Who this policy covers
Flared is the placeholder name for the service operator. The legal operator, address, jurisdiction, and privacy contact will be confirmed before launch. This draft describes the planned hosted service separately from this marketing preview.
Self-hosted installations run in their owner’s Cloudflare account. The installation owner controls their data and is responsible for the privacy information they provide to visitors. Flared does not receive default telemetry or standing administrative access from self-hosted installations.
This marketing website
This preview does not include advertising trackers, third-party analytics scripts, signup collection, or nonessential cookies. Fonts and logo assets are served locally. Hosting infrastructure may process technical request information to deliver and secure the site. Links to GitHub and other providers lead to services with their own privacy policies.
Account and service information
When the hosted service launches, it will process your verified email address, account and workspace information, links and their destinations, domain configuration, and usage. Cloud sign-in uses emailed one-time codes or magic links. Session cookies support authentication.
Polar will handle checkout and payments as merchant of record. Flared will retain subscription and billing references needed to apply your plan. Payment-card details are handled by the payment provider, not stored by Flared. Cloudflare provides hosting, storage, queues, and transactional email.
What click analytics records
The planned analytics pipeline records aggregate click totals and daily breakdowns by country, device category, and referring hostname where available. It does not store raw IP addresses, full user-agent strings, or complete referrer URLs in product analytics.
Clicks are not unique people. Bot filtering is best effort, test traffic is labeled, and missing or delayed analytics is reported. Flared does not use visitor cookies or cross-site identifiers for this analytics feature. Infrastructure security logs are separate from product analytics.
Security and operator access
The service design uses HTTPS, managed encryption at rest, tenant isolation, and restricted, audited operator access. Authorized operators can technically access hosted data for support, security, and operations. We do not describe hosted analytics as end-to-end encrypted or operator-blind.
A public short link reveals its destination when followed. Do not use a short URL as access control for confidential content.
Retention and deletion
Planned aggregate retention is 30 days on Free and 365 days on Plus. Export files expire after 24 hours. Operational logs retain at most seven days; administrative audit records and minimal deletion tombstones retain 90 days. Email-delivery status expires after 30 days.
Deleting an account starts an asynchronous deletion process that revokes credentials, disables routing, and removes tenant data. Minimal domain-and-slug reservations remain permanently so an old short address cannot be reassigned. These reservations contain no tenant identity or destination.
Cloudflare recovery history may retain deleted data for its recovery window, up to 30 days for the hosted deployment. Restore procedures must reapply deletion records. A downgrade includes a 30-day export grace period for older history.
Questions and privacy requests
The privacy contact and request process are placeholders pending confirmation of the operator. They must be completed before account registration opens. Depending on applicable law, you may have rights concerning access, correction, deletion, objection, restriction, or portability of your personal information.
The operator’s jurisdiction, processing grounds, international transfer arrangements, and applicable request procedures will be finalized before this policy takes effect.