Effective 11 August 2026 · Last updated 18 August 2026
You never have to sign in. No password, ever, and no account to create before you can play. Your flags live on your device, and the app works completely without a network. You can sign in with Google whenever you want your collection to follow you to another phone and survive losing this one — that is your choice, and if you make it we hold the email address and first name Google gives us, and show you which account your flags are attached to.
It keeps a copy of your review history on our server, so your collection can follow you to a new phone. While you play without an account that copy is attached to a random identifier and to nothing about you; once you sign in, it is attached to your account. You can delete it at any time, from inside the app or from this page, even after uninstalling. A copy with no account attached is deleted after twelve months without use, because there is nobody left to ask us.
Two other things leave your device: usage events that count what happens in the app, and crash reports when something goes wrong. Neither carries your name, your email, your location, or anything you typed. Once you sign in, those events are labelled with the same random identifier your collection uses — so we can tell that one person came back on two days rather than that two people came once. Never your email, never your name.
Your progress lives in your browser or app's own storage (IndexedDB) and never leaves it. That includes:
Deleting the app deletes all of it from your device. Some of it is also copied to our server — see the next section — but the copy on your device is the one the app actually reads: everything you see is computed there, and nothing you do waits for a network.
When your device has a connection, Flagory sends a copy of three things to a database we run on Supabase (EU region): the answers you have given (which flag, which mode, right or wrong, how long you took, and the day it happened), the flags you have mixed up with which, and a line per practice session (when it started and ended, how many questions, how many right). It is the same information the app already keeps on your device.
It is attached to a random identifier created on your device — not to you, and not to a login you had to make. Alongside it we store a two-word name the app assigns you, like Amber Falcon, drawn from a fixed list. You can replace that with a name you type, which is shown to people you play against and to nobody else. Nobody can type a name about you, and there is no other free-text field in Flagory — no chat, no comments, no profile.
This exists for one reason: so that a new phone can pick up where the old one left off. That happens by signing in with Google: the copy is attached to the account, and signing into that account on another device brings your history with you.
Your device also holds a key of its own, which it uses to prove to the server that it is still the same device if its sign-in ever lapses. You are never shown it and never asked for it — it is not a password and not something you can lose — and we store only a one-way hash of it. Earlier versions of Flagory showed this key as a recovery code and asked you to write it down; that is no longer how any of this works, and this page said otherwise for longer than it should have.
Your settings and your reminder times are not sent, and neither is anything about
the device itself. Your streak counter was on that list until we started
counting how long streaks last: the number of days rides with
session_complete in the usage events below, and nowhere else.
Flagory uses PostHog to count what happens in the app, so we can tell
whether it is working — whether people finish sessions, which modes get used, whether
reminders get opened. Events are tied to the same random identifier your
collection uses, not to you and not to a login you had to make. Data is processed on
PostHog's EU infrastructure (eu.i.posthog.com).
That identifier is what makes a profile, and one is built for you whether or not you sign in. It is how we can tell one person coming back four times from four people arriving once — which is the only question worth asking about an app meant to be used tomorrow as well as today. The honest word for it is pseudonymous rather than anonymous: it is a random string, it is never your name and never your email, and once you have signed in it is the same string on whichever phone you are holding.
These are all of the events the app sends. There are no others:
| Event | What rides with it |
|---|---|
app_open |
your language setting; the language your phone asks for, which is not always the same one; whether you are signed in — a yes or a no, never the account |
onboarding_step |
which step number |
session_start |
whether it was a Learn or free-play session |
review |
the mode, whether the answer was right, how many milliseconds it took |
session_complete |
how many questions, how many correct, XP earned, and how many days your streak now stands at |
flag_mastered, flag_fading |
which country code |
tier_unlocked |
which rank |
notif_scheduled, notif_opened |
which day a reminder was set for |
streak_freeze_used |
nothing |
signin_started |
which of the places you met the offer to sign in — the first screen, your collection, settings, or after you mastered a flag. Nothing about you |
signin_done |
whether it was a new account, a return, or two collections becoming one — and how many flags came with this phone. Never the account, never the email |
signin_failed |
one of two words: no connection, or it did not go through |
signed_out, account_deleted |
that it happened, and nothing else |
hoist_complete, hoist_shared |
your score out of ten — never which flags, and never who |
duel_played |
your score out of ten |
duel_created, duel_shared |
whether the challenge was sent to somebody you have played or left on a link — never who, and never the link itself, because a duel's link is its key and no event may ever carry one |
duel_opened |
whether Flagory was new to you, and whether you opened it in the app or a browser |
offer_shown, offer_taken |
nothing — whether the install offer appeared, and whether it was taken |
Every one of them also carries which version of Flagory you are running and which edition of the flag data it was built with — so that when something goes wrong, we can tell which build it went wrong on.
What you type is never sent. In Type It mode the app compares your answer on your device and sends only whether it was right.
When the app hits an unexpected error it sends the error itself and a short note about where it happened, through the same PostHog connection and the same anonymous identifier. Event details are deliberately excluded from crash reports, so nothing you typed can travel inside one.
PostHog can do considerably more than the above by default. Flagory turns those features off in code, and a test checks that they stay off, because some of them can otherwise be switched back on from a web dashboard without changing the app:
| Capability | Status |
|---|---|
| Session recording / replay of your screen | Off |
| Automatic capture of every tap and click | Off |
| Automatic page-view tracking | Off |
| Person profiles (building a profile of you) | On, and keyed to the same random identifier as your collection — never your email, never your name. It is built whether or not you sign in, because otherwise the only people we could count coming back would be the people who signed in. It holds the events in the table above and nothing else. |
| Performance and web-vitals capture | Off |
Flagory also does not collect, and has no way to collect:
Nothing is sold, and nothing is shared with anyone for their own purposes. PostHog processes the events above on our behalf and does nothing else with them.
Reminders are scheduled by your device, by the app, for the day your flags are actually due. They are not push notifications: no server sends them, and no server knows they exist. You can turn them off in Settings, or refuse the permission when it is asked for.
All 254 flags and every typeface ship inside the app. Once installed, Flagory needs no network connection to work — you can learn, finish a session, keep a streak and read your statistics with no connection at all, and a test in our build fails if that ever stops being true. The two places it connects to when it can are PostHog, for the events above, and Supabase, for the copy of your history.
Flagory is suitable for all ages and is rated accordingly. It requires no sign-in, has no chat and no comments, no ads and no purchases. The one thing anybody can write is the name shown beside their own score, which is checked against a blocklist and a fixed character set before the database will accept it. It does not knowingly collect personal information from anyone, children included.
If you are in the EU or the UK: the usage events and crash reports are processed on the basis of legitimate interest in understanding whether the app works. They are pseudonymous and we hold nothing that ties them to you, so we cannot single those out to hand over or delete on request.
The copy of your review history is different, and this changed with version 1.1. It is stored so your collection can follow you between devices — the purpose you use the feature for — and it is identified, so we can single it out: by the random identifier your device created, and by your Google account if you attached one. So you can obtain it, and you can have it deleted, and deleting it needs neither our involvement nor your waiting on us — it is a button in Settings, in the app or on the website.
What that copy holds: your answers, the sessions they belong to, the two-word name the app assigned you, and — only if you chose to type one — the name you type, which is shown to people you play against. If you signed in with Google, it is attached to the email address and first name Google gave us. If you never signed in, there is nothing in it that names you at all.
Deleting the app removes everything on your device. You can contact us with any question or complaint, or complain to your national data protection authority.
If this policy changes, the date at the top changes with it. Material changes — a new category of data, a new recipient — will be described in the app's release notes rather than slipped in quietly.
Questions, complaints, or anything about this policy: info@fxxking.de