Privacy Policy
Flame is built local-first. Connected features share only the context needed for the action you choose.
The short version: workspace data stays local by default. AI providers and other services receive information only when you use the connected feature. Remote Access is optional; its Secure Relay can carry encrypted workspace traffic but cannot read it.
Looking for the Chrome extension disclosures? Read the Flame Browser Bridge Privacy Policy.
1. Information we collect
We aim to collect as little as possible. Depending on how you use Flame, that may include:
- The email address (and optional name) you give us to join the early-access waitlist, subscribe to our mailing list, or create an account.
- Which kinds of email you asked to receive — for example release notes or new-feature announcements — so we only send you those.
- The name, email address, and message you submit through our contact form, so we can respond to you.
- Crash-report details only when you explicitly choose to send a locally saved report.
- Your Flame version and operating system from the desktop app — only if you turn that on. It is off by default, tied to a random number generated on your computer, and never carries your name, files, project names, or paths. See section 6.
- A short-lived, one-way hashed value derived from your IP address when you submit the waitlist form. We use it only to prevent abuse and rate-limit submissions; we do not store your raw IP address for this purpose.
- Anything else you choose to send us (for example, a support message).
2. What stays on your device
Flame is a local-first desktop app. Your projects, files, editor state, terminal sessions, settings, paired-device records, and local logs stay on your device unless you deliberately use a connected feature, submit a report, or share that information with us.
3. How we use information
We use the limited information above to send your early-access invite and the updates you selected, respond to your messages, and improve Flame's reliability and performance. Joining the early-access waitlist also subscribes you to product updates; once your invite is sent we remove you from the waitlist and keep only that subscription. Every email we send carries a link to change which updates you receive or to unsubscribe entirely — unsubscribing deletes your address from both the mailing list and the waitlist, and we keep no record of it. We do not sell your personal information, and we do not use your data to train models.
4. Your code and AI providers
When you ask an AI agent to act, prompts and the context you include may be sent directly to the model provider you configure, subject to that provider's terms. The same principle applies to git hosts, CI systems, issue trackers, and other integrations. With a local compatible model, model requests stay on your machine. Flame may also contact its update service over HTTPS when the desktop app checks for a newer version.
5. Remote Access
Remote Access is off when you do not need it. If you choose Anywhere mode, your computer and paired device establish an end-to-end encrypted session through Flame Secure Relay. The relay does not receive the session key and cannot read files, terminal traffic, Git content, AI conversations, or other workspace content.
The relay processes limited connection metadata: that a host registration is online, short-lived rendezvous identifiers, connection timing and byte volume, and the IP addresses of the two live network connections. Live IP addresses are held in memory for the connection and are not written to disk. Encrypted workspace payloads are relayed, not stored. Pairing does not require a Flame account, email address, or name.
The browser companion is JavaScript delivered from connect.flame-ide.com. Its delivery origin and build pipeline are part of Flame's trust boundary. Remote Access is optional and can be turned off in Flame.
6. Telemetry and crash reports
Version and operating system — optional, off by default. Flame can tell us which version you are running and which operating system you are on, so we know which versions are still in use and when an old OS can safely be dropped. It sends nothing until you tick the optional box on the User Agreement screen or in Settings → Diagnostics, and you can turn it back off at any time.
When it is on, the entire message is six values — app_version, release_channel, os_platform, os_version, arch, install_type (for example 0.1.9, stable, windows, Windows 11, x64, installer) — plus a random number generated on your computer. The OS version is deliberately coarse: a major version like "Windows 11", and every Linux system reports simply "Linux", because a precise build number would help narrow down individual machines.
It never carries your name or email, your hostname or OS username, file names or paths, project or repository names, source code, terminal output, AI prompts, hardware identifiers, or your locale and timezone. There is no free-text field of any kind. The random number is not derived from your hardware, we hold nothing linking it to you, and turning the setting off deletes it — turning it back on generates a new one, so the two periods cannot be linked. You can see the exact message your computer would send, before deciding, from the "?" next to the checkbox.
This is processed by Google LLC using Google Analytics. Because the message travels over the internet, Google receives the connection IP address as it would for any web request; we neither receive nor store it, Google Signals and ad personalization are off, and it is never used for advertising. Event-level data is retained for two months.
Crash reports are separate and still manual-send. They are saved on your device and transmitted only if you explicitly choose to send one. You can review the full report first, and Flame redacts your home directory and operating-system username before building it. Reports may include the app version, operating system, runtime versions, error details, and crash context; they are not intended to include project source code.
7. Cookies and tracking (this website)
This section is about flame-ide.com, not the desktop app. The app uses no cookies and has no tracking scripts; the only thing it can send is the optional version/OS message in section 6, which is a separate choice made inside the app.
On this website we use Google Analytics 4 (GA4) and Google Tag Manager (GTM) to understand website performance, user journeys, and improve our services. These tools drop performance and analytics cookies on your browser.
We respect your privacy choices: these non-essential cookies load only if you expressly consent via our cookie banner (GDPR compliant), which defaults to "denied" until you choose. You can change or withdraw your consent at any time using the Cookie settings link in our footer, which reopens the banner. We also honor Global Privacy Control (GPC) browser signals as an opt-out, and we keep Google Signals and ad personalization disabled so analytics is never used for advertising.
8. Sharing and processors
We share personal information only with the service providers (sub-processors) needed to operate, under appropriate data-protection agreements. These currently include:
- Google LLC: Google Analytics 4 and Google Tag Manager, for website metrics — and, only while you have it switched on, the optional desktop version/OS message described in section 6. The website and the app report into separate Analytics properties.
- Our waitlist and email delivery provider: to store waitlist sign-ups and send early-access invites and release notes.
- Infrastructure providers used to operate Flame services: to deliver the website, updates, the browser companion, and the content-blind Secure Relay. Relay providers receive encrypted traffic and ordinary network metadata, not plaintext workspace content.
Where these providers process data outside your region (for example, in the United States), transfers are covered by appropriate safeguards such as the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses. We do not sell your personal information, and we do not share it for cross-context behavioral advertising (complying with CCPA/CPRA).
9. Data retention
Local data remains on your device until you delete it or uninstall Flame. Information sent to Flame IDE is kept only as long as needed for support, security, legal, audit, or dispute resolution purposes. Waitlist and mailing-list email addresses are encrypted at rest and access is restricted to the systems and people that need it to operate early access and send the updates you asked for; when you unsubscribe, the record is deleted rather than kept on a suppression list. Google Analytics identifiers expire automatically according to standard rules, and event-level data from the optional desktop version/OS message is retained for two months; the aggregate counts derived from it describe versions and platforms, not people. Flame Secure Relay does not persist IP addresses or encrypted workspace payloads; short-lived rendezvous identifiers rotate automatically.
10. Your rights
You can request access to, correction of, or deletion of your personal information at any time by emailing support@flame-ide.com.
Under GDPR (for European Union users) and CCPA/CPRA (for California users), you have rights to access, delete, rectify, or opt-out of the sharing of your personal data. We honor Global Privacy Control (GPC) signals sent by your browser as a valid opt-out, and we will never discriminate against you for exercising your privacy rights.
11. Children
Flame is not directed to children, and we don't knowingly collect their data.
12. Changes to this policy
We may update this policy as Flame evolves. We'll post the new version here and update the date above; significant changes will be communicated to waitlist members.
13. Who we are and how to contact us
The data controller responsible for your personal information is Flame IDE. Questions about privacy or to exercise your rights? Email support@flame-ide.com.
EU, EEA, and UK users also have the right to lodge a complaint with their local data protection authority.