Latent · revision 1.0

Latent privacy policy

What data the Latent Android app keeps locally, what its supporting service processes and the choices available to you.

Effective
7 August 2026
Last reviewed
7 August 2026

This policy describes data handled by Latent, an Android-first darkroom workflow application published by FlowBench. FlowBench is operated by Kye Michael Tonkin, ABN 49 476 860 632, in Australia. Contact hello@flowbench.com.au for privacy questions or complaints.

The public FlowBench website has a separate website privacy notice.

At a glance

Latent is local first. Your detailed darkroom working data remains on your device unless you deliberately export it or use hosted recovery. Latent does not contain advertising, sell personal information, build behavioural advertising profiles or use your data to train artificial-intelligence models.

Google sign-in is used for account identity, one-time trial eligibility, purchase restoration and hosted recovery. It is not used to publish your darkroom activity or make it social.

Data kept on your device

Latent stores user-created darkroom data locally, including information you enter or generate about:

  • film, chemistry, tanks, reels and other inventory;
  • development processes and stage timings;
  • planned, active and completed development runs;
  • notes, reviews, outcomes, preferences and application settings; and
  • locally held history and recovery state.

Manual export creates a portable file at your direction. You decide where that export is saved or sent. An exported file is outside FlowBench’s control once it leaves the application, so protect it as you would other personal records.

Removing the app may remove locally stored data unless Android, a device-transfer feature or a copy you made retains it. Hosted recovery is not a substitute for keeping manual exports that matter to you.

Account and identity data

When you sign in with Google, Latent and its supporting service process the Google account’s stable subject identifier and the email address, display name and profile image supplied by Google. Latent also processes authentication and session information needed to establish, refresh, revoke and protect your signed-in session. Google credentials and passwords are not provided to FlowBench.

Account data is used to identify the same Latent account across sessions, determine one-time trial eligibility, restore purchase access and associate hosted recovery data with the correct account.

Trial, entitlement and purchase data

Latent processes records needed to administer its explicit 720-hour trial and one-time Google Play purchase. These records can include account identifiers, trial start and expiry times, current access state, entitlement events, Google Play product and order references, purchase tokens, acknowledgement or verification state, and revocation or restoration events.

Google Play handles payment details. FlowBench does not receive your full card or bank-account number. Purchase tokens and related verification records are security-sensitive and should not be sent through ordinary support email.

Hosted recovery

When hosted recovery is used, Latent uploads encrypted recovery envelopes containing app data selected by the recovery process. The service retains three successful hosted-recovery days for an account, with older successful recovery points removed as newer ones are accepted.

Recovery payloads are protected with transport encryption in transit. Stored recovery envelopes are encrypted, and service-managed encryption keys are held separately in the service database. This design reduces exposure of stored payloads, but it is not end-to-end encryption: the service controls the key material required to process recovery. A compromise of the service and its keys could therefore expose recoverable content.

Hosted recovery is best effort. It is not live synchronisation, versioned archival storage or a promise of perpetual retention. It may not protect against loss of the hosting system itself. Use manual export for a copy you directly control.

Operational and security data

The Latent service necessarily processes network and security information such as IP address, request time, route, response status, user-agent or app-version information, rate-limit state and security events where logged. It also processes service health, database migration, recovery and purchase-verification events needed to operate and protect the service.

Production logs are bounded and are intended for operations, fault diagnosis, abuse prevention and security—not behavioural analytics.

Support and deletion correspondence

If you contact FlowBench, the message may include your email address, message, attachments and any technical detail you choose to provide. Account-deletion requests also create a controlled Google Workspace correspondence thread used to verify identity, record the request and confirm completion.

Do not email passwords, Google tokens, Google Play purchase tokens or recovery payloads unless FlowBench specifically requests an item through an approved secure process.

Service providers and disclosures

Latent may rely on the following providers for the stated purposes:

  • Google Identity for Google sign-in and account claims;
  • Google Play for app distribution, purchase processing, entitlement verification, refunds and revocations;
  • Expo / EAS Update for signed application builds and delivery of permitted application updates;
  • Google Workspace for privacy, support and deletion correspondence; and
  • Hetzner for the Latent service, database and hosted-recovery infrastructure.

Information is disclosed to these providers only as needed for their role, and may also be disclosed to professional advisers or authorities where authorised or required by law. Each provider controls parts of its own infrastructure and may process information under its own terms and in provider-controlled regions.

Processing locations

The primary Latent service and database are hosted on Hetzner infrastructure in Germany. Operational database backups are encrypted using Restic and kept under the deployed policy of 14 daily and 8 weekly snapshots. They are presently on the same host boundary and do not constitute off-host disaster recovery.

Google, Google Play, Expo/EAS Update and Google Workspace may process data in other provider-controlled regions. As a result, personal information may be handled outside Australia.

Security

Latent uses TLS for supported network traffic in transit. The service applies access controls, bounded logging, database separation and encrypted operational backups. Hosted recovery envelopes are encrypted at rest with service-managed key material as explained above.

No internet service or storage system can be guaranteed completely secure. Keep your device protected, install authentic updates and do not share sign-in, purchase or recovery credentials.

Retention and account deletion

Local darkroom data remains on your device until you delete it, clear application storage or remove the application, subject to copies created by Android or your own exports.

While an account is active, server-side identity, session, trial, entitlement, purchase and hosted-recovery records are kept as needed to provide and protect the service. Hosted recovery keeps three successful recovery days. Operational database backups age out under the 14-daily/8-weekly Restic policy; a deleted record may therefore remain in an encrypted backup until that snapshot expires and is not restored except as part of controlled disaster recovery.

You can request deletion in the app or through the public Latent account-deletion pathway. After identity verification, deletion removes the account profile, active sessions, reminders, account entitlement ledger, hosted-recovery key and hosted recovery points from the live service.

Latent preserves narrowly scoped, keyed records that an account has already used its one-time trial and, where applicable, already established purchase ownership. These trial-eligibility and purchase-ownership tombstones are retained for fraud prevention and entitlement integrity. They are not a usable profile, darkroom history or recovery payload. Purchase and financial records may also remain with Google Play under Google’s obligations. Deletion does not itself refund a purchase.

Support and deletion correspondence is retained only while reasonably needed to verify and complete the request, maintain an auditable outcome, resolve disputes or meet legal obligations.

Your choices and requests

You can choose whether to sign in and start the trial, whether to make a purchase, whether to use hosted recovery and when to create a manual export, subject to the app’s access model. You may request access to, correction of or deletion of personal information controlled by FlowBench by emailing hello@flowbench.com.au. FlowBench may verify your identity before acting on account information.

If you have a complaint, describe the concern and the account or interaction involved. FlowBench will consider it and respond through the contact channel. This policy does not limit rights or remedies that apply under law.

Changes to this policy

Material changes will be published at this stable, public URL. The effective and last-reviewed dates show when the policy changed or was checked against the product. Earlier text remains available through controlled repository history.

Revision history

Revision Date Change
1.0 7 August 2026 Initial consolidated Latent app and service privacy policy.