Flum Back to home

Privacy

Last updated 13 September 2026

Flum is a design tool, and it is in testing: not open to the public, with accounts given by invitation to a small number of people helping to test it. It needs an email address to know whose work is whose, and it needs somewhere to keep the designs. That is close to the whole of what it collects, and this page names the rest.

It is written to satisfy both the Brazilian LGPD (Lei 13.709/2018) and the European GDPR, including the UK version, because Flum is reachable from everywhere and it would be dishonest to write only for one of them. Where the two regimes give a right by different names, both names are here.

Who is responsible

The controller of this data — the controlador under the LGPD, the controller under the GDPR — is Flum, reachable at hello@flum.cc. That address reaches a person, and it is the address for every request on this page.

Flum has not appointed a data protection officer or an EU representative. It is a small service in testing, the processing described below is limited and low-risk, and neither appointment is required at this size. If that stops being true, this page says so before it stops being true.

What is collected

Flum runs no analytics, no tracking pixels, no session recording and no advertising identifiers. Your email address is not sold, rented, or traded. If any of that changes, the date at the top of this page changes with it, and the section below on changes says how you are told.

Why, and what allows it

The GDPR asks for a lawful basis for each purpose and the LGPD asks for a hipótese legal. They line up like this:

No consent is asked for because none of the above runs on consent. Nothing here is used for advertising, and there is no processing you would have to opt out of.

The deploy token never reaches us

If you connect a hosting provider to publish a site, the access token you paste is kept in your own browser and sent nowhere except to that provider’s own API. It is not transmitted to Flum, not written to Flum’s database, and so not present in Flum’s backups.

The cost of that choice is that the token does not follow you between browsers: connect the provider again on a new machine. Disconnecting deletes it from that browser. Sites already deployed stay up.

Who processes it

Each acts on Flum’s instructions for that purpose alone and is bound by its own data processing terms. They are described by what they do rather than named, which is what the GDPR allows when it asks for the recipients or the categories of recipients (Art. 13(1)(e)).

You can have the names. Write to hello@flum.cc and Flum will tell you which companies these are — that is your right under GDPR Art. 15(1)(c) and LGPD Art. 18, VII, and it is answered without argument. The two you pick yourself, the identity provider and the hosting provider, are named in the product at the moment you choose them.

Where it goes

The database is in the United States, so your data is transferred there and processed there. If you are in Brazil, that is an international transfer under LGPD Art. 33. If you are in the EEA, the UK or Switzerland, it is a transfer under GDPR Chapter V, and it relies on the Standard Contractual Clauses the processors above incorporate into their terms, together with their own supplementary measures.

Sign-in emails pass through the email provider on their way to you, and every request reaches the service through a content delivery network, which is global by design.

How long it is kept

Your projects stay until you delete them or close your account. Backups of the database are taken on the hosting provider’s schedule — currently daily, retained for up to seven days — so a deleted project can persist in a backup for up to about a week after it is gone from the live database.

The technical logs described above are kept for as long as the service that produced them keeps them, which is typically days to a few weeks.

Deleting it

Deleting a project removes it from the live database, on every device, at once. Closing your account removes the account and every project in it in the same operation — there is no window in which the account is gone and the work is not, and nothing is left behind for the next person who signs up with your address. Backups age out as described above.

Both are in the product: Profile → Danger zone closes the account, and the menu on a project card deletes one. Neither needs to be requested by email. Download a project as .json first if you may want it back.

Your rights

Under both regimes you may ask Flum to:

Access and deletion are self-service inside the product, which is faster than writing. For anything else, write to hello@flum.cc. Flum answers within the periods the law sets — under the GDPR, one month; under the LGPD, immediately for a simplified answer or within fifteen days for a full one — and does not charge for it.

If an answer does not satisfy you, you can complain to a supervisory authority: the ANPD in Brazil, your national data protection authority in the EEA, or the ICO in the United Kingdom.

No automated decisions

Nothing about you is decided automatically in a way that produces legal or similarly significant effects. There is no profiling, no scoring and no automated refusal of service — the anti-abuse check in front of the sign-in form judges the request, not the person, and a failed check can be retried.

Cookies and what your browser stores

Flum sets no advertising or analytics cookies, and there is no consent banner because there is nothing to consent to. What exists is strictly necessary to the service you asked for:

All of it is cleared by signing out and clearing site data for this site in your browser.

Security

Access to a project is restricted at the database, connections are encrypted in transit, the application sends a content security policy that limits what a page may load, and the deploy token described above is never transmitted to Flum at all. No service can promise that it will never be breached, and this page does not. If a breach affects your data and the law requires you and the authorities to be told, you will be told.

Children

Flum is not directed at children. Accounts are not knowingly created for anyone under 16 in the EEA and the United Kingdom, or under 13 elsewhere. If you believe a child has an account, write to hello@flum.cc and it will be closed and its data deleted.

Changes

When this page changes, the date at the top changes with it. Where a change materially affects how your data is handled, you are told by email at the address on your account, or in the product, before it takes effect.

Contact

hello@flum.cc