Last updated: July 10, 2026
Flit. ("Flit", "we", "us", or "our") operates the Flit. mobile application and the website at flitcard.online (together, the "Service") — a platform for creating and sharing digital greeting cards and celebration invitations ("cards"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to this policy.
Contact: orra.system.io@gmail.com
Account information. When you sign in with Google, Sign in with Apple, or email and password, we collect your email address, display name, profile photo URL (if provided by the sign-in provider), and an authentication identifier.
Content you create. When you make a card we store the content you enter, such as the title, message, event details (e.g., date, venue), the chosen template and theme, the visibility setting (private or public), the recipient email address you provide, and — if you add photos — the Google Drive folder link and the specific image file identifiers you select for each section.
We do not host or store your photos or videos. Images stay in your own Google Drive. Each time a card is viewed, the images are loaded directly from the public Google Drive folder you provided.
Device and technical data. We collect your push notification token (Firebase Cloud Messaging), app version, device type and operating system, IP address, and basic log data.
Usage data. We collect limited interaction data such as card view counts and timestamps (e.g., when a card was created or first opened). We also use Google Analytics for Firebase to collect usage statistics — such as screens or pages visited, session and device information, and approximate location derived from your IP address — to understand how the Service is used.
To show photos on a card, you provide a link to a Google Drive folder that you have set to "Anyone with the link." We use the Google Drive API to read the list of image files in that folder and display them on your card. We access only the public folder link you provide — we do not request access to your private Google Drive, and we do not copy or store the images. You control what is shared by managing your folder's sharing permissions in Google Drive. Anything you place in a folder linked to a public card may be viewable by anyone who has the card link.
With your permission, we send push notifications through Firebase Cloud Messaging (for example, when you receive a card). You can turn notifications off at any time in your device settings. In this version of the Service we do not send marketing emails.
We use the following service providers to operate the Service, which process data on our behalf:
We do not sell your personal information. We may disclose information if required by law or to protect the rights, safety, and security of our users and the Service.
Published cards automatically expire 7 days after publishing and become inaccessible; expired cards are deleted after a short grace period. Account information is retained until you delete your account. You may request deletion of your account and associated data at any time (see Section 8).
You can access, correct, or delete your information, and delete your account, from within the app (Settings → Delete Account) or by emailing us at orra.system.io@gmail.com. Depending on where you live (for example, the EEA/UK under the GDPR, or California under the CCPA/CPRA), you may have additional rights, including the right to access, port, restrict, or object to certain processing. To exercise any right, contact us at the email above; we will respond as required by applicable law.
The Service is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children under that age. If you believe a child has provided us personal information, please contact us and we will delete it.
We use reasonable administrative, technical, and organizational measures to protect your information. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Your information may be processed and stored on servers operated by Google/Firebase that are located in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide notice within the app.
If you have questions or requests regarding this Privacy Policy or your data, contact us at orra.system.io@gmail.com.