Skip to main content

Last updated August 2, 2026

Privacy and Data Protection Policy

Byteflare AI is a proposal and scoping platform for freelancers, agencies, and enterprise teams. This policy explains, in plain English, what data we hold, why we hold it, who else sees it, how long we keep it, and what you can ask us to do about it.

Clause

1. Scope of This Policy

This Privacy and Data Protection Policy explains how Byteflare AI handles information when you visit our website, create an account, invite colleagues into a workspace, draft and send client proposals, or pay for a subscription. It covers the marketing site, the signed-in product, our public tools, and the proposal links you share with your clients.

It does not cover third-party websites you reach from links inside a proposal or from our site, or the way your own clients handle documents once you send them. Where this policy refers to the GDPR it means the EU General Data Protection Regulation and the UK GDPR, which we apply to all users regardless of where they are based.

This policy sits alongside our Terms of Service, which govern your use of the product.

Clause

2. Who We Are and How to Contact Us

Byteflare AI is the data controller for the personal data described in this policy — that is, we decide why and how it is processed. For the content you and your team put into the product (your client briefs, scopes, and proposals) we act as a processor on your behalf, and you remain the controller of any personal data contained in it.

  • Controller: Byteflare AI, 548 Market St PMB 62466, San Francisco, CA 94104, United States.
  • Privacy and data protection enquiries: privacy@byteflare.app
  • General product support: support@byteflare.app
  • Legal notices: legal@byteflare.app

We have not appointed a dedicated Data Protection Officer, because our processing does not meet the Article 37 thresholds that require one. Privacy requests are handled directly by the team at the address above. We do not currently have an establishment in the EU or the UK; if we appoint an Article 27 representative, their details will be published here.

Clause

3. Personal Data We Collect About You

This is data that identifies you as a Byteflare user. We collect it because you give it to us, or because it is generated automatically when you use the service.

  • Account and authentication data: your email address, password credentials held by our authentication provider, and — if you choose to sign in with Google — the account identifier and email address Google returns to us. We never receive your Google password.
  • Profile data: display name, chosen avatar, and your theme and workspace preferences.
  • Plan and trial data: your current plan, whether you have used your free trial, and when a trial ends.
  • Organisation and membership data: the workspaces you belong to, your role in each one (owner, admin, or member), your membership status, and the email addresses used to invite people into a workspace.
  • Branding data: the business name and logo image your organisation uploads for white-labelled proposals.
  • Billing and subscription data: customer and subscription identifiers from our payment provider, subscription status, billing interval, currency, amount, and any scheduled cancellation date. We do not receive or store full card numbers.
  • Usage and product analytics: pages and features used, events such as generating a scope or exporting a PDF, along with the browser and device information and approximate location that our analytics provider derives from your IP address. This category is only collected if you accept analytics cookies.
  • Technical and security data: IP addresses and request metadata used for rate limiting, abuse prevention, and error diagnostics.
  • Correspondence: the content of emails and support requests you send us.
  • Referral data: a referral code stored in your browser if you arrive through a referral link, and recorded on your profile if you then sign up.

Clause

4. Customer Content We Process For You

Separately from the account data above, Byteflare stores and processes the working content you create. We treat this as yours. We do not sell it, we do not use it to train AI models, and we do not use it for advertising.

  • Project records: project names, client names, and the briefs, notes, emails, and requirements you paste in.
  • Generated scopes and proposals: deliverables, pricing, timelines, assumptions, exclusions, terms, and every revision you keep.
  • Templates: the reusable scope, pricing, and terms templates saved in your workspace.
  • Proposal delivery records: whether a proposal link is active, expired, or revoked, when a proposal was viewed, and any acceptance a client records against it, including the name they enter.
  • Proposal engagement records: when a shared proposal link is opened, and how long each section of the proposal is read for. These events are recorded against a pseudonymous viewer identifier that is derived separately for every proposal link, so the same reader cannot be linked across two different proposals. We do not store the reader's IP address or browser user-agent alongside these events, and automated traffic such as link previews, crawlers, and messaging-app fetchers is discarded rather than recorded.
  • Workspace activity: favourites, visit history within your own workspace, trashed items, and the audit-style records that show which member did what.

Your client briefs may contain personal data about your clients and their staff. You decide what to put into Byteflare, so you are the controller of that information and are responsible for having a lawful basis to share it with us. We process it only to provide the service to you and on your instructions.

Clause

5. Why We Process Data, and Our Lawful Basis

Under Article 6 of the GDPR every purpose needs a lawful basis. Ours are set out below, purpose by purpose.

  • Creating and running your account, storing your projects, and generating scopes and proposals — performance of a contract (Article 6(1)(b)).
  • Sending, expiring, and revoking client proposal links, and recording views and acceptances — performance of a contract with you; legitimate interests in giving both sides a reliable record of what was sent (Article 6(1)(b) and (f)).
  • Recording that a shared proposal was opened and which sections were read, so that the sender knows whether their proposal reached its recipient and can follow up: legitimate interests (Article 6(1)(f)). We do not rely on consent here, because the reader of a proposal is not a Byteflare user and never sees our consent notice. We limit the impact of this by storing a per-link pseudonymous identifier rather than an IP address, by discarding automated traffic, and by making the results visible only to the sender. You can object at any time (see section 11).
  • Organisation membership, roles, invitations, and access control — performance of a contract, and our legitimate interest in keeping workspaces secure (Article 6(1)(b) and (f)).
  • Taking payment, managing subscriptions and seats, and issuing invoices — performance of a contract and compliance with tax and accounting obligations (Article 6(1)(b) and (c)).
  • Service emails such as password resets, invitations, trial reminders, and billing notices — performance of a contract (Article 6(1)(b)).
  • Security, rate limiting, fraud prevention, and abuse detection — legitimate interests in protecting the service and its users (Article 6(1)(f)).
  • Error monitoring and crash diagnostics — legitimate interests in keeping the product working correctly (Article 6(1)(f)).
  • Optional product analytics, usage measurement, and session replay — your consent (Article 6(1)(a)), given through the consent notice and withdrawable at any time.
  • Responding to support requests — performance of a contract and legitimate interests in helping our users (Article 6(1)(b) and (f)).
  • Complying with legal obligations and defending legal claims — legal obligation and legitimate interests (Article 6(1)(c) and (f)).

Clause

6. How AI Processing Works

Byteflare uses large language models to turn briefs into structured scopes, suggest pricing and timelines, generate clarifying questions, and analyse text in our public tools. To do that, the text you submit for a given request is sent to a third-party model provider, processed, and returned as a draft. Nothing is generated locally on our servers.

  • Anthropic (Claude models) is our primary model provider. It receives the brief or text you submit, the surrounding project context needed for the request, and our instructions.
  • Amazon Web Services (Amazon Bedrock) is used as a fallback provider when the primary provider is unavailable, and receives the same request content.

We only send the content required for the request you triggered. We do not send your password, your payment details, or other users' projects. Both providers are engaged as processors under terms that prohibit using submitted content to train their models, and both are instructed to retain content only as long as needed to return a response and meet their own abuse-monitoring obligations.

AI output is a draft for you to review and edit. No decision with legal or similarly significant effects is made about you automatically, and there is no automated profiling of you within the meaning of Article 22.

If a brief contains personal data you would rather not send to a model provider, remove or redact it before generating. Once you press generate, that text has been transmitted.

Clause

7. Processors and Sub-Processors

We share data with a small number of vendors who help us run the service. Each one is bound by a contract that limits them to processing on our instructions, and each receives only what it needs.

  • Supabase — authentication, database, and file storage. Receives your account credentials and email, profile, organisation, project, proposal, and template records. Hosted in the United States.
  • Vercel — application hosting and content delivery. Processes request metadata such as IP address, user agent, and URL in order to serve pages.
  • Anthropic — AI model inference. Receives the content you submit for generation, as described in section 6.
  • Amazon Web Services (Amazon Bedrock) — fallback AI model inference. Receives the same content when the primary provider is unavailable.
  • Paddle.com Market Limited — Merchant of Record for subscriptions. Receives your name, email, billing address and country, payment-method details entered in its hosted checkout, and transaction history. Paddle acts as an independent controller for the payment processing it performs.
  • Stripe and Lemon Squeezy — alternative payment processors used where a workspace is billed through them instead of Paddle. Each receives the billing details needed to take payment and returns subscription status to us.
  • PostHog — product analytics. Receives event names, page paths, device and browser information, an IP-derived approximate location, and your user identifier once signed in. Only used if you accept analytics cookies. Requests are proxied through our own domain so they are not blocked by default browser settings.
  • Vercel Analytics — aggregate page-view and performance measurement. Only loaded if you accept analytics cookies.
  • Sentry — error monitoring. Receives stack traces, the URL and browser state at the time of an error, and your user identifier. Session replay and personally identifiable enrichment are only enabled if you accept analytics cookies; basic error reporting runs regardless because it is necessary to keep the service working and secure.
  • Upstash — Redis cache used for rate limiting. Receives short-lived counters keyed to a user identifier or IP address. No proposal content is stored there.
  • Google — only if you choose to sign in with Google. Google authenticates you and returns your email address and account identifier.

We do not sell personal data, we do not share it with data brokers, and we do not run advertising or advertising cookies on this site. If we add or replace a processor we will update this list.

Clause

8. International Transfers

Byteflare is operated from the United States, and the processors listed above are primarily based in or route data through the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, your data will therefore be transferred outside your home region.

For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), incorporated into our agreements with each processor, together with technical measures such as encryption in transit and at rest. You can request a copy of the safeguards that apply to a specific transfer by emailing privacy@byteflare.app.

Clause

9. How Long We Keep Data

We keep data only as long as we need it for the purpose it was collected for, or as long as the law requires.

  • Account, profile, organisation, and membership records: for as long as your account is open.
  • Projects, scopes, proposals, and templates: for as long as your account is open, so you can revisit and reuse them. Items you move to trash are removed when you empty it.
  • Proposal link, view, and acceptance records: for as long as the parent project exists, so you retain a record of what was sent and agreed.
  • Deleted accounts: when you delete your account we remove your projects, generated scopes, templates, favourites, visit records, checkout sessions, workspace memberships, profile, and authentication record. Residual copies may persist in encrypted backups for a short period before those backups rotate out.
  • Billing and tax records: retained by us and by our payment provider for as long as tax and accounting law requires, typically seven years. This survives account deletion because we are legally obliged to keep it.
  • Analytics events: retained by our analytics provider under its standard retention schedule and deleted or anonymised when it expires. If you withdraw consent we stop sending new events.
  • Error monitoring data: kept for a limited diagnostic window, normally no longer than 90 days.
  • Rate-limiting counters: short-lived, expiring within minutes to hours.
  • Support correspondence: kept for up to 24 months after the conversation ends.

Clause

10. Cookies and Similar Technologies

We keep our use of cookies and browser storage deliberately small, and we split it into two categories. There is no third category: we do not use advertising, retargeting, or social media tracking cookies.

  • Strictly necessary — set without consent because the product cannot work without them. These include your authentication session cookies, the cookie that records which workspace you are working in, a short-lived referral cookie if you arrived through a referral link, the cookie that stores your consent decision itself, and browser storage that remembers your light or dark theme.
  • Analytics — only set after you press Accept in the consent notice. These are the product analytics and page-measurement cookies and identifiers used by PostHog and Vercel Analytics, plus Sentry session replay. They tell us which features are used and where people get stuck.

If you press Reject, no analytics scripts are loaded at all, no analytics cookies are set, session replay stays off, and our servers stop sending your usage events. Everything else in the product continues to work exactly as before.

Engagement recording on shared proposal links is separate from the choice above and is not controlled by the consent notice. When someone opens a proposal that one of our users has sent to them, we record that view and the reading time per section against a pseudonymous, per-link identifier. This sets no cookies and stores nothing on the reader's device, so it is not a cookie choice to make. We rely on legitimate interests for it, as set out in section 5, and it can be objected to under section 11.

Your decision, and the date you made it, are stored in a first-party cookie that lasts twelve months so we do not ask again on every visit. You can change your mind at any time using the Cookie preferences link in the footer of any page, or by clearing cookies in your browser.

Clause

11. Your Rights Under the GDPR

If the GDPR applies to you, you have the following rights. We will respond within one month, and we will not charge you for exercising them. We may ask you to confirm your identity first, and if a request is manifestly unfounded or excessive we will explain why before refusing it.

  • Access — ask what personal data we hold about you and get a copy. Much of it is already visible in your account settings; for a full export, email privacy@byteflare.app.
  • Rectification — correct data that is wrong or incomplete. Your name, avatar, and preferences can be edited directly in Settings; email us for anything you cannot change yourself.
  • Erasure — delete your account and its content from Settings, under Account. This removes your profile, projects, scopes, templates, favourites, visit records, and workspace memberships. Billing records we must keep for tax purposes are retained, and we will tell you what those are on request.
  • Restriction — ask us to pause processing while a dispute about accuracy or lawful basis is resolved. Email privacy@byteflare.app and we will freeze the relevant data rather than delete it.
  • Portability — receive the data you gave us in a structured, machine-readable format, or ask us to send it to another provider where technically feasible. Individual proposals can be exported as PDFs from the product; for a full machine-readable export, email privacy@byteflare.app.
  • Objection — object to processing we carry out on the basis of legitimate interests, including security analytics, diagnostics, and proposal engagement recording. Email privacy@byteflare.app explaining your situation and we will stop unless we have compelling grounds that override your rights.
  • Withdrawal of consent — withdraw your consent to analytics at any time using the Cookie preferences link in the footer and pressing Reject. This takes effect immediately and does not affect processing carried out before you withdrew.
  • Automated decisions — we do not make decisions about you by automated means that produce legal or similarly significant effects, so there is nothing to opt out of. AI-generated drafts are always reviewed by a person, namely you.

If a request concerns content inside a workspace you do not own, we may need to route it through the workspace owner, because they are the controller of that content.

Clause

12. Complaints to a Supervisory Authority

If you think we have handled your data badly, please contact privacy@byteflare.app first — we would rather fix it directly. You also have the right to complain to a data protection supervisory authority, and you do not need to speak to us first.

In the EEA you may complain to the supervisory authority in the country where you live, work, or where the issue occurred; the full list is published by the European Data Protection Board. In the United Kingdom, the relevant authority is the Information Commissioner's Office. In Switzerland, it is the Federal Data Protection and Information Commissioner.

Clause

13. Children's Data

Byteflare is a business tool for professional use. It is not directed at children, and you must be at least 18 years old to open an account. We do not knowingly collect personal data from children.

If we learn that we hold data belonging to a child, we will delete it. If you believe a child has given us their data, email privacy@byteflare.app and we will act on it promptly.

Clause

14. How We Protect Data

We apply security measures appropriate to the sensitivity of what we hold, and we review them as the product grows.

  • Encryption in transit using HTTPS everywhere, and encryption at rest for the database and file storage.
  • Row-level access rules in the database so members can only reach the workspaces and projects they belong to.
  • Role-based access control inside the product, with owner, admin, and member permissions enforced on the server rather than only in the interface.
  • Proposal links that can be expired or revoked, and which serve a frozen snapshot so a shared document cannot be silently altered after the fact.
  • Rate limiting and abuse protection on public endpoints and on AI generation.
  • A strict content security policy and standard browser hardening headers.
  • Payment card details handled entirely inside our payment provider's hosted checkout, so they never reach our servers.
  • Internal access to production data limited to the people who need it to operate and support the service.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will tell affected users without undue delay where the risk is high.

Clause

15. Changes to This Policy

We update this policy when the product changes, when we add or replace a processor, or when the law requires it. The date at the top of this page always reflects the current version.

For material changes — a new purpose, a new category of data, or a new processor receiving your content — we will notify you by email or in the product before the change takes effect. If a change affects what you consented to, we will ask for your consent again through the consent notice rather than assuming your previous answer still applies.

Clause

16. Contact Us

Questions, requests, and complaints about privacy are all welcome at the same address, and a person reads them.

  • Email: privacy@byteflare.app
  • Post: Byteflare AI, 548 Market St PMB 62466, San Francisco, CA 94104, United States