Privacy Policy
Last updated June 14, 2026
Flash Papers (“Flash Papers”, “we”, “us”) is operated by Intertwine Financial Technologies LLC. This policy explains what data we collect when you use flashpapers.ai, why we collect it, and the choices you have. We have tried to keep both the service and this policy data-minimal: you bring your own AI key, and we store as little about you as the product allows.
Information we collect
- Account information. When you sign in with Google, we receive your name, email address, profile image URL, and Google account identifier. We use these to create and authenticate your account.
- Your AI provider API key (BYOK). If you choose to save an API key for an AI provider — Google (Gemini), Anthropic (Claude), or OpenRouter — we store it encrypted at rest using AES-256-GCM. It is decrypted only in memory, only to make the generation request you ask for, and it is sent only to the provider you selected for that paper. We never log it, never display it back to you in full (only the last few characters), and never share it with any third party other than the AI provider it belongs to. You can remove it at any time from your dashboard.
- Content you generate.For each Flash Paper, we store the source paper URL you submit, the generated HTML, an inferred title, status, timestamps, and token counts. Generated papers are published at a public, unlisted URL (“/p/…”) so you can share them.
- Usage analytics. We use Plausible Analytics, a privacy-friendly, cookieless service. It does not use cookies, does not collect personal data, and does not track you across other websites. We see aggregate page-view and event counts, not individuals.
- Technical logs. Like any web service, our servers process standard request metadata (such as IP address and browser user-agent) transiently for security and operation.
How we use your information
- To authenticate you and operate your account.
- To generate Flash Papers at your request, using your own AI provider API key.
- To store and display the papers you create.
- To keep the service secure, reliable, and abuse-free.
- To understand aggregate usage so we can improve the product.
We do not sell your personal information, and we do not use your papers or API key to train any model.
Service providers we share data with
We rely on a small set of infrastructure providers (subprocessors). Each receives only the data needed to perform its function:
- Google — sign-in (OAuth) and, if you generate with Gemini, the Gemini API. When you generate a paper with Gemini, your Google API key and the paper you submit are sent to Google and handled under Google’s Privacy Policy and the Gemini API terms.
- Anthropic — the Claude API. If you generate with a Claude model, your Anthropic API key and the paper you submit are sent to Anthropic and handled under Anthropic’s Privacy Policy and the Anthropic API terms.
- OpenRouter — model routing. If you connect OpenRouter and generate with it, your OpenRouter credential and the paper you submit are sent to OpenRouter (which forwards the request to the underlying model provider you chose) and handled under OpenRouter’s Privacy Policy and the OpenRouter terms.
- Neon — managed PostgreSQL hosting for our database.
- Google Cloud Platform — server hosting for the application.
- Cloudflare — domain registration and DNS.
- Plausible — privacy-friendly, cookieless analytics.
Cookies
We use a single essential cookie to keep you signed in. We do not use advertising or cross-site tracking cookies, and our analytics provider is cookieless.
Data retention and deletion
We keep your account data and papers until you delete them. You can remove your saved API key at any time from your dashboard, and you can permanently delete your entire account — your profile, your encrypted API key, and all of your generated papers — directly from your dashboard. You can also email us at [email protected] to request deletion. Aggregate, non-identifying analytics may persist.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data. You can manage your API key and delete your account directly from your dashboard; to exercise any of these other rights, contact us at [email protected]. We will respond within a reasonable time.
Security
All traffic is served over HTTPS. Your AI provider API key is encrypted at rest with AES-256-GCM and is never written to logs. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your data and minimize what we hold in the first place.
Children
Flash Papers is not directed to children under 13, and we do not knowingly collect personal information from them.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be made reasonably prominent.
Contact
Questions or requests? Email us at [email protected].