Company's compliance with the above laws and policies is ongoing and is subject to periodic review and update as legal requirements evolve.


By using the Flame application and Service, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy.