Blog
Sold as Local Control
Talk to enough police officers running an automated license plate reader network and you get the same account, almost word for word. A handful of cameras, mounted at the roads into and out of town. A short retention window, thirty days is the number that comes up most. Vehicles only, no faces. If a plate is not on a hot list, nothing happens. If it is, every unit in the area gets the alert. And crucially: my department controls this, the data belongs to us, and once we delete it, it is gone.
Every part of that description can be accurate, and the officer describing it is very often being completely honest. That is what makes the gap worth writing down, because it is not a lie anyone is telling. It is a company’s marketing doing what marketing does, repeated in good faith by users nobody higher up ever corrected.
Where the data actually lives
Start with custody, the simplest fact to check and the one most at odds with “we control this.” A Flock camera holds an image only long enough to compress and transmit it. It uploads to Flock’s own cloud infrastructure almost immediately and is wiped from the device. From that point forward, the department is not holding the data. It is logging into a platform Flock built, governed by settings Flock configured, to view data sitting on Flock’s servers. “We own the data” is a line in the contract. Custody, the actual technical control of where the information sits and who can reach it, belongs to the vendor from nearly the first second.
The toggle that turned itself back on
The clearest evidence that local control is thinner than advertised is not theoretical. Flock’s platform includes a “national lookup” setting that, when enabled, lets any agency anywhere in the country query a city’s camera network. Cities that explicitly restricted that setting have found it re-enabled anyway, not through any decision their own department made, but through a vendor-side default nobody local was told about. Mountain View, California is the clean case study: the city had set access to California only, then discovered that more than 250 outside agencies had queried its cameras regardless, close to 600,000 searches in a single year, the overwhelming majority never approved by the city that paid for the system.
That is not a hypothetical about what could happen if the settings changed. It is the documented result of trusting the settings as given. More than fifty cities have since canceled their Flock contracts after audits turned up exactly this kind of unauthorized access: agencies with no relationship to the city querying data the city believed was locked down.
The contract changed under the people who signed it
Even the paperwork is not stable ground. Flock’s earlier terms of service stated plainly that the company would not sell customer data. That sentence is gone from the current terms. In its place is a clause granting Flock a perpetual license to keep using a city’s data to improve its own product, a right that survives even after the city cancels its contract. A city council that voted to approve this system under one set of promises is very likely operating, right now, under a materially different one, and most of them do not know it changed.
A black box to the badge, too
The distrust and pushback police face over these systems usually lands on the officer standing next to the cruiser, and that is aimed at the wrong target. The officer describing his eight cameras in good faith does not know who searched his city’s network last month, because that log lives on Flock’s platform, not his department’s. He does not know whether the sharing settings he was told were locked are the settings actually in effect, because Mountain View’s own department did not know either until an audit told them. He likely did not install the cameras and could not remove them himself if the city ended the contract tomorrow, because Flock’s own technicians handle both ends of that relationship, as they did in Denver. The public cannot see any of this either, and typically finds out the way Mountain View, Cleveland, and Evanston did: by accident, after the fact, through an audit or a reporter, rather than through anything the system was built to disclose on its own.
A department that cannot show its own residents what the system did, because the department itself cannot fully see what the system did, is not positioned to ask for anyone’s trust. It is asking for faith in a black box that neither side holds the key to. That is a solvable problem, and solving it would do more to rebuild trust in the officers using this technology than any amount of insisting the technology is fine.
The judgment call is already being automated away
Custody, sharing, and the contract are not the only places “we control this” is thinner than it sounds. The verification step is eroding too, the moment a human being is supposed to look at an automated flag and confirm it is real before anyone draws a weapon.
The Institute for Justice has documented at least twenty-six cases since 2018, most of them since 2023, of license plate cameras misreading a single character, an O for a 0, a 7 for a 2, and officers treating that misread as confirmed rather than as a lead to check. In Sherwood, Arkansas, a misread plate led officers to detain an innocent couple at gunpoint while their six-week-old baby sat alone in the back seat. In another case, a misread letter led to grandparents held at gunpoint in front of their three-year-old granddaughter. In another, a misread digit led to a man held at gunpoint, a police dog set on him, and hours in jail, all before anyone checked the actual plate against the actual car. Multiple residents are now suing over stops like these. The pattern in each case is the same: the algorithm’s flag was treated as the judgment, not as a prompt for one.
Flock’s own product roadmap points further in that direction, not back from it. The company’s drone-as-first-responder platform, launched in late 2025, lets an operator dispatch a drone to the location of an automated camera hit, a gunshot alert, or a 911 call with a single click, extending the automated trigger from a stationary camera to an airborne response. None of this requires a human being to have looked at the scene first. It requires a human being to have clicked the button the system presented.
None of this is an argument against the technology existing. It is a warning about which direction the trend is already running: toward less human verification standing between an automated flag and an armed response, not more, at exactly the moment cities are being told a human is still the one in charge.
What “we control this” actually means today
None of this requires believing an officer describing his eight cameras is dishonest. He is describing the system as it was sold to him, and as far as his own daily use goes, that description is probably accurate. The problem is that “my department controls this” was never really true, even in the best-run, most honestly operated department, because the architecture, the access settings, the retention defaults, and the legal terms governing all of it are decided by a private company whose business model rewards a bigger network and more searchable data, not a smaller one. A promise of local control that the vendor can quietly revise, override, or reinterpret is not local control. It is a courtesy, offered for as long as it is convenient to offer it.
What real local control would look like
None of this means local control is impossible, only that what departments have today is not it. A few concrete things would have to be true that are not true now.
The department, not Flock, would hold the copy that matters, either on its own storage or under a contract that gives the city an independent, verifiable audit trail proving Flock cannot read, retain, or repurpose the footage without the city’s logged authorization. A login to a vendor’s dashboard is not custody.
The department would also be able to install or remove its own cameras, not place a call to Flock and wait. Denver’s 110 cameras were put up by Flock’s own technicians and taken down by Flock’s own technicians; the city’s part in both was signing off, not doing the work. A department that cannot touch its own hardware does not control it, whatever the org chart says.
Sharing would default to off. National and statewide lookup would require the city to enable each outside agency one at a time, with the request and approval recorded in a log the city holds, not a company-wide toggle Flock’s own engineers can reset in a routine update.
Deletion would be verified, not promised. Thirty days stated in a policy is a marketing claim. Thirty days confirmed by an audit the city can run itself, or pay an outside party to run, is a fact.
The contract could not change under the city without the city agreeing again. Any change to retention, sharing, or Flock’s own rights over the data would need a new signature, not a quietly revised terms-of-service page nobody in the department ever rereads.
Canceling would mean the cameras come down and the data actually leaves, not a vendor that keeps recording anyway. That part is not hypothetical either. Cleveland’s council voted to end its contract, the contract expired, and Flock kept the cameras running and police kept using them regardless, until the council reversed itself and renewed rather than force the issue. When Evanston terminated its contract, Flock removed the cameras, then reinstalled them without the city’s permission, and did not finish taking the second round down until early the following year. Dayton and Evanston both resorted to the same fix while waiting for Flock to act: city workers pulled trash bags over the cameras themselves, because the contracts they had signed gave them no faster way to make a live camera stop recording. Denver is the fair counterexample: when its contract lapsed in March 2026, the city’s 110 cameras were actually decommissioned and removed, proof that clean removal is possible. It is just not something a city can currently assume it will get without a fight.
And the public would see more than a list of who searched the network. A real yearly accounting, published on a fixed schedule, would include every outside agency that queried the city’s cameras that year, the way Mountain View found out by accident and every city should be able to find out on purpose. It would include the total number of searches and what they were run for. It would include the false positive rate, how many alerts were misreads that should never have sent an officer to a car, a number the Institute for Justice has had to reconstruct case by case through lawsuits and news reports precisely because no department or vendor publishes it on its own. It would include how many alerts led to an actual arrest, how many led to a stop that found nothing, and how many turned out to be the wrong car entirely, the false-arrest count sitting next to the hit count instead of staying invisible. A department that can tell you how many cars a camera network correctly flagged can also tell you how many people it got wrong, and a system that will not publish the second number has not earned credit for the first. The department would see all of this first, automatically, not have to file a request to learn what happened on its own network.
An automated flag would require a human being to confirm the actual plate against the actual car before it justifies a felony stop, logged as a distinct verification step, not folded silently into the alert itself. A misread character would be a false alarm caught on the way to the car, not something a family in Sherwood, Arkansas finds out about at gunpoint.
None of that requires banning the technology or opposing the police using it well. It requires making “we control this” a standard a city can verify, instead of a sentence a vendor can quietly make untrue.
Sources
- Flock Safety FAQ
- Security Systems News: Flock Safety defends control of ALPR data
- Tech Times: Flock Safety Crosses 100,000 Cameras as 53 Cities Cancel Over Unauthorized Federal Data Access
- ACLU of Massachusetts: Flock Gives Law Enforcement All Over the Country Access to Your Location
- ACLU: Flock Can Share Driver-Surveillance Data Even When Police Departments Opt Out
- Linton News: Flock’s New Terms Remove “No-Sale” Promise On Customer Data and Assert “Perpetual Ownership”
- ACLU: Municipalities, Beware of Changes in Flock’s Legal Terms
- Flock Safety Terms and Conditions
- News 5 Cleveland: Flock cameras are still on in Cleveland, even though the contract expired
- 404 Media: Cities Are Covering Flock Cameras With Trash Bags
- 9News: Denver removes all 110 Flock license plate reader cameras as contract expires
- State of Surveillance: 30+ Cities Have Canceled Flock Safety Contracts
- Flock Safety: What To Expect When You Become A Flock Safety Customer
- Institute for Justice: Dozens of Innocent Motorists Have Been Pulled Over, Detained at Gunpoint, or Jailed Due to AI License Plate Camera Errors
- Carscoops: Cops Draw Guns On Arkansas Family After ALPR Camera Flags Wrong Plate
- Center for Democracy and Technology: AI in Policing, Automatic License Plate Readers
- DroneLife: From Police to Private Sector, Flock Safety Launches Drone-as-Security Platform
- Flock Safety: Flock Alpha, Drone as First Responder