Scope
This policy explains how Grant Williams, a Georgia sole proprietor doing business as Flante ("Flante," "we," "us," or "our"), handles personal information through this website, the Flante macOS application, and the services that support them. It does not govern files after you export them to your own computer, Google Drive, or Anki, or the independent practices of third-party services.
Information we collect
Website and waitlist. If you join the broader-access list, we collect your email address, consent choice, signup source, status, and signup time. For abuse prevention, the website stores a one-way hash derived from an IP address to count submission attempts without retaining the address itself in the waitlist database. Hosting providers may also process ordinary request information such as IP address, browser or device type, requested pages, and timestamps.
Account, eligibility, and support. The app processes your email address, password through the authentication provider, user ID, invitation and access status, current-student and adult-purchaser attestations, eligibility review and expiration dates, email-update preference, account timestamps, and a randomly generated device identifier used to enforce one active device. We verify control of an eligible Mercer email and may manually approve or reverify pilot eligibility; we do not ask for a student-ID image or class schedule during ordinary enrollment. Authentication and Google tokens are stored in macOS Keychain. We receive the contents of messages you send to support.
Billing. Paddle collects payment details and processes checkout as merchant of record. Flante receives and stores limited billing records such as your Paddle customer and subscription identifiers, billing email, price, subscription and payment status, trial and billing-period dates, cancellation state, refunds, and webhook event identifiers. Flante does not receive your complete card number or card security code.
Course and generation content. The app processes the reading guides, learning objectives, source names, relevant excerpts, selected figures, instructions, prior drafts, generated notes, citations, and other content you choose to use. For Anki features, it may also process generated notes, coverage targets, selected card text, source information, and selected image candidates needed for AI-assisted planning, matching, or card drafting. Anki collection scanning and final card or deck changes occur locally through AnkiConnect.
Operational records. We process generation status, topic title, objective count, timing and phase information, errors, model-response identifiers, token usage, cost, and similar reliability, security, and service-operation records. A separate pooled timing sample contains only an operation type, duration, repair-pass indicator, and objective count; it does not contain an account, device, topic, objective text, notes, or sources.
How we use information
We use information to create and authenticate accounts; verify paid-pilot eligibility; create and administer trials and subscriptions; prevent duplicate trials and account sharing; provide, recover, and improve generation and Anki features; export files at your direction; secure the service and enforce device and abuse controls; diagnose failures; estimate completion times; monitor reliability and cost; respond to support, refund, and privacy requests; send product updates when you opt in; and comply with law or protect users, Flante, and others. We do not use course content for advertising.
Local processing and cloud processing
Imported workspace text, extracted figures, generated-history copies, and exports are stored locally on your Mac unless you choose to transmit or export them. When you use AI-assisted features, the content needed for that request is encrypted in transit and sent to Flante’s backend and OpenAI. This can include excerpts, objectives, selected images, prior notes, revision instructions, and the limited Anki content described above. Do not submit protected health information or other sensitive or confidential information that Flante is not authorized and configured to receive.
Google Drive
Google Drive access is optional. Flante requests the drive.file scope, which allows it to access files it creates or files and folders you explicitly select for use with the app. Google access and refresh tokens are stored in macOS Keychain and removed from the Mac when you disconnect. Disconnecting locally does not itself revoke access at Google; you can also revoke Flante in your Google Account permissions.
When inserting a local figure into a native Google Doc, Flante uploads the asset to the destination you selected, briefly creates a public-read link so Google Docs can retrieve it, and then requests removal of that permission. If a cleanup request fails, the permission may remain until you remove it in Google Drive. Flante’s use and transfer of information received from Google APIs is limited to providing and improving the user-facing Drive export feature and complies with the Google API Services User Data Policy, including its Limited Use requirements.
Service providers and disclosures
We disclose information only as needed to operate the service, at your direction, or for the legal and safety reasons described below. Current providers include Supabase for authentication, database, storage, backend functions, and entitlement records; OpenAI for AI-assisted generation and source lookup; website hosting and database infrastructure; Google when you choose Drive export; and Paddle for checkout, subscription administration, receipts, applicable transaction-tax handling, fraud prevention, payment recovery, refunds, chargebacks, and billing support. Payment information is entered on Paddle’s secure checkout rather than collected directly by Flante.
Providers process information under their own terms and privacy commitments. OpenAI may retain API prompts, responses, images, and related metadata for abuse monitoring or application-state purposes under the configuration and policies applicable to Flante’s API account. OpenAI states that API data is not used to train its models unless the API customer affirmatively opts in. See OpenAI’s API data controls.
We may also disclose information when reasonably necessary to comply with law or legal process; investigate fraud, abuse, or security incidents; enforce our Terms of Use; protect rights, safety, and service integrity; or complete a merger, financing, acquisition, reorganization, or transfer of the service, subject to appropriate notice and protections where required.
Sale, advertising, and tracking
Flante does not sell personal information, share it for cross-context behavioral advertising, or use third-party advertising trackers. We do not currently use advertising cookies or analytics cookies. Essential authentication or hosting technologies and ordinary server logs may still be used to operate and secure the website.
Retention
Imported workspace data and local history remain on your Mac until you remove them, reset the workspace, delete the account through the app, or uninstall and remove the app’s data. Server-side generation batches, jobs, passes, and recoverable generated results are assigned a seven-day expiration and are deleted through periodic cleanup; deletion may occur after the exact expiration time. Shared qualified-literature cache entries, which contain search queries, source metadata, and excerpts but no user identifier, are assigned a 30-day expiration.
Account, access, device-session, email-preference, user-linked operational, and cost records are generally retained while the account exists and deleted when the account is deleted, subject to backups, security needs, legal obligations, and records that must be retained to establish or defend legal claims. Minimum billing, transaction, entitlement, refund, and webhook records may remain after account deletion for tax, accounting, fraud, chargeback, refund, and legal recordkeeping; these records do not include course content. Pooled timing samples are retained for service estimation until no longer useful. Waitlist records remain until you ask us to remove them or they are no longer needed for access communications. Hashed rate-limit records remain until they are no longer needed for security or abuse prevention. Our providers may retain information under their own applicable retention rules.
Your choices and requests
You may manage or cancel your subscription through Paddle, disconnect Google Drive, revoke Flante through Google, decline or opt out of optional product-update email, and delete your Flante account in the app. Account deletion first requests immediate cancellation of an active subscription, then removes the authentication account and associated app-account records through database deletion rules, and the app removes its local workspace and saved tokens. If billing cancellation cannot be confirmed, deletion is stopped so a renewal cannot become invisible. Deletion does not automatically remove a separately submitted website-waitlist record, delete files already exported to your folders, Google Drive, or Anki, remove minimum billing records described above, or immediately remove provider backups or records retained where legally permitted.
You may ask to access, correct, or delete personal information, or withdraw an email preference, by contacting us. We may need to verify your identity and may retain information where an exception applies. Depending on where you live, you may have additional privacy rights and a right to appeal a denied request. We will not discriminate against you for exercising an applicable privacy right.
Security
Flante uses safeguards intended to protect information, including encrypted network transport, macOS Keychain for tokens, authenticated backend requests, row-level database access controls, request-size limits, and account and device checks. No storage or transmission system is completely secure, so we cannot guarantee absolute security. If you believe your account or information has been compromised, contact us promptly.
Health and institutional information
Flante is a study tool and is not designed or offered as a system for protected health information. We do not represent that Flante is configured for HIPAA-regulated use, and use of the service does not create a business associate agreement. Do not submit identifiable patient information, protected health information, education records, examination material, or other institutional information unless you are lawfully authorized to disclose it to Flante and every involved provider—and unless Flante has expressly confirmed in writing that the service is configured for that use.
Children
Flante is intended for adult postsecondary students. The paid Service is not offered for purchase by anyone under 18. We do not knowingly collect personal information from children under 13. If you believe a child has submitted personal information, contact us so we can investigate and delete it where appropriate.
Changes to this policy
We may revise this policy as the service, providers, or legal requirements change. We will post the revised policy with a new last-updated date and provide additional notice when required by law or when a change materially affects how previously collected information is used.
Contact
For privacy questions or requests, email flantenotes@gmail.com. Please do not include patient information, passwords, or other sensitive content in an email request.