Flock Safety’s automated license-plate cameras are easy to describe and harder to understand.

A camera beside a road photographs passing vehicles. Software reads the license plate, records the time and location, and identifies characteristics such as the vehicle’s make, model, color and visible features. Police can later search the resulting database for a plate number or for a description of a vehicle seen near a crime.

That is the product. The more important question is what happens after the photograph is taken.

In August, Flock announced changes intended to address concerns about privacy and police misuse. The company said it would recommend a seven-day default retention period for new law-enforcement customers, require additional audit and search controls, and introduce automated lockouts when searches appear abnormal. Flock also said officers would need to provide more information about why they were searching the system. The company described the changes as additional guardrails for its platform.

The changes came as the technology faced increasing scrutiny in Alabama and elsewhere. WBRC reported in August that Calera Police required employees to complete in-person Flock training and created additional rules to limit misuse. The department’s chief said the technology needed stronger regulation after concerns arose about searches conducted outside the law or without proper authorization. Calera’s new safeguards were reported by WBRC.

Those are reasonable steps. They are also a useful reminder that the central issue with automated license-plate readers is not simply whether a camera can recognize a plate accurately.

The central issue is that ordinary travel becomes searchable data.

What the cameras actually collect

Automated license-plate recognition, or ALPR, is not facial recognition. Flock says its system does not collect biometric information or identify a driver’s face. It records a vehicle, its plate, the surrounding image, the camera location and the time of capture. Flock’s privacy materials describe the data it collects.

That distinction matters, but it does not make the system trivial.

A license plate is a persistent identifier attached to a moving object. If cameras are placed at enough intersections, neighborhood entrances, shopping centers and major roads, repeated observations can reveal where a vehicle has been and when it was there.

Flock’s own description of its search system illustrates the change from a traditional traffic camera. Investigators can search by time and location, but also by characteristics such as vehicle type, color, make or model. The system may be useful even when a plate is obscured or unreadable because investigators can search for a vehicle description instead. Flock explains these search capabilities in its frequently asked questions.

This is not a complete record of every person’s movements. Cameras miss vehicles. Plates are misread. A vehicle may be borrowed, sold or driven by someone other than its owner. A database entry is evidence that a vehicle appeared at a particular place, not proof of who was driving or what that person was doing.

But a system does not need to be perfect to become consequential. It only needs to produce enough plausible leads that investigators, courts and the public begin treating its output as a routine part of law enforcement.

The important change is not the camera

Flock’s cameras are only one part of the system. The more significant component is the searchable network behind them.

Sen. Josh Hawley, Republican of Missouri, said in an Aug. 26 letter opening a Senate investigation that Flock claims to operate more than 120,000 cameras in 49 states and process more than 20 billion vehicle scans each month. Those figures are company or company-reported network figures cited by Hawley, not an independent government census. Hawley’s letter raised questions about the scale and governance of the network.

The scale changes the nature of the tool.

A single camera may help answer a narrow question: Was a particular vehicle near a location at a particular time?

A connected network can answer a broader one: Where has this vehicle appeared across multiple jurisdictions, and what route might it have taken?

That is why the debate cannot be reduced to whether a local police department has a legitimate use for one camera. The relevant questions include whether data can be searched across agencies, who can authorize those searches, how long records are retained, whether outside agencies can request access and what happens when a local government ends its contract.

Flock says local agencies control user access, searches are logged, and data is generally deleted after a defined period. The company has also said that its customers control sharing settings. Those are company statements about the platform’s controls.

Those controls are important. They are not the same thing as public law.

A policy can be changed by a company. An agency can interpret a rule broadly. A supervisor can fail to review an audit log. An employee can enter a misleading reason for a search. A database can be technically secure and still be used in ways the public did not understand when the system was approved.

Seven days is better than 30. It is not a complete answer.

Flock’s announcement received attention because it proposed cutting the standard retention period from 30 days to seven for new law-enforcement customers. But the qualification matters: the change does not automatically apply to every existing customer. Flock’s follow-up explanation says private-sector customers retain the terms established for their accounts, while the seven-day default applies to new law-enforcement customers. The company outlined those distinctions in a separate explanation.

Retention is important because a shorter window means fewer historical movements are available for retrospective searches.

But retention is only one dimension of surveillance.

A seven-day database can still reveal a great deal about someone’s routines. It can still identify vehicles that repeatedly visit a workplace, a home, a medical facility, a place of worship or a political demonstration. It can still be shared while the data exists. And a shorter retention period does not answer whether agencies may use the system for purposes unrelated to the investigation that justified the search.

There is also a practical difference between a rule and an enforceable technical limit. If a system is configured to delete data after seven days, that is stronger than merely telling users they should not keep it. If administrators can export records, preserve images as evidence or move information into another system, the effective life of the data may be longer than the default setting suggests.

This is where local contracts and public oversight matter more than product brochures.

The company is adding guardrails because the network has become a governance problem

Flock says the new safeguards include required audit assistance, more detailed search reasons, offense filtering, evidence-preservation tools and proactive lockouts for unusual behavior. The company describes these measures as ways to make misuse more difficult and legitimate investigations easier to review. The company’s announcement lists the additional controls.

That is technically sensible. Good security systems do not rely on users behaving perfectly. They limit permissions, record activity, detect unusual behavior and require additional approval for sensitive actions.

But there is a limitation built into this approach: most of these safeguards operate inside the company’s platform.

The public generally cannot inspect the underlying software. Local residents may not know which agencies can search their area’s data. They may not know how many searches occurred, how often searches were shared or whether a department complied with its own policy. Even when audit records exist, they are useful only if someone is required to review them and consequences follow misuse.

The American Civil Liberties Union has argued that Flock’s proposed changes leave major questions unresolved, including data sharing, contractual control and the company’s role in determining how customer data can be accessed and used. The ACLU also warns that replacing Flock with another ALPR vendor would not by itself solve the broader problem. Those are the ACLU’s assessments of Flock’s policies and contracts, not neutral technical findings.

That criticism does not establish that every Flock search is unlawful or that the cameras never help solve crimes. It identifies a different issue: whether a private technology company should become the practical rule-maker for a nationwide system that records the movements of people who are not suspected of anything.

What Alabama communities should ask

Before renewing or expanding an ALPR contract, local officials should ask questions more specific than “Does it reduce crime?”

  • How many vehicles are scanned each month?
  • How many searches are conducted?
  • What percentage of searches produce a useful investigative lead?
  • How many searches involve people or vehicles not connected to a reported crime?
  • Can outside agencies search the data, and under what conditions?
  • Can federal agencies request access?
  • Who reviews search logs?
  • How quickly are suspicious searches investigated?
  • Can officers export images or search results?
  • What happens to exported data after the local contract ends?
  • Does the city control the raw data, or only access to a vendor-managed copy?
  • What independent evidence shows that the system improves public safety?

These are not anti-technology questions. They are the ordinary questions that should accompany any system capable of collecting information about an entire population.

Calera’s response—training every employee and adding local guardrails—is more serious than simply installing cameras and trusting users. But training is not the same as oversight, and oversight is not the same as a law that clearly defines what the system may do.

The decision communities are making

Flock’s technology may help investigators locate stolen vehicles, identify vehicles connected to crimes and reconstruct limited travel patterns. Those are real uses.

The technology also creates a record of routine movement at a scale that earlier police tools could not easily produce. That record is valuable precisely because most people captured in it have done nothing wrong.

The question is not whether a camera can photograph a license plate. It can.

The question is whether communities are comfortable turning ordinary travel into a privately managed, searchable infrastructure—and whether they have written rules strong enough to control that infrastructure when the company’s policies change, when agencies share data or when a legitimate tool is used for an illegitimate purpose.

Flock’s new safeguards may reduce some risks. They do not remove the need for public rules.

A system that watches everyone cannot be governed by good intentions alone.