Privacy Policy

Flushia is an audio fiction service. This policy explains, in plain English, exactly what personal data we collect, why we collect it, who else sees it, how long we keep it, and what you can require us to do about it. We have tried to make it readable rather than defensive.

Last updated 24 August 2026 · Version 1.3

01Who we are

Flushia (“Flushia”, “we”, “us”) is an audio fiction application and website operated by [LEGAL ENTITY NAME], a company registered in [EU MEMBER STATE] under company number [COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS].

For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), we are the controller of the personal data described in this policy. That means we decide what is collected and why, and we are the party you can hold responsible for it.

We have not appointed a Data Protection Officer. We are not required to: we do not carry out large-scale systematic monitoring, and our processing of special category data is limited in the way described in section 6. Privacy questions are handled directly by the operator of the service at the address below.

One address handles everything — privacy and data protection requests, legal notices, and ordinary support: .

02Scope of this policy

This policy covers the Flushia website at flushia.com and the Flushia applications for iOS and Android. It applies to everyone who uses the service, wherever they are.

It does not cover the App Store, Google Play, or any other service you reach through a link from ours. When you buy a subscription, that purchase happens inside Apple’s or Google’s systems under their own privacy policies, not ours — see section 7.

Flushia is intended only for people aged 18 and over. See section 13.

03Summary

The short version. Every line here is expanded on later, and where the summary and the detailed section could be read differently, the detailed section governs.

WhatWhyKept for
Email address and passwordTo create and secure your accountUntil you delete your account
What you played, and how far you gotTo resume playback and show your historyUntil you delete it, or your account
Your favouritesTo show you your own listUntil you remove them, or delete your account
Subscription statusTo give you access to the library, and to meet tax and accounting dutiesDuration of the subscription, then up to 7 years for accounting
Waitlist email addressTo email you once, when the app launchesUntil launch, or until you unsubscribe
Product analytics eventsTo understand how the app is used, with your consentUp to 12 months

Things we do not do, and undertake in this policy not to do: we do not sell your personal data; we do not share it for cross-context behavioural advertising; we carry no advertising SDKs and collect no advertising identifiers (IDFA or AAID); we do not collect your precise location, your contacts, your photos, or your microphone; and we never see your card number.

04What we collect

This section is written from our actual database schema and our actual analytics calls. If we add a field, this section changes with it.

a. Account data. Your email address; a password stored only as a bcrypt hash, never as the password itself; optionally a display name if you give one; and the date your account was created. If you sign in with Apple or Google instead, we receive an identifier and an email address from them — and if you use Apple’s “Hide My Email” feature, the address we receive is Apple’s relay address, not your real one.

b. Session data. To keep you signed in on a phone, we store a hashed refresh token and its expiry date against your account. We store the hash, not the token.

c. Listening data. For each story you play, the story and how many seconds into it you reached, plus when you last listened. Separately, the stories you mark as favourites. This is the data that makes “resume where you left off” work. It is also the most personal data we hold — see section 6.

d. Subscription data. An identifier from RevenueCat, our subscription infrastructure provider, together with the plan you are on, whether it is active, and when the current period ends. We do not receive, process, or store your card number, bank details, or billing address. Those go to Apple or Google and stay there.

e. Waitlist data. If you enter your email address on our website before launch, we store that address and the date you entered it, for the single purpose of telling you when the app is available.

f. Technical data. Our servers keep ordinary web server logs, which include IP addresses, timestamps and the URL requested. These are generated automatically by the hosting software and are used for security and debugging.

g. Analytics events. Where you have consented, we record a small, fixed set of product events: an account being created, a sign-in, a story being played, a favourite being added, a subscription starting, and a waitlist sign-up. Website page views are also counted. We do not record the content of anything you type.

h. Correspondence. If you email us, we keep the email so we can answer it and so we have a record of what was asked.

05Why we use it, and our legal basis

Under the GDPR every use of personal data needs a lawful basis. Ours are set out below. Where we rely on legitimate interests, we have carried out a balancing exercise and summarised the result.

PurposeData usedLegal basis (GDPR Art. 6)
Creating your account and signing you inAccount data, session dataPerformance of a contract, Art. 6(1)(b)
Delivering stories, remembering your position, and showing your favouritesListening dataPerformance of a contract, Art. 6(1)(b)
Deciding whether you may access premium storiesSubscription dataPerformance of a contract, Art. 6(1)(b)
Keeping the service secure, preventing abuse, sharing of credentials and fraudTechnical data, session dataLegitimate interests, Art. 6(1)(f)
Understanding how the product is used so we can improve itAnalytics eventsConsent, Art. 6(1)(a)
Telling you once when the app launchesWaitlist dataConsent, Art. 6(1)(a)
Emailing you about your account — verifying your address, resetting your password, confirming a deletion or an exportAccount dataPerformance of a contract, Art. 6(1)(b)
Telling you about new stories, and reminding you about a story you startedAccount data, listening dataConsent, Art. 6(1)(a)
Answering your messagesCorrespondenceLegitimate interests, Art. 6(1)(f)
Meeting tax, accounting and legal obligationsSubscription dataLegal obligation, Art. 6(1)(c)

Our balancing test, in short. For security and abuse prevention we use the minimum data that will do the job, we do not use it to build a profile of you, and a service that could not defend itself against credential stuffing or paywall circumvention would harm the very users it holds data about. We consider that our interest does not override your rights and freedoms. You may object to this processing at any time under Art. 21 — see section 11.

Consent is real consent. Analytics are off until you agree, refusing costs you nothing, and you can withdraw at any time with the same ease you gave it. Withdrawing does not make the processing before withdrawal unlawful. The same is true of marketing email: the box at sign-up starts unticked, it is separate from agreeing to the terms, and leaving it unticked costs you nothing — every account feature works identically either way. Account emails are a different thing and are not marketing: you cannot unsubscribe from a password reset, and they carry no unsubscribe link because there is nothing there to switch off.

06Listening data and sensitive categories

We want to be direct about this rather than bury it. Flushia publishes romantic fiction. A record of which of those stories a named person chose to listen to could, taken together, allow inferences about their private life and relationships — the kind of information GDPR Art. 9 treats as a special category. We would rather assume it does than argue that it does not.

We do not ask you for that information and we do not set out to derive it. But we recognise what our own listening history could imply, and we handle it accordingly:

  • Listening history and favourites are visible to you and to nobody else. There is no social layer, no public profile, no “what your friends are listening to”, and nothing is ever posted anywhere on your behalf.
  • We never disclose to any third party which specific stories a specific person played. The analytics event we send records that a story was played and which story it was, against an account identifier — it is not enriched with your email address or name.
  • Access to the production database is limited to the operator of the service and used for administration and support only.
  • We never use listening data for advertising, and we do not build audience segments from it. There is nothing to sell, because we do not sell it.
  • You can erase this data without closing your account, by deleting individual history entries and favourites, or by asking us to clear the lot.

If you would rather we did not keep a listening history at all, tell us at and we will clear it. Note that resume-where-you-left-off will stop working, because that feature is the history.

07Who we share it with

We do not sell personal data and we do not share it for advertising. We do use a small number of service providers, who process data on our instructions under written contracts that meet GDPR Art. 28. They are:

ProviderWhat they processWhere
Apple and GoogleSign-in identifiers; and all payment processing for subscriptions, as principals rather than as our processorsUnited States and worldwide
RevenueCatSubscription status and an account identifierUnited States
PostHogThe analytics events listed in section 4(g)United States (see section 8)
Mailgun (Sinch)Your email address and the contents of account emails — verifying your address, resetting your password, confirming a deletion or an exportUnited States (see section 8)
ResendYour email address and your first name, for marketing emails only, and only if you asked for themUnited States (see section 8)
Cloudflare (R2)Audio files only. No personal data is stored thereEuropean Union and worldwide edge
DigitalOceanHosting for our application and database, including server logs[DATA CENTRE REGION]
ElevenLabsStory text submitted for narration. No user data is sentUnited States

Beyond those providers, we will disclose personal data only where we are legally required to — a binding order from a court or a competent authority — or where it is necessary to establish, exercise or defend a legal claim. If we are ever compelled to disclose your data, we will tell you unless we are legally prohibited from doing so.

If Flushia is ever sold or merged, personal data may transfer to the buyer. We would notify you before that happened and before any new policy applied to you, so that you can delete your account first if you prefer.

08International transfers

Some of the providers above are located in the United States, so some personal data is transferred outside the EEA. Where that happens, the transfer is made under one of the safeguards permitted by Chapter V of the GDPR: either the provider’s certification under the EU–US Data Privacy Framework, or the European Commission’s Standard Contractual Clauses, supplemented by the technical measures described in section 10.

You may ask us for a copy of the relevant safeguard by writing to .

We keep the volume of these transfers as small as we can. Audio content, the account database, and the application itself are hosted in the European Union.

09How long we keep it

We keep personal data only for as long as the purpose it was collected for requires. In practice:

DataRetention period
Account dataFor as long as your account exists. Deleted within 30 days of you deleting your account.
Listening history and favouritesUntil you delete them, or within 30 days of account deletion, whichever comes first.
Session tokensUntil they expire, and purged routinely thereafter.
Subscription recordsFor the life of the subscription. Records needed for tax and accounting are then kept for the statutory period, up to 7 years, and used for nothing else.
Accounting records after account deletionUp to 7 years from the deletion. Stripped first of your account identifier, email address and name, so that what remains is a payment record that cannot be linked back to you, and deleted automatically once the 7 years pass.
Waitlist email addressesUntil the app launches and the launch email is sent, or until you unsubscribe. Deleted within 30 days after that.
Analytics eventsUp to 12 months from the event.
Marketing consent recordThe date you agreed, and the date you unsubscribed if you did. Kept for as long as your account exists, because it is the only proof that we had your permission — and, if you unsubscribe, the only thing stopping us mailing you again by mistake. Deleted with the account.
Server logsUp to 90 days, unless a specific security incident requires us to keep a log longer.
CorrespondenceUp to 24 months after the matter is closed.

Backups are a partial exception, as they are with every service that takes backups seriously: data you delete may persist in an encrypted backup until that backup rotates out, which takes no more than 90 days. Restored backups are re-processed against deletion requests.

10How we protect it

The measures below are ones we actually implement. We have deliberately not listed certifications we do not hold or controls we have not built.

  • Passwords are stored only as bcrypt hashes with a per-password salt. We cannot read your password, and neither can anyone who obtains the database.
  • Session refresh tokens are stored as hashes, not in a form that could be replayed.
  • All traffic between your device and our servers is encrypted with TLS.
  • Audio files live in a private bucket that is not publicly readable. Playback is served through short-lived signed URLs issued only after we have checked that your account is entitled to that story.
  • Administrative functions are behind a separate, role-gated login, and are not reachable with an ordinary user account.
  • Every push to our codebase is scanned automatically for accidentally committed credentials, and a commit that contains one is blocked before it can be deployed.
  • Access to production systems is limited to the operator of the service.

No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by Art. 33, and we will notify you directly without undue delay where Art. 34 requires it.

11Your rights (EEA, UK and Switzerland)

If you are in the European Economic Area, the United Kingdom or Switzerland, you have the following rights. They are free to exercise, and using them will never result in a worse service.

  • Access (Art. 15). Ask what we hold about you and receive a copy of it. You do not have to ask us: the same file described under portability below is downloadable on demand.
  • Rectification (Art. 16). Have inaccurate data corrected and incomplete data completed.
  • Erasure (Art. 17). Have your data deleted, in the app under Profile, or on this website at flushia.com/delete-account if you no longer have the app. Deletion removes your account, email address, name, favourites, listening history and every signed-in device. Two things survive it, and we would rather say so here than surprise you: an accounting record with no identifier, email or name attached, kept for as long as tax law requires and no longer; and the billing records held by Apple, Google and RevenueCat for any purchase you made, which are theirs rather than ours and which we have no ability to delete on your behalf.
  • Restriction (Art. 18). Have us pause processing while a dispute about accuracy or legitimate interests is resolved.
  • Portability (Art. 20). Receive the data you gave us in a structured, machine-readable format — a JSON file, in the app under Profile or on this website at flushia.com/my-data — or have it sent directly to another controller where technically feasible.
  • Objection (Art. 21). Object to processing based on legitimate interests. Where you object to direct marketing, we will stop, without exception and without asking why.
  • Withdraw consent (Art. 7(3)). Withdraw consent to analytics, to marketing email or to launch email at any time, as easily as you gave it. Every marketing email carries an unsubscribe link, and one click is enough — no login, no form, no reason asked. The link does not expire, so an email from a year ago still works.
  • Complain. Lodge a complaint with a supervisory authority — see section 17.

Erasure and portability you can carry out yourself, in seconds, without asking us — in the app under Profile, or at flushia.com/delete-account and flushia.com/my-data, which work without the app and confirm by email so that nobody else can use them against your account. For anything else, write to from the address on your account. We will respond within one month. If a request is genuinely complex we may extend that by up to two further months, and we will tell you within the first month if we do. We may ask you to confirm your identity, but only where we have a real doubt, and only for information proportionate to that doubt.

UK users: the same rights apply under the UK GDPR and the Data Protection Act 2018, and the supervisory authority is the Information Commissioner’s Office.

12Your rights (United States)

This section applies if you live in a US state with a comprehensive privacy law — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana. Some of these rights may be available to you regardless of where you live, because in most cases we apply them to everyone.

  • Know and access. Ask what categories of personal information we have collected about you, where it came from, why we collected it, who we disclosed it to, and receive a copy.
  • Delete. Ask us to delete personal information we collected from you, subject to the narrow exceptions the statutes allow (for example, records we must keep for tax purposes).
  • Correct. Ask us to fix inaccurate personal information.
  • Opt out. Opt out of the sale of personal information, of sharing for cross-context behavioural advertising, and of profiling with legal or similarly significant effects.
  • Limit sensitive information. Limit our use of sensitive personal information to what is necessary to provide the service.
  • Non-discrimination. Not be denied service, given a worse price, or given a lower quality of service for exercising any of these rights. We offer no financial incentives for personal information.
  • Appeal. If we refuse a request, appeal that refusal. Write to with “Appeal” in the subject line and we will respond in writing with our reasoning.

We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding twelve months. That includes the personal information of anyone we know to be under 16. Because we do not sell or share, there is no opt-out link to provide — but we honour Global Privacy Control signals as an opt-out request in any event.

Under California’s CPRA, listening history of the kind described in section 6 may constitute sensitive personal information. We use it only to provide the service you asked for, which is the permitted purpose, and for nothing else.

An authorised agent may submit a request on your behalf with written proof of authorisation. California residents may also request disclosure of the categories of personal information disclosed for business purposes under the “Shine the Light” law.

13Children

Flushia is for adults. The service is intended for people aged 18 and over, and you confirm that you meet that requirement when you create an account. We do not knowingly collect personal data from anyone under 18.

Our age check is a self-declaration during onboarding. We are stating that plainly rather than implying a stronger control than we operate: we do not verify identity documents.

If we learn that an account belongs to someone under 18, we will terminate it and delete the associated personal data promptly. If you are a parent or guardian and believe a child has created an account, write to and we will act on it.

14Cookies and similar technologies

Our website uses two categories of storage, and neither is used for advertising.

  • Strictly necessary. A cookie that remembers the choice you made about analytics, and — for administrators signing in to our internal admin panel, not for ordinary visitors — session and anti-forgery cookies. These are required for the site to work, so they do not require consent.
  • Analytics. Storage used by our analytics provider to count visits and product events. Nothing in this category is written, and no request is made to the provider, until you consent. You can withdraw at any time, in the footer of any page, and the cookies are deleted when you do.

The same rule governs analytics we send from our own servers rather than from your browser: a product event is recorded only where consent has been given.

The mobile applications do not use cookies. They store a session token in your device’s secure storage so you do not have to sign in every time, and they carry no advertising or tracking SDKs of any kind.

Every cookie we can set is listed by name, with its purpose and its lifetime, in our Cookie Policy.

15Automated decision-making

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of GDPR Art. 22, and we do not profile you for that purpose.

The service does make one automated decision: whether your subscription entitles you to open a particular story. That is a contractual check against your subscription status, and if you think it is wrong, contact and a person will look at it.

16Changes to this policy

We will update this policy when what we do changes. The version number and the “last updated” date at the top of this page always reflect the current text.

If a change is material — a new purpose, a new category of data, a new recipient, or a materially longer retention period — we will notify you by email or in the app before it takes effect, and where the law requires your consent we will ask for it rather than assume it. Continuing to use the service after a non-material change means the updated policy applies.

17Contact and complaints

Write to us first — most things are quicker to fix directly: , or by post to [LEGAL ENTITY NAME], [REGISTERED ADDRESS].

You also have the right to complain to a data protection supervisory authority. You may complain to the authority in the EU member state where you live, where you work, or where you believe an infringement occurred. Our lead supervisory authority is [LEAD SUPERVISORY AUTHORITY]. A list of EEA authorities is published by the European Data Protection Board. In the United Kingdom the authority is the Information Commissioner’s Office.

We would rather you told us first, but you are not required to, and nothing in this policy limits your right to go straight to a regulator.