Skip to main content

Privacy Policy

Last updated: September 11, 2026

Google API data and Limited Use

Flare's use and transfer of information received from Google APIs, including raw, aggregated, and derived Google Workspace API data, complies with the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including their Limited Use requirements.

We do not use, transfer, or sell this data to create, train, or improve foundational, generalized, or non-personalized AI or machine-learning models. This restriction also applies to our service providers. We use Google user data only to provide the audit analysis and investigation features you request, and share it with service providers only as needed to deliver those features with your authorization.

Human access to Google user data is limited to the exceptions allowed by the Limited Use requirements, such as your explicit consent for specific support requests, security investigations, or legal obligations.

How we protect your data

We protect Google user data and other sensitive information using the following safeguards:

  • Encryption in transit: Flare uses HTTPS/TLS to protect data sent between your browser, Flare, and the APIs used to provide the service.
  • Encryption at rest: Our hosted Supabase database encrypts stored data at rest. Workspace and GitHub OAuth credentials receive additional AES-256-GCM encryption before database storage, using a server-side encryption key stored separately from those records.
  • Access controls: Protected requests require authentication and server-side checks that restrict access to the account that owns the analysis or connector. Sensitive audit credential tables are unavailable through public database roles, and service credentials stay on the server.
  • Data minimization: Flare selects audit fields for analysis and applies automated filtering for recognized secrets before sending analysis inputs to our AI provider. Complete uploaded log files are not retained after analysis; saved findings include only selected supporting event excerpts. Filtering does not remove all personal information, such as actor identities or IP addresses needed for an investigation.

What we collect

Flare collects your email address and name when you create an account. For GCP, we store OAuth tokens in restricted server-side connector configuration so Flare can fetch audit logs. For AWS, we store the role ARN, ExternalId, Region, and account metadata needed to request short-lived credentials. We never ask for or store AWS access keys. For Workspace and GitHub, we encrypt OAuth access and refresh tokens in server-side storage and retain the verified customer or organization identity. Workspace collection includes login, admin and OAuth-token report metadata; GitHub collection includes organization web audit metadata. These connectors do not read Gmail, Drive file contents or repository contents. Flare does not retain complete raw log files after analysis. We persist analysis results, anomaly findings, and up to five selected source-event excerpts for each finding so you can review its evidence.

How we use it

Your data is used solely to provide the Flare anomaly detection service. We do not sell or use your data for advertising. GCP OAuth tokens and short-lived AWS role credentials are used only to fetch the audit activity you ask Flare to analyze. Selected audit fields, such as actors, timestamps, actions, resource identifiers and network information, are sent to our AI processing provider during analysis. Results, selected evidence, aggregate frequency baselines and follow-up conversations are stored to support investigation.

Data retention

Analysis results, anomaly findings, and their selected source-event excerpts are retained until you delete the analysis or close your account. GCP tokens and AWS role configuration are deleted when you disconnect the corresponding cloud connector. Workspace and GitHub credentials are deleted on disconnect, which also cancels pending authorizations; saved analyses remain until deleted. Provider-side authorization must be revoked in Google or GitHub separately. Expired temporary authorization records are rejected immediately and cleaned up hourly in bounded batches. Account erasure removes audit-source records and keeps only a hash of the account identifier to prevent delayed callbacks from restoring deleted data. You can request full account deletion at any time through Support.

Third parties

We use Supabase for data storage, Clerk for authentication, Vercel for application hosting, and Anthropic for AI analysis. Selected audit information and investigation context are sent to Anthropic's commercial API to generate findings and follow-up answers. Anthropic states that it does not train on commercial API inputs or outputs by default. We do not authorize training on Google user data, including by opting into training or submitting that data as model feedback. Our service providers may process data only for the purposes described here, subject to the Google Limited Use restrictions above.

Support

Questions about your data or cloud connection? Visit Flare Support or email ariel@tryflare.ai.