Flair Українською

Privacy Policy

Last updated 18 September 2026

Flair records a spoken idea, writes it into a carousel in your voice, and lets you design and export the slides. Almost everything it handles is your unpublished writing, your voice and your photographs. This page says exactly what happens to each of them.

In short

Who is responsible

The controller of your personal data is [LEGAL NAME], a sole proprietor established in the Netherlands, at [POSTAL ADDRESS][, registered with the Dutch Chamber of Commerce under KvK number [NUMBER]].

You can reach a human at [SUPPORT EMAIL] about anything on this page. That is the same address the app’s Contact support row opens.

What happens to your voice

This is the part of Flair most worth being precise about, so it gets its own section.

When you tap the microphone, your phone opens an encrypted connection directly to Soniox, our speech-to-text provider, and streams audio to it. The connection is opened with a key that Flair’s server mints for that one recording: it is single-use, it expires within a minute, and it can do nothing else.

Three things follow, and all three are architectural rather than promises we simply make:

Audio is processed in Soniox’s European Union region.

What does get kept is the text. The transcript of what you said becomes an idea and a carousel in your account, because that is the thing the product exists to make, and it stays until you delete it.

What Flair collects

Your account. A Flair account exists from the moment you open the app, before you sign in to anything, and is identified by a random id. If you sign in with Apple, that identity is attached to the same account, along with whatever Apple chooses to share: an email address, which may be Apple’s private relay address, and your name, which Apple sends exactly once. Flair never sees your Apple password and never asks for one. The account also holds your interface language and your defaults for new carousels.

The things you make. Transcripts of what you spoke, text you pasted, the carousels and slides written from them, the designs you build, the photographs you choose from your library, and a record of each export. Photographs are stored in a private bucket and are reachable only through short-lived signed links issued to your account. Flair reads your photo library only for the images you pick, and asks for permission to add exported slides to your camera roll.

Your voice profile. Your answers to the onboarding questions and any writing samples you paste, plus the profile written from them. Samples are used to learn how you write, and for nothing else.

Your subscription. Whether you have an active subscription, which product, which store, when it renews. This comes from RevenueCat and from the app store you bought through. Flair never receives your card details, and never handles a payment. Apple does.

Usage data, if you leave it on. Which screens are reached, which steps are completed, whether a generation succeeded, how long it took. These events carry your account id so a session on Monday and a session on Friday are one person rather than two, and they carry no content: not your transcript, not your carousels, not your photographs. Share usage data in the You tab turns this off in one tap.

Diagnostics. When something crashes, a report with the error, the stack trace and your account id. Your session token is stripped from these reports before they are sent.

What Flair never does

Why we are allowed to process it

WhatLegal basis under the GDPR
Running the account, writing carousels, storing your work, exporting slidesPerformance of the contract you enter into by using Flair (Art. 6(1)(b))
Sign-in, and merging an account you started before signing inPerformance of the contract (Art. 6(1)(b))
Subscriptions, entitlement, invoicing recordsPerformance of the contract, and legal obligation for records (Art. 6(1)(b) and (c))
Usage data, which you can switch offLegitimate interests in knowing whether the product works (Art. 6(1)(f))
Crash reports, abuse prevention, rate limits, spend limitsLegitimate interests in keeping the service running and secure (Art. 6(1)(f))

Who else processes it

These are our processors. Each one is under a data processing agreement, handles only what its job needs, and may not use any of it for its own purposes.

ProviderWhat it handlesWhere
SonioxLive speech-to-text. Audio, in memory, not storedEuropean Union
SupabaseThe database, sign-in and photo storage. Everything in your accountFrankfurt, Germany
Fly.ioThe Flair API, which streams carousels. Transcript text in transit, never stored on itAmsterdam, Netherlands
AnthropicWriting the carousel and the voice profile. The transcript and profile sent with each requestUnited States
RevenueCatSubscription state. Your account id and purchase statusUnited States
PostHogUsage data, if you leave it on. Events and your account id, no contentEuropean Union
SentryCrash reports. Errors and your account idEuropean Union
CloudflareServing this website. Standard web request logsGlobal network

Apple is not on this list, because Apple is not our processor. When you buy a subscription or sign in with Apple, Apple handles that as a company responsible in its own right, under Apple’s privacy policy.

Where your data goes

Your account, your work and your photographs are stored in the European Union.

Three providers are in the United States: Anthropic, which writes the carousels, RevenueCat, which tracks subscriptions, and Fly.io, which runs the API on machines in Amsterdam. Those transfers are covered by the European Commission’s Standard Contractual Clauses in each provider’s data processing agreement, and, where the provider is certified, by the EU-US Data Privacy Framework.

How long it is kept

WhatHow long
AudioNot kept at all, by anyone
Your account, carousels, designs and photographsUntil you delete them, or until you delete your account
A deleted accountDeactivated immediately, then permanently erased after 30 days. You can cancel during those 30 days by signing back in
Generation records and edit history, which improve your voice profile12 months
Purchase and billing recordsAs long as tax and accounting law requires
Crash reports90 days
Usage data12 months

Your rights

Under the GDPR you may ask for a copy of your data, correct it, delete it, object to processing based on legitimate interests, ask us to restrict it, or take it elsewhere.

Two of those do not need to go through anyone:

For anything else, write to [SUPPORT EMAIL] and you will have an answer within one month.

If you think we have handled your data badly, please tell us first, but you have the right to complain to a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens.

Children

Flair is not for children. You must be at least 16 years old to use it. We do not knowingly collect anything from anyone younger, and if we learn that we have, the account is deleted.

Changes to this policy

If this policy changes in a way that affects you, the app will tell you before the change takes effect. The date at the top is when this version was published, and every earlier version is in this page’s git history.

Contact

[LEGAL NAME]
[POSTAL ADDRESS]
[SUPPORT EMAIL]