Last updated: April 19, 2026

Privacy Policy

Flint is built on a simple principle: your financial data belongs to you, not us.

The short version

Flint has no servers of its own. Your income, expenses, and financial targets are stored in an encrypted database on your device and never transmitted anywhere. The on-device AI runs entirely offline — no data from your conversations with it leaves your phone.

The only outbound network calls the app makes are:

  1. Company logo lookups via the Brandfetch API — when you search for a brand name while adding an item.
  2. AI model downloads from Hugging Face — only when you explicitly tap “Download” in the Advisor screen.

That’s it. There is no Flint account, no cloud sync, no advertising identifier, and no analytics pipeline collecting your financial figures.


Information we collect

Information stored only on your device

When you use Flint you create financial data — income streams, recurring expenses, categories, and settings. This data is stored exclusively on your device in a SQLCipher-encrypted database. Flint has no backend and no mechanism to access this data remotely. If you uninstall the app, this data is deleted.

Information sent to third parties

Brandfetch (logo lookups)

When you search for a company or brand while adding a burn or income item, Flint queries the Brandfetch Brand Search API with the text you typed. This is used only to suggest a company logo — no financial figures, amounts, or personal information are included in this request. Logo lookups are optional; you can pick a generic icon instead and no request is made.

Brandfetch’s privacy policy is available at brandfetch.com.

Hugging Face (AI model downloads)

The Advisor feature requires a language model file to be downloaded to your device. When you initiate a download, Flint fetches the file from Hugging Face. This is a standard HTTPS file download; Hugging Face may log the request (IP address, user agent) per their own privacy policy. No financial data is transmitted.

Once downloaded, the model runs entirely on-device. No prompts, no responses, and none of your financial data are ever sent to Hugging Face or any other service.

Google Play

Flint is distributed through Google Play. Google may collect installation and in-app-purchase data as described in the Google Play privacy policy.


Analytics

Flint includes an optional anonymous usage analytics toggle — shown during onboarding and accessible in Settings. This feature is not currently active. No analytics SDK is present in the app and no usage data is collected regardless of the toggle’s state. If we introduce analytics in a future version, this policy will be updated and the toggle will control real data collection.


Data security

Your financial data is stored using SQLCipher, an AES-256 encrypted SQLite variant. The encryption key is generated on first launch and stored in the Android Keystore, which is hardware-backed on supported devices. This means the database file is unreadable without the device’s unlock credentials even if extracted.


Data retention and deletion

All data Flint creates lives on your device. To delete it, uninstall the app. There is no account to delete and no server-side data to request removal of.


Children

Flint is not directed at children under 13 and does not knowingly collect any information from children.


Changes to this policy

If we make material changes — particularly if we introduce server-side features or activate the analytics toggle — we will update the date at the top of this page and, where appropriate, notify users through the app.


Contact

Questions about this policy? Reach us at privacy@flintkit.app.