Effective Date: September 24, 2026 Operator: Flaeti Inc., a Delaware corporation
Flaeti is a private communication and controlled-sharing service that provides end-to-end encrypted messaging and controlled content sharing between users who have mutually established a connection. Flaeti is operated by Flaeti Inc., a Delaware corporation ("Flaeti," "we," "our," or "us").
This Privacy Policy explains what information Flaeti collects, why we collect it, how we use it, who we share it with, and what we cannot access even if compelled by legal process. We encourage you to read it carefully.
Flaeti is designed around a foundational principle: the content of your communications belongs to you. We have built our technical architecture so that we do not hold the keys needed to read your messages or access your documents, and are structurally unable to do so. This Privacy Policy describes both what we choose not to collect and what we are technically unable to access.
For purposes of applicable data protection law, Flaeti Inc. is the controller of the personal data described in this Policy. If you use Flaeti through a business account, the business may also determine how certain data about its members is used.
If you have questions about this Policy, contact us at [email protected].
When you create a Flaeti account, we collect:
When you establish a mutual connection with another Flaeti user, we record:
We do not record the content of any communication exchanged through that connection.
If you create or join a business account on Flaeti, we collect:
Flaeti maintains an audit log associated with each account. The audit log records account-level events such as connection establishment, connection termination, and sharing policy changes. The audit log does not record message content or document content.
To deliver push notifications to your device, Flaeti associates your account with a Firebase Cloud Messaging token issued by Google LLC. This token is a device-specific identifier used solely to route notification triggers to your device. See Section 4.1 for a full description of how push notifications work and what information is transmitted through Firebase Cloud Messaging.
To deliver encrypted content and to support the sharing type you choose (SHOW, LEND, or GIVE), Flaeti's servers hold delivery information associated with each encrypted item. This includes the connection through which the item was sent, the time it was sent, the sharing type selected by the sender and related status information (such as expiration or revocation), and the size of the encrypted item. This information does not include the content of any message or document.
Flaeti does not collect the following:
Flaeti uses the information described in Section 2 solely for the following purposes:
Flaeti does not sell your information. Flaeti does not use your information for advertising. Flaeti does not share your information with third parties except as described in Section 4 and Section 6.
Flaeti uses a limited number of third-party infrastructure providers to operate the service. Each is described below. We do not use third-party analytics services, advertising networks, crash reporting services, or social login providers.
Flaeti uses Firebase Cloud Messaging, operated by Google LLC, to deliver push notifications to your device.
When a new encrypted message is available, Flaeti transmits to Google's FCM infrastructure only a device-specific FCM token and an opaque notification payload. The payload contains only a static event type and an internal connection identifier. It does not contain your identity, the sender's identity, message content, message preview, file names, business names, or any other personally identifiable information.
Google receives a device token, a delivery timestamp, and this opaque payload, and may process device and network information in the ordinary course of operating Firebase Cloud Messaging. Google cannot read Flaeti communications through this mechanism.
Upon receiving the notification trigger, the Flaeti application fetches the encrypted message from Flaeti's servers and decrypts it locally on your device using decryption keys held only on your device. Message content is never transmitted through or accessible to Firebase Cloud Messaging.
Google's handling of FCM data is governed by Google's Privacy Policy, available at policies.google.com/privacy. Flaeti has executed a Data Processing Agreement with Google covering Firebase services.
Flaeti's application servers are hosted by Render Services, Inc. All communication between your device and Flaeti's servers is routed through Render's infrastructure over encrypted HTTPS connections.
Flaeti's application server does not emit request logs and does not capture or retain user IP addresses at the application layer. Render retains application-level stdout/stderr logs for seven days for operational purposes. These logs contain server operational output and do not contain user IP addresses or user content. Render's internal network routing infrastructure may process connection information at the infrastructure layer; this data is not accessible to Flaeti and cannot be produced by Flaeti in response to legal process.
Flaeti's database is hosted by Supabase Inc., running on Amazon Web Services infrastructure located in Oregon. Supabase stores all account metadata, connection records, business account records, member rosters, sharing policy configurations, audit log entries, delivery and sharing records, and encrypted message and document content.
All message content and document content stored in Supabase is end-to-end encrypted ciphertext. Supabase has no technical ability to read, access, or process the content of your communications or documents. Supabase holds encrypted data on Flaeti's behalf as an infrastructure service only.
Flaeti has executed a Data Processing Agreement with Supabase Inc. (Version 1, effective August 1, 2026) covering database hosting services, incorporating Standard Contractual Clauses for international data transfers where applicable.
Flaeti's source code is hosted by GitHub, Inc., a subsidiary of Microsoft Corporation. No user data is transmitted to or stored in GitHub. GitHub is included here for completeness and transparency only.
Flaeti does not currently use a third-party payment processor, customer support platform, email service provider, or analytics service. When additional subprocessors are engaged, this Privacy Policy will be updated prior to or at the time those services are activated. Material changes will be communicated to users as described in Section 10.
All Flaeti user data is stored in the United States. Our application servers are hosted by Render Services, Inc. and our database is hosted by Supabase Inc., running on AWS infrastructure, both located in Oregon. Push notifications are routed through Firebase Cloud Messaging, operated by Google LLC, using globally distributed delivery infrastructure. The FCM notification payload contains no personally identifiable Flaeti user data, as described in Section 4.1.
Flaeti retains account registration information, connection records, business account records, delivery and sharing records, and audit log entries for as long as your account remains active. When your account is deleted, Flaeti deletes or de-identifies your account registration information, connection records, and audit log entries within thirty days, except where retention is required by applicable law or valid legal process.
Encrypted message and document content is retained in Supabase for as long as the relevant connection or sharing relationship remains active, or until deleted by the user, whichever occurs first. Flaeti does not retain plaintext content at any time. The ciphertext stored on Flaeti's servers is unreadable without decryption keys held only on user devices.
FCM tokens are retained for as long as your account remains active and push notifications remain enabled. Disabling push notifications or deleting your account results in FCM token deletion.
You may delete your Flaeti account at any time through the application or by contacting [email protected]. Upon account deletion, Flaeti initiates deletion of your account registration information, connection records, and associated metadata within thirty days. Encrypted ciphertext associated with your account is deleted on the same schedule. FCM tokens associated with your account are deleted upon account deletion.
Flaeti cannot recover deleted accounts or deleted content.
Flaeti responds to valid legal process issued by courts and government authorities with appropriate jurisdiction. We review all legal process for legal sufficiency, specificity, and proportionality before producing any data.
Because of our end-to-end encryption architecture, Flaeti cannot produce the content of user communications or documents in response to legal process. We do not hold decryption keys and cannot read ciphertext stored on our servers.
What Flaeti can produce in response to valid legal process is limited to the account metadata described in Section 2, to the extent it exists at the time of the request. A complete description of what Flaeti can and cannot produce, our legal process requirements, our user notice practices, and our emergency request procedures is available in our Law Enforcement Guidelines at flaeti.com/law-enforcement.
Flaeti's default practice is to notify affected users before producing data in response to legal process, to the extent permitted by law. We will not notify users where prohibited by court order, applicable gag provision, or where notification would create an imminent risk to safety. A full description of our user notice practices is available in our Law Enforcement Guidelines.
Flaeti publishes an annual transparency report disclosing aggregate information about legal process received and our responses. Our first transparency report will cover the period from September 24, 2026 through December 31, 2027 and will be published no later than March 31, 2028.
All Flaeti user data is stored in the United States, as described in Section 5.1.
If you access Flaeti from outside the United States, including from the European Economic Area, the United Kingdom, or other jurisdictions with data protection laws governing cross-border data transfers, you acknowledge that your data will be transferred to, stored in, and processed in the United States. United States data protection laws may differ from the laws of your home jurisdiction.
Flaeti relies on Standard Contractual Clauses approved by the European Commission as the legal basis for transfers of personal data from the EEA and UK to the United States. Our subprocessors Google LLC and Supabase Inc. each maintain Standard Contractual Clauses as part of their Data Processing Agreements. Copies of applicable Standard Contractual Clauses are available upon request by contacting [email protected].
If you are located in the European Economic Area or the United Kingdom, you may have additional rights under applicable data protection law, including the right to access, correct, restrict, or delete your personal data, and the right to lodge a complaint with a supervisory authority. Where those laws apply, we process personal data on the following legal bases: performance of our contract with you (operating your account and delivering the service), our legitimate interests in operating a secure service and preventing abuse, and compliance with legal obligations. To exercise your rights, contact [email protected].
If you are located in California, you may have additional rights under the California Consumer Privacy Act, as amended. Flaeti does not sell personal information and does not share personal information for cross-context behavioral advertising. To exercise your rights under California law, contact [email protected].
Because Flaeti cannot read the content of encrypted communications, we cannot access, correct, or export that content in response to a rights request. It is held only on user devices and as ciphertext we cannot decrypt.
Flaeti will respond to verified rights requests within the timeframes required by applicable law.
Flaeti's security model is architectural. The content of your communications is end-to-end encrypted on your device before it is transmitted to Flaeti's servers. Flaeti's servers receive and store only ciphertext. Decryption keys are held only on user devices, and Flaeti's systems and personnel do not have access to them.
For account metadata that Flaeti does hold, we implement industry-standard administrative, technical, and physical safeguards appropriate to the nature of the data. Authentication credentials are stored in cryptographic form and are not recoverable by Flaeti.
No security system is impenetrable, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal data, we will notify affected users and applicable authorities as required by law. If you become aware of a security vulnerability or incident affecting Flaeti, please report it to [email protected].
Flaeti is not intended for anyone under 18 years of age, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete the associated account and data promptly. If you believe a person under 18 is using Flaeti, please contact [email protected].
Flaeti may update this Privacy Policy from time to time. When we make material changes, we will notify users through the Flaeti application and update the effective date at the top of this document. Your continued use of Flaeti following notice of material changes constitutes your acceptance of the updated Policy.
Material changes that affect data practices in ways that are adverse to users will be communicated with no less than thirty days advance notice before taking effect, to the extent permitted by applicable law.
The current version of this Privacy Policy is always available at flaeti.com/privacy.
Flaeti Inc.
Privacy inquiries: [email protected] Legal process and law enforcement requests: [email protected] General legal inquiries: [email protected]
Law Enforcement Guidelines: flaeti.com/law-enforcement Terms of Service: flaeti.com/terms Privacy Policy: flaeti.com/privacy
Flaeti Privacy Policy — Version 1.0
Effective Date: September 24, 2026
Operator: Flaeti Inc., a Delaware corporation