Privacy Policy
Effective July 3, 2026
Flint exists to get you warm introductions without giving up the thing that makes them possible — the private texture of your relationships. This policy explains what Flint collects, what never leaves your Mac, what reaches our servers, and the choices you have. We have tried to write it the way we write everything: plainly.
1. What this policy covers
This Privacy Policy applies to the Flint macOS application, the Flint service and MCP server available at api.tryflint.xyz, and the website at tryflint.xyz (together, "Flint" or the "Service"), operated by the Flint team ("we", "us"). It describes how we handle personal information when you use the Service.
Flint can be used from inside third-party AI assistants — such as Claude, ChatGPT, Cursor, VS Code, or Claude Code — via MCP. Those assistants are separate products: what you type into them, and what Flint returns into your conversation there, is also governed by that provider's own privacy policy (see Section 7).
2. The short version
- Flint works from metadata, never contents. Who you talk to, how often, how recently — never the words inside your messages, calls, or email. Local sources are analyzed on your Mac; if you connect Gmail, our servers read only email headers (Section 5).
- You decide what is shared. Introductions are double opt-in: nothing is sent to anyone until you approve it, and contact details are only exchanged once both sides agree.
- We do not sell your data. No advertising, no data brokers, no exceptions.
- Google user data is handled under Google's Limited Use policy. The full commitment is in Section 5.
3. Information we collect
Information you provide
- Account information. When you create an account or sign in with Google, we receive your name, email address, and profile photo.
- Profile information. Details you add about yourself — your role, company, what you are working on — and professional profile information (such as your LinkedIn profile) you choose to import.
- Introductions and messages. The asks you create (who you are looking to meet and why), your responses to introduction requests, and the messages you write and send through Flint.
Information processed on your Mac
The Flint macOS app builds your relationship graph from communication metadata in the sources you grant it access to: iMessage, WhatsApp, Phone & FaceTime call history, Contacts, Calendar, and Mail. For each source, Flint reads metadata only — participants, timestamps, frequency, and direction of contact — never the contents of messages, calls, or attachments. Access is controlled by macOS permissions (such as Full Disk Access) that you grant explicitly and can revoke at any time in System Settings.
Gmail, if you connect it
You can optionally connect one or more Gmail accounts as an additional source for your graph. Gmail is the one source processed on our servers rather than on your Mac, using Google's headers-only permission: Flint extracts who you email and when — never message bodies or attachments — and folds that into your relationship scores. The details are in Section 5.
Information about your contacts
Much of the relationship data Flint processes describes the people in your network, who may not use Flint themselves. What Flint holds about them is limited to what your own communication history shows — names, contact identifiers, and how often and how recently you were in touch — plus the public professional enrichment described below. Outside the double-opt-in introduction flow in Section 7 — which you start and approve — Flint never contacts the people in your graph and never reveals what it knows about them to other users. If someone who does not use Flint wants information about them removed, Section 10 explains how.
Information we derive
- Relationship data. From that metadata, Flint computes tie-strength scores and a map of your network — the names and contact identifiers of people you know and how warm each relationship is. Where derived relationship data is needed to answer your searches or route introduction requests, it syncs to our servers. The underlying message contents never do.
- Enrichment data. We may supplement contact profiles with publicly available professional information — such as current role, company, and public profile links — obtained from enrichment providers.
Information collected automatically
- Usage and device data. Basic records of how the Service is used — feature activity, error and crash reports, app version, device type, and IP address — used for security, debugging, and improving Flint.
4. How we use information
We use the information described above to:
- Provide the Service — build your relationship graph, rank warm paths, answer your searches, and route introduction requests.
- Facilitate the introductions you ask for, with consent from everyone involved.
- Keep the Service safe — authenticate you, and prevent fraud, spam, and abuse.
- Improve Flint — fix bugs, measure performance, and understand which features matter.
- Communicate with you about your account and the Service.
- Comply with legal obligations.
We do not sell personal information, and we do not use it for third-party advertising.
5. Google user data
If you sign in with Google or connect a Google account to Flint, we access Google user data through Google's APIs. This section describes exactly what we request and how it is handled.
What we request
- Basic profile information — your name, email address, and profile photo — used to create and secure your Flint account.
- Gmail metadata, only if you choose to connect a Gmail account. Flint requests Google's headers-only Gmail permission and uses it to extract relationship metadata — who you email, and when — on our servers, to build and refresh your relationship graph. This permission does not allow Flint to read the bodies of your messages or your attachments, and Flint uses it solely for the graph features described here.
Limited Use disclosure
Flint's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In line with that policy:
- We only use Google user data to provide and improve the user-facing features described above.
- We do not transfer Google user data to anyone else, except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets — and in that case only after obtaining your explicit prior consent.
- We do not use Google user data for advertising of any kind.
- We do not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models.
- No human reads this data, except with your explicit consent, when necessary for security or abuse investigations, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.
Revoking access
You can disconnect a Google account inside Flint at any time, or revoke Flint's access from your Google Account permissions page. When you disconnect a Gmail account, we delete the Google user data we hold for it and rebuild your graph without that source — people known only through that inbox drop out of your network. The only exception is records we are required to keep for legal or security reasons.
6. Where your data lives
Flint splits its work deliberately. Reading and analyzing your communication metadata happens locally on your Mac, behind macOS permissions you control. The contents of your iMessage, WhatsApp, phone, calendar, and mail activity are never uploaded to our servers. The one exception to local processing is Gmail, an optional cloud source whose headers-only metadata is processed on our servers, as described in Section 5.
Our servers store the smaller set of data needed to run the parts of Flint that cannot be local: your account and profile; your asks and introduction requests and their status; the messages you send through Flint; the derived relationship data needed to answer your searches and route introductions; and, if you connect Gmail, the credentials for that connection and the email metadata used to build your graph. To make search work, profile and ask text may be converted into vector embeddings by our infrastructure providers.
Our servers may be located in a different country from you. Where data-protection law requires it, we rely on appropriate safeguards for such cross-border transfers.
8. Retention and deletion
- We keep server-side information for as long as your account is active, or as needed to provide the Service.
- You can delete your account by contacting us at support@tryflint.xyz. We delete your information within 30 days, except records we must retain for legal, security, or fraud-prevention reasons.
- Data processed locally stays on your Mac. Revoking Flint's macOS permissions stops further reading immediately, and deleting the app removes its local database.
- Disconnecting a Google account triggers deletion of the associated Google user data, as described in Section 5.
9. Security
Data moving between your Mac, our servers, and your assistant is encrypted in transit using TLS. Server-side data is protected with access controls and the principle of least privilege. Local data sits behind macOS's own protections and the permissions you grant. No system is perfectly secure — if you find a vulnerability, please tell us at support@tryflint.xyz and we will act quickly.
10. Your rights and choices
You can ask us to access, correct, export, or delete the personal information we hold about you by writing to support@tryflint.xyz. Depending on where you live — for example under the GDPR, UK GDPR, or the California Consumer Privacy Act — you may have statutory rights to the same effect, and the right to complain to your local data-protection authority.
You are also always in control at the source:
- Grant Flint access to as many or as few macOS data sources as you like — every feature degrades gracefully.
- Revoke any macOS permission at any time in System Settings.
- Disconnect Google access at any time (Section 5).
- Decline any introduction request. Nothing is ever sent on your behalf without your approval.
If you do not use Flint but believe a Flint user's network includes information about you, write to support@tryflint.xyz and we will remove it.
11. Children
Flint is a professional networking tool that requires its users to be at least 18 years old, as set out in the Terms of Service. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us personal information, contact us and we will delete it.
12. Changes to this policy
When this policy changes, we will post the new version here and update the effective date above. If a change is material, we will notify you in the app or by email before it takes effect.
13. Contact
Questions about privacy at Flint go to support@tryflint.xyz. We read everything.
Looking for the rules of the road instead? Read the Terms of Service.