Privacy Policy
Welcome to Flints ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application and services (collectively, the "Service").
Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
1. Information We Collect
a. Information You Provide Directly
We collect the following information that you voluntarily provide when you create an account and use the Service:
- Account Information: Your name, email address, and profile picture, obtained through Google OAuth authentication. We never store your password — authentication is handled entirely by Google.
- Notes and Content: All notes, folders, tags, knowledge-map links, and other content you create, edit, or store within Flints. This includes the text of your notes and the [[links]] you create between them.
- Shared Content: Notes or knowledge maps you choose to share publicly via a shareable link. Once shared publicly, anyone with the link can view that content.
- User Preferences: Settings you configure within the Service, such as your preferred language, theme (dark/light mode), and view mode (list/map).
- Correspondence: Messages and any attachments you send us when you contact us for support, feedback, or otherwise.
b. Information Collected Automatically
When you access the Service, we may automatically collect the following information through standard server logging and application diagnostics:
- Usage Data: Which features you use, actions you take, frequency of use, session duration, and navigation patterns within the application.
- Device Information: Browser type and version, operating system, device type (desktop, tablet, mobile), screen resolution, and language settings.
- Log Data: IP address, access times and dates, pages viewed, referring URLs, and HTTP status codes. Server logs are automatically rotated and deleted after 90 days.
- Cookies and Similar Technologies: Session cookies and local storage, described in detail in Section 5. See Section 5 for full details on these technologies.
c. Information We Do NOT Collect
In the interest of transparency, we want to be explicit about what we do not collect:
- Payment Information: Flints is currently a completely free service. We do not collect, process, or store any payment card numbers, billing addresses, or financial account information.
- Precise Location Data: We do not use GPS, Wi-Fi triangulation, or any other method to determine your precise geographic location.
- Biometric Data: We do not collect fingerprints, facial recognition data, voiceprints, or any other biometric identifiers.
- Social Media Profiles: Beyond your Google account name and email used for authentication, we do not access or collect information from your social media accounts.
- Third-Party Data Broker Data: We do not purchase or otherwise obtain personal data about you from third-party data brokers or marketing companies.
- Advertising Identifiers: We do not collect mobile advertising identifiers (IDFA, GAID) or use device-fingerprinting techniques to track users across devices for advertising purposes.
2. How We Use Your Information
We use the information we collect for the following specific purposes:
- To Provide and Maintain the Service: Creating and managing your account, storing your notes and their connections, powering the knowledge-map visualization, synchronizing your data across sessions, and enabling import/export functionality.
- To Improve the Service: Analyzing aggregated, anonymized usage patterns to enhance existing features, identify and fix bugs, optimize performance, and develop new capabilities. All analytics are performed on aggregated data that cannot reasonably be traced back to you individually.
- To Communicate With You: Responding to your support inquiries, providing customer assistance, and sending important service-related announcements (such as scheduled maintenance windows or security updates). We will never send marketing emails without your explicit opt-in consent.
- To Ensure Security and Prevent Abuse: Detecting, preventing, and responding to fraud, abuse of our Service, unauthorized access attempts, and other potentially harmful activity. This includes rate limiting, abuse detection, and security monitoring.
- To Comply With Legal Obligations: Meeting applicable regulatory requirements, responding to valid subpoenas, court orders, or other lawful requests from government authorities, and protecting our legal rights.
3. Legal Bases for Processing
If you are located in the European Union (EU), European Economic Area (EEA), United Kingdom, or another jurisdiction that requires a legal basis, we rely on the following legal bases to process your personal data:
- Performance of a Contract: We process your data to perform our Terms of Service, which form a contract with you when you create an account — for example, storing and syncing your notes.
- Legitimate Interests: We process data in pursuit of our legitimate business interests, such as improving the Service, preventing fraud, ensuring security, and analyzing system performance, provided these interests are not overridden by your privacy rights.
- Consent: Some processing — such as non-essential cookies or marketing communications (if introduced in the future) — relies on your explicit consent, which you may withdraw at any time.
- Legal Obligation: We process data where necessary to comply with applicable law, including tax and accounting regulations.
If you have questions about the legal basis for processing your personal data, please contact us using the details in Section 14 below.
4. How We Share Your Information
We do not sell, trade, or rent your personal information to any third party. We may share your information only in the following limited circumstances:
- With Your Explicit Consent: When you choose to share notes or knowledge maps via public links, the content of those specific notes becomes accessible to anyone who has the link. You can revoke public sharing at any time.
- With Service Providers: We may share limited information with trusted third-party providers who help us operate the Service (cloud hosting and infrastructure partners such as Render.com, and Google for authentication). These providers are contractually bound to use your data only to provide services to us, are subject to strict data-protection obligations, and are prohibited from using your data for their own purposes.
- For Legal Compliance: When required by law, regulation, court order, or other valid legal process, we may disclose your information. We will attempt to notify you of such requests unless prohibited by law or in cases involving imminent danger.
- In Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will provide advance notice via email and/or a prominent notice on the Service before your information becomes subject to a different privacy policy.
- As Aggregated and De-Identified Data: We may share aggregated, anonymized data that cannot reasonably be used to identify you — for example, by publishing statistics about overall usage patterns or system performance metrics.
Publicly shared notes are accessible to anyone with the link. We are not responsible for the actions of third parties who access publicly shared content. We recommend you carefully consider what you share publicly.
5. Cookies and Tracking Technologies
Flints uses a minimal set of cookies and local-storage technologies necessary for the Service to function properly:
- Session Cookies (Essential): Required for authentication, maintaining your logged-in session, and preventing cross-site request forgery (CSRF) attacks. These cookies are strictly necessary for the Service to function and cannot be disabled.
- Preference Cookies and Local Storage: Used to remember your application preferences across sessions, including your theme choice (dark/light mode), language selection, and view mode (list/map). These are stored in your browser's local storage and are not transmitted to our servers.
6. Data Security
We take the security of your data seriously and implement multiple layers of protection:
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher (HTTPS). We enforce HTTPS for all connections and support HSTS (HTTP Strict Transport Security).
- Secure Authentication: We use Google OAuth 2.0 for authentication. We never store, transmit, or have access to your Google password. Authentication tokens are securely managed and regularly rotated.
- Encryption at Rest: Your data is stored on encrypted storage volumes. Database backups are also encrypted.
- Access Controls: Our infrastructure follows the principle of least privilege. Only authorized personnel with a legitimate need can access production systems, and all access is logged and audited.
- Regular Audits: We conduct regular security assessments, code reviews, and dependency vulnerability scans. Critical and high-severity vulnerabilities are patched within 48 hours of discovery.
- Incident Response: We maintain a documented incident-response plan and will notify affected users within 72 hours of discovering a data breach, in accordance with applicable law.
While we strive to use commercially acceptable means to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents and notifying affected users.
7. Data Retention
We retain your personal information only for as long as necessary to provide the Service and fulfill the purposes described in this policy:
- Account Data: Retained for the lifetime of your account. When you delete your account, all account information is permanently removed within 30 days.
- Notes and Content: Retained until you choose to delete them or delete your account. You have full control over your content at all times and can delete individual notes or all notes at once.
- Publicly Shared Content: Retained until you explicitly revoke the share link or delete the content. Revoking a share link immediately makes the content inaccessible to the public.
- Log Data: Server access logs are automatically aggregated and deleted after 90 days. Error logs containing minimal information are retained for up to 30 days for debugging purposes.
- Support Communications: If you contact us for support, we may retain your correspondence for up to 2 years to maintain context for ongoing issues and improve our support quality.
Upon account deletion, we will permanently and irreversibly remove all your personal data, notes, and content within 30 days, except where retention is required by applicable law. We perform secure deletion using industry-standard methods.
8. Your Privacy Rights and Choices
Depending on your jurisdiction (including but not limited to the GDPR in the EU/EEA, the CCPA/CPRA in California, and the LGPD in Brazil), you may have the following rights regarding your personal data:
- Right to Access: You have the right to request a copy of the personal data we hold about you. We will provide this in a commonly used, machine-readable format within 30 days of your request.
- Right to Rectification: You have the right to request correction of any inaccurate or incomplete personal data. You can update your account information directly in your account settings.
- Right to Erasure ('Right to be Forgotten'): You have the right to request deletion of your personal data. Upon receiving such a request, we will permanently delete your data within 30 days unless retention is required by law.
- Right to Data Portability: You can export all your notes and data at any time in JSON format using the Export feature in Settings. This export includes all your notes, their content, and their connections.
- Right to Object: You have the right to object to the processing of your personal data for certain purposes, including direct marketing. We do not currently engage in direct marketing, but if this changes, you will have the ability to opt out.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing that occurred before the withdrawal.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
- Right to Lodge a Complaint: You have the right to file a complaint with your local data protection authority if you believe your rights have been violated.
Additional Information for California Residents (CCPA/CPRA)
The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant California residents additional rights over their personal information. We do not sell your personal information for monetary consideration, and we have not done so in the preceding 12 months. You may exercise your rights to know, delete, and correct your data, and to opt out of any "sale" (if applicable), by contacting us using the details in Section 14 — you are guaranteed not to be discriminated against for doing so.
To exercise any of these rights, please contact us at the email address provided below. We will verify your identity before processing your request and respond within 30 calendar days. There is no fee for exercising your rights, except in cases of manifestly unfounded or excessive requests.
9. Automated Decision-Making and Profiling
Flints does not use automated decision-making or profiling to make any decision about you that produces legal or similarly significant effects. Features within the Service, such as the knowledge map and link suggestions, operate entirely on your own content and are not used for external profiling or advertising purposes.
10. Children's Privacy
The Service is not intended for use by children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected personal data from a child under 13 without appropriate parental or guardian consent, we will take immediate steps to delete that information from our systems.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at the email address below. We will investigate and promptly remove any such information.
11. International Data Transfers
Flints is operated from Uzbekistan. If you access the Service from outside Uzbekistan, your information may be transferred to, stored, and processed in Uzbekistan or other countries where our infrastructure providers operate.
We ensure that any international transfers of personal data are conducted in accordance with applicable data protection laws, including implementing appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms where required.
12. Third-Party Links and Services
The Service may include integrations with third-party services such as Google OAuth, or may contain links to third-party websites within user-generated content. We are not responsible for the privacy practices, content, or security of such third-party services or websites. This Privacy Policy applies solely to Flints, and we encourage you to review the privacy policy of any third-party site you may visit.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other operational reasons. When we make material changes, we will notify you by:
- Posting the updated policy on this page with a revised "Effective date" at the top.
- Displaying a prominent notice within the Service, such as a banner notification.
- Sending an email notification to the address associated with your account (for material changes).
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy. If you do not agree with the revised policy, you should stop using the Service and contact us to delete your account.
14. Contact Us
If you have any questions, concerns, complaints, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: joraboyevismoiljon649@gmail.com
- Address: Flints, Fergana, Uzbekistan
- Response Time: We will endeavor to acknowledge your inquiry within 2 business days and provide a substantive response within 30 calendar days.
For data protection inquiries related to the EU/EEA, you may also contact your local data protection supervisory authority.
This Privacy Policy was last updated on July 18, 2026.