Privacy
Last updated 13 September 2026
Flum is a design tool, and it is in testing: not open to the public, with accounts given by invitation to a small number of people helping to test it. It needs an email address to know whose work is whose, and it needs somewhere to keep the designs. That is close to the whole of what it collects, and this page names the rest.
It is written to satisfy both the Brazilian LGPD (Lei 13.709/2018) and the European GDPR, including the UK version, because Flum is reachable from everywhere and it would be dishonest to write only for one of them. Where the two regimes give a right by different names, both names are here.
Who is responsible
The controller of this data — the controlador under the LGPD, the controller under the GDPR — is Flum, reachable at hello@flum.cc. That address reaches a person, and it is the address for every request on this page.
Flum has not appointed a data protection officer or an EU representative. It is a small service in testing, the processing described below is limited and low-risk, and neither appointment is required at this size. If that stops being true, this page says so before it stops being true.
What is collected
- Your email address. Used to sign you in, to send the six-digit codes that do it, and to send you notices about your account or about these policies. There is no marketing mail and no newsletter.
- Your name and profile picture, if you sign in through an identity provider and it hands them over. They are shown to you, in your own account, and nowhere else.
- Your projects. Each one is stored as a single compressed record, readable only by the account that owns it. That restriction is written into the database as a row-level security policy rather than left to the application to remember.
- Ordinary technical records. The services listed below keep the sort of logs any web service keeps — an IP address, a timestamp, a browser string — to deliver pages, block abuse and diagnose faults. Flum does not build profiles from them.
Flum runs no analytics, no tracking pixels, no session recording and no advertising identifiers. Your email address is not sold, rented, or traded. If any of that changes, the date at the top of this page changes with it, and the section below on changes says how you are told.
Why, and what allows it
The GDPR asks for a lawful basis for each purpose and the LGPD asks for a hipótese legal. They line up like this:
- Running your account and storing your projects — necessary to perform the contract you entered by using Flum. GDPR Art. 6(1)(b); LGPD Art. 7, II.
- Keeping the sign-in form from being used to send mail to strangers, through the anti-abuse check in front of it, and keeping the service standing generally — our legitimate interest in a service that is not abused, weighed against how little it costs you. GDPR Art. 6(1)(f); LGPD Art. 7, IX.
- Answering a request under this page, or a lawful order — a legal obligation. GDPR Art. 6(1)(c); LGPD Art. 7, II.
No consent is asked for because none of the above runs on consent. Nothing here is used for advertising, and there is no processing you would have to opt out of.
The deploy token never reaches us
If you connect a hosting provider to publish a site, the access token you paste is kept in your own browser and sent nowhere except to that provider’s own API. It is not transmitted to Flum, not written to Flum’s database, and so not present in Flum’s backups.
The cost of that choice is that the token does not follow you between browsers: connect the provider again on a new machine. Disconnecting deletes it from that browser. Sites already deployed stay up.
Who processes it
- A managed database and authentication provider, in the United States — where your account and your projects are stored.
- A content delivery and security provider — which serves these pages and runs the anti-abuse check in front of the sign-in form.
- An email delivery provider — which delivers the sign-in codes and account notices, and nothing else.
- An identity provider, if you choose to sign in through one. It tells Flum your email address, and your name and picture where you have them; Flum tells it nothing about you.
- A hosting provider, if you choose to publish a site — reached with your own credentials, not Flum’s.
Each acts on Flum’s instructions for that purpose alone and is bound by its own data processing terms. They are described by what they do rather than named, which is what the GDPR allows when it asks for the recipients or the categories of recipients (Art. 13(1)(e)).
You can have the names. Write to hello@flum.cc and Flum will tell you which companies these are — that is your right under GDPR Art. 15(1)(c) and LGPD Art. 18, VII, and it is answered without argument. The two you pick yourself, the identity provider and the hosting provider, are named in the product at the moment you choose them.
Where it goes
The database is in the United States, so your data is transferred there and processed there. If you are in Brazil, that is an international transfer under LGPD Art. 33. If you are in the EEA, the UK or Switzerland, it is a transfer under GDPR Chapter V, and it relies on the Standard Contractual Clauses the processors above incorporate into their terms, together with their own supplementary measures.
Sign-in emails pass through the email provider on their way to you, and every request reaches the service through a content delivery network, which is global by design.
How long it is kept
Your projects stay until you delete them or close your account. Backups of the database are taken on the hosting provider’s schedule — currently daily, retained for up to seven days — so a deleted project can persist in a backup for up to about a week after it is gone from the live database.
The technical logs described above are kept for as long as the service that produced them keeps them, which is typically days to a few weeks.
Deleting it
Deleting a project removes it from the live database, on every device, at once. Closing your account removes the account and every project in it in the same operation — there is no window in which the account is gone and the work is not, and nothing is left behind for the next person who signs up with your address. Backups age out as described above.
Both are in the product: Profile → Danger zone closes the account, and the menu on a project card deletes one. Neither needs to be requested by email. Download a project as .json first if you may want it back.
Your rights
Under both regimes you may ask Flum to:
- confirm whether it holds data about you, and give you a copy — LGPD Art. 18, I and II; GDPR Art. 15;
- correct anything incomplete or wrong — LGPD Art. 18, III; GDPR Art. 16;
- delete it — LGPD Art. 18, VI; GDPR Art. 17;
- hand it over in a portable, machine-readable form, or send it to another provider — LGPD Art. 18, V; GDPR Art. 20;
- restrict or object to processing that runs on legitimate interests — LGPD Art. 18, § 2º; GDPR Arts. 18 and 21;
- be told who it has been shared with — LGPD Art. 18, VII — and, under the LGPD, to be told the consequences of refusing to provide it, which for the email address is simply that there is no account.
Access and deletion are self-service inside the product, which is faster than writing. For anything else, write to hello@flum.cc. Flum answers within the periods the law sets — under the GDPR, one month; under the LGPD, immediately for a simplified answer or within fifteen days for a full one — and does not charge for it.
If an answer does not satisfy you, you can complain to a supervisory authority: the ANPD in Brazil, your national data protection authority in the EEA, or the ICO in the United Kingdom.
No automated decisions
Nothing about you is decided automatically in a way that produces legal or similarly significant effects. There is no profiling, no scoring and no automated refusal of service — the anti-abuse check in front of the sign-in form judges the request, not the person, and a failed check can be retried.
Cookies and what your browser stores
Flum sets no advertising or analytics cookies, and there is no consent banner because there is nothing to consent to. What exists is strictly necessary to the service you asked for:
- your sign-in session, kept by your browser so you are not asked to sign in on every page;
- your editor’s local state, and — if you connected one — your hosting provider’s token;
- a short-lived cookie the anti-abuse check may set while it decides whether a request is from a person.
All of it is cleared by signing out and clearing site data for this site in your browser.
Security
Access to a project is restricted at the database, connections are encrypted in transit, the application sends a content security policy that limits what a page may load, and the deploy token described above is never transmitted to Flum at all. No service can promise that it will never be breached, and this page does not. If a breach affects your data and the law requires you and the authorities to be told, you will be told.
Children
Flum is not directed at children. Accounts are not knowingly created for anyone under 16 in the EEA and the United Kingdom, or under 13 elsewhere. If you believe a child has an account, write to hello@flum.cc and it will be closed and its data deleted.
Changes
When this page changes, the date at the top changes with it. Where a change materially affects how your data is handled, you are told by email at the address on your account, or in the product, before it takes effect.