1. About this policy
This policy explains how ItsFlag AI ("we", "us", "our") handles personal data when you use our website and service. It covers the account you create, the scans you run, and the technical data our infrastructure records. It forms part of our Terms of Service.
It does not cover the websites whose documents you analyze. When you scan a company's Terms of Service, that company's own privacy practices apply to your dealings with them, not this policy — and a scan does not create any relationship between you and them.
The short version
We collect the minimum needed to run scans and bill for Pro: your email, your plan state, and a record of each scan. Analyzing a document means sending its text to a reader service and an AI provider. We use no advertising or analytics trackers, we never see your card number, and we do not sell personal data.
2. Information we collect
Account information
| What | Why we hold it |
|---|---|
| Email address | To identify your account, sign you in, and contact you about your account, billing, or changes to our terms |
| Password | Stored only as a salted hash by our authentication provider. We never see or store your password itself |
| Google account identifier | Only if you choose to sign in with Google. We receive your email address and a user identifier — not your Google password or contacts |
| Account role | To distinguish an ordinary user from an administrator |
| Account creation date | To show "member since" and to support security investigations |
Plan and billing information
| What | Why we hold it |
|---|---|
| Plan state and remaining scan credits | To enforce free-tier limits and unlock Pro features |
| Payment-provider customer and subscription identifiers | To link your account to your subscription so renewals, cancellations, and refunds apply to the right person |
We never receive your card details
Card numbers, expiry dates, and security codes are entered on our payment provider's own checkout pages and are held by them. They never reach our servers, and we cannot see them.
Scan information
| What | Why we hold it |
|---|---|
| The website or document address you submitted | To show what was analyzed and to build your history |
| The document address we actually retrieved | Discovery may resolve to a different page than the one you typed; we record which document the result is based on |
| The toxicity score and the full analysis | This is the result itself: the summary and every finding, including any clause text quoted from the document |
| The language of the scan | Results are generated and stored in the language you scanned in |
| A canonical address, a content fingerprint, and the document's stated effective date | To recognize that a document has not changed since a previous scan, so a repeat scan can reuse the earlier analysis instead of re-reading it |
| The date and time of the scan | To order your history and show when a result was produced |
If you paste document text instead of a link, that text is processed to produce your result. We do not keep the pasted text as a separate record, but any part of it that the analysis quotes as evidence for a finding is stored inside the result.
Preferences and technical data
| What | Why we hold it |
|---|---|
| Language and theme preference | So the interface stays in the language and appearance you chose. See “Cookies and local storage” |
| Session cookie | To keep you signed in. See “Cookies and local storage” |
| Server logs from our hosting provider — IP address, browser user agent, requested address, timestamp, and error details | To keep the Service running and secure, diagnose faults, and detect abuse such as credit-limit circumvention |
We do not ask for your name, postal address, phone number, or date of birth, and there is no field to provide them.
3. How we use your information
- To provide the Service: locating documents, retrieving them, generating analysis, and returning your result.
- To maintain your account and scan history, and to let you re-open and share past results.
- To operate plans and credits: tracking remaining free scans and unlocking Pro.
- To take payment, process renewals and cancellations, and handle refunds and billing disputes.
- To keep the Service secure: detecting and investigating abuse, fraud, multiple-account credit farming, and attacks.
- To provide support when you contact us, and to answer privacy requests.
- To improve the Service: understanding which failures occur so discovery and analysis can be fixed. We look at aggregate patterns and error cases, not at individual users' reading habits.
- To comply with the law and to enforce our Terms.
What we don't do with it
We do not use your scans or your email for advertising, we do not sell or rent personal data, we do not build profiles about you for third parties, and we do not use your submitted documents to train our own models.
The AI provider that performs the analysis is a separate company operating under its own terms. We select providers that do not train on submitted content, but we cannot audit them, and their handling of the text is governed by their agreement with us — not by this policy. Do not submit confidential material.
4. Legal bases for processing
If the GDPR or UK GDPR applies to you, these are the legal bases we rely on:
| Purpose | Legal basis |
|---|---|
| Creating your account, running scans, storing history, taking payment | Performance of a contract with you |
| Security, abuse prevention, fault diagnosis, and improving the Service | Our legitimate interests in operating a secure and functional service, balanced against your rights |
| Responding to legal requests, keeping records of transactions | Compliance with a legal obligation |
| Anything we ask your permission for | Your consent, which you may withdraw at any time |
5. Who processes your information
We use the following service providers. Each acts on our instructions under a contract, and each receives only what it needs for its function.
| Provider | Function | What it receives |
|---|---|---|
| Supabase | Authentication and database hosting | Your email address, password hash, account record, and all of your scan records |
| Stripe | Payment processing and subscription management | Your email address and subscription identifiers, plus the card details you enter directly on Stripe's checkout |
| Optional sign-in | Only used if you choose Google sign-in; Google confirms your identity and returns your email address | |
| Jina AI | Document retrieval and text conversion (r.jina.ai, s.jina.ai) | The address of the document being analyzed, so it can be fetched and converted to plain text. Sent for both automatic discovery and retrieval |
| AI analysis provider | Clause analysis and scoring | The extracted document text, or the text you pasted, together with our analysis instructions. No account or billing data is sent |
| Render | Application hosting | Technical request data and server logs, including IP addresses |
The AI analysis provider is an OpenAI-compatible service we configure and may change as models improve. We will tell you which provider is in use if you ask at privacy@itsflag.com.
We may also disclose information where we are legally required to — in response to a valid legal request, to establish or defend a legal claim, or to protect the rights, safety, or property of our users, the public, or us. If we are ever involved in a merger, acquisition, or sale of assets, account data may transfer to the acquirer, who would remain bound by this policy or give you notice before changing it.
6. What we don't collect or do
- No advertising or analytics trackers. The Service loads no advertising pixels, no analytics scripts, and no third-party tracking cookies.
- No sale of personal data. We do not sell, rent, or trade personal data, and we do not share it for cross-context behavioural advertising.
- No card data. Payment details are held by our payment provider and never reach us.
- No advertising profiles. We do not build or buy audience segments, and we do not target you based on the documents you scan.
- No unnecessary identity data. We do not collect your name, address, phone number, date of birth, or any government identifier.
- No training on your documents. We do not use submitted content to train our own models.
9. How long we keep information
| Data | Retention |
|---|---|
| Account record | For as long as your account is open. Deleted when you close it |
| Scans and results | Until you delete them, or until your account is closed — deleting an account deletes its scans automatically |
| Billing records | Kept as long as tax and accounting law requires, typically up to seven years, even after an account closes. This is a legal obligation we cannot waive at request |
| Server logs | A short rolling window kept by our hosting provider for security and diagnostics, then overwritten |
| Support and privacy correspondence | Up to two years, so we can show how a request was handled |
To have your account and scans deleted, email privacy@itsflag.com from the address on the account. We will confirm and complete deletion within 30 days. Deletion is permanent and cannot be undone, so export anything you want to keep first.
10. Your rights
Depending on where you live, you have some or all of these rights. We honour them for everyone, wherever you are, unless the law requires us to keep something:
- Access — get a copy of the personal data we hold about you.
- Correction — have inaccurate data fixed.
- Deletion — have your account and scans erased.
- Portability — receive your data in a machine-readable form.
- Restriction and objection — ask us to pause a use, or object to processing based on legitimate interests.
- Withdraw consent — where we relied on your consent, withdraw it at any time.
- Complain — raise a complaint with your data-protection authority. In the EU that is your national authority; in the UK, the Information Commissioner's Office.
If you are in California
Under the CCPA and CPRA you may request to know the categories and specific pieces of personal information we have collected, its sources, and our purposes; request deletion or correction; and opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of. We will not discriminate against you for exercising any right, and we do not use sensitive personal information for inferring characteristics.
How to exercise a right
Email privacy@itsflag.com from the address on your account and tell us what you want. We may need to confirm it is really you before acting on a request about someone's data. We answer within 30 days, and will tell you if a request will take longer or if a legal exception means we cannot fully comply. Exercising a right is free; we may charge only for a repetitive or clearly excessive request, and will say so first.
You may also use an authorized agent where the law allows, provided we can verify their authority.
11. International transfers
We operate as an online service and our providers are located in several countries, primarily the United States. If you use the Service from outside the country where a provider processes data, your information will be transferred internationally.
Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on an appropriate safeguard — an adequacy decision covering the destination, or the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) in our contract with the provider. You can ask us which mechanism applies to a given provider.
12. Security
- All traffic to and from the Service is encrypted in transit with HTTPS.
- Passwords are stored only as salted hashes by our authentication provider; we cannot read them.
- Database access is restricted by row-level security, so a signed-in user can only read their own account row and their own scans.
- Administrative privileges are checked on the server for every request, independently of what the interface shows.
- Provider credentials — including the AI provider's API key — are encrypted at rest with AES-256-GCM, and the system refuses to store such a key at all if its encryption key is not configured.
- Secrets are held in the server environment only and are never sent to the browser.
No service can promise perfect security, and we do not. If we discover a breach affecting your personal data, we will notify you and the relevant regulator where the law requires it, without undue delay. If you find a vulnerability, please report it to legal@itsflag.com rather than disclosing it publicly, and we will work with you in good faith.
13. Children
The Service is not intended for children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has created an account, email privacy@itsflag.com and we will delete the account and its data.
Where local law sets a higher age of digital consent than ours, we treat that higher age as the threshold for users in that country.
14. Changes to this policy
We may update this policy as the Service changes. The revised version is posted on this page with a new "Last updated" date.
If a change materially affects how we handle your personal data — a new category of data, a new purpose, or a new type of recipient — we will notify you by email or in the Service before it takes effect, and seek your consent where the law requires it. Previous versions are available on request.
15. Contact us
For any privacy question, or to exercise a right, email privacy@itsflag.com. For anything else, support@itsflag.com reaches us just as well.
ItsFlag AI is the controller of the personal data described in this policy. We have not appointed a data-protection officer, as we are not required to; privacy requests are handled directly by the team operating the Service.