Privacy Policy

Last updated: July 2026

What we store

Your account profile (email, display name), the blueprints you create, the companies you launch (mission briefs, agent configurations, messages, tasks, deliverables, cost records), and evaluation scores of dissolved companies.

This data exists to run your missions and show you their history. We do not sell it, share it with advertisers, or use it to train models.

Your API keys

FlashCo runs on a bring-your-own-key model. Your LLM API key is encrypted with AES-256-GCM before storage and decrypted only inside our runtime at the moment a request to your provider is made.

Keys are never shown to agents, never included in model context, and every tool output is scanned to redact credential-shaped strings before it reaches a model. You can delete your key at any time in Settings; we recommend setting a spend limit directly with your provider.

Integration credentials

When you connect integrations (GitHub, Notion, Slack, content systems, etc.), tokens and credentials are encrypted at rest per company, used only to execute the tool calls your agents make for that company, and destroyed with the company's data when you delete it.

OAuth-based integrations use standard authorization flows — we store only the tokens the provider issues, never your passwords.

Third-party processors

FlashCo runs on Supabase (database, authentication, file storage), Vercel (web hosting), and Fly.io (agent runtime). Your LLM traffic goes directly from our runtime to your model provider (e.g. Anthropic) under your own key. If paid features are enabled, payments are processed by Stripe — we never see your card details.

Deletion

Dissolved companies can be permanently deleted from your dashboard, which removes their messages, tasks, deliverables, and credentials. Deleting your API key removes it immediately. For full account deletion, contact us and we will remove your profile and associated data.

Research context

FlashCo is an open research reference implementation. We may analyze aggregated, de-identified usage patterns (e.g. average mission cost, pattern effectiveness scores) to improve multi-agent system design and publish findings. Published research never includes your mission content, deliverables, or identity.

Contact

Questions about this policy or your data: kacem.aitoual@gmail.com.