Skip to main content
NestGrid logoNestGrid

Did Flock's Platform Update Change Your ALPR Retention?

Flock's August 2026 platform update cut the ALPR retention default from 30 to 7 days and added audit requirements, but it did not reset retention windows already approved for existing customers. As of late August 2026, Flock's own policy and FAQ pages disagree on the number, so an administrator should verify retention against the contract or order form and the storage-deletion configuration, not Flock's web pages.

If you administer a Flock ALPR system, the immediate post-update question is not whether Flock changed its privacy language. It is narrower and more practical: did the August 2026 platform update change your actual retention setting?

As of August 25, 2026, the supported answer is: Flock changed the default and recommendation for license plate reader data retention from 30 days to 7 days, and it added several audit and access-control requirements. No source reviewed for this article supports the stronger claim that Flock silently reset already approved retention windows for existing customers.

Security administrator desk with contract, storage settings panel, audit log, and conflicting browser windows

The reason this needs a dated verification is that Flock’s own public pages do not line up cleanly. Flock’s August 13 announcement says the default is being cut from 30 days to 7 days and describes the 7-day setting as the recommended approach.[1] As observed on August 25, Flock’s FAQ, License Plate Reader Policy, and Compliance Tools pages also point to 7 days.[2][3][4] But the Flock Evidence Policy, updated August 12, still refers to a 30-day default, and the Trust Center data-privacy language still says license plate recognition data is retained for 30 days by default.[5][6]

That conflict is not proof that the system is deleting at the wrong interval. It is proof that a single public Flock page is not a reliable way to answer a board member, supervisor, resident, or public-records requester who asks what your effective ALPR retention window is today.

What changed in the August 13 update

Flock’s August 13, 2026 announcement made the 7-day retention window the new center of gravity for ALPR data. The company said it was reducing its default data-retention period from 30 days to 7 days and tied that change to its claim that more than 90% of searches that do not include a full license plate happen within a week.[1]

The same announcement described a wider package of controls: mandatory Audit Assistance for customers by the end of 2026, required case codes for all law-enforcement searches by the end of 2026, proactive account lockouts where misuse is detected, and multi-factor authentication for all Flock logins in August 2026.[1]

Update itemWhat Flock said changedAdministrative consequence
ALPR retention defaultDefault/recommendation moved from 30 days to 7 daysNew deployments and customers adopting the recommendation should be checked against the 7-day deletion configuration, not older 30-day public language
Audit AssistanceMandatory for customers by the end of 2026Audit review becomes part of the expected control environment rather than an optional extra
Case codesRequired for all law-enforcement searches by the end of 2026Searches should become easier to tie to a stated investigative purpose
Proactive lockoutsAccounts may be locked where misuse is detectedThe local admin may need to account for access interruptions during misuse review
MFAMandatory for all Flock logins in August 2026Login support and user enrollment become part of the update’s operational work

Evidence Mode is the important companion feature to the shorter default. Flock described it as a way to preserve specific ALPR records for active investigations while allowing the general rolling retention period to remain short. The company also said Evidence Mode would be free for customers that adopt the 7-day recommendation and that it was “rolling out in the coming weeks” as of August 13.[1]

That last phrase matters. Based on the available public materials, live availability of Evidence Mode for every customer on August 25 was not independently verified. An administrator should treat it as an announced rollout item unless they can confirm it inside their own tenant or through Flock support.

Calendar shrinking from a month to a week beside a locked approved contract

What did not change: approved retention authority

The easy mistake is to read “new default” as “everyone was changed.” The sources do not support that. Flock’s public explanation of data deletion says 7-day retention is the default and that data is hard deleted on a rolling basis after 7 days, but it also says retention may be increased or decreased on a case-by-case basis when required by a customer’s law or policy.[7]

Flock’s materials also distinguish customer control from vendor preference. In its customer-control explanation, Flock says customers own and control their Flock data, including retention choices, subject to their agreements and applicable rules.[8] For extended ALPR retention, Flock’s August 13 update says retention of up to one year requires approval from an elected official and/or governing body.[1]

So the administrative hierarchy is not complicated, even if the web pages are. Your contract or order form and applicable local law or policy come first. The storage-deletion configuration comes next. Audit evidence comes after that. Flock’s public FAQ and trust pages are useful context, but they are not the proof of what your system is currently configured to do.

For an HOA, neighborhood association, campus, or agency that has already had tense conversations about camera placement and false alerts, this distinction is not academic. A resident may hear “Flock changed to 7 days” and assume older data cannot exist. A board member may see a 30-day reference on a Flock page and assume nothing changed. Both assumptions are weaker than the local approval record and the configured deletion evidence. For broader board-level context on reliability concerns, see Are Flock Safety Cameras Reliable for Home Security?.

How to verify your effective retention window

Do not start with the public FAQ. Start with the documents that can survive a meeting packet, audit review, or records dispute.

  1. Pull the signed contract, order form, amendment, or governing-body approval that states the retention period or authorizes the Flock deployment.
  2. Check whether local law, procurement language, board policy, agency policy, or a later vote requires a shorter or longer window.
  3. Verify the storage-deletion configuration that enforces the window. For the 7-day default, Flock describes deletion as a rolling hard delete implemented through an AWS S3 lifecycle policy.[7]
  4. Confirm audit evidence. Flock says CloudTrail logs deletion actions and that the process is tested annually through SOC 2 Type II controls.[7]
  5. If your agency uses Flock’s Transparency Portal, check whether the published retention statement matches the approved and configured window. Flock says more than 1,500 agencies publish through the Transparency Portal.[4]
  6. If your organization is relying on Evidence Mode, verify whether it is actually enabled and available in your tenant, rather than assuming availability from the August 13 rollout language.
Process flow from contract to cloud storage lifecycle to audit checklist to verification badge

The public deletion explanation gives enough to know what evidence to ask for, but not enough to replace local verification. Flock says 7-day deletion is a rolling hard delete, that the AWS S3 lifecycle policy performs deletion, that AWS CloudTrail logs the action, and that the deletion process is covered by annual SOC 2 Type II testing.[7] Those are useful control points. They are not, by themselves, a screenshot of your customer-specific configuration.

Exact admin-portal directions are also a place to be careful. Publicly accessible, first-hand screenshots or an unauthenticated walkthrough of the relevant Flock admin setting were not available for this review; help.flocksafety.com requires authentication. Any instruction that claims a precise menu path inside admin.flocksafety.com should be treated as unverified unless it comes from your tenant, your support correspondence, or current Flock documentation available to your account.

A simple evidence packet for the next question

When someone asks whether the platform update changed your retention, the cleanest answer is usually a small packet, not a paragraph pasted from a vendor page.

  • The current contract, order form, amendment, or governing approval that authorizes the retention period.
  • The local policy or legal requirement, if it changes the vendor default.
  • A dated export, screenshot, support confirmation, or system record showing the configured deletion window.
  • Audit evidence or support documentation showing deletion logging and review controls.
  • A note that Flock’s public pages were inconsistent as of August 25, 2026, so they were not used as the controlling authority.

Why the optionality still matters

Civil-liberties groups noticed the same distinction administrators have to track: a shorter default is not the same thing as a mandatory cap. The Electronic Frontier Foundation called Flock’s reforms “Too Little, Too Late” and emphasized that the 7-day default is optional, with localities able to change it back.[9] The ACLU, quoted in The Hill, described the announcement as a “thinly veiled PR attempt.”[10]

Those reactions do not change the configuration question, but they explain why a sloppy answer is risky. If an agency or board tells the public “Flock is now 7 days,” while its approved setting remains 30 days or longer, it has not simplified the issue. It has created a new one.

The reverse is also true. If a customer adopted the 7-day recommendation and has the lifecycle and audit evidence to show it, older 30-day language on another Flock-owned page should not be treated as the operative rule. It is documentation lag unless your own approval record or configuration says otherwise.

The answer to “did they change our settings?”

Based on the available materials, Flock’s August 13 platform update changed the ALPR retention default and recommendation from 30 days to 7 days. It also added or announced stronger audit, case-code, lockout, MFA, and Evidence Mode controls. It did not, on the sources available as of August 25, silently reset retention periods that existing customers had already approved.

For administrators checking Flock ALPR retention settings after the platform update, the reliable answer is not sitting on whichever Flock web page happens to be current. It is in your approved retention authority, your configured deletion mechanism, and the audit trail that shows what the system did. Until Flock reconciles its own 7-day and 30-day public language, those pages are context, not proof of your effective ALPR retention window.

References

  1. Flock Updates Privacy, Accountability, Security, and Transparency Safeguards — Flock Safety — August 13, 2026 — https://www.flocksafety.com/blog/flock-guardrails-address-lpr-privacy-concerns-and-police-transparency
  2. Flock FAQ — Flock Safety — https://www.flocksafety.com/faq
  3. License Plate Reader Policy — Flock Safety — https://www.flocksafety.com/legal/lpr-policy
  4. Compliance Tools — Flock Safety — https://www.flocksafety.com/trust/compliance-tools
  5. Flock Evidence Policy — Flock Safety — August 12, 2026 — https://www.flocksafety.com/legal/flock-evidence-policy
  6. Trust Center Data Privacy — Flock Safety — https://www.flocksafety.com/trust/data-privacy
  7. How Flock Deletes License Plate Data: 7-day Retention — Flock Safety — https://www.flocksafety.com/blog/how-does-flock-handle-license-plate-data-deletion
  8. Customers Own and Control Their Flock Data — Flock Safety — https://www.flocksafety.com/blog/customers-own-and-control-their-flock-data
  9. Too Little, Too Late: Flock Admits Their Technology Needs Reforms — Electronic Frontier Foundation — https://www.eff.org/deeplinks/2026/08/too-little-too-late-flock-admits-their-technology-needs-reforms
  10. Flock cameras AI surveillance privacy updates — The Hill — https://thehill.com/policy/technology/6027324-flock-cameras-ai-surveillance-privacy-updates/

Resolution

Investigating — no confirmed fix yet.

Protocol background

For general spec/firmware mechanics, see Compatibility & Protocols.

No linked protocol reference for this update yet.

Still happening for you?

Let us know if this regression is still occurring on your setup -- it feeds the re-verification and demotion queue.

Blogarama - Blog Directory