FlagPilot Privacy Policy
Effective Date: July 16, 2026
Last Updated: July 16, 2026
1. Introduction
Welcome to FlagPilot ("FlagPilot," "we," "our," or "us"). FlagPilot is a developer platform for managing feature flags, rollouts, target users, webhooks, APIs, SDKs, and CLI tooling.
This Privacy Policy explains in detail what information we collect, why we collect it, how we protect it, who we share it with, how long we keep it, and the rights and choices available to you. It is designed to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Brazil's Lei Geral de Proteção de Dados (LGPD), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable regional data protection laws.
By using FlagPilot, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
2. Scope
This policy applies to the FlagPilot website, dashboard, APIs, SDKs, CLI, MCP server, documentation, billing systems, customer support channels, and all related services (collectively, the "Service"). It covers information we collect directly from you, information generated through your use of the Service, and information you configure the Service to process on your behalf (such as Target User identifiers).
This policy does not cover the practices of third-party websites, applications, or integrations you choose to connect to FlagPilot (e.g., your own backend systems, Slack, or Discord) — please review their respective privacy policies separately.
3. Who We Are (Data Controller)
FlagPilot is operated by FlagPilot ("FlagPilot", "we", "our", or "us") and is the data controller responsible for the personal information described in this Privacy Policy. FlagPilot is a trade name rather than a separate legal entity.
We have not appointed a formal Data Protection Officer, as we do not meet the GDPR threshold requiring one at our current scale. Privacy inquiries can be directed to the contact above, and we will respond within the timeframes required by applicable law.
4. Information We Collect
4.1 Account Information
- Google Account ID
- Name
- Email address
- Avatar / Profile picture (optional)
- Profile settings and preferences
- Company or organization name, if provided
Authentication Information
When you sign in using Google, we receive certain information from your Google account, such as:
- Your name
- Email address
- Google Account ID (subject identifier)
- Profile picture (if available)
We use this information to:
- Create and manage your FlagPilot account
- Authenticate your identity
- Secure your account
- Personalize your dashboard
We do not receive your Google password.
4.2 Project Information
- Project and environment names (e.g., development, staging, production)
- Feature flag keys, descriptions, types, and default values
- Rollout configuration (percentage values, sticky-hash settings)
- Target User identifiers: opaque IDs you provide for feature targeting (e.g.,
usr_123). See §5 for details on how this data is specifically handled. - Audit history: records of who changed what flag, when, and how, within your own account
- Webhook configuration (endpoint URLs and event subscriptions you set up)
- API keys and authentication tokens (stored encrypted)
4.3 Billing Information
Payments are handled by our payment processor, acting as Merchant of Record. We may store subscription identifiers, customer identifiers, billing status, plan information, renewal dates, and usage metrics tied to your billing plan (e.g., evaluation counts for metered overage). We do not store full payment card details — these are collected and processed directly by our payment processor.
4.4 Usage and Technical Data
- Browser type, device information, operating system, IP address
- Pages visited, documentation usage, feature interactions within the dashboard
- Diagnostic and performance information (e.g., API response times, error rates)
- Log data including access times and API request metadata
4.5 Analytics Data
With your consent (where required by applicable law), we use analytics tools to understand product usage and improve FlagPilot. This may include aggregate usage patterns, feature adoption, and session behavior. See §9 for details on consent and opt-out.
4.6 Error Monitoring Data
We use error monitoring tooling to detect and diagnose software errors, which may incidentally capture technical context (e.g., stack traces, request metadata) at the time an error occurs.
4.7 Communications
Support requests, correspondence, feedback, and any information you voluntarily provide when contacting us.
4.8 Information We Do Not Collect
We do not knowingly collect special categories of personal data (health information, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, or biometric/genetic data) through the Service. Our Target Users feature is specifically designed around opaque identifiers, not personal information about your application's end users.
5. Target Users — Detailed Handling
Because this feature involves data about your end users, not just you as our customer, it warrants specific detail:
- FlagPilot stores only opaque identifiers supplied by you (e.g., a
userId, a Firebase UID, an Auth0 subject, a Supabase UID) — strings with no inherent personal meaning to us. - We do not require, request, validate, or cross-reference these identifiers against any real-world identity.
- We strongly recommend you avoid using directly identifiable personal information (names, emails) as the identifier value itself. If you choose to do so anyway, that data becomes subject to this policy as personal information, and you remain responsible for ensuring you have appropriate legal basis and user consent for us to process it as your data processor.
- Evaluation results for Target Users (whether a given ID matches your configured list) are computed on request and are not separately logged with identifying detail beyond aggregate evaluation counts (see §4.4 and §12).
- If you are a customer acting as a data controller for your own end users, and our processing of Target User identifiers on your behalf falls within scope of GDPR Article 28, contact us at support@tryflagpilot.com to discuss a Data Processing Agreement.
6. API Keys and Authentication
API keys authenticate applications connecting to FlagPilot's evaluation API, CLI, and SDKs. Keys are stored encrypted and scoped to a project and environment. You are responsible for protecting your API keys — treat them like passwords. If a key is compromised, rotate it immediately from your dashboard. We log key usage (timestamps, source IP where available) for security and abuse-detection purposes.
7. How We Use Information and Legal Bases (GDPR)
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing and improving the Service | Performance of a contract |
| Authenticating users and securing accounts | Performance of a contract / Legitimate interest |
| Processing subscriptions and billing | Performance of a contract |
| Providing customer support | Performance of a contract |
| Protecting against abuse, fraud, and security threats | Legitimate interest / Legal obligation |
| Diagnosing and fixing software errors | Legitimate interest |
| Understanding product usage (analytics) | Consent, where required |
| Complying with legal and tax obligations | Legal obligation |
We do not sell your personal information, and we do not use it for purposes incompatible with those listed above without providing notice and, where required, obtaining your consent.
8. How We Share Information — Third-Party Services
We share information with the following categories of service providers, each acting as our data processor (or sub-processor) under contractual data protection terms. In the interest of transparency, we name our current providers below; this list may change as our infrastructure evolves, and material changes will be reflected in an updated "Last Updated" date.
| Provider | Purpose |
|---|---|
| Authentication (Google Sign-In) | |
| Better Auth | Authentication and session management |
| Dodo Payments | Payment processing, subscription billing, and tax compliance (Merchant of Record) |
| Google Analytics | Product usage analytics (with consent, where required) |
| PostHog | Product usage analytics and feature adoption tracking (with consent, where required) |
| Sentry | Error monitoring and diagnostics |
| Better Stack | Uptime monitoring, logging, and status page infrastructure |
| Vercel | Application hosting and content delivery |
| Neon | Data storage and infrastructure |
We may also disclose information:
- To comply with a legal obligation, court order, or governmental request
- To protect the rights, property, or safety of FlagPilot, our users, or the public
- In connection with a sale of the business or its assets, subject to confidentiality obligations
- With your consent, or at your direction (e.g., when you configure a Slack or Discord webhook integration)
We do not sell personal information, and we do not share personal information with third parties for their own independent marketing purposes.
9. Cookies and Analytics Consent
We use the following categories of cookies:
- Necessary cookies: required for authentication, session management, and core security functionality. These cannot be disabled without breaking the Service.
- Analytics cookies (Google Analytics, PostHog): used with your consent, where required by applicable law (e.g., under the EU ePrivacy Directive and GDPR), to understand aggregate usage patterns and improve the product.
You can update your cookie preferences at any time via Cookie Preferences available from the website footer or Account Settings. Where required by law, we present a consent banner before setting non-essential cookies.
10. Your Privacy Rights
10.1 General Rights (GDPR, UK GDPR, and similar frameworks)
Depending on applicable law, you may request:
- Access to the personal data we hold about you
- Correction of inaccurate or incomplete data
- Deletion of your data, subject to legal exceptions
- Restriction of processing in certain circumstances
- Portability — receiving your data in a structured, commonly used, machine-readable format
- Objection to processing based on legitimate interests or for direct marketing
- Withdrawal of consent at any time, where processing is based on consent
- The right to lodge a complaint with your local data protection supervisory authority
10.2 CCPA / CPRA (California Residents)
Where applicable, California residents may additionally request:
- The right to know what personal information we collect, use, and disclose, and the categories of sources and recipients
- The right to delete personal information, subject to exceptions
- The right to correct inaccurate personal information
- The right to opt out of the sale or sharing of personal information — FlagPilot does not sell or share personal information as defined under CCPA/CPRA
- The right to limit use of sensitive personal information — we do not collect sensitive personal information as defined by the CPRA in the ordinary course of providing the Service
- The right to non-discrimination for exercising any of the above rights
10.3 LGPD (Brazil) and Other Jurisdictions
Residents of Brazil, Canada, and other jurisdictions with applicable data protection frameworks have similar rights to access, correct, delete, and port their data, and to object to certain processing, under LGPD, PIPEDA, and other local law as applicable.
10.4 How to Exercise Your Rights
Submit requests via support@tryflagpilot.com or the contact methods published on the FlagPilot website. We will respond within the timeframe required by applicable law (typically 30 days under GDPR, 45 days under CCPA/CPRA, each extendable with notice in certain circumstances). We may need to verify your identity before fulfilling certain requests.
11. International Data Transfers
Your information may be processed outside your country of residence, including in the United States, using appropriate safeguards where required by law. Where we transfer personal data out of the European Economic Area, United Kingdom, or Switzerland, we rely on mechanisms which may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The UK International Data Transfer Addendum, where applicable
- Transfers to jurisdictions covered by an adequacy decision
Where required, we rely on Standard Contractual Clauses (SCCs), adequacy decisions, or other lawful transfer mechanisms provided by our service providers.
12. Data Retention
We retain information only as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements:
- Account data: retained for the duration of your account, plus 30 days after closure for legal and dispute-resolution purposes
- Billing records: retained as required by applicable tax and accounting law (commonly 6-7 years, depending on jurisdiction)
- Project and flag configuration data: retained for the duration of your account
- Audit history: retained for 12 months, supporting your own team's accountability needs
- Aggregate usage/analytics data: retained per your plan's stated history window; we do not retain detailed per-evaluation logs beyond a short operational window
- Error monitoring data: retained per our error monitoring provider's default retention window, typically 30 days, sufficient for diagnosis but not indefinite storage
Upon account deletion, we delete or anonymize personal data within 30 days, except where retention is legally required.
13. Data Security
We implement security measures designed to protect your information, including:
- HTTPS/TLS encryption in transit
- Encryption of API keys and authentication tokens at rest
- Access controls limiting data access to what's needed for support and operations
- Security headers and monitoring across our infrastructure
- Authentication safeguards for account access
No service can guarantee absolute security. In the event of a data breach affecting your personal information, we will notify affected users and relevant supervisory authorities as required by applicable law (e.g., within 72 hours under GDPR, where feasible).
14. Automated Decision-Making
We do not use your personal information for automated decision-making, including profiling, that produces legal or similarly significant effects on you. Flag evaluation logic operates on rules and identifiers you configure yourself and does not constitute automated decision-making about you as a data subject.
15. Children's Privacy
FlagPilot is not intended for children under 16 years of age, or the minimum age required by applicable law in your jurisdiction. We do not knowingly collect personal information from children. If we become aware that we have inadvertently done so, we will take steps to delete it.
16. Third-Party Links and Integrations
The Service may allow you to configure integrations with third-party services (e.g., Slack, Discord, or your own backend systems). This Privacy Policy does not extend to the practices of third parties you choose to integrate with — review their respective privacy policies independently.
17. Changes to This Policy
We may update this Privacy Policy periodically. The "Last Updated" date at the top reflects the most recent revision. Where changes are material, we will provide notice via email or a prominent notice within the Service prior to the change taking effect.
18. Contact
Questions regarding this Privacy Policy may be submitted via support@tryflagpilot.com or the contact methods published on the FlagPilot website. If you are located in the EEA or UK and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
