Privacy Policy
Flushia is an audio fiction service. This policy explains, in plain English, exactly what personal data we collect, why we collect it, who else sees it, how long we keep it, and what you can require us to do about it. We have tried to make it readable rather than defensive.
Last updated 24 August 2026 · Version 1.3
01Who we are
Flushia (“Flushia”, “we”, “us”) is an audio fiction application and website operated by [LEGAL ENTITY NAME], a company registered in [EU MEMBER STATE] under company number [COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS].
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), we are the controller of the personal data described in this policy. That means we decide what is collected and why, and we are the party you can hold responsible for it.
We have not appointed a Data Protection Officer. We are not required to: we do not carry out large-scale systematic monitoring, and our processing of special category data is limited in the way described in section 6. Privacy questions are handled directly by the operator of the service at the address below.
One address handles everything — privacy and data protection requests, legal notices, and ordinary support: .
02Scope of this policy
This policy covers the Flushia website at flushia.com and the Flushia applications for iOS and Android. It applies to everyone who uses the service, wherever they are.
It does not cover the App Store, Google Play, or any other service you reach through a link from ours. When you buy a subscription, that purchase happens inside Apple’s or Google’s systems under their own privacy policies, not ours — see section 7.
Flushia is intended only for people aged 18 and over. See section 13.
03Summary
The short version. Every line here is expanded on later, and where the summary and the detailed section could be read differently, the detailed section governs.
| What | Why | Kept for |
|---|---|---|
| Email address and password | To create and secure your account | Until you delete your account |
| What you played, and how far you got | To resume playback and show your history | Until you delete it, or your account |
| Your favourites | To show you your own list | Until you remove them, or delete your account |
| Subscription status | To give you access to the library, and to meet tax and accounting duties | Duration of the subscription, then up to 7 years for accounting |
| Waitlist email address | To email you once, when the app launches | Until launch, or until you unsubscribe |
| Product analytics events | To understand how the app is used, with your consent | Up to 12 months |
Things we do not do, and undertake in this policy not to do: we do not sell your personal data; we do not share it for cross-context behavioural advertising; we carry no advertising SDKs and collect no advertising identifiers (IDFA or AAID); we do not collect your precise location, your contacts, your photos, or your microphone; and we never see your card number.
04What we collect
This section is written from our actual database schema and our actual analytics calls. If we add a field, this section changes with it.
a. Account data. Your email address; a password stored only as a bcrypt hash, never as the password itself; optionally a display name if you give one; and the date your account was created. If you sign in with Apple or Google instead, we receive an identifier and an email address from them — and if you use Apple’s “Hide My Email” feature, the address we receive is Apple’s relay address, not your real one.
b. Session data. To keep you signed in on a phone, we store a hashed refresh token and its expiry date against your account. We store the hash, not the token.
c. Listening data. For each story you play, the story and how many seconds into it you reached, plus when you last listened. Separately, the stories you mark as favourites. This is the data that makes “resume where you left off” work. It is also the most personal data we hold — see section 6.
d. Subscription data. An identifier from RevenueCat, our subscription infrastructure provider, together with the plan you are on, whether it is active, and when the current period ends. We do not receive, process, or store your card number, bank details, or billing address. Those go to Apple or Google and stay there.
e. Waitlist data. If you enter your email address on our website before launch, we store that address and the date you entered it, for the single purpose of telling you when the app is available.
f. Technical data. Our servers keep ordinary web server logs, which include IP addresses, timestamps and the URL requested. These are generated automatically by the hosting software and are used for security and debugging.
g. Analytics events. Where you have consented, we record a small, fixed set of product events: an account being created, a sign-in, a story being played, a favourite being added, a subscription starting, and a waitlist sign-up. Website page views are also counted. We do not record the content of anything you type.
h. Correspondence. If you email us, we keep the email so we can answer it and so we have a record of what was asked.
05Why we use it, and our legal basis
Under the GDPR every use of personal data needs a lawful basis. Ours are set out below. Where we rely on legitimate interests, we have carried out a balancing exercise and summarised the result.
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating your account and signing you in | Account data, session data | Performance of a contract, Art. 6(1)(b) |
| Delivering stories, remembering your position, and showing your favourites | Listening data | Performance of a contract, Art. 6(1)(b) |
| Deciding whether you may access premium stories | Subscription data | Performance of a contract, Art. 6(1)(b) |
| Keeping the service secure, preventing abuse, sharing of credentials and fraud | Technical data, session data | Legitimate interests, Art. 6(1)(f) |
| Understanding how the product is used so we can improve it | Analytics events | Consent, Art. 6(1)(a) |
| Telling you once when the app launches | Waitlist data | Consent, Art. 6(1)(a) |
| Emailing you about your account — verifying your address, resetting your password, confirming a deletion or an export | Account data | Performance of a contract, Art. 6(1)(b) |
| Telling you about new stories, and reminding you about a story you started | Account data, listening data | Consent, Art. 6(1)(a) |
| Answering your messages | Correspondence | Legitimate interests, Art. 6(1)(f) |
| Meeting tax, accounting and legal obligations | Subscription data | Legal obligation, Art. 6(1)(c) |
Our balancing test, in short. For security and abuse prevention we use the minimum data that will do the job, we do not use it to build a profile of you, and a service that could not defend itself against credential stuffing or paywall circumvention would harm the very users it holds data about. We consider that our interest does not override your rights and freedoms. You may object to this processing at any time under Art. 21 — see section 11.
Consent is real consent. Analytics are off until you agree, refusing costs you nothing, and you can withdraw at any time with the same ease you gave it. Withdrawing does not make the processing before withdrawal unlawful. The same is true of marketing email: the box at sign-up starts unticked, it is separate from agreeing to the terms, and leaving it unticked costs you nothing — every account feature works identically either way. Account emails are a different thing and are not marketing: you cannot unsubscribe from a password reset, and they carry no unsubscribe link because there is nothing there to switch off.
06Listening data and sensitive categories
We want to be direct about this rather than bury it. Flushia publishes romantic fiction. A record of which of those stories a named person chose to listen to could, taken together, allow inferences about their private life and relationships — the kind of information GDPR Art. 9 treats as a special category. We would rather assume it does than argue that it does not.
We do not ask you for that information and we do not set out to derive it. But we recognise what our own listening history could imply, and we handle it accordingly:
- Listening history and favourites are visible to you and to nobody else. There is no social layer, no public profile, no “what your friends are listening to”, and nothing is ever posted anywhere on your behalf.
- We never disclose to any third party which specific stories a specific person played. The analytics event we send records that a story was played and which story it was, against an account identifier — it is not enriched with your email address or name.
- Access to the production database is limited to the operator of the service and used for administration and support only.
- We never use listening data for advertising, and we do not build audience segments from it. There is nothing to sell, because we do not sell it.
- You can erase this data without closing your account, by deleting individual history entries and favourites, or by asking us to clear the lot.
If you would rather we did not keep a listening history at all, tell us at and we will clear it. Note that resume-where-you-left-off will stop working, because that feature is the history.
08International transfers
Some of the providers above are located in the United States, so some personal data is transferred outside the EEA. Where that happens, the transfer is made under one of the safeguards permitted by Chapter V of the GDPR: either the provider’s certification under the EU–US Data Privacy Framework, or the European Commission’s Standard Contractual Clauses, supplemented by the technical measures described in section 10.
You may ask us for a copy of the relevant safeguard by writing to .
We keep the volume of these transfers as small as we can. Audio content, the account database, and the application itself are hosted in the European Union.
09How long we keep it
We keep personal data only for as long as the purpose it was collected for requires. In practice:
| Data | Retention period |
|---|---|
| Account data | For as long as your account exists. Deleted within 30 days of you deleting your account. |
| Listening history and favourites | Until you delete them, or within 30 days of account deletion, whichever comes first. |
| Session tokens | Until they expire, and purged routinely thereafter. |
| Subscription records | For the life of the subscription. Records needed for tax and accounting are then kept for the statutory period, up to 7 years, and used for nothing else. |
| Accounting records after account deletion | Up to 7 years from the deletion. Stripped first of your account identifier, email address and name, so that what remains is a payment record that cannot be linked back to you, and deleted automatically once the 7 years pass. |
| Waitlist email addresses | Until the app launches and the launch email is sent, or until you unsubscribe. Deleted within 30 days after that. |
| Analytics events | Up to 12 months from the event. |
| Marketing consent record | The date you agreed, and the date you unsubscribed if you did. Kept for as long as your account exists, because it is the only proof that we had your permission — and, if you unsubscribe, the only thing stopping us mailing you again by mistake. Deleted with the account. |
| Server logs | Up to 90 days, unless a specific security incident requires us to keep a log longer. |
| Correspondence | Up to 24 months after the matter is closed. |
Backups are a partial exception, as they are with every service that takes backups seriously: data you delete may persist in an encrypted backup until that backup rotates out, which takes no more than 90 days. Restored backups are re-processed against deletion requests.
10How we protect it
The measures below are ones we actually implement. We have deliberately not listed certifications we do not hold or controls we have not built.
- Passwords are stored only as bcrypt hashes with a per-password salt. We cannot read your password, and neither can anyone who obtains the database.
- Session refresh tokens are stored as hashes, not in a form that could be replayed.
- All traffic between your device and our servers is encrypted with TLS.
- Audio files live in a private bucket that is not publicly readable. Playback is served through short-lived signed URLs issued only after we have checked that your account is entitled to that story.
- Administrative functions are behind a separate, role-gated login, and are not reachable with an ordinary user account.
- Every push to our codebase is scanned automatically for accidentally committed credentials, and a commit that contains one is blocked before it can be deployed.
- Access to production systems is limited to the operator of the service.
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by Art. 33, and we will notify you directly without undue delay where Art. 34 requires it.
11Your rights (EEA, UK and Switzerland)
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the following rights. They are free to exercise, and using them will never result in a worse service.
- Access (Art. 15). Ask what we hold about you and receive a copy of it. You do not have to ask us: the same file described under portability below is downloadable on demand.
- Rectification (Art. 16). Have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17). Have your data deleted, in the app under Profile, or on this website at flushia.com/delete-account if you no longer have the app. Deletion removes your account, email address, name, favourites, listening history and every signed-in device. Two things survive it, and we would rather say so here than surprise you: an accounting record with no identifier, email or name attached, kept for as long as tax law requires and no longer; and the billing records held by Apple, Google and RevenueCat for any purchase you made, which are theirs rather than ours and which we have no ability to delete on your behalf.
- Restriction (Art. 18). Have us pause processing while a dispute about accuracy or legitimate interests is resolved.
- Portability (Art. 20). Receive the data you gave us in a structured, machine-readable format — a JSON file, in the app under Profile or on this website at flushia.com/my-data — or have it sent directly to another controller where technically feasible.
- Objection (Art. 21). Object to processing based on legitimate interests. Where you object to direct marketing, we will stop, without exception and without asking why.
- Withdraw consent (Art. 7(3)). Withdraw consent to analytics, to marketing email or to launch email at any time, as easily as you gave it. Every marketing email carries an unsubscribe link, and one click is enough — no login, no form, no reason asked. The link does not expire, so an email from a year ago still works.
- Complain. Lodge a complaint with a supervisory authority — see section 17.
Erasure and portability you can carry out yourself, in seconds, without asking us — in the app under Profile, or at flushia.com/delete-account and flushia.com/my-data, which work without the app and confirm by email so that nobody else can use them against your account. For anything else, write to from the address on your account. We will respond within one month. If a request is genuinely complex we may extend that by up to two further months, and we will tell you within the first month if we do. We may ask you to confirm your identity, but only where we have a real doubt, and only for information proportionate to that doubt.
UK users: the same rights apply under the UK GDPR and the Data Protection Act 2018, and the supervisory authority is the Information Commissioner’s Office.
12Your rights (United States)
This section applies if you live in a US state with a comprehensive privacy law — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana. Some of these rights may be available to you regardless of where you live, because in most cases we apply them to everyone.
- Know and access. Ask what categories of personal information we have collected about you, where it came from, why we collected it, who we disclosed it to, and receive a copy.
- Delete. Ask us to delete personal information we collected from you, subject to the narrow exceptions the statutes allow (for example, records we must keep for tax purposes).
- Correct. Ask us to fix inaccurate personal information.
- Opt out. Opt out of the sale of personal information, of sharing for cross-context behavioural advertising, and of profiling with legal or similarly significant effects.
- Limit sensitive information. Limit our use of sensitive personal information to what is necessary to provide the service.
- Non-discrimination. Not be denied service, given a worse price, or given a lower quality of service for exercising any of these rights. We offer no financial incentives for personal information.
- Appeal. If we refuse a request, appeal that refusal. Write to with “Appeal” in the subject line and we will respond in writing with our reasoning.
We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding twelve months. That includes the personal information of anyone we know to be under 16. Because we do not sell or share, there is no opt-out link to provide — but we honour Global Privacy Control signals as an opt-out request in any event.
Under California’s CPRA, listening history of the kind described in section 6 may constitute sensitive personal information. We use it only to provide the service you asked for, which is the permitted purpose, and for nothing else.
An authorised agent may submit a request on your behalf with written proof of authorisation. California residents may also request disclosure of the categories of personal information disclosed for business purposes under the “Shine the Light” law.
13Children
Flushia is for adults. The service is intended for people aged 18 and over, and you confirm that you meet that requirement when you create an account. We do not knowingly collect personal data from anyone under 18.
Our age check is a self-declaration during onboarding. We are stating that plainly rather than implying a stronger control than we operate: we do not verify identity documents.
If we learn that an account belongs to someone under 18, we will terminate it and delete the associated personal data promptly. If you are a parent or guardian and believe a child has created an account, write to and we will act on it.
15Automated decision-making
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of GDPR Art. 22, and we do not profile you for that purpose.
The service does make one automated decision: whether your subscription entitles you to open a particular story. That is a contractual check against your subscription status, and if you think it is wrong, contact and a person will look at it.
16Changes to this policy
We will update this policy when what we do changes. The version number and the “last updated” date at the top of this page always reflect the current text.
If a change is material — a new purpose, a new category of data, a new recipient, or a materially longer retention period — we will notify you by email or in the app before it takes effect, and where the law requires your consent we will ask for it rather than assume it. Continuing to use the service after a non-material change means the updated policy applies.
17Contact and complaints
Write to us first — most things are quicker to fix directly: , or by post to [LEGAL ENTITY NAME], [REGISTERED ADDRESS].
You also have the right to complain to a data protection supervisory authority. You may complain to the authority in the EU member state where you live, where you work, or where you believe an infringement occurred. Our lead supervisory authority is [LEAD SUPERVISORY AUTHORITY]. A list of EEA authorities is published by the European Data Protection Board. In the United Kingdom the authority is the Information Commissioner’s Office.
We would rather you told us first, but you are not required to, and nothing in this policy limits your right to go straight to a regulator.