Privacy policy
Your data, no spin.
Last updated: July 2026. This page describes what Flambeau processes, why, where, for how long — and how to exercise your rights (GDPR).
The principle first: we cannot read your capsules
The content of your capsules is encrypted in your browser, before anything is sent. Our servers only store encrypted data, which neither Flambeau nor its hosts can decrypt. The recovery phrase, the only decryption key, is never transmitted to us. Details on the Security page.
The data we process
To provide the service (legal basis: performance of the contract):
- Your account: email address, name (optional), language, watchkeeper settings, sign-in and proof-of-life timestamps.
- Your recipients: the name and email address you enter, and their public cryptographic material. By saving them, you entrust us with data about third parties: only do so for people you genuinely intend a capsule for. They are contacted only at the moment of a delivery, never before, never for anything else.
- Your capsules: encrypted content (unreadable to us) and cleartext metadata — title, type, recipient, dates. Do not put sensitive information in a title.
- The watchkeeper: the history of life checks and deliveries (necessary for operation and for the traceability of triggering).
- Support: the messages you write in the help chat, tied to an anonymous identifier.
That's all. No ad trackers, no third-party analytics, no reselling of data — to anyone, ever.
Cookies
A single, strictly necessary cookie: your sign-in session (httpOnly, secure). The help widget keeps a conversation identifier in your browser. No advertising or audience-measurement cookies — which is why you see no consent banner: there is nothing to consent to.
Where your data lives
The database is hosted in Frankfurt (Germany, EU) and our processing runs in the same region. Our processors:
- Neon (database, hosted on AWS Frankfurt);
- Vercel (application hosting, functions run in Frankfurt);
- Resend (email delivery: sign-in links, life checks, deliveries);
- Mistral AI (help-chat assistant: your support messages may be processed by its API to generate a reply — never the content of your capsules, which we do not hold in the clear).
Mistral AI is a French company. Neon, Vercel and Resend are US companies operating under EU-recognized transfer safeguards (standard contractual clauses / Data Privacy Framework). A useful reminder: even with access to the database, the content of your capsules stays encrypted.
For how long
Your data is kept for as long as your account exists — that is the very nature of the service: a capsule must be able to wait for years. Expired tokens (sign-in, verification) become unusable immediately. If you delete your account, everything is erased: capsules, recipients, history, sessions.
Your rights
Access, rectification, erasure, portability, objection — the GDPR fully applies:
- Delete your account: directly from your settings — immediate and permanent erasure of all your data.
- Destroy a capsule: at any time from your vault.
- Any other request (access, rectification, question): via the help chat at the bottom of the page — a human replies.
You may also lodge a complaint with your data protection authority (for France, the CNIL — cnil.fr) if you believe your rights are not respected.
See also: Security · Legal notice