Skip to main content
NestGrid logoNestGrid

Do Flock Safety Camera Privacy Claims Hold Up?

Flock Safety reassures residents that its cameras use no facial recognition, feed no national database, and auto-delete footage — but its own contracts and audit logs tell a narrower story. This dated, claim-by-claim report marks each public privacy assurance Confirmed, Disputed, or Broken as of August 25, 2026, so homeowners and HOA members can judge a deployment on the record rather than the marketing.

Last updated

As of August 25, 2026, the homeowner question around Flock Safety cameras is no longer simply “is this surveillance?” It is more specific: which of the company’s privacy assurances still holds when you read the contracts, settings, audit logs, and documented reversals behind the sales language? Treated one by one, the answer is uneven. The facial-recognition assurance survives, but only inside a narrow product-spec box. Several other assurances do not.

Pole-mounted automatic license plate recognition camera watching a suburban neighborhood entrance at dusk

The August 25, 2026 claim grid

The status labels below mean exactly what they say: Confirmed means the available record supports the claim as stated, or supports it within a stated technical scope. Disputed means the claim may be partly true but depends on settings, exceptions, or later policy language a resident cannot safely assume. Broken means the available record directly contradicts the public assurance.

Flock privacy assuranceStatus as of Aug. 25, 2026What the record supportsWhat a homeowner or HOA should verify
“No facial recognition.”Confirmed, with scopeThe available product-spec record supports that Flock’s license-plate reader product is not facial recognition. That does not prove the system cannot be used to follow vehicles, map movement, or expose camera feeds through other controls. [1]Ask whether any deployed product includes person tracking, live-streaming, PTZ controls, or integrations beyond fixed ALPR.
“No national database.”BrokenA template contract grants Flock a worldwide, perpetual license to use, host, store, reproduce, modify, disclose, and distribute agency data; Flock also had a one-click “Enable National Lookup” setting, and one audit logged more than 450,000 national-database searches in 30 days in spring 2025. [2]Ask whether National Lookup is enabled, who can enable it, whether outside agencies can search local reads, and whether the local contract modifies Flock’s template license.
“We don’t share data with ICE.”Disputed to Broken, depending on wordingThe narrower claim that Flock had no direct federal contracts at the time is different from saying ICE-adjacent access did not happen. Reporting documented CBP and HSI pilot programs, a CEO admission that public statements were inaccurate, and local officers searching on ICE’s behalf. [3][4]Ask for direct federal contracts, pilot programs, indirect agency access, and audit logs showing searches requested by outside agencies.
“Data auto-deletes.”DisputedFlock announced a seven-day default retention period on Aug. 13, 2026, down from 30 days, plus Evidence Mode, required case codes, and Audit Assistance with proactive lockout. The ACLU still objects that seven days exceeds its recommended 48-hour limit, and Flock says about 90% of searches happen within a week. [1][5]Ask for the actual retention setting, Evidence Mode rules, who can extend retention, and whether the contract still allows a longer period.
“We do not do heat maps / tracking.”Broken where stated flatlyIn Oshkosh, Wisconsin, Flock’s CISO denied heat-map tracking to the city council in April 2026. The city approved the contract, learned the next day that the system does produce heat maps, and rescinded the agreement. [6]Ask for the exact map, heat-map, search, export, and analytic capabilities, not a general statement about “tracking.”
“Access is controlled.”DisputedControls exist, but documented examples show why settings and logs matter: an Oregon department approved searches with weak or junk reasons, and separate reporting found more than 60 Condor PTZ camera feeds and admin panels exposed on the open internet before Flock said the issue was fixed within 48 hours. [4][7]Ask who reviews searches, what case-code rules block, how often audits occur, and whether internet-exposed devices are independently tested.
“The system is accurate and solves crime.”Unverified for this privacy questionFlock has claimed fewer than nine human-reported errors per 1 million alerts and has promoted broad crime-solving figures, but those are company assertions rather than independent proof that the privacy tradeoff is justified. [1][8]Ask for local false-alert logs, local outcomes, independent evaluations, and a privacy analysis separate from arrest anecdotes.

Oshkosh shows what “narrower than advertised” looks like

The cleanest Flock privacy test is not a national argument. It is a municipal meeting in Oshkosh, Wisconsin, where a direct question received a direct answer that did not hold.

Exterior view of Oshkosh City Hall

In April 2026, Flock’s chief information security officer told the Oshkosh Common Council that the system did not create heat maps tracking people’s driving patterns. The council approved the contract. The city then learned the next day that the system does produce heat maps, and Oshkosh rescinded the agreement, which the ACLU described as the shortest-lived Flock contract on record. [6]

That episode matters because it separates two very different conversations. One conversation is whether a city may decide, after open debate, that license-plate readers are worth the privacy cost. The other is whether residents can rely on a vendor’s crisp assurance when the actual product capability, contract language, or administrative setting says something narrower. Oshkosh is about the second problem.

The same ACLU report also points to earlier false claims that Flock had partnered with the ACLU in Urbana, Illinois, in 2021, and to a 2026 LinkedIn post about New Mexico legislation that the ACLU says misrepresented its position. The ACLU is an advocacy organization, and its campaign posture should not be mistaken for neutral government fact-finding. But these particular claims are useful because they are tied to dated public statements and named local proceedings, not just a generalized objection to cameras. [6]

For residents trying to evaluate Flock Safety camera risks for smart home owners, the lesson is practical: do not ask whether a reassuring sentence sounds plausible. Ask which product function, contract clause, and audit field makes it true.

No facial recognition: confirmed, but only inside the product-spec box

The facial-recognition claim deserves cleaner treatment than it often gets. The available record supports the narrow statement that Flock’s core ALPR product reads plates rather than identifying faces. That is not the claim that breaks here. If a board member says, “Flock is not facial recognition,” that statement can be true within the product category.

But that sentence is often asked to carry more weight than it can bear. A system can avoid face identification and still create searchable location records tied to vehicles. It can avoid biometric face matching and still allow many agencies to query plate reads. It can avoid recognizing faces and still raise live-feed, admin-access, or map-analytics questions. The confirmed part is therefore narrow: no facial recognition is not the same as no tracking risk.

That distinction matters at neighborhood entrances. A Ring or other homeowner-owned camera is usually installed by one household and governed by that household’s settings; a Flock camera at an entrance is infrastructure approved on behalf of everyone who drives through. If you are comparing those two models, the better question is not whether one has a camera and the other has a camera. It is who chose it, who can search it, and how long the resulting records remain searchable. The broader consumer-camera contrast is covered in Flock cameras vs. home security privacy.

The national database claim breaks on settings, contracts, and logs

The “no national database” assurance is where the marketing phrase and the operating record separate most sharply. The ACLU of Massachusetts identified template contract language granting Flock a worldwide, perpetual license to use, host, store, reproduce, modify, disclose, and distribute agency data. It also documented a one-click “Enable National Lookup” setting and an audit log showing more than 450,000 national-database searches over 30 days in spring 2025. [2]

Map of the United States with camera icons connected to a central database icon

Those are not the same kind of evidence. The contract language shows legal permission. The setting shows product architecture. The audit log shows use. Together, they make it hard to treat “no national database” as a plain-language statement a resident would understand.

A vendor may argue that it does not maintain a single government-owned national database in the way residents imagine one. That narrower architecture argument does not answer the homeowner’s real question: can plate data collected at my neighborhood entrance be searched by agencies elsewhere, and can local officers search plate data collected elsewhere? If National Lookup exists, can be enabled, and has generated hundreds of thousands of searches in a month, the answer cannot be reduced to “no national database.” [2]

Even the size of the network should be handled carefully. Published camera counts vary by source and date: the ACLU of Massachusetts referred to roughly 90,000 cameras in July 2025, while the ACLU described more than 120,000 cameras in August 2026. Those figures should not be harmonized into one neat master count, but the direction is enough for a local vote: a neighborhood camera is not merely a local device if its data can participate in a broader lookup network. [2][5]

ICE sharing: “no direct federal contract” is not the same as no access

The immigration-enforcement claim requires more precision than either side’s slogan usually gives it. Reporting in 2026 described Flock’s position as having no current direct federal contracts. That narrower statement is materially different from saying Flock data cannot be used for immigration enforcement or ICE-adjacent searches. NPR reported that CBP and Homeland Security Investigations pilot programs had existed, that Flock’s CEO admitted public statements had “inadvertently provided inaccurate information,” and that local officers had performed searches on ICE’s behalf. [3]

That is why “we don’t share data with ICE” cannot be accepted without defining the verb “share.” Direct contract access, pilot-program access, a local officer running a query for a federal agency, and a shared lookup network are different mechanisms. A resident does not need to prove that all of them are currently happening in a given town to ask that each one be contractually blocked or logged.

The practical request is straightforward: show the agency-sharing settings, the list of agencies with access, the policy governing outside-agency requests, and the audit log fields that would reveal when a local officer searches for someone else. If a city or HOA cannot produce those records, the privacy assurance is not yet verified at the level residents actually need.

Auto-delete now means a seven-day default, Evidence Mode, and exceptions

Flock’s strongest recent move on retention is dated. On Aug. 13, 2026, the company announced privacy guardrails that include a seven-day default retention period, down from 30 days; Evidence Mode for preserving data tied to a case; mandatory Audit Assistance with proactive lockout; and required case codes. [1]

That does improve the old “auto-delete” claim, but it does not make the claim self-executing. A default is not the same as a fixed contractual maximum. Evidence Mode exists specifically to keep some material longer. Required case codes are only meaningful if weak entries are rejected or reviewed. Audit Assistance matters only if the reviewing party has authority to lock out abuse and if the local agency accepts that process in its contract.

The ACLU’s objection is also narrower than “no retention ever.” It argues that seven days is still too long and points to 48 hours as its recommended retention limit. That 48-hour figure should be understood as the ACLU’s civil-liberties standard, not as a neutral legal requirement. Flock, for its part, says about 90% of searches happen within a week, which helps explain why the company picked seven days and also why critics view that week as the most surveillance-relevant period. [5]

For a 2026 privacy audit, the retention question should be asked in dated form: is this deployment governed by the Aug. 13, 2026 guardrails, an older 30-day setting, or a separate contract term? The same discipline applies to other smart-home platforms; a dated settings audit is often more useful than a general privacy impression, as in a smart home assistant data privacy check.

Heat maps and tracking: ask about the function, not the label

Residential street grid with glowing heat trails showing vehicle movement patterns

After Oshkosh, a resident should not accept a flat denial about heat maps unless the answer identifies the actual feature being denied. Does the system generate density maps? Can it show vehicle travel patterns over time? Are those maps aggregate only, or can a user pivot from a map to plate-level records? Can an agency export the results? The word “tracking” is too slippery to settle those questions.

This is also where the debate can become artificially theatrical. A heat map is not automatically the same as a live tail on a named person. It can be aggregate, delayed, or constrained. But a vendor denial that leaves residents believing the feature does not exist is a different problem. Oshkosh rescinded because the capability did exist after the denial was made. [6]

A good local policy therefore should not say only “no tracking.” It should name which map functions are enabled, which users can access them, what time windows they cover, whether individual plate records can be reached from analytic views, and how those actions appear in an audit log.

Access controls are only as real as the logs someone reads

The August 2026 case-code requirement is a real control, but the reason for caring about it is already in the record. In Oregon, reporting cited by the ACLU described one department approving 111 searches with the reason “investigation” and 20 searches with the reason “hehehe” in September 2025. That is not a sophisticated hacking scenario. It is a reminder that a search-reason box does little if the system accepts junk, no supervisor checks it, or the audit process happens too late. [5]

There is also the separate security-control problem. In December 2025, 404 Media reported that more than 60 Flock Condor PTZ camera feeds and admin panels were live on the open internet and discoverable through Shodan; the outlet said it verified exposure on the ground in Bakersfield. Flock said the exposed feeds were fixed within 48 hours. [4]

PBS NewsHour later corroborated the controversy around exposed Flock camera access while covering the broader dispute over whether the cameras help solve crimes or invade privacy. [7]

That Condor episode should not be stretched into a claim that every Flock camera feed is exposed. It is a narrower warning: “controlled access” is not proven by saying logins exist. It is proven by network exposure testing, role limits, audit trails, lockout rules, and a record of what happens when a control fails. The same basic discipline applies to consumer cameras; if a device appears exposed or behaves unexpectedly, an IP camera lockdown protocol starts with evidence, not reassurance.

Crime-solving numbers do not answer the privacy audit

Flock’s performance claims should be kept in their own lane. The company has claimed fewer than nine human-reported errors per 1 million alerts and has promoted broad claims about its role in solving reported U.S. crime. Those are company-reported figures, not independent proof that a particular neighborhood deployment is accurate, necessary, or proportionate. [1][8]

This distinction matters in city and HOA meetings because a crime anecdote often arrives exactly when residents are asking a privacy-control question. A board can believe that plate readers sometimes help police and still require a separate answer on retention, outside-agency access, National Lookup, and audit review. Effectiveness, even if locally demonstrated, does not verify the privacy claims.

Cancellation figures should be handled the same way. GovTech reported in June 2026 that Flock was facing a surveillance backlash, while other outlets and groups have published differing tallies of canceled contracts. Those numbers should be attributed by source and date rather than blended into a single national backlash score. For a local resident, one documented reversal like Oshkosh is more useful than an inflated-looking national count. [8][6]

What to ask before a board or council makes the camera permanent

A Flock deployment should not be approved or renewed on bundled privacy language. Each assurance needs its own document, setting, and date. If the vendor says there is no facial recognition, ask which products are covered by that statement. If the city says there is no national database, ask whether National Lookup exists in the tenant, whether it is enabled, and who can change that setting. If someone says ICE cannot access the data, ask whether that excludes direct contracts only, or also outside-agency requests and local searches performed on a federal agency’s behalf.

  • Get the signed contract, not a slide deck, and compare it with any Flock template language about data licenses, disclosure, and agency sharing.
  • Ask for screenshots or administrator exports showing National Lookup, outside-agency access, retention period, Evidence Mode permissions, and case-code enforcement.
  • Require a sample audit log that shows who searched, what plate or list was searched, what reason was entered, which agency requested it, and who reviewed it.
  • Put the policy date in the motion or contract exhibit, especially if the deployment is relying on Flock’s Aug. 13, 2026 guardrails rather than older 30-day retention language.
  • Separate public-safety claims from privacy claims. Local crime outcomes may matter, but they do not prove that retention, sharing, or audit controls are adequate.

For residents already past the approval stage, the next move is not just another public comment. It is a records request, a contract comparison, and a vote-counting exercise. The practical steps for that are different from this claim audit and are better handled in a cancellation-focused guide such as how to cancel your HOA’s Flock Safety contract. If the concern is misuse after deployment, the examples in Flock camera misuse and home security privacy are the more direct next stop.

The bottom line as of August 25, 2026 is not that every Flock claim is false. It is that the claims cannot be accepted as one package. “No facial recognition” remains confirmed only within its narrow technical scope. “No national database,” “we don’t share data with ICE,” “data auto-deletes,” “no heat maps,” and “controlled access” all require the specific contract terms, enabled settings, retention rules, audit process, Evidence Mode limits, case-code enforcement, and policy date that make the words true.

References

  1. Flock Guardrails Address LPR Privacy Concerns and Police Transparency — Flock Safety, Aug. 13, 2026.
  2. Flock gives law enforcement all over the country access to your location — ACLU of Massachusetts, Oct. 7, 2025.
  3. Flock contracts canceled over immigration surveillance concerns — NPR, Feb. 17, 2026.
  4. Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves — 404 Media, Dec. 22, 2025.
  5. Despite New Updates, Flock’s Creepy Cameras Remain Major Civil Liberties Threat — ACLU, Aug. 13, 2026.
  6. Flock Safety Credibility Lost as It Repeatedly Lies to City Councils, Police Departments, and Public Across the Country — ACLU, July 2, 2026.
  7. Police say Flock cameras help solve crimes. But critics call them an invasion of privacy — PBS NewsHour, July 15, 2026.
  8. Why Flock Safety Finds Itself in a Surveillance Backlash — GovTech, June 4, 2026.

Known issues with this device / protocol

Spec-version history

For active regressions on this protocol, see Update Watch.

No linked Update Watch entries yet.

Report / Feedback

Flag a stale or incorrect compatibility claim -- it feeds the re-verification queue.

Blogarama - Blog Directory