Rideshare Dashcam Privacy: Flock Mobile ALPR Plan [2026]
A leaked Flock Safety sales deck, obtained through a Georgia public-records request, shows the company pitched a plan to turn up to 350,000 Uber, Lyft, and delivery vehicles into mobile license plate readers through a partnership with dashcam maker Nexar. Flock says the deal was never executed. The episode exposes a hard asymmetry for anyone who drives: you cannot opt out of being scanned, but you can absolutely control what your own dashcam publishes.

A sales deck that was never supposed to be public has put rideshare dashcam privacy at the center of the surveillance debate. In early August 2026, 404 Media reported on a Flock Safety presentation obtained through a Georgia public-records request by Dunwoody resident Jason Hunyar. The deck, pitched to the state's Office of the Attorney General, referenced a "Nexar partnership which includes 350k Uber/Lyft and other delivery service devices" — in plain terms, a plan to turn hundreds of thousands of working vehicles into a roaming automated license plate reader network.
Flock says the partnership was never executed, and no Uber or Lyft deal is known to exist. But the pitch itself is the story. It shows that a mobile ALPR fleet built on gig-economy vehicles was considered marketable to law enforcement, and it exposes an uncomfortable asymmetry for everyone who drives: you have essentially no control over being scanned, and total control over what your own camera publishes.
This guide covers what the leaked deck actually said, why a moving plate reader is a different threat model from a pole camera, what the law does and does not require, and the practical redaction workflow that rideshare drivers, delivery couriers, and dashcam creators should be running before any clip goes online.
What Exactly Did the Leaked Flock Presentation Propose?
The presentation proposed extending Flock's license plate reader coverage beyond fixed cameras by using dashcams already installed in gig-economy vehicles. According to 404 Media, the deck was authored by Flock and delivered to Georgia's Office of the Attorney General in August 2025, and it named dashcam manufacturer Nexar as the partner supplying roughly 350,000 devices across Uber, Lyft, and delivery fleets.
The technical hook was that Nexar's hardware already did the hard part. The presentation touted "clear license plate capture with Full HD video" — meaning the cameras drivers had bought for their own protection were already producing footage good enough to read plates reliably. No new hardware deployment, no permitting fights with city councils, no pole installation contracts. Just a data pipe from cameras that were already rolling.
Flock's response to 404 Media was direct: it "never executed the partnership with Nexar." Neither Uber, Lyft, nor Nexar responded to requests for comment. So the honest framing is that this was a plan, not a program. But a plan presented to a state attorney general's office is not a whiteboard sketch — it is a product concept mature enough to sell.
That distinction matters because the underlying economics have not changed. Millions of dashcams are already deployed, most of them capable of legible plate capture, and most of them owned by people whose contracts with a platform give them limited leverage over how their data is used. The pitch failed. The opportunity it identified did not go away.
Would Uber and Lyft Drivers or Passengers Have Known?
Probably not, and no law would have forced anyone to tell them. Reporting on the leaked deck notes that it remains unclear whether Uber, Lyft, or the drivers themselves would have known their vehicles were collecting data for law enforcement, and that passengers certainly would not have been told.
This is where most people's intuition about privacy law breaks down. Recording consent rules in the United States overwhelmingly govern audio captured inside the vehicle, not video captured of the public road ahead. A driver in an all-party consent state has to think carefully about the cabin microphone. Nobody has to think about the outward-facing lens, because a plate on a public street has historically been treated as exposed by default.
The result is a disclosure gap. The passenger consents (or does not) to being recorded inside the car. Nobody consents to the car functioning as a mobile sensor for a third-party surveillance vendor, because in the framework as written, there is no one whose consent is legally required.
Who Was Actually the Data Subject Here?
Three groups, none of whom were in the room:
- The driver, whose route history becomes a law enforcement product without additional compensation or contractual clarity.
- The passenger, whose pickup and dropoff points sit inside that route history — including trips to a clinic, a lawyer's office, or a partner's home.
- Every bystander vehicle the dashcam passed, which is the largest group by orders of magnitude and has no relationship with any of the companies involved.
Why Is a Moving License Plate Reader Different From a Pole Camera?
Because a fixed camera waits for you and a mobile one follows you. That single difference changes almost everything about what the resulting dataset can prove.

A pole-mounted ALPR is a tripwire on an arterial road. It records that your plate crossed one point at one time. Aggregate enough poles and you get a coarse travel graph, which is exactly what the Kansas lawsuit arguing that ALPR networks function as GPS trackers is built on.
A rideshare fleet is something else. Gig vehicles do not drive arterials — they drive destinations. They idle in apartment complex lots, hospital pickup lanes, bar districts at 2 a.m., suburban cul-de-sacs, and the parking areas of clinics, mosques, synagogues, methadone programs, and immigration attorneys. They do it at the precise hours humans actually move. Fixed ALPR infrastructure covers almost none of that, largely because installing a camera in a private lot requires someone's permission.
The Supreme Court described the stakes of that kind of dataset in Carpenter v. United States, holding that comprehensive location records provide "an intimate window into a person's life, revealing not only his particular movements, but through them his 'familial, political, professional, religious, and sexual associations'" (opinion PDF, supremecourt.gov). Carpenter concerned cell-site data, but the reasoning maps cleanly onto a plate scanner that rides along on other people's errands.
Scale compounds the problem. A city might host a few hundred fixed Flock cameras. A national rideshare fleet is a six-figure sensor count that reshuffles its geographic coverage every single day, which makes it far harder to map, audit, or avoid than a static installation. Our breakdown of Flock Safety cameras and your license plate privacy rights covers how limited the oversight already is for the stationary version.
Is Any of This Legal?
Mostly yes, under current US doctrine, which is precisely why privacy advocates are alarmed rather than reassured. Courts have generally held that a license plate displayed on a public road carries no reasonable expectation of privacy, and the third-party doctrine has long treated data handed to a private company as fair game.
The most recent significant test went the surveillance vendor's way. A federal judge in the Eastern District of Virginia granted summary judgment for the city of Norfolk in early 2026, dismissing a challenge to its 176-camera Flock network on the reasoning that the deployment was not extensive enough to constitute a Fourth Amendment search. The Institute for Justice, which backed the plaintiffs, has indicated it will appeal.
Note what that reasoning implies. "Not extensive enough" is a threshold argument, not a categorical one — it invites the question of what would be extensive enough. A network of 350,000 mobile cameras riding along the actual travel patterns of a metro area is a much stronger fact pattern for plaintiffs than 176 poles. The California ALPR class actions over data retention and sharing are testing an adjacent theory under state statute rather than the Fourth Amendment.
Meanwhile, officer-level abuse of existing ALPR systems is already documented, as covered in our reporting on Flock data misuse and police stalking cases. Widening the sensor network without fixing the audit layer widens the abuse surface too.
Can I Opt Out of Being Scanned?
No, and it is worth being blunt about that rather than selling false comfort. There is no ALPR opt-out registry, no deletion request form, and no notice requirement in most US states. Covering or obscuring your own plate is illegal essentially everywhere. A handful of states restrict retention periods or agency access, but nothing gives an individual driver a veto.
What you can control is the footage you generate and publish. That is not a consolation prize — for most people it is the larger exposure, because a Flock scan sits in a law-enforcement database with at least nominal access logging, while a YouTube upload sits in public, indexed, permanent, and scrapeable by anyone with a browser.
| Being scanned by ALPR | Footage you publish | |
|---|---|---|
| Your control | None | Complete |
| Who can access it | Agencies with database access | Anyone, forever |
| Reversibility | No deletion right | Blur before upload, or delete |
| Legal exposure to you | None | GDPR, platform TOS, defamation, harassment claims |
| Fix available today | No | Yes — automated redaction |
If I Drive Rideshare With a Dashcam, Am I Doing the Same Thing?
On a smaller scale, yes — and this is the part of the story most coverage skipped. If you drive for Uber, Lyft, DoorDash, or Instacart with a dashcam running, you are already operating a private, single-node version of the exact system the Flock deck proposed. Your camera is capturing legible plates, pedestrian faces, house numbers, and the interior of your cabin, all correlated with GPS timestamps.
That does not make you a surveillance vendor. It does give you a redaction duty the moment you share any of it. The distinction the law and the platforms both care about is collection versus publication. Recording for your own safety and insurance is broadly permitted. Broadcasting it is a separate act with separate rules.
The Future of Privacy Forum's guidance on privacy best practices for rideshare drivers using dashcams makes the same split: mount the camera visibly, post recording notices inside and on the vehicle, consider verbal notification, and "only share video and audio with third parties for relevant reasons that align with the original reason for recording."
The Three Things Your Dashcam Captures That Need Redaction
- Plates of uninvolved vehicles. Every car you pass is a data subject. In the EU and UK, a plate is personal data outright, and the household exemption evaporates the moment you publish. Our guide on why weak blur fails GDPR under forensic de-pixelation explains why a light Gaussian smear is not enough.
- Faces — pedestrians, other drivers, and your own passengers. Cabin-facing cameras are the highest-risk stream you own, because your passenger did not choose to appear in your content.
- Location-identifying detail. House numbers, business signage, and the pickup address visible in the frame together reconstruct exactly where a specific person was at a specific time.
Do I Have to Tell My Uber or Lyft Passengers I'm Recording?
Frequently yes, and you definitely cannot publish them. Uber's driver guidance states that you "may need to notify/tell riders if you're recording in or around your vehicle, based on local laws," and that "some locations require riders' consent for being recorded."
On publication the same guidance is unambiguous: do not post any images, audio, or videos of a person on social media. That is a platform rule with a deactivation penalty attached, and it applies regardless of whether your state's recording law would have allowed it. Drivers have lost accounts over viral passenger clips.
Roughly a dozen US states operate all-party consent regimes for audio recording, including California, Florida, Illinois, Massachusetts, Pennsylvania, and Washington. The practical baseline that satisfies most jurisdictions and both major platforms is: a visibly mounted camera, a recording notice sticker where a rider will see it before the door closes, and a brief verbal mention at pickup on longer trips.
Can I Post Dashcam Footage Online With Plates and Faces Visible?
Not safely, and increasingly not legally. Once footage leaves your device for a public audience, four separate regimes apply at once:
- Platform policy. Uber and Lyft both restrict publishing rider footage. YouTube and TikTok both accept privacy complaints from identifiable individuals and will remove content.
- Data protection law. Under GDPR and UK GDPR, publishing an identifiable face or plate makes you a controller processing personal data with no lawful basis. See our universal dashcam blurring guide for the jurisdiction-by-jurisdiction breakdown.
- Monetization rules. Ad-supported channels face additional scrutiny, covered in our guide to showing license plates in monetized videos.
- Civil exposure. Misidentifying a vehicle in a "bad driver" compilation has produced real harassment campaigns against innocent plate owners.
Motovloggers face the identical calculus, which we cover in is motovlogging legal and how to post dashcam videos online.
How to Blur License Plates and Faces in Dashcam Footage With BGBlur

The workflow takes three steps and runs entirely in your browser, with no software install on the phone or laptop you already use between rides.
Step 1: Upload Your Clip
Drag the dashcam file into BGBlur. Input formats include MP4, MOV, and M4V, which covers essentially every consumer dashcam export including Nexar, Viofo, BlackVue, 70mai, Garmin, and Thinkware. Processing happens client-side in the browser, and uploads are deleted within 24 hours with no permanent storage.
Step 2: Let AI Detection Find Plates and Faces
Choose license plate blur, face blur, or both. BGBlur's detection pass identifies every plate and face in the frame, then motion tracking locks onto each one across the timeline. This is the step that makes dashcam footage practical to redact at all — a car overtaking you crosses the frame in about two seconds, which is 60 frames of manual keyframing at 30fps, per vehicle, for every vehicle. Motion tracking collapses that into a single automated pass.
Step 3: Review and Export
Scrub the preview to confirm nothing was missed, adjust or add regions where a plate was partially occluded, then export. Output supports MP4, MOV, and WebM up to 4K, so a 4K dashcam file does not get downsampled on the way out.
✅ Motion-Tracked Redaction
Every detected plate and face keeps its blur as it moves, scales, and rotates through the frame. On dashcam footage — where the camera itself is moving and the subjects are moving in a different direction — this is the difference between a five-minute job and an afternoon of rotoscoping.
✅ Solid Blur Strength That Survives Enhancement
Light Gaussian blur can be partially reversed by upscaling models, which is why regulators increasingly treat weak pixelation as inadequate anonymization. Use the strongest available blur on plates specifically; those seven characters are the highest-value target in the frame.
✅ Batch Processing for Regular Uploaders
Business tier handles queued batches, which matters if you shoot daily and publish weekly. Our roundup of tools for dashcam content creators covers where redaction fits into a full production pipeline.
Who Should Be Most Concerned
Rideshare and delivery drivers: You run a camera for eight hours a day across hundreds of addresses. Archive originals for insurance, blur anything you post, and never publish cabin footage of a passenger.
Dashcam YouTubers and motovloggers: Your entire content format is other people's vehicles. Automated plate and face blur is a production step, not an optional one.
Fleet and logistics operators: You hold employee and third-party footage under a retention policy. A subject access request or a discovery order arrives redacted or it arrives as a liability.
Ordinary drivers: You cannot stop the scanning. You can stop adding to the public record every time you post a clip of a parking lot incident.
Journalists and advocates covering surveillance: Publishing evidence of ALPR deployments should not doxx the bystanders caught in your own footage.
Pro Tips for Dashcam Redaction
- Keep the original, always. Blur the publication copy only. Insurers and police need the unmodified file.
- Blur your own plate too if you post regularly — a consistent plate across dozens of videos maps your home, your schedule, and your routes.
- Do a final pass at 0.25x speed. Detection is strong but single-frame reflections and sharply angled plates are the usual misses.
- Redact the cabin stream separately. It has different rules and a much lower threshold for platform enforcement.
- Strip location metadata from the exported file before uploading — blurring the frame does not remove GPS EXIF from the container.
- Set a retention limit on raw footage. Deleting what you no longer need is the cheapest privacy control that exists.
The Bottom Line on Rideshare Dashcam Privacy
The Flock–Nexar pitch never became a product, but it correctly identified something true: the largest untapped surveillance network in the country is the one ordinary people already bought and mounted on their own windshields. Whether that network ever gets aggregated by a vendor is a policy fight playing out in courts from Norfolk to Wichita to California, and it will not be settled by anything you do this week.
What you can settle this week is your own output. Every clip you publish with a legible plate or an identifiable face is a permanent, indexed, publicly searchable data point about a person who never agreed to appear. That is the one node of the surveillance graph you fully own — and the one where a two-minute redaction pass genuinely closes the gap.
If you drive rideshare, run a dashcam channel, or just post the occasional parking lot incident, make automatic plate and face blur the last step before upload. BGBlur does it in the browser with motion tracking, no install, and 24-hour deletion, and it takes less time than writing the video description. You cannot opt out of being scanned. You can absolutely stop being the one doing the scanning.