Privacy

Privacy Policy

Flame is built local-first. Choose between the Desktop IDE or Website policy below.

Last updated: August 29, 2026

Flame IDE Summary: Flame is a local-first desktop application. Source code, workspaces, git repositories, terminal sessions, and credentials stay solely on your machine. AI requests travel directly between your machine and your chosen model provider. Telemetry is optional and off by default.

Looking for companion app disclosures? Read the Flame Mobile Privacy Policy or the Flame Browser Bridge Privacy Policy.

1. Local-first desktop environment

This section applies specifically to the Flame IDE desktop application installed on your computer (macOS, Windows, Linux).

Flame is engineered from the ground up as a local-first development environment. You do not need to create an account with Flame to use the editor, build code, run terminals, or manage local projects. The desktop application contains no advertising SDKs, tracking pixels, or web cookies.

2. What stays on your device

Your source code, projects, workspace files, editor configurations, terminal sessions, personal settings, paired-device records, and local logs stay exclusively on your device. Nothing leaves your machine unless you deliberately use a connected service, configure a remote AI provider, establish an encrypted Remote Access session, or manually submit a diagnostic crash report.

3. Your code, integrations, and AI providers

When you ask an AI agent to act within Flame, prompts and the relevant workspace context you include are sent directly from your computer to the model provider you configure(such as Anthropic, OpenAI, Google, or custom API endpoints), subject to that provider's privacy policy and terms. Flame does not proxy, inspect, or store your prompts or source code on our servers.

If you configure a local on-device model (such as through Ollama or llama.cpp), all AI interactions remain strictly on your local machine with zero network transmission. Integrations with git hosts (GitHub, GitLab), CI systems, and package registries communicate directly between your machine and those services. Flame IDE also contacts its HTTPS update service periodically to check for new software releases.

4. Remote Access and Secure Relay

Remote Access is disabled by default. If you choose to enable Anywhere mode, your host computer and paired client device establish an end-to-end encrypted session through Flame Secure Relay. The relay server never receives the encryption keys and is cryptographically incapable of reading files, terminal sessions, Git data, AI conversations, or any workspace content.

The relay processes only transient connection metadata necessary to route traffic: online registration status, rotating rendezvous identifiers, connection timing, byte volume, and the IP addresses of the active network sockets. Live IP addresses are held only in volatile memory during the connection and are never saved to disk. Encrypted payloads are relayed in real time and never stored. Pairing does not require creating an account, email address, or name.

The web companion interface is delivered from connect.flame-ide.com. Remote Access can be toggled off at any time in Flame Settings.

5. Telemetry and crash reports

App version and OS telemetry: optional and off by default. Flame can report which version you run and your operating system, helping us understand which versions are in active use and when legacy operating systems can be retired safely. Flame sends zero telemetry until you explicitly opt in on the User Agreement screen or in Settings → Diagnostics, and you can disable it at any time.

When enabled, the payload is restricted to six coarse fields: app_version, release_channel, os_platform, os_version, arch, install_type (for example 0.1.9, stable, windows, Windows 11, x64, installer), accompanied by a locally generated random identifier. The OS version is deliberately generalized (e.g. major versions like "Windows 11" or "Linux") to prevent device fingerprinting.

Telemetry never includes your name, email, hostname, OS username, file paths, project names, source code, terminal commands, AI prompts, or hardware serial numbers. The random identifier is stored locally; disabling telemetry deletes the file immediately, and re-enabling generates an entirely new identifier so the two periods cannot be linked. You can preview the exact payload in Settings before deciding.

This data is processed via Google Analytics Measurement Protocol. Google receives connection IP addresses as part of standard HTTPS requests, but Flame neither stores nor links them; Google Signals and ad personalization are permanently disabled. Event-level data is automatically purged after two months.

Crash reports are entirely separate and require manual confirmation. If an unexpected error occurs, a report is saved locally on your machine. It is transmitted only if you review and explicitly choose to send it. Flame automatically redacts your operating-system username and home directory paths prior to compilation. Reports contain app runtime versions, stack traces, and error context, and do not contain project source code.

6. Data processors used for IDE services

For features within the desktop application that involve network transmission, we use the following vetted providers:

  • Google LLC (Measurement Protocol): Only while you have version/OS telemetry switched on, anonymous OS/version messages are reported into an isolated desktop telemetry property.
  • Relay & Update Hosting Infrastructure: Delivers signed software updates and powers the content-blind Secure Relay service. Relay hosts process encrypted packets and standard network routing metadata without access to plaintext data.

International data transfers are covered by standard contractual safeguards, including the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.

7. Desktop data retention

Local IDE data remains on your computer until you remove it or uninstall Flame. Diagnostic event data from the optional desktop telemetry setting is retained in Google Analytics for two months before automated deletion; aggregate version counts describe software builds rather than individuals. Flame Secure Relay operates entirely in volatile memory and does not persist IP addresses, connection logs, or encrypted payloads.

8. Your privacy rights and contact

Under the General Data Protection Regulation (GDPR), UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA), you have enforceable rights regarding personal information. Because Flame stores no accounts, code, or personal identifiers for the IDE, diagnostic data is tied only to an anonymous random UUID that you can purge at any time by toggling off the setting.

For privacy inquiries, contact the data controller at support@flame-ide.com.