Privacy
Last updated 13 September 2026
Flum is a design tool. It needs an email address to know whose work is whose, and it needs somewhere to keep the designs. That is the whole of what it collects, and this page names all of it.
What is collected
- Your email address. Used to sign you in and to send the six-digit codes that do it. Nothing else is sent to it — there is no newsletter and no product mail.
- Your projects. Each one is stored as a single compressed record, readable only by the account that owns it. This is enforced by the database itself, not by the app asking politely.
- Nothing else. There is no analytics, no tracking pixel, no session recording, and no advertising identifier anywhere in Flum. Your email is not sold, rented, or shared.
The deploy token never reaches us
If you connect Vercel to publish a site, the access token you paste is kept in your own browser and sent nowhere except to Vercel’s own API. It does not travel to Flum’s servers and it is not in any backup, which means a breach of Flum cannot be used to deploy to your Vercel account.
The cost of that choice is that the token does not follow you between browsers: connect Vercel again on a new machine. Disconnecting deletes it from that browser. Sites already deployed stay up.
Who processes it
- Supabase — the database and the accounts, hosted in the United States (us-east-1).
- Cloudflare — hosting, DNS, and the anti-abuse check in front of the sign-in form.
- Resend — delivery of the sign-in emails, and nothing else.
- Google or GitHub — only if you choose to sign in with one. They tell us your email address and nothing more; we tell them nothing about you.
- Vercel — only when you publish a site, and using your own credentials, not ours.
Because the database is in the United States, your data is transferred there. If you are in Brazil, this is an international transfer under the LGPD, and using Flum is your agreement to it.
How long it is kept
Your projects stay until you delete them or close your account. Backups are taken daily and kept for seven days, so a deleted project can survive in a backup for up to a week before it is gone for good.
Deleting it
Deleting a project deletes it everywhere, on every device. Closing your account deletes the account and every project in it in the same operation — there is no window where the account is gone and the work is not, and nothing is left behind for the next person who signs up with your address.
Both are in the product: Profile → Danger zone closes the account, and the menu on a project card deletes one. Neither needs to be requested by email. Download a project as .json first if you may want it back.
Your rights
Under the LGPD you may confirm what is held, access it, correct it, ask for it in a portable form, and have it deleted. Access and deletion are self-service, as above. For anything else, write to hello@flum.cc.
Cookies
Flum sets no advertising or analytics cookies. Your browser keeps your sign-in session, your editor’s local state, and — if you connected one — your Vercel token. All of it is cleared by signing out and clearing site data.
Children
Flum is not directed at children under 13 and accounts are not knowingly created for them.
Changes
If this page changes in a way that matters, the date at the top changes with it and the account gets an email before the change takes effect.