This explains what Flame collects, why, who else sees it, and how to get rid of it. It describes the app as it actually works, not as a category of app in general.
Flame is operated by Flame Software, Gangnam-gu, Seoul, Republic of Korea. For privacy questions, or to exercise any right described here, write to bananatalkmain@gmail.com.
Flame is for adults. You must be 18 or over to create an account, and the app will not accept an age below 18.
| Data | Why |
|---|---|
| Email address and password | To create and secure your account. Passwords are stored only as a bcrypt hash — we cannot read yours. |
| Name, age, gender, who you want to meet | To build your profile and to decide who you are shown to. |
| Bio and interests | Shown on your profile; interests are also used for filtering. |
| Photos | Shown on your profile. Your main photo must contain a detectable face — see section 4. |
| Precise location | Distance-based matching. We store the coordinates your device reports and the city, state and country they resolve to. |
| Messages, stories and reports you send | To deliver them, and to investigate reports. |
Your gender and who you are looking to meet are both part of your profile, and together they may reveal something about your sexual orientation. Under UK and EU data protection law that is special category data. We process it only to run the matching that Flame exists to provide, and only because you chose to provide it when you created your profile. You can change either field at any time in Edit Profile, or delete your account entirely (section 8).
Your main photo must contain a detectable human face before your profile can go live. This is what makes Flame harder to use with a stolen or fake photo.
That check runs entirely on your phone. Flame uses Google ML Kit's on-device face detection: the image is analysed locally, and only the result — a face was found, or was not — decides whether the photo can be used. We do not run face recognition, we do not compute a faceprint or any biometric identifier, we do not compare your face against any database, and photos are not sent anywhere for this purpose.
Photos you keep on your profile are stored with DigitalOcean Spaces (section 5).
We use these providers to run the service. Each receives only what its job requires.
| Provider | What it receives | Where |
|---|---|---|
| DigitalOcean Spaces | Your profile photos and story media | United States (SFO3) |
| Mailgun | Your email address and the contents of emails we send you | United States or European Union, depending on configuration |
| Google — Sign in with Google | Confirms your identity if you sign in this way. Google tells us your email, name and account identifier. | United States |
| Google — Firebase Cloud Messaging | Device tokens, to deliver push notifications | United States |
| OpenAI | The text of an individual message, only when someone taps to translate it — see below | United States |
Flame can translate a message you have received into your own language. This is not automatic. When, and only when, you tap Translate on a message, the text of that one message is sent to OpenAI to be translated and the translation is returned to you. Messages you never translate are never sent. We do not send the sender's name, your identity or anything else about the conversation, and we cache the translation so the same message is not sent twice.
If you would rather no message text left our servers, do not use the translate button.
Flame's servers and database are hosted with DigitalOcean in the United States. If you use Flame from the UK, the EU or anywhere outside the US, your information is transferred there and to the providers in section 5. We rely on the European Commission's Standard Contractual Clauses, and the UK Addendum where it applies, for those transfers.
Settings → Delete account, inside the app. You can also email bananatalkmain@gmail.com and ask us to do it.
Deleting is immediate and cannot be undone. We erase your photos from storage, your messages and conversations, your matches, every like and pass you made and every one made about you, your stories, the reports you filed, and every signed-in session. We remove your name, bio, interests, location, and your Google, Apple or Facebook identifier. Other people stop carrying any block record naming you.
Your email address is released. We replace it with a random value rather than keeping it, which means two things: we no longer hold it, and you are free to sign up again later with the same address.
What remains is an anonymous record that the account existed, with no information identifying you. We keep it so that conversations other people had do not break, and we may keep a minimal record longer where we must — for example to enforce a ban after a serious safety report.
Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another service. Most of this is available directly in the app: Edit Profile changes your information, Settings changes what is visible, and Delete account erases it. For anything else, write to bananatalkmain@gmail.com and we will respond within one month.
If you are in the UK or EU and you think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first.
Passwords are stored as bcrypt hashes. Password reset codes are stored hashed, expire after fifteen minutes, are single use, and stop working after five wrong attempts. Traffic between the app and our servers is encrypted in transit. Changing your password signs out every other device.
No service can promise perfect security, and we will not pretend otherwise. If a breach affects you, we will tell you and the relevant regulator as the law requires.
If we change this policy we will update the date at the top, and we will tell you in the app before anything material takes effect.