Privacy Policy

Last updated: February 11, 2026

1. Information We Collect

When you create a Superflag account we collect your email address and password (stored as a hash). When you use the service we store the apps, environments, and feature flag configurations you create.

We automatically collect basic usage data such as config sync request counts per environment. This powers the metered billing on your account and is not shared with third parties.

2. How We Use Your Information

  • To provide and maintain the Superflag service
  • To track usage for billing purposes (config sync requests)
  • To send transactional emails related to your account
  • To respond to support requests

3. Data Storage and Security

Your data is stored in secure, managed databases. API keys are hashed with SHA-256 before storage and are only displayed once at creation time. We use HTTPS for all data in transit.

4. Third-Party Services

We use the following third-party services to operate Superflag:

  • Convex — database and backend infrastructure
  • Stripe — payment processing
  • Vercel — hosting and analytics

Each service has its own privacy policy. We do not sell your data to any third party.

5. Your Rights

You can export or delete your data at any time by contacting us. Deleting your account will remove all associated apps, environments, flags, and keys.

6. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes by posting the new policy on this page with an updated date.

7. Contact

If you have questions about this privacy policy, reach out at support@superflag.sh.