Privacy policy

Last updated: July 14, 2026 · Applies to flashbudget.io and its API

This policy describes what data we process, why, and your rights, in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR.

1. Data we collect

Email updates ("Get updates" form): your email address, IP address and browser user-agent, with the date of signup. Legal basis: your consent. Purpose: sending product updates. Retention: until you ask for deletion.

Account / project creation: project name and email address. Purpose: operating your account, matching subscription payments, and contacting you about the service (contract performance).

Build uploads (API): firmware binaries (.elf) sent by your CI are analyzed in memory and deleted immediately after analysis — the binary itself is never stored. We store only the derived size metadata: symbol names, sections and byte sizes, per branch and commit identifier, to provide diffs and history.

Online demo: files uploaded to the demo are analyzed in memory and never stored.

Server logs: our web server (Nginx) records IP addresses and requested URLs for security and debugging, retained for a limited period.

2. What we do NOT do

No advertising, no sale of data, no tracking cookies, no analytics scripts. The site currently loads fonts from Google Fonts, which transmits your IP address to Google when the page loads; we plan to self-host fonts.

3. Processors

Hostinger (hosting, EU/international infrastructure) and Stripe (payment processing; Stripe receives the data you enter at checkout, including your email — see Stripe's own privacy policy). We do not receive or store card numbers.

4. Your rights

You may request access, correction, deletion or export of your data, and withdraw consent at any time: contact@flashbudget.io. Deleting your project deletes its build history.

5. Security

All traffic is encrypted (HTTPS). API tokens are stored only as one-way hashes. Access to production data is restricted to the operator.