//Legal
Privacy Policy
Last updated 18 August 2026. This page is https://flarehq.dev/privacy. It covers the website, hosted scans, and accounts. The flare-deep CLI and local MCP server do not send us source unless you call our API.
Who we are
Flare (flarehq.dev) is the controller of personal data described here. To ask a privacy question, request an export, or delete data we still hold after you use the dashboard, use the contact form. We do not publish a support email.
What we collect
Anonymous URL scans
- The URL and host you asked us to scan.
- Findings produced from that scan, shown to you in the browser. We do not keep anonymous scans as account history.
- A short-lived rate-limit counter keyed to a one-way hash of your network address (not the address itself) and the host, so each website gets one free scan per network. That hash is not tied to an account.
When you sign in
- Email address, and GitHub identity if you use GitHub sign-in.
- Scan history, findings, grades, and projects for sites you track.
- Billing state (plan, Stripe customer id). Card numbers are handled by Stripe; we never see the full card.
- Optional Pro data you choose to connect: repository metadata, encrypted database connection strings, verified domains, Guard events, checklist ticks, and knowledge notes you paste into the dashboard.
- Messages you send through the contact or ambassador forms.
This website
Page views via Vercel Web Analytics. See Website analytics.
What we do not collect
- Your application source code, except snippets that appear in a finding you asked us to store.
- Database rows from a connected database. Schema and policy checks are read-only.
- The full value of a detected credential. We store a redacted fragment so you can recognise it. Live-key checks send the secret only to the provider that issued it (OpenAI, Anthropic, Stripe, GitHub, Slack, Google, Supabase, and similar identity endpoints), on a non-billable read. We do not log the secret.
- Advertising cookies or cross-site trackers. We do not sell personal data.
How we use it
- To run scans and show you reports, history, and Pro features you turn on.
- To enforce free-tier limits, rate limits, and acceptable use.
- To bill through Stripe and handle cancels, invoices, and taxes.
- To answer contact-form messages and ambassador applications.
- To produce anonymised aggregate statistics (for example, how often a check fires). Those are never tied to you or a named host in public.
- If you are on Pro and we have an AI provider configured, to write plain-English summaries or extra recon. That uses the finding text, not your source tree.
Processors
We use other companies to run the product. They process data on our instructions:
- Vercel — hosting, serverless functions, cron, and Web Analytics.
- Supabase — authentication and the database that stores accounts, scans, and connections.
- Stripe — subscriptions, invoices, and the billing portal.
- Anthropic — optional model calls for report wording on Pro, when that feature is enabled.
Connection strings are encrypted at rest before they are stored. You can revoke a connection at any time from the dashboard.
Website analytics
Vercel Web Analytics counts page views. It sets no cookies and builds no cross-site identifier. It records the page, referrer, country, and device or browser type. A daily-rotated hash derived from the request is used to tell visitors apart within a day; the IP used to compute that hash is not stored. Analytics does not run on the CLI, the scan API, or MCP, only on pages loaded in a browser. A content blocker stops it; the product does not depend on it.
Sharing and legal requests
We do not sell your data. We may share it with the processors above, or if the law requires it, or to prevent abuse of the scanner (for example notifying an operator if someone is using Flare against infrastructure they have no right to test). Shared report links only work if you create them; they can be unpublished.
Retention
- Anonymous scans: not kept as history; rate-limit hashes expire.
- Account data: until you delete the account or we close it under the terms.
- Contact-form messages: until we have handled them, then deleted or minimised.
- Stripe records: whatever Stripe must keep for payments and tax.
Your rights
Depending on where you live (including Australia’s Privacy Act and, if it applies, GDPR or similar), you can ask us to access, correct, or delete personal data, or to export a copy. Deleting the account in the dashboard is the fastest path. For anything that does not cover, use the privacy contact form. We may need enough detail to find your records (the email on the account).
If a scan of an app you operate exists and you want it removed, tell us via the security contact form from an address at that domain. You do not need an account.
Children
Flare is not directed at children under 16. We do not knowingly collect their data. If you believe we have, use the contact form and we will delete it.
Changes
We will date material updates on this page. Continued use after a change is acceptance of the new policy.
Contact
Contact form, topic “privacy” (https://flarehq.dev/contact?topic=privacy). Terms: https://flarehq.dev/terms.