Flour Privacy

Privacy

Effective 13 August 2026. Short version: we store what Flour needs to work for you, nothing that would be interesting to sell, and you can delete all of it.

What we collect

DataWhyWhereRetention
Email addressPasswordless sign-in and account recoverySupabase AuthUntil you delete the account
History — your questions and the answersSo your work is there next sessionSupabase, row-level-secured to your user IDUntil you delete it
Shared responsesTo render the public share link you createdSupabase, public readUntil you or we remove it
Events — page view, tool opened, answer completed, shareTo know which tools earn their placeSupabase13 months
Message content sent to the modelTo generate the responseAnthropic API, via our server proxyPer Anthropic's retention policy

What we do not do

Cookies and local storage

Flour sets no advertising or analytics cookies. It uses localStorage for exactly one thing: your Supabase session token, so you stay signed in. Sign out and it is removed.

The model provider

Prompts are relayed to Anthropic through our server-side proxy so that our API key is never exposed to your browser. Anthropic processes that content under its own terms and privacy policy. Do not submit information you would not be comfortable sending to a third-party processor — no personal health data, no customer records, no trade secrets you cannot afford to disclose.

Your rights

Depending on where you live you may have rights of access, correction, deletion, portability, restriction and objection, and the right to complain to a supervisory authority. To exercise any of them, email privacy@flour.si from the address on the account. We aim to respond within 30 days.

Account deletion removes your auth record, your history and your events. Shared pages you created are also removed unless you ask us to keep them.

Children

Flour is not directed at children under 13 (or under 16 in the EEA/UK), and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

Security

Data is protected by Supabase row-level security: your history rows are readable only by your authenticated user ID. Transport is HTTPS throughout. No system is perfectly secure; if we become aware of a breach affecting you, we will notify you and the relevant authority as required by law.

International transfers

Flour uses providers whose infrastructure may sit outside your country, including the United States. Where required, transfers rely on standard contractual clauses or an equivalent mechanism operated by those providers.

Changes

If this policy changes materially, the effective date above changes and the change is announced on the site.

Template notice. This is a clear, honest starting point, not legal advice. Have a qualified privacy lawyer review it against your actual data flows before relying on it.

Terms Open the bench