Legal
Privacy Policy
Last updated: May 31, 2026
This Privacy Policy explains what data Flayel (the web app at flayel.vercel.app and the Flayel Chrome extension) collects, why we collect it, where it is stored, and the choices and rights you have. Flayel is a project-continuity tool for people who build with AI. We collect the minimum needed to remember your project context and feed it back to your AI tools.
1. Who we are
Flayel ("Flayel", "we", "us") provides a project-memory web application and an optional Chrome browser extension. For any privacy question or request you can reach us at privacy@flayel.dev.
2. Data we collect
We collect only what is needed to operate the product:
- Account data — your email address and display name, provided when you sign up via our authentication provider (Supabase Auth).
- Project content you create — projects, the six Project Brain memory slots (vision, architecture, progress, decisions, user feedback, monetization), tasks, notes, AI-tool entries, content-calendar items, and uploaded launch assets.
- AI workflow context (extension) — when you explicitly click the Flayel bird to capture an AI chat or scan & save a page, we collect the text excerpt you captured, the page title, and the page URL. Capture is always initiated by you; the extension does not silently read or stream your pages in the background.
- Operational metadata — timestamps, the AI tool a session came from, a computed "Ship Score", and audit-log entries (action, time, IP address, and user agent) used for security and abuse prevention.
We do not collect passwords (handled by Supabase Auth), payment card numbers (handled by our payment processor if/when paid plans are enabled), or any special categories of personal data.
3. Authentication
Sign-in is handled by Supabase Auth. When you log in, Supabase issues a session (access + refresh token). In the web app these tokens are stored in cookies. In the Chrome extension, the same tokens are passed from a signed-in Flayel tab into the extension and stored in chrome.storage.local on your own device so the extension can talk to your account. We never see or store your password.
4. AI workflow context & user-generated content
The core purpose of Flayel is to remember your project and re-inject it into AI tools. Content you capture or type — chat excerpts, brain slots, decisions, saved articles — is user-generated content that belongs to you. We process it only to: store it in your project, generate a formatted context block you can paste into AI tools, and compute your Ship Score. We do not sell this content and we do not use it to train any model.
5. Where data is stored (Supabase)
Application data is stored in Supabase (PostgreSQL database plus object storage for uploaded files). Row-Level Security policies restrict every row to its owner, so one user cannot read another user's projects, sessions, memory, or files. Uploaded launch assets are kept in an owner-scoped storage bucket.
- Stored in Supabase: account profile, projects, Project Brain memory, sessions/captures, saved resources, tasks, AI-tool entries, uploaded files, audit logs.
- Stored locally on your device (chrome.storage.local): your Supabase session tokens, the selected project, the app URL, and a cached copy of your project's formatted context so the extension works offline. This never leaves your machine except when used to authenticate calls to our API.
6. Data we transmit
The extension transmits data to the Flayel API (over HTTPS) only when you take an action:
- Capture a chat → sends the captured summary/excerpt + source URL/title to
/api/sessions/auto-log. - Scan & save → sends the page URL, title, and a short excerpt to
/api/resources/save. - Inject / copy context → reads your project context (from the local cache or a signed, time-limited URL) — this is data flowing to you, not new data we collect.
- Token refresh → sends your refresh token to
/api/ext/refresh-tokento mint a new session when the old one expires.
7. Cookies & session handling
The web app uses strictly necessary cookies to keep you signed in (Supabase auth cookies) and short-lived activity cookies used for session timeout. We do not use third-party advertising or cross-site tracking cookies. The extension does not set cookies; it uses local extension storage as described above.
8. Service providers
We share data only with infrastructure providers that process it on our behalf:
- Supabase — authentication, database, and file storage.
- Vercel — application hosting and delivery.
- AI/LLM provider — when you use an AI feature, the relevant project text is sent to our model provider to generate the result; it is not used to train their models per their API terms.
- Email provider — to send transactional emails (e.g. digests, reminders) if you opt in.
9. Your rights
You can access and edit your data inside the app at any time. You may request a copy of your data, correction of inaccurate data, or deletion of your account and all associated data. To exercise these rights, use the data deletion page or email privacy@flayel.dev.
10. Data deletion
You can delete individual projects from within the app. To delete your entire account and all associated data, submit a request on the Data Deletion page. We process verified deletion requests within 30 days. Deletion is permanent and removes your profile, projects, memory, sessions, saved resources, and uploaded files. Minimal audit records required for security and legal compliance may be retained for a limited period.
11. Data retention
We keep your data for as long as your account is active. When you delete your account, we remove your content as described above. Backups are rotated on a rolling basis.
12. Children
Flayel is not directed to children under 13 and we do not knowingly collect their data.
13. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by updating the "Last updated" date above.
14. Contact
Privacy requests: privacy@flayel.dev. General support: support@flayel.dev.
