Privacy Policy
Last updated: August 11, 2026
1. Introduction
Flaude is operated by Sidekick CommV, a company registered in Belgium ("we," "us," or "our"). We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your information when you use our Figma plugin and website (together, "the Service"). Your use of the Service is also governed by our Terms of Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Password (securely hashed — we never see or store your password in plain text)
- Your display name, if you choose to provide one
If you join a waiting list or leave your email in one of our sign-up forms without creating an account, we store that email address and which list it came from, so we can tell you when the thing you asked about is ready.
2.2 Publishing to the library
If you publish a screen to the Flaude library, we create a public contributor profile for you. Your @handle, display name, avatar and bio are visible to anyone, signed in or not, along with the screens you publish. This is the point of publishing, but it is worth being explicit: it is public, and search engines can index it. Your email address is never shown on your public profile.
2.3 Payment Information
Payment processing is handled entirely by Revolut, our third-party payment processor. We do not store your credit card number or payment details. We receive only:
- Transaction IDs and payment status (to activate your subscription)
- The email address associated with your payment
2.4 Designs, prompts and how we use them
When you use Flaude, your text prompts are sent to Anthropic (Claude) to generate or modify designs, and pass through our server to reach it. Flaude connects to Claude through your own Anthropic account: you authorise us via OAuth and we store only the resulting access tokens, encrypted at rest. We never ask for or store an API key.
Because the request runs under your Anthropic account, how Anthropic handles that data — including whether it may be used to improve their models — is governed by the Anthropic terms that apply to your plan and by your own privacy settings with them. Those terms differ between consumer subscriptions and commercial API access, so please review Anthropic's Privacy Policy and your Anthropic account settings.
What we store on our own servers
Being specific here, because "passes through our server" and "is kept on our server" are different things and you deserve the second one in writing. When you build or rebuild a screen through Flaude's MCP server, we keep a durable record of that build, linked to your email address:
- the prompt or instruction that produced the screen
- the structured description of the screen (its layers, sizes, colours and text) and the operations that built it
- a PNG image of the finished screen
- whether the result passed our automated quality checks
We use this to operate and improve Flaude: to find where the engine gets things wrong, to fix those defects, and to measure whether a change actually made rebuilds more accurate. Reviewing real failures is how the product gets better; we would rather tell you that plainly than bury it.
The screen images are stored at unlisted addresses that are not linked from anywhere and not indexed, but they are not individually password-protected. Please treat anything you build through Flaude as you would a file on a shared drive: do not put secrets, credentials, or personal data belonging to other people into a design and expect it to stay private.
We do not sell your prompts, designs or images, we do not claim ownership of them, and we do not use them to train AI models: not our own, and we do not hand them to anyone else to train theirs.
You can ask us to delete your stored builds at any time using the contact address in section 10, without closing your account.
2.5 Usage records
When you use the MCP server we record which tools ran, how long they took, how much data they moved, and whether the result passed its checks, against your email address. This is how we find slow or broken tools and keep costs down. It is not advertising data and it is never sold.
3. How We Use Your Information
We use your email address and account data to:
- Provide and maintain the Service
- Process payments and manage your subscription
- Send important account notifications (e.g., payment confirmations)
- Respond to support requests
- Comply with legal obligations
We do not use your information for marketing purposes or send promotional emails unless you explicitly opt in.
4. Information Sharing
We do not sell, rent, or trade your personal information. Your data is shared only with the following service providers, solely to operate the Service:
- Supabase — authentication, database, and storage of the screen images described in section 2.4 (hosted in Ireland, EU)
- Revolut — payment processing
- Vercel — website hosting (Frankfurt, EU)
- Fly.io — hosting for the Flaude MCP server, which handles your email address, your usage records, and the designs it builds (Frankfurt, EU)
- Anthropic — AI processing via Claude (United States)
- Google — AI processing via Gemini, only if you connect a Google account for that purpose (United States)
- Resend — sending account and payment emails; receives your email address and the contents of those messages
- PostHog — product analytics, only if you accept analytics cookies (EU region). See section 5.1.
We may also disclose information if required by law, court order, or government request, or to protect our rights, safety, or property.
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you before your data is subject to a different privacy policy.
5. Cookies
We use cookies strictly for:
- Authentication — keeping you signed in across sessions
- Security — preventing unauthorized access to your account
- Preferences — remembering your settings
The cookies above are essential and are set regardless of your choice, because without them the Service cannot sign you in.
5.1 Analytics (optional, only with your consent)
If you press "Accept" on the cookie banner, we also load two analytics tools:
- Vercel Web Analytics — page views and visitor counts. It is cookieless and does not build a profile of you.
- PostHog (hosted in the EU) — product analytics. It sets a cookie so we can tell whether the same browser copied a screen, hit a paywall, or came back on a later day. We record only a fixed, named list of actions, such as copying a screen or starting a signup. We do not use autocapture, so ordinary clicks and typing are not recorded, and we do not create a stored profile for visitors who never sign in.
Neither is used for advertising, and we do not sell or share this data with advertisers. If you press "Decline", neither tool is loaded at all and no analytics events are sent. You can change your mind at any time by clearing this site's data in your browser, which makes the banner appear again.
6. Data Security
We protect your data with:
- Encryption in transit (HTTPS/TLS)
- Secure password hashing (never stored in plain text)
- Access controls and authentication on all systems
No method of transmission over the internet is 100% secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security.
7. Data Retention
We retain your account information for as long as your account is active. After account deletion:
- Personal data is deleted within 30 days
- Backup data is purged within 90 days
- Data required for legal or financial compliance (e.g., transaction records) may be retained longer as required by law
- Third-party providers (Revolut, Supabase) retain data in accordance with their own privacy policies
8. Your Rights
Depending on your location, you may have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — correct inaccurate information
- Deletion — request deletion of your data
- Portability — receive your data in a portable format
- Objection — object to certain processing activities
- Withdraw Consent — where we process based on your consent (e.g., if you opt in to marketing emails), you may withdraw that consent at any time
To exercise any of these rights, email flaude.support@gmail.com. We will respond within 30 days of receiving a verified request. If you believe we have handled your data improperly, you also have the right to complain to your local data protection authority; in Belgium, where we are established, that is the Gegevensbescherming / Autorité de protection des données.
9. International Data Transfers
Your account, your designs and the database that holds them stay in the European Union. The only processing that happens outside the EEA is the AI step itself, because that is where the model providers run.
Your data is processed in the following locations:
- EU (Frankfurt) — website hosting via Vercel
- EU (Ireland) — database, authentication and file storage via Supabase
- EU (Frankfurt) — the Flaude MCP server via Fly.io
- EU — product analytics via PostHog, if you accept analytics cookies
- United States — AI processing via Anthropic, and via Google if you connect a Google account
Where personal data leaves the European Economic Area, we rely on the transfer mechanisms our providers make available: the EU-US Data Privacy Framework where the provider is certified, and Standard Contractual Clauses otherwise.
10. Children's Privacy
The Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately and we will delete it.
11. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for their privacy practices and encourage you to review their privacy policies.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date above. For significant changes, we will notify you by email.
13. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users without undue delay and report to the relevant supervisory authority within 72 hours, as required by GDPR Articles 33 and 34.
14. GDPR Information (EU Users)
If you are in the European Economic Area (EEA), our legal bases for processing your data are:
- Contract — processing your email and payment data is necessary to provide the Service you signed up for
- Legitimate Interests — maintaining security and preventing fraud
- Legal Obligation — retaining transaction records as required by law
You have the right to lodge a complaint with your local data protection authority.
15. Contact Us
The data controller is Sidekick CommV, a company registered in Belgium. For any privacy or data-rights question, including deletion of the stored builds described in section 2.4, email flaude.support@gmail.com.