Have You Been Flocked? Your License Plate May Already Be Searchable
You don’t have to commit a crime to enter the database.
You drive to work.
The grocery store.
Synagogue.
Your doctor’s office.
Your child’s school.
A restaurant.
Your attorney’s office.
You aren’t being followed.
You haven’t been pulled over.
You haven’t committed a crime.
But along the way, cameras mounted beside roads may photograph your vehicle, read your license plate, record where and when it was seen and temporarily place that observation into a searchable database.
That’s the technology behind Flock Safety.
And Americans are beginning to ask a very reasonable question:
Exactly how much should the government be able to learn about where our cars go?
What Exactly Is Flock?
Flock Safety operates automated license plate recognition cameras, commonly called ALPRs.
They’re different from ordinary security cameras.
Rather than simply recording hours of video, an ALPR is designed to identify vehicles passing the camera.
According to Flock, its system can capture:
License plate images.
Vehicle characteristics.
Date and time.
Camera location.
Flock says its ALPR product does not collect facial-recognition or biometric data.
So imagine your car passes one at:
8:13:42 AM.
The system might create a record essentially saying:
Plate ABC123 — observed here — at this time.
One observation sounds boring.
Thousands of cameras are where things become interesting.
One Camera Isn’t Really the Controversy
Imagine your local police department puts a camera at the entrance to town.
A stolen car drives past.
The plate matches a hot list.
Police receive an alert.
They recover the vehicle.
That’s an easy use case to understand.
Flock and law-enforcement agencies point to cases involving stolen vehicles, wanted suspects and missing people as examples of why ALPRs can be valuable.
But now expand the concept.
Flock reportedly has approximately:
120,000 cameras.
Across:
49 states.
Suddenly we’re not discussing a camera anymore.
We’re discussing a network.
And networks can answer questions individual cameras cannot.
The Camera Doesn’t Need to Follow You
This is the fascinating part.
Imagine cameras record your car at five different locations:
8:02 AM — near your neighborhood.
8:37 AM — near your office.
12:18 PM — across town.
5:41 PM — near a particular building.
6:27 PM — heading home.
No camera physically followed you.
But connect the observations and you’ve potentially reconstructed part of your day.
Do that repeatedly and patterns can emerge.
That’s why privacy advocates are concerned.
Tracking doesn’t necessarily require one camera watching you continuously.
A sufficiently large number of cameras can potentially reconstruct movement from individual observations.
“Have I Been Flocked?” Lets You Search Something Different
There’s now a website called Have I Been Flocked?
It has compiled public-record audit logs containing approximately:
241 million Flock searches
involving roughly:
4.7 million license plates.
You can enter your license plate and see whether it appears in the audit information they’ve collected.
But there’s an extremely important distinction:
A result does not mean police were investigating you.
The website is searching collected audit logs of searches performed in Flock systems.
And its records aren’t necessarily complete because they’re assembled from public-record requests to agencies.
So don’t enter your plate, see a result and immediately conclude:
“The government was following me.”
That’s not what the result establishes.
Can Regular Citizens Search Flock?
Generally, no.
There isn’t supposed to be a public Flock law-enforcement search engine where you can type:
“Show me everywhere ABC123 traveled.”
Flock says access is restricted to authorized users, searches are tied to individual accounts, and search activity is logged.
For law-enforcement systems, Flock says searches must have an investigative purpose and the general public cannot browse the database.
The new Have I Been Flocked site isn’t giving you direct access to Flock.
It’s aggregating audit records obtained through public-record requests.
That’s an important difference.
So Could Someone Abuse It?
That’s one of the biggest concerns.
Any database powerful enough to help find criminals is potentially powerful enough to be misused.
Imagine someone with access searching:
An ex-spouse.
A girlfriend.
A journalist.
A political opponent.
A neighbor.
Someone attending a protest.
Someone visiting a particular medical facility.
That’s why audit logs matter.
Flock says every search is associated with a specific account and recorded for review.
And amid mounting criticism, the company has announced additional safeguards scheduled to take effect around the beginning of 2027.
Among them are requirements for stronger search justification, mandatory auditing intended to detect abnormal searches, and the ability to restrict or suspend suspicious users.
Flock CEO Garrett Langley has publicly warned people abusing the system:
“You will get caught.”
That’s reassuring.
But privacy advocates ask a different question:
Should misuse merely be detectable—or should certain searches require stronger authorization before they happen?
That’s where this debate becomes much harder.
What If Flock Gets My License Plate Wrong?
This is a legitimate concern.
ALPR systems aren’t infallible.
Flock’s own License Plate Reader Policy acknowledges that plate translation can occasionally be incomplete or inaccurate and specifically instructs users to confirm the computer-generated translation before acting on an alert or search.
That safeguard matters enormously.
Imagine your plate is:
ABC1238
and a wanted vehicle is:
ABC1288.
Or perhaps the vehicle has:
The same color.
Similar body style.
Similar make.
A plate that is partially obscured.
An automated match should be an investigative lead—not unquestionable proof.
A computer alert should never magically become probable guilt.
Could an Innocent Person Actually Get Stopped?
Potentially, yes.
Automated plate-reader errors and mistaken vehicle identifications have contributed to wrongful or highly problematic stops in the broader ALPR ecosystem, and recent reporting on Flock has highlighted concerns involving misreads and improper use.
But that doesn’t mean:
“Flock sees your car and police will arrest you.”
The appropriate process is for an ALPR hit to be independently verified.
Look at the actual photograph.
Confirm the plate.
Confirm the vehicle.
Evaluate the circumstances.
Then act.
Technology should help an officer investigate.
It shouldn’t replace the officer’s judgment.
Do Law-Abiding Citizens Have Anything to Worry About?
This deserves a nuanced answer.
If you’re asking:
“Does Flock automatically consider me suspicious because it photographed my car?”
No.
The cameras routinely capture vehicles belonging to completely innocent people.
That’s inherent to how ALPR systems operate.
But if you’re asking:
“Does the existence of a searchable record of innocent people’s movements create legitimate privacy concerns?”
Absolutely.
Those are two completely different questions.
You can simultaneously believe:
Flock can help solve serious crimes.
and:
Large-scale searchable location databases need extremely strong safeguards.
Those positions aren’t contradictory.
“But I’m Not Doing Anything Wrong”
This is where privacy conversations often get stuck.
Someone says:
“I don’t care. I’m not a criminal.”
But privacy isn’t synonymous with hiding criminal behavior.
Imagine somebody could request a list showing every vehicle that visited:
An addiction-treatment facility.
A fertility clinic.
A religious institution.
A political meeting.
A divorce attorney.
A mental-health provider.
A domestic-violence shelter.
You don’t have to be doing anything illegal for location information to be sensitive.
Privacy is the ability to live an ordinary lawful life without every movement becoming somebody else’s searchable history.
Don’t We Have Constitutional Rights?
Yes—but the legal question surrounding vehicle movements is complicated.
Courts have long recognized that people generally have a reduced expectation of privacy in license plates displayed publicly on vehicles.
A police officer standing beside a road can obviously see your plate.
The harder question is what happens when technology changes the scale.
There’s a meaningful practical difference between:
An officer happened to see your car on Tuesday
and:
A database can potentially reconstruct weeks of your vehicle’s movements across many locations.
American courts have increasingly wrestled with this broader issue in other forms of location surveillance.
The constitutional debate isn’t simply:
“Can police see a license plate?”
Of course they can.
The emerging question is:
At what point does automated, aggregated surveillance become something fundamentally different?
That issue is far from settled everywhere.
Can You Opt Out?
For ordinary drivers passing public-facing ALPR cameras, generally there isn’t a personal Flock opt-out button that prevents your plate from being captured.
Your license plate is intentionally displayed on your vehicle and visible from public roads.
The “Do Not Sell” option in Flock’s website privacy policy concerns personal information governed by that privacy policy; it should not be confused with a universal ability to tell roadside ALPR cameras:
“Don’t photograph my vehicle.”
If your local government operates Flock cameras, the meaningful controls are largely civic:
Local ordinances.
Police policies.
Retention requirements.
Sharing restrictions.
Public-record laws.
City council decisions.
State legislation.
And ultimately whether your community chooses to deploy the technology at all.
More than 50 jurisdictions have reportedly ended or suspended Flock relationships amid the current controversy.
How Are These Cameras Even Powered?
This part is surprisingly clever.
Many Flock cameras don’t require traditional wired infrastructure.
Flock says its cameras can use:
Solar power.
Battery power.
And cellular LTE connections for communications.
That dramatically simplifies deployment.
No fiber connection is necessarily required.
No nearby network closet.
No trenching Ethernet down the road.
Put the camera on suitable infrastructure.
Give it power.
Connect through cellular service.
That architecture is part of what allows ALPR networks to expand relatively quickly.
Flock’s deployment documentation also supports installations using AC power and existing infrastructure such as utility, traffic-signal and light poles.
Does Flock Pay Cities to Use Their Poles?
I wouldn’t make that blanket claim.
Installation arrangements vary by municipality and contract.
Flock’s own deployment documentation explicitly contemplates cameras being mounted on existing utility, light and traffic-signal poles, as well as other suitable infrastructure.
But whether Flock pays a particular city for pole access, the city pays Flock under a camera contract, another entity owns the pole, or some other arrangement exists depends on the specific deployment.
That’s something residents can investigate through:
Contracts.
Procurement records.
City council minutes.
Public-record requests.
If you’re curious about cameras in your neighborhood, look at the actual municipal contract.
That’s far more useful than guessing.
What Happens to Your Data?
Currently, Flock says ALPR information is typically retained for 30 days, although customers and applicable laws can require different retention periods.
But that is changing.
Beginning January 1, Flock has announced plans to reduce its standard retention period from 30 days to seven days as part of its new safeguards.
That’s a major reduction.
Thirty days can provide a month-long movement history.
Seven days dramatically shrinks that window.
But critics still argue the fundamental concern remains:
Why should movements of people suspected of absolutely nothing enter a searchable system in the first place?
The Cybersecurity Question Nobody Should Ignore
Now imagine the database itself gets compromised.
This is something I think deserves more attention.
Whenever we create a centralized repository containing sensitive information, we create something attackers may want.
Vehicle movements can potentially reveal:
Where executives work.
Where employees live.
When facilities are occupied.
When someone travels.
Relationships between locations.
Operational routines.
Flock says its data is encrypted during transmission and storage and that criminal-justice information is stored in AWS GovCloud.
Those are important safeguards.
But cybersecurity professionals operate from a simple assumption:
Any valuable database deserves to be treated as a potential target.
The more powerful the database becomes, the more serious access control, logging, MFA, encryption, retention and incident response become.
There’s Another Risk: Legitimate Credentials
A database doesn’t need to be “hacked” in the Hollywood sense.
Someone could steal an authorized user’s credentials.
Phish an officer.
Compromise an endpoint.
Abuse an existing account.
Exploit excessive permissions.
That’s why every sensitive search should be attributable.
Who searched?
When?
Why?
What did they access?
What happened afterward?
Good cybersecurity isn’t merely keeping outsiders outside.
It’s making sure insiders—and compromised insider accounts—can’t operate invisibly.
This Is the Real Flock Debate
Flock presents an extraordinary example of the tradeoff technology continually forces society to confront.
Imagine a child is kidnapped.
Police know the suspect’s vehicle.
A camera detects it ten minutes later.
Nobody is going to complain that technology helped bring that child home.
Imagine instead that someone searches a journalist’s vehicle because they want to know who she’s meeting.
Same technology.
Very different use.
That’s why the question:
“Is Flock good or bad?”
isn’t particularly useful.
Ask better questions.
Who can search?
For what crimes?
With what justification?
For how long is information retained?
Who can share it?
Are searches audited?
Does a warrant ever become necessary?
What happens when someone abuses access?
How are false matches handled?
Can citizens see the policies governing their community?
And who gets to decide when surveillance has gone too far?
Convenience Changes the Scale of Surveillance
A police officer has always been able to stand on a public street and read your license plate.
That’s not new.
What’s new is making that observation:
Automatic.
Cheap.
Continuous.
Searchable.
Shareable.
And potentially available across enormous geographic areas.
Technology didn’t invent surveillance.
It removed much of the friction that used to limit it.
That’s the distinction worth debating.
Because friction sometimes protects privacy without anyone realizing it.
It used to require people, time and effort to reconstruct someone’s movements.
Now software can potentially do portions of that work in seconds.
Before You Decide Whether Flock Scares You, Ask One Question
Don’t ask:
“Do I trust the police?”
And don’t ask:
“Do I have anything to hide?”
Those oversimplify the issue.
Ask:
“What rules would I want governing this database if someone I didn’t trust eventually controlled it?”
That’s a much better cybersecurity question.
Because governments change.
Employees change.
Technology changes.
Databases get larger.
Capabilities expand.
And once surveillance infrastructure exists, removing it can be considerably harder than installing it.
Flock may help investigators solve crimes.
It may help recover stolen vehicles.
It may help find missing people.
Those are meaningful benefits.
But a network capable of producing extraordinarily useful investigative intelligence also deserves extraordinarily serious oversight.
The debate isn’t whether technology can watch us.
It clearly can.
The debate is who gets to look back—and under what rules.
70% of all cyber attacks target small businesses, I can help protect yours.
#Cybersecurity #DataPrivacy #Surveillance #DataProtection #Technology
You don’t need to commit a crime to enter a police-searchable database. You just need to drive past the camera.