01
Information We Collect
We collect information you provide directly to us when creating an account or using the Service. This includes:
- Account information such as your name and email address
- Configuration settings and preferences you save within the app
- Request collections and environment variables you choose to sync to the cloud
- Usage data to understand how the product is being used and improve it
We do not collect the content of your API requests unless you explicitly enable cloud sync and backup features.
02
How We Use Your Information
We use the information we collect solely to operate and improve the Service:
- Provide, maintain, and improve core functionality
- Authenticate your identity and manage your account
- Sync your collections across devices when you opt into cloud sync
- Communicate with you about product updates, security notices, and support
- Analyze aggregate usage trends to guide product decisions
We do not sell your data. We do not use your data to train AI models. We do not share your data with third parties except as described in this policy.
03
Local-First Architecture
Flint is designed with a local-first philosophy. By default, all your API requests, collections, environment variables, and credentials are stored on your machine only. Nothing leaves your device unless you explicitly enable cloud sync.
When you use the free tier, no request data touches our servers. Your API keys, headers, and payloads remain entirely local.
04
Third-Party Services
We use a limited set of third-party services to operate the platform:
- Supabase — authentication and cloud database for sync features
- AI providers — when you use AI features, requests are sent to the provider you select (Anthropic, OpenAI, Google). Your own API key is used, and provider terms apply.
We do not use advertising networks, analytics brokers, or data marketplaces.
05
Data Security
We implement industry-standard security measures to protect your data. All data in transit is encrypted using TLS. Data at rest in our cloud database is encrypted. We follow the principle of least privilege for internal data access.
No method of transmission or storage is 100% secure. If you discover a security vulnerability, please disclose it responsibly to security@flint.sh.
06
Your Rights
You have the right to access, correct, and delete your personal data at any time. You can:
- Export all your data from the account settings page
- Delete your account and all associated cloud data permanently
- Opt out of non-essential communications at any time
To exercise any of these rights, contact us at privacy@flint.sh.
07
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify registered users by email if the changes are material.
Continuing to use Flint after changes take effect constitutes acceptance of the revised policy.
08
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please reach out:
- Email: privacy@flint.sh
- Response time: within 5 business days