Privacy policy
How information is handled across the Flitten marketing website, Flitten Prompts, and Flitten Pages. These shared policies also cover Flitten Resources (tools and books).
Updated 2 October 2026 · Covers Marketing, Prompts, Pages, and Resources
Policy draft: operator identity, support contact, and paid-offer details are pending. These pages do not claim legal certification or replace the terms that must be supplied before payment.
Who handles your information
Flitten operates these services. Contact [email protected] for privacy, legal, and support requests. For access, plans, and general inquiries, message @flittenacademy on Messenger (https://m.me/flittenacademy). These policies cover the shared Flitten brand; Prompts and Pages remain separate products with separate user records and sign-in sessions.
A Google account is mandatory for both products. Your requested Google email is used to grant and check access separately for Prompts and Pages. An inactive or expired grant prevents new sign-in and authenticated use.
Information we process
Google sign-in provides your account identifier, verified email address, display name, and profile information available through the requested sign-in permissions. Prompts can also store a separate AI connection authorization, planning ideas, answers, prompt versions, settings, limits, and subscription expiry information.
Pages stores account information, private uploaded ZIP drafts, archive inspection results, website names and addresses, selected finished files, publishing metadata, usage, and ZIP-check counters. Website files you publish are public. Do not upload credentials, private records, or information that must remain confidential.
Payment and support handling may require contact details, payment references, transaction confirmations, and correspondence. Do not send passwords, bank login details, card credentials, bKash PINs, or verification codes.
Why we use it
We use information to authenticate you, save and resume your work, generate requested planning output, publish and manage websites, enforce limits and subscription access, handle support and payment verification, and protect the service from abuse. We do not install advertising or analytics trackers on the marketing website.
Where a lawful basis or consent is required by the law that applies to you, processing must rely on an appropriate basis. Optional browser preferences are stored only when you allow them.
AI processing and Google
When you request AI planning through a connected account in Prompts, relevant ideas, answers, and project context are sent to Google’s AI service to produce the requested response. Your sign-in permission and AI connection are separate. Disconnecting the AI connection stops its future use through Flitten.
Pages does not send ZIP contents or dependencies to AI to inspect or build your website. Archive inspection and extraction take place on the hosting server. Google sign-in and AI processing are also subject to Google’s applicable terms and privacy practices.
Hosting, public content, and providers
Flitten uses hosting infrastructure and databases to provide the services. Google processes sign-in and requested AI activity. If a deployment uses Cloudflare Tunnel or other network infrastructure, that provider can process traffic and network information to route and protect requests.
Public website visitors can access files you publish through Pages. Third-party scripts or embeds that you include can collect visitor information independently. You are responsible for those integrations, disclosures, and permissions.
Product interfaces can also request font resources from Google Fonts. These resource requests transmit ordinary network and browser information needed to fetch the fonts. The marketing website uses system fonts and does not make those font requests.
Support access and security
Authorized administrators can manage account access and subscription time. In Prompts, a limited support impersonation session can be used to view the workspace as a user. Administrative functionality is restricted, and the support session is time limited.
We use measures such as server-side access checks, separate product sessions and databases, encrypted stored AI credentials, input bounds, and isolation of public hosted files. No service can promise absolute security. Report suspected exposure promptly and revoke affected third-party permissions where appropriate.
Retention and deletion
Account and project records are retained while needed to operate your account, satisfy a paid offer, investigate abuse, or meet applicable recordkeeping obligations. Private Pages ZIP drafts expire after 24 hours and are cleaned when their owner opens the workspace; drafts are removed after publication or discard. Published files remain available until the site is deleted or otherwise removed.
Deleting a website removes its active address and hosted release. Updates replace the public release and remove earlier hosted releases. Backup copies, provider records, legal records, and information required for disputes may remain subject to their retention processes. Account closure requests require identity verification. We do not promise an unimplemented automatic deletion deadline.
Your choices and requests
You can sign out, disconnect AI access in Prompts, remove your projects or websites using available product controls, and change marketing cookie preferences. You may request access, correction, deletion, or other rights available under applicable law through the published privacy contact.
The services are not designed for collecting sensitive personal information from children. Do not provide such information in prompts or uploaded files. We may need to verify your identity and explain any lawful restrictions before completing a request.
Resources tools and library
Many Resources tools process selected files locally in your browser. Tools that call external APIs send the requested inputs to those providers; review the tool’s instructions before submitting sensitive information. Books and covers load from cdn.flitten.com through Cloudflare R2. Normal request data, such as IP address and browser headers, reaches the hosting provider.
The reader and tools can store preferences, progress, watchlists, or local working data in browser storage. Use their reset controls or clear site storage to remove it. Resources has no advertising scripts or ad-blocker checks. Navigation to third-party sites follows their policies.
Operator and contact
Operator identity not yet published.
A verified support and privacy contact will be published here before paid offers are made available.