Legal
Privacy Policy
What we collect when you use Flare, why we collect it, and the choices you have over it.
01Overview
This policy explains what personal data Flare ("Flare", "we", "us") collects when you use flares.in and the Flare application, why we collect it, who we share it with, and the choices you have. Flare is a product operations platform: it turns product intent, bug reports, and meetings into structured, agent-readable context for teams building software.
If your organization uses Flare, your organization (the "Workspace Owner") controls the account and is responsible for the instructions it gives us about your data. If you are a person reporting a bug through a Flare-powered widget embedded in someone else's product, that product's owner is the data controller and Flare processes your report on their behalf.
02Data we collect
Account & workspace data - name, email address, password hash or OAuth identity, organization and workspace membership, role, and profile details you add.
- Product content you create: tickets, comments, project plans, epics, stories, tasks, acceptance criteria, risks, decisions, and project updates.
- Bug report evidence submitted through the Flare reporter widget or SDK: screenshots, annotated images, session replay recordings, console logs, failed network requests, device and browser metadata, and the URL or route at the time of capture.
- Meeting data: calendar events and metadata read from connected Google or Microsoft calendars, meeting recordings, transcripts, participant lists, and agent-generated outcomes, decisions, and follow-ups extracted from calls.
- AI-generated content: summaries, extracted requirements, generated plans, and other outputs our AI features produce from the content above.
- Billing data: your plan, subscription status, invoices, and usage counters. Card and payment details are collected and processed directly by our payment processor, not stored on our servers.
- API tokens and MCP session data: hashed personal access tokens, granted scopes, and an audit trail of the actions taken through the API or Model Context Protocol server.
- Usage and diagnostic data: log-in activity, feature usage, and, once you interact with the page, anonymized analytics events via Google Analytics.
03Calendar and meeting data specifically
Connecting a calendar is optional and requires you to explicitly authorize Flare through Google or Microsoft sign-in. We request the minimum scopes needed to detect and schedule around meetings: read-only access to your calendar list and event details. We do not request access to send email, modify unrelated files, or read your inbox.
Recording a meeting requires a separate, explicit action. When enabled, our capture provider joins the call as a participant to record and transcribe it, and we log a consent event for that session. Anyone who does not want a call recorded should say so before it starts or leave before the recorder joins - your organization is responsible for following the recording-consent laws that apply in its jurisdiction and participants' locations.
You can disconnect a calendar or delete a meeting recording and its transcript at any time from within the app; doing so removes our access going forward and deletes the stored recording, subject to the retention rules below.
04How we use data
- To operate Flare: authenticate you, run your workspace, and display your projects, tickets, and meetings.
- To power AI features: our agents read the content described above to triage tickets, plan projects, and extract meeting outcomes. AI processing for these features is performed using Google's Gemini models under a processing agreement that prohibits use of your data to train Google's general-purpose models.
- To provide evidence for bug reports: screenshots, recordings, and logs are made available to your team through short-lived signed URLs (typically valid for fifteen minutes) rather than public links.
- To bill your account through our payment processor, Razorpay, and send billing-related notices.
- To maintain security: we keep audit logs of sensitive actions (ticket changes, plan publication, agent task execution) so admins can review who changed what.
- To communicate with you about your account, changes to the service, or in response to a support request.
06Data retention
We retain workspace content for as long as your account is active. If you delete a project, ticket, meeting recording, or calendar connection, we remove it from active systems promptly and from backups within our standard backup rotation window. If you close your account, we delete or anonymize your personal data within a reasonable period, except where we must retain records to comply with legal, tax, or accounting obligations.
07Security
Data is encrypted in transit. Workspace data is isolated with row-level security policies so that one organization cannot read another's records. Evidence media (screenshots, recordings, attachments) is served through time-limited signed URLs rather than being publicly accessible. API tokens are stored hashed, scoped, and rate-limited, and sensitive actions are recorded in an audit log. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
08Your rights and choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent (such as a calendar connection) at any time without affecting processing that already occurred. Workspace members should generally exercise these rights through their organization's admin, since the organization controls most workspace content; if you contact us directly at hello@flares.in, we will route your request appropriately and respond within a reasonable time.
09Children's privacy
Flare is a business tool and is not directed at, or intended for use by, children. We do not knowingly collect personal data from children under 16.
10International data transfers
Flare and its service providers operate infrastructure in multiple regions, including India and other regions used by our hosting and database providers. Where we transfer personal data across borders, we rely on appropriate safeguards such as standard contractual clauses or the transfer mechanisms our providers make available.
11Changes to this policy
We may update this policy as Flare's features change. If a change is material, we will notify workspace admins by email or through the product before it takes effect. The "Effective" date above reflects the version currently in force.
12Contact us
Questions about this policy or a data request can be sent to hello@flares.in.
Questions about this document
