Privacy Policy
Last updated 25 August 2026
Flock is a Mac app for running coding agents, built local-first. This policy explains what we collect, what we deliberately do not, and the choices you have.
1. Who we are
Flock Labs ("we", "us") is the data controller for the personal data described below. For any privacy question, or to exercise your rights, contact us at contact@theflock.sh.
2. What we collect
Account and identity
When you create a flock ID, you sign in with Google. We receive your email address and name from Google, and you choose a public handle. We store your profile (handle, email, referral count, and any teams you belong to) so friends can find you and so your presence works across devices.
Billing
There is none. flock is free and open source, we take no payment, and we hold no payment data.
Product and technical data
We keep basic usage counters tied to your account. When you visit this website or download the app, our host and CDN process standard technical data such as IP address and user agent to serve the request and keep the service secure.
Website analytics
This website uses Vercel Web Analytics to count page views and referrers, so we can tell which pages are useful. It sets no cookies, stores no identifier on your device, and does not follow you to other sites. Each visit is turned into a short-lived hash that we cannot reverse into a person, and the reports we see are counts.
Separately, when you download the app we record one row: the time, the version you were sent, the site you arrived from, and the country the request came from. We do this because knowing how many people download flock, and where they heard about it, is the one number that tells us whether any of this is working. That row holds no IP address, no device or browser identifier, and nothing that lets us pick you out of the count or link one download to another.
Both of these run on the website only. The app does not carry analytics of any kind.
3. What stays on your machine
By design, most of what you do in flock never reaches us:
- Your code and repositories. Agents run locally against your own checkouts.
- Prompts and agent output. The conversation between you and your agents stays local.
- The knowledge graph. It runs in a Postgres container on your own machine. Nothing leaves.
- Voice. Dictation is transcribed on-device with a local model. Audio is not uploaded.
- Model keys. Your Claude, OpenCode, and Codex credentials are used by the app on your machine and passed through to those providers. We do not store them on our servers.
4. Shared graph
A team can point flock at a shared knowledge graph it hosts itself. That graph holds the notes your agents write (decisions, attempts, file claims), and it lives wherever your team runs it: on your own infrastructure, under your own control. We do not host it and cannot read it.
5. Model providers
Flock orchestrates coding agents that run on providers you choose and authenticate yourself, such as Anthropic (Claude), OpenAI (Codex), and OpenCode. When you use those agents, your prompts and code are sent directly from your machine to that provider under your own account and their terms and privacy policy. Flock is not a party to that exchange.
6. How we use your data
- To create and run your account and flock ID.
- To provide collaboration features you initiate (friends, shared sessions).
- To provide support and respond to you.
- To keep the service secure and prevent abuse.
- To meet our legal obligations.
7. Legal bases
Where the GDPR applies, we rely on: performance of a contract (running your account), legitimate interests (securing the service, understanding aggregate usage), consent (where we ask for it, which you may withdraw), and legal obligation (where the law requires it).
8. Who we share with
We use a small set of processors to run flock:
- Google: sign-in.
- Supabase: account database and authentication backend.
- Vercel: website and serverless hosting, and the cookieless website analytics described in section 2.
- Discord: optional community (only if you join).
We do not sell your personal data. We share it only with these providers to run the service, or where required by law.
9. International transfers
Some providers process data outside your country. Where that happens, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.
10. Retention
We keep account data for as long as your account is active. If you close your account, we delete or anonymise your personal data within a reasonable period, except where we must keep it to meet a legal obligation.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing. To exercise any of these, email contact@theflock.sh. You also have the right to complain to your local data protection authority.
12. Security
We use encryption in transit, scoped access controls, and reputable infrastructure providers. No system is perfectly secure, but the local-first design means the most sensitive material, your code and your agent activity, never leaves your machine in the first place.
13. Children
Flock is not directed to children and is not intended for anyone under 16. We do not knowingly collect data from children.
14. Changes
We may update this policy as flock evolves. We will change the date at the top and, for material changes, give notice in the app or by email.
15. Contact
Questions about this policy or your data: contact@theflock.sh.