Skip to content

Privacy Policy

Effective and last updated: September 6, 2026. Version: 2026-09-06.

This policy explains how FlagWire handles personal data when providing the Service.

  • Account data: name, email address, verification state, linked sign-in provider identifiers, organization membership, and security/session records.
  • Customer configuration: projects, environments, flags, segments, rules, versions, comments, and audit records.
  • Runtime operations: SDK family and version, project and environment identifiers, evaluation reason, approximate aggregate counts, request outcome, and security signals. FlagWire does not intentionally place evaluation context values, email addresses, full URLs, or raw SDK keys in runtime analytics or application logs.
  • Billing data: plan and entitlement state, provider event identifiers, transaction status, and customer identifiers required to reconcile Dodo Payments. FlagWire does not store full card or bank-account details.
  • Support data: messages and technical information you choose to provide when requesting help.

We process data to create and secure accounts, provide feature evaluation and configuration delivery, authorize changes, maintain auditability, reconcile billing, prevent abuse, monitor reliability, respond to support requests, and comply with legal obligations. We do not sell personal data or use customer targeting context for advertising.

Remote evaluation processes only the context attributes an application sends. Customers control those attributes and are responsible for having a lawful basis to use them. Send only attributes required by targeting rules. Do not send passwords, payment details, health records, travel itineraries, full URLs, or other sensitive content unless a separate written agreement expressly covers that processing.

The dashboard debugger is designed to be ephemeral: supplied context is bounded, is not returned in the response, and is not intentionally written to billing analytics, exposure events, audit history, or application logs.

FlagWire uses service providers for edge hosting and storage, payment processing, transactional email, identity sign-in, monitoring, and source operations. The current list and purposes are on the Subprocessors page. We disclose data when required by law or necessary to protect users, the Service, and others from material harm.

Account, membership, configuration, version, and audit data are retained while the relevant account or organization remains active. Session records expire under the Service’s session policy. Aggregate operational and security records are kept only as long as reasonably needed for reliability, fraud prevention, and billing reconciliation.

Account deletion removes the user from active Service data after the confirmation process. Organization deletion removes active organization configuration and revokes its access path. You must transfer ownership or delete organizations for which you are the sole owner before deleting your account. Paid organizations must complete cancellation before organization deletion so money and entitlement state cannot diverge.

Service-provider backups and legally required billing, tax, dispute, and fraud records may persist under provider retention schedules or applicable law. Dodo Payments independently retains transaction records as merchant of record.

We use access controls, origin restrictions, encrypted transport, hashed credentials and keys, rate limits, immutable versions, monitoring, and recovery controls described on the Security page. No system is completely secure.

Providers may process data in countries outside your own. Where required, transfers rely on applicable contractual or legal safeguards.

You can update account data, export project configuration, revoke keys, remove members, and request or perform deletion through the Service where available. Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data. Contact support@flagwire.dev; we may verify identity before acting.

FlagWire is not intended for children under 18. We may update this policy and will present a new version for acceptance when a material contractual change requires it.