FlashData legal

FlashData Privacy Policy

Effective 2026-08-26. Last updated 2026-08-26.

Version 2026-08-26

Who we are

This Privacy Policy describes how FlashData ("we", "us") collects, uses, and shares information when you use flashdata.dev, flashdata.rocosen.asia, the FlashData API, and related websites (the "Service").

Questions: support@flashdata.dev.

Information we collect

Account data: name, email address, password hash, and legal-acceptance records.

Billing data: Stripe customer, subscription, invoice, and payment identifiers. We do not store full card numbers. Stripe processes payment details under its own privacy policy.

Usage data: API keys (stored as digests), query metadata, job status, credit reservations and settlements, webhook delivery attempts, and request identifiers. Query parameters may include search terms, video IDs, and similar source inputs you submit.

Technical data: IP address hashes or peppers used for rate limiting and abuse prevention, browser and device signals needed for session security, and server logs with request IDs.

Optional data you choose to provide: cloud storage destination credentials (encrypted), customer webhook URLs and signing secrets (encrypted), and support correspondence.

How we use information

We use this information to create and secure accounts, provide the API and console, meter usage, bill and grant credits, send transactional email (verification, password reset, receipts), detect abuse, debug incidents, and comply with law.

We do not sell personal information and we do not use account data for third-party advertising.

Processors and sharing

We share information with service providers that help us operate the Service: Stripe (payments), Brevo (transactional email), MongoDB and Redis infrastructure, and query upstreams such as Serper for Google results and YouTube retrieval for YouTube sources.

Upstream providers receive the query inputs you submit so they can return results. Do not submit secrets or personal data in query parameters unless you intend that provider to process them.

We may disclose information if required by law, to protect the Service, or in connection with a merger or sale of assets, with notice where legally required.

Retention and security

Account, billing, credit-ledger, and job records are kept for as long as the account is active and as needed for billing, audit, and legal obligations. Deleted accounts follow a scheduled grace period before irreversible anonymization.

API key secrets, storage credentials, webhook secrets, and billing event payloads are encrypted at rest with versioned keys. Passwords are stored as one-way hashes. We use HTTPS in transit on public endpoints.

No method of transmission or storage is completely secure. You are responsible for protecting API keys and account credentials.

Your choices

You may access and update profile information in the console, rotate or revoke API keys, manage billing through Stripe Checkout and Customer Portal, and request account deletion from account settings.

You can unsubscribe from non-transactional email if we ever send it. Transactional mail required to operate the account cannot be disabled while the account remains open.

If you are in a jurisdiction with additional privacy rights, email support@flashdata.dev and we will respond within a reasonable period.

Children and international use

The Service is not directed to children under 16. We do not knowingly collect their personal information.

The Service is operated from infrastructure that may be located in the United States or other regions. By using the Service you understand that your information may be processed outside your country of residence.

Changes

We may update this policy by publishing a new version. Material changes that require re-acceptance will be presented in the product before you continue using the console. Continued use after the effective date of a version you already accepted constitutes acceptance of that version.