Privacy Policy

Last updated: 2026-08-19

The short version: the local tool sends us nothing, and the hosted service manages accounts and access without ever receiving the content of your plans.

1. The local tool sends nothing

The flanner CLI, MCP server and local web UI run entirely on your machine. Plans, versions, history and freshness results live in a SQLite database in your home directory. No account is needed and nothing is transmitted.

If you never sign up for Flanner Mesh, we hold no data about you at all, and this policy has nothing to describe.

2. What the hosted service stores

Signing up for Flanner Mesh creates records. All of them:

  • Your email address. It is how you sign in and the only way we can reach you.
  • Your team. Its name, who belongs to it, each member's role, and which workspaces they may read.
  • Device records. A label, a platform, and the public half of the key each machine generated. The private half never leaves the machine and we could not ask for it.
  • An audit trail of administrative actions: members invited or removed, devices enrolled or revoked, entitlements issued.
  • Billing records. A customer id and subscription state from Stripe, plus how many seats you owe.

3. What it does not store

The content of your plans. Not the text, not the titles, not the file names. Plans sync directly between your own devices; they do not pass through us on the way.

Card details. Stripe handles payment. We never receive a card number.

Passwords. There are none. You sign in with a mailed link, and machines authenticate with a key they hold.

4. The relay, and why it cannot read anything

Two devices normally connect directly. When a firewall prevents that, traffic falls back to a relay we operate.

The relay forwards encrypted QUIC. It has no key and cannot decrypt what it carries, so it sees that two devices are talking and roughly how much, but not what about. Relayed traffic is not logged for content, because there is no content to log.

5. Who else is involved

We use a small number of processors, and only these:

  • Stripe — payments and subscription state.
  • Our email provider — delivering sign-in links and invitations.
  • Vercel Analytics — aggregate page counts on this marketing site. It sets no cookie and does not build a profile of you.
  • Web3Forms — if you join the Mesh waitlist, your email address is relayed to our inbox through their service. That is the only thing the waitlist form does.

We do not sell personal data, and we do not use it to train models.

6. How long it is kept

Account, team and device records are kept while the account exists. Delete the account and they are removed within 30 days, apart from billing records we are required to retain for tax and accounting.

Sign-in links expire after 30 minutes and are spent on first use. Audit records are kept for as long as the account exists, because their purpose is to let an admin see what happened.

7. Your rights

You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Write to support@flanner.io and we will respond within 30 days.

Deletion is genuinely simple here, because the list in section 2 is short. There is no archive of your work to hunt through.

8. Security

A device key is the credential, and we only ever hold public keys. A breach of our systems would expose email addresses, team structure and public keys. It would not let anyone read your plans, and it would not let anyone impersonate one of your devices.

If you believe you have found a vulnerability, please see the reporting section of the Acceptable Use Policy.

9. Children

The service is for professional use and is not directed at children under 16. We do not knowingly collect their data.

10. Changes and contact

Changes are published here with a new date at the top. Material changes are emailed to account holders before taking effect.

Flanner is the data controller. Reach us at support@flanner.io.