ItsFlagAI

Terms & Policies

Privacy Policy

What we collect, who processes it, how long we keep it, and how to get it deleted — described field by field.

Last updated

On this page15
  1. 1. About this policy
  2. 2. Information we collect
  3. 3. How we use your information
  4. 4. Legal bases for processing
  5. 5. Who processes your information
  6. 6. What we don't collect or do
  7. 7. Cookies and local storage
  8. 8. Shared results are public
  9. 9. How long we keep information
  10. 10. Your rights
  11. 11. International transfers
  12. 12. Security
  13. 13. Children
  14. 14. Changes to this policy
  15. 15. Contact us

1. About this policy

This policy explains how ItsFlag AI ("we", "us", "our") handles personal data when you use our website and service. It covers the account you create, the scans you run, and the technical data our infrastructure records. It forms part of our Terms of Service.

It does not cover the websites whose documents you analyze. When you scan a company's Terms of Service, that company's own privacy practices apply to your dealings with them, not this policy — and a scan does not create any relationship between you and them.

The short version

We collect the minimum needed to run scans and bill for Pro: your email, your plan state, and a record of each scan. Analyzing a document means sending its text to a reader service and an AI provider. We use no advertising or analytics trackers, we never see your card number, and we do not sell personal data.

2. Information we collect

Account information

WhatWhy we hold it
Email addressTo identify your account, sign you in, and contact you about your account, billing, or changes to our terms
PasswordStored only as a salted hash by our authentication provider. We never see or store your password itself
Google account identifierOnly if you choose to sign in with Google. We receive your email address and a user identifier — not your Google password or contacts
Account roleTo distinguish an ordinary user from an administrator
Account creation dateTo show "member since" and to support security investigations

Plan and billing information

WhatWhy we hold it
Plan state and remaining scan creditsTo enforce free-tier limits and unlock Pro features
Payment-provider customer and subscription identifiersTo link your account to your subscription so renewals, cancellations, and refunds apply to the right person

We never receive your card details

Card numbers, expiry dates, and security codes are entered on our payment provider's own checkout pages and are held by them. They never reach our servers, and we cannot see them.

Scan information

WhatWhy we hold it
The website or document address you submittedTo show what was analyzed and to build your history
The document address we actually retrievedDiscovery may resolve to a different page than the one you typed; we record which document the result is based on
The toxicity score and the full analysisThis is the result itself: the summary and every finding, including any clause text quoted from the document
The language of the scanResults are generated and stored in the language you scanned in
A canonical address, a content fingerprint, and the document's stated effective dateTo recognize that a document has not changed since a previous scan, so a repeat scan can reuse the earlier analysis instead of re-reading it
The date and time of the scanTo order your history and show when a result was produced

If you paste document text instead of a link, that text is processed to produce your result. We do not keep the pasted text as a separate record, but any part of it that the analysis quotes as evidence for a finding is stored inside the result.

Preferences and technical data

WhatWhy we hold it
Language and theme preferenceSo the interface stays in the language and appearance you chose. See “Cookies and local storage”
Session cookieTo keep you signed in. See “Cookies and local storage”
Server logs from our hosting provider — IP address, browser user agent, requested address, timestamp, and error detailsTo keep the Service running and secure, diagnose faults, and detect abuse such as credit-limit circumvention

We do not ask for your name, postal address, phone number, or date of birth, and there is no field to provide them.

3. How we use your information

  • To provide the Service: locating documents, retrieving them, generating analysis, and returning your result.
  • To maintain your account and scan history, and to let you re-open and share past results.
  • To operate plans and credits: tracking remaining free scans and unlocking Pro.
  • To take payment, process renewals and cancellations, and handle refunds and billing disputes.
  • To keep the Service secure: detecting and investigating abuse, fraud, multiple-account credit farming, and attacks.
  • To provide support when you contact us, and to answer privacy requests.
  • To improve the Service: understanding which failures occur so discovery and analysis can be fixed. We look at aggregate patterns and error cases, not at individual users' reading habits.
  • To comply with the law and to enforce our Terms.

What we don't do with it

We do not use your scans or your email for advertising, we do not sell or rent personal data, we do not build profiles about you for third parties, and we do not use your submitted documents to train our own models.

The AI provider that performs the analysis is a separate company operating under its own terms. We select providers that do not train on submitted content, but we cannot audit them, and their handling of the text is governed by their agreement with us — not by this policy. Do not submit confidential material.

5. Who processes your information

We use the following service providers. Each acts on our instructions under a contract, and each receives only what it needs for its function.

ProviderFunctionWhat it receives
SupabaseAuthentication and database hostingYour email address, password hash, account record, and all of your scan records
StripePayment processing and subscription managementYour email address and subscription identifiers, plus the card details you enter directly on Stripe's checkout
GoogleOptional sign-inOnly used if you choose Google sign-in; Google confirms your identity and returns your email address
Jina AIDocument retrieval and text conversion (r.jina.ai, s.jina.ai)The address of the document being analyzed, so it can be fetched and converted to plain text. Sent for both automatic discovery and retrieval
AI analysis providerClause analysis and scoringThe extracted document text, or the text you pasted, together with our analysis instructions. No account or billing data is sent
RenderApplication hostingTechnical request data and server logs, including IP addresses

The AI analysis provider is an OpenAI-compatible service we configure and may change as models improve. We will tell you which provider is in use if you ask at privacy@itsflag.com.

We may also disclose information where we are legally required to — in response to a valid legal request, to establish or defend a legal claim, or to protect the rights, safety, or property of our users, the public, or us. If we are ever involved in a merger, acquisition, or sale of assets, account data may transfer to the acquirer, who would remain bound by this policy or give you notice before changing it.

6. What we don't collect or do

  • No advertising or analytics trackers. The Service loads no advertising pixels, no analytics scripts, and no third-party tracking cookies.
  • No sale of personal data. We do not sell, rent, or trade personal data, and we do not share it for cross-context behavioural advertising.
  • No card data. Payment details are held by our payment provider and never reach us.
  • No advertising profiles. We do not build or buy audience segments, and we do not target you based on the documents you scan.
  • No unnecessary identity data. We do not collect your name, address, phone number, date of birth, or any government identifier.
  • No training on your documents. We do not use submitted content to train our own models.

7. Cookies and local storage

We use the smallest set of cookies the Service can run on. All of them are first-party. None are used for advertising or analytics, which is why the Service shows no cookie-consent banner — strictly necessary cookies and a preference you set yourself do not require consent.

NameTypePurposeLifetime
Authentication cookies set by SupabaseStrictly necessaryKeep you signed in and refresh your session securelyUntil you sign out or the session expires
itsflag_sessionStrictly necessaryDevelopment and demo sign-in only. Not set when the Service runs against a real authentication providerUntil you sign out
itsflag_localePreferenceRemembers whether you chose English or ArabicOne year

We also store one item in your browser's local storage — the key "theme", holding your light or dark preference. It never leaves your device and is not sent to us.

You can clear or block cookies in your browser settings. Blocking the authentication cookies will make signing in impossible.

8. Shared results are public

A share link needs no sign-in

When you share a result, it becomes readable by anyone who has the link — with no account and no password. The page shows the document analyzed, the score, the summary, and every finding, including quoted clause text.

Share links are unlisted and are not intended to be guessable, but treat them as public. Anyone you send one to can pass it on, and a link posted on a public page can be found by a search engine. Deleting the scan removes the shared page.

If a result was shared and you need it removed, delete the scan from your history or email privacy@itsflag.com.

9. How long we keep information

DataRetention
Account recordFor as long as your account is open. Deleted when you close it
Scans and resultsUntil you delete them, or until your account is closed — deleting an account deletes its scans automatically
Billing recordsKept as long as tax and accounting law requires, typically up to seven years, even after an account closes. This is a legal obligation we cannot waive at request
Server logsA short rolling window kept by our hosting provider for security and diagnostics, then overwritten
Support and privacy correspondenceUp to two years, so we can show how a request was handled

To have your account and scans deleted, email privacy@itsflag.com from the address on the account. We will confirm and complete deletion within 30 days. Deletion is permanent and cannot be undone, so export anything you want to keep first.

10. Your rights

Depending on where you live, you have some or all of these rights. We honour them for everyone, wherever you are, unless the law requires us to keep something:

  • Access — get a copy of the personal data we hold about you.
  • Correction — have inaccurate data fixed.
  • Deletion — have your account and scans erased.
  • Portability — receive your data in a machine-readable form.
  • Restriction and objection — ask us to pause a use, or object to processing based on legitimate interests.
  • Withdraw consent — where we relied on your consent, withdraw it at any time.
  • Complain — raise a complaint with your data-protection authority. In the EU that is your national authority; in the UK, the Information Commissioner's Office.

If you are in California

Under the CCPA and CPRA you may request to know the categories and specific pieces of personal information we have collected, its sources, and our purposes; request deletion or correction; and opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of. We will not discriminate against you for exercising any right, and we do not use sensitive personal information for inferring characteristics.

How to exercise a right

Email privacy@itsflag.com from the address on your account and tell us what you want. We may need to confirm it is really you before acting on a request about someone's data. We answer within 30 days, and will tell you if a request will take longer or if a legal exception means we cannot fully comply. Exercising a right is free; we may charge only for a repetitive or clearly excessive request, and will say so first.

You may also use an authorized agent where the law allows, provided we can verify their authority.

11. International transfers

We operate as an online service and our providers are located in several countries, primarily the United States. If you use the Service from outside the country where a provider processes data, your information will be transferred internationally.

Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on an appropriate safeguard — an adequacy decision covering the destination, or the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) in our contract with the provider. You can ask us which mechanism applies to a given provider.

12. Security

  • All traffic to and from the Service is encrypted in transit with HTTPS.
  • Passwords are stored only as salted hashes by our authentication provider; we cannot read them.
  • Database access is restricted by row-level security, so a signed-in user can only read their own account row and their own scans.
  • Administrative privileges are checked on the server for every request, independently of what the interface shows.
  • Provider credentials — including the AI provider's API key — are encrypted at rest with AES-256-GCM, and the system refuses to store such a key at all if its encryption key is not configured.
  • Secrets are held in the server environment only and are never sent to the browser.

No service can promise perfect security, and we do not. If we discover a breach affecting your personal data, we will notify you and the relevant regulator where the law requires it, without undue delay. If you find a vulnerability, please report it to legal@itsflag.com rather than disclosing it publicly, and we will work with you in good faith.

13. Children

The Service is not intended for children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has created an account, email privacy@itsflag.com and we will delete the account and its data.

Where local law sets a higher age of digital consent than ours, we treat that higher age as the threshold for users in that country.

14. Changes to this policy

We may update this policy as the Service changes. The revised version is posted on this page with a new "Last updated" date.

If a change materially affects how we handle your personal data — a new category of data, a new purpose, or a new type of recipient — we will notify you by email or in the Service before it takes effect, and seek your consent where the law requires it. Previous versions are available on request.

15. Contact us

For any privacy question, or to exercise a right, email privacy@itsflag.com. For anything else, support@itsflag.com reaches us just as well.

ItsFlag AI is the controller of the personal data described in this policy. We have not appointed a data-protection officer, as we are not required to; privacy requests are handled directly by the team operating the Service.