This policy describes what data we process, why, and your rights, in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR.
Email updates ("Get updates" form): your email address, IP address and browser user-agent, with the date of signup. Legal basis: your consent. Purpose: sending product updates. Retention: until you ask for deletion.
Account / project creation: project name and email address. Purpose: operating your account, matching subscription payments, and contacting you about the service (contract performance).
Build uploads (API): firmware binaries (.elf) sent by your CI are analyzed in memory and deleted immediately after analysis — the binary itself is never stored. We store only the derived size metadata: symbol names, sections and byte sizes, per branch and commit identifier, to provide diffs and history.
Online demo: files uploaded to the demo are analyzed in memory and never stored.
Server logs: our web server (Nginx) records IP addresses and requested URLs for security and debugging, retained for a limited period.
No advertising, no sale of data, no tracking cookies, no analytics scripts. The site currently loads fonts from Google Fonts, which transmits your IP address to Google when the page loads; we plan to self-host fonts.
Hostinger (hosting, EU/international infrastructure) and Stripe (payment processing; Stripe receives the data you enter at checkout, including your email — see Stripe's own privacy policy). We do not receive or store card numbers.
You may request access, correction, deletion or export of your data, and withdraw consent at any time: contact@flashbudget.io. Deleting your project deletes its build history.
All traffic is encrypted (HTTPS). API tokens are stored only as one-way hashes. Access to production data is restricted to the operator.