The real power—and risk—of automated license plate readers is not a single snapshot; it’s the searchable, time-stamped trail that accumulates between capture and deletion, and the policy choices that determine how long that trail endures and who can preserve it.
The Short Version
- Flock’s ALPR systems store plate reads in the cloud and auto-delete them after a configurable retention window; the company shifted its recommended default from 30 days to 7 days, with case-based exceptions.
- Agencies, not just the vendor, set retention and access rules; some communities keep data longer under local policy or state law, and “Evidence Mode” lets investigators preserve specific records.
- Short retention does not eliminate privacy risk: networked cameras and cross-agency search can still reveal location patterns for ordinary drivers during the time data exists.
- Procurement and governance matter as much as technology; quiet local adoptions and vendor-run clouds can narrow public oversight over how data is used and for how long.
What Flock cameras actually collect and where it lives
Flock Safety’s systems are automated license plate readers (ALPRs): still-image cameras that capture a plate number and associated metadata—time, GPS location, and vehicle attributes like make, model, and color. The company’s own trust and legal materials describe a cloud-centric architecture: images and metadata are uploaded, encrypted, searchable by authorized users, and then automatically purged after a retention period. In earlier years, company language and city FAQs commonly referenced 30 days as the standard window; in 2026, Flock announced a recommended and default shift to seven days, paired with a mechanism to preserve records tied to an active investigation beyond the ordinary purge cycle.
Two points follow from the company’s statements. First, the system is not built for open-ended archiving by default; it is a rolling store that trims itself on a schedule. Second, “default” is not destiny. Flock emphasizes that customers control retention to match their law or policy, and it has offered extended retention up to one year when a jurisdiction requires it. That variation across deployments is the fulcrum of the oversight problem because it means the same technology can behave very differently from county to county.
Retention windows, evidence preservation, and the practical effect of “short”
Flock’s current materials describe automatic, permanent deletion once the designated period ends; the company presents the new seven-day default as a privacy guardrail that still supports the vast majority of investigations. At the same time, its “Evidence Mode” explicitly creates an evidentiary lane for selected records: if a plate read relates to a case number, it can be moved into cold storage and retained beyond the routine schedule. In other words, the ordinary store shrinks quickly; the exceptional store can persist as long as law or policy permits, with some documentation indicating up to a year in certain programs.
Does a shorter default erase the surveillance concern? Not necessarily. Network scale matters. With enough cameras in enough places, even seven days of linked plate reads can reveal sensitive patterns of life—homes visited nightly, religious services attended weekly, clinic drop-offs—all before deletion. That is why courts and policy bodies have focused not only on retention length but also on coverage density, use constraints, and cross-agency sharing: the same seven-day buffer can function as a thin trace in a small town or a rich dossier in a metro region stitched together by interagency search.
Who decides: local policy, vendor levers, and real-world variance
Across Flock’s own documentation and customer-facing FAQs, the company is clear: communities set retention in accordance with their policies and laws. Many have run at 30 days; Flock now recommends seven. But there are jurisdictions with statutory or policy mandates for much longer retention, and Flock markets configurations to meet those regimes. That elasticity—law-driven, policy-driven, or administrator-selected—means the practical privacy profile is a local decision as much as a vendor promise. The company’s evidence policy states that data is “permanently deleted and irretrievable” after the customer’s retention period ends; until that moment, however, recent reads and associated images remain accessible to authorized users, subject to whatever audit and approval flows the agency implements.
Governance gaps compound the risk. In Trempealeau County, for example, local reporting described an agreement for Flock cameras with a 30-day retention setting and controversy over whether the adoption occurred without a county board vote. Process disputes do not, by themselves, prove misuse, but they do signal how procurement shortcuts can sidestep the very deliberation where retention and preservation rules should be hammered out in public.
Access controls, misuse, and the limits of audit promises
ALPRs succeed or fail on access governance: who can search, under what standard, with what logging, and who reads those logs. Flock’s CEO has argued that detected abuses are rare—fewer than a dozen across eight years—and points to audit tooling meant to surface suspicious search patterns. Those claims suggest a direction of travel on oversight, but they also place heavy weight on internal controls and after-the-fact auditing in a vendor-controlled cloud. Even when default retention is brief, the window is wide enough for improper queries unless role-based controls, case-number requirements, and supervisory review are enforced consistently—not just available as features.
The broader ALPR ecosystem shows why policy matters more than brand. National surveys and litigation records document agencies that kept non-Flock plate data for months or years, sometimes indefinitely, illustrating how institutional appetite, storage rules, and public records posture, more than camera optics, determine long-run privacy impact. Shortening a default reduces exposure; it does not substitute for enforceable limits on purpose, sharing, and preservation.
Opacity in a vendor cloud and why oversight keeps lagging
Unlike a local records server, a vendor-operated cloud creates friction for public understanding: policies can be posted, but verifying actual practice—the exact retention setting, how often “Evidence Mode” is invoked, or whether deletion jobs ran on schedule—requires audit logs and lifecycle records typically outside routine public access. Even sympathetic communities and police chiefs often lack the in-house capacity to test whether configured rules and deletion guarantees match reality. That asymmetry is not unique to Flock, but it is intrinsic to subscription surveillance infrastructure, where procurement teams buy outcomes and dashboards rather than systems they can independently inspect.
When journalists or researchers surface misconfigurations or exposed devices, vendors often respond by distinguishing those endpoints from the secured cloud. That distinction can be technically valid and still underscore the same oversight deficit: if the public cannot see into the pipeline except when something fails visibly, confidence rests on vendor assertions and episodic audits rather than continuous, independent verification.
NO LICENSE PLATE READERS HERE: Tremonton-Garland Police have decided not to move forward with license plate recognition technology after testing it in the community.
Police say the camera was a Motorola system, not a Flock Safety camera, and was being tested on a trial basis to… pic.twitter.com/lG3lD86m5E
— Heidi Hatch KUTV (@tvheidihatch) August 25, 2026
What a credible guardrail regime looks like
The evidence supports three conclusions. First, the claim that Flock “keeps your location forever” overstates the company’s stated practice; it has long documented automatic deletion after a set period and now recommends seven days as the default, with permanent deletion at expiry. Second, the privacy risk is not nullified by a shorter default because investigators can preserve specific reads and because dense networks let even short-lived data reconstruct meaningful slices of people’s lives. Third, the determinant of harm is governance: retention settings, preservation criteria, audit rigor, and the transparency necessary to prove the rules are being followed.
Practical steps for communities and agencies
If a community chooses to deploy ALPRs, the safeguards should be codified up front and tested continuously. That means: a publicly adopted retention schedule short enough to minimize non-suspect tracking; strict, logged, case-linked preservation rules; mandatory case numbers on all queries; periodic, published deletion and audit reports; and an external audit that verifies both cloud lifecycle enforcement and the invocation rate of preservation features. Contract terms should guarantee agency access to raw audit logs and deletion attestations and specify sanctions for noncompliance. Anything less leaves the balance of power—and public trust—anchored to vendor blogs rather than verifiable practice.
Sources:
lifesitenews.com, flocksafety.com, thehill.com, foxbusiness.com, nypost.com, wxow.com, cnn.com



