Privacy Policy

Last updated: May 2026

This Privacy Policy describes how Flitch Solutions Pty Ltd ABN 57 682 821 512 of 191 St Georges Terrace, Perth, WA 6000, Australia ("Flitch", "we", "us" or "our") collects, uses, and discloses your personal information when you visit our website at flitch.io, use our AI dashboard creation platform, or otherwise interact with us. This policy is designed to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Information We Collect

We collect the following kinds of personal information:

Information You Provide Directly

  • Account Information: Name and email address when you sign in via Google or Microsoft OAuth.
  • Profile Information: Company name, job title, and other details you choose to provide.
  • Payment Information: Billing address and payment details (processed securely by Stripe; we do not store card numbers).
  • Communications: Information you provide when contacting us for support or feedback.

Information Collected Automatically

  • Usage Data: Information about how you use our services, including dashboards created, features accessed, and interaction patterns.
  • Device Information: IP address, browser type, operating system, device identifiers, and screen resolution.
  • Log Data: Server logs including access times, pages viewed, and referring URLs.

Information from Third Parties

  • Authentication Providers: If you sign in via Google or Microsoft, we receive your name and email address from those services.
  • Data Connections: When you connect external data sources (databases, spreadsheets), we access only the data you authorise for dashboard creation.

User Content

  • Data Files: CSV files, Excel spreadsheets, and files you turn into data on the Data page via Upload & extract (PDFs, documents, images). The dataset is stored in encrypted cloud storage (Amazon S3). Only metadata (column names, data types, row counts) is stored in our database. For Upload & extract, the original source file is stored in S3 too and read to pull out its data. The dataset and any source file are deleted when you delete the dataset.
  • Data Connections: Data accessed through connections you configure (databases, cloud storage, APIs). Connected data is queried live and not copied to our database. We store connection credentials and metadata only.
  • Prompts and Instructions: Text prompts you provide to generate dashboards.
  • Prompt Attachments: Images and GeoJSON map files attached during dashboard creation or update, used as visual and map context (not data). Images kept with the dashboard persist until the dashboard is deleted. The temporary upload buffer is cleared within 24 hours. To turn a document into data, use Upload & extract on the Data page.

Sensitive Information: We do not intentionally collect sensitive information (such as health information, racial or ethnic origin, political opinions, or biometric data). If your uploaded data contains sensitive information, you are responsible for ensuring you have appropriate consent and legal basis to share that data with us.

2. How We Collect and Store Information

Collection Methods

  • Direct collection: Through account registration forms, support communications, and service usage.
  • Automated collection: Through cookies, server logs, and analytics tools when you use our platform.
  • Third-party collection: Through authentication providers (Google, Microsoft) when you choose to sign in with those services.

Storage and Security

Your personal information is stored on secure servers provided by Amazon Web Services (AWS) located primarily in the United States. We implement industry-standard security measures including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Access controls and authentication requirements
  • Regular security assessments and monitoring
  • OAuth-only authentication (no password storage)

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, maintain, and improve our AI dashboard creation platform.
  • Account Management: To create and manage your account, process transactions, and provide customer support.
  • AI Processing: To process your prompts and data through AI models to generate dashboards (see Section 4 for details).
  • Communications: To send you technical notices, updates, security alerts, and administrative messages.
  • Analytics and Session Replay: To understand how users interact with our services and diagnose issues. This includes page views, feature usage, and recordings of user interactions with sensitive content (data tables, chat messages, connection details) masked. For visitors in the EU, UK, EEA, and Switzerland, analytics and session replay only run with your explicit consent via our cookie banner.
  • Security: To detect, investigate, and prevent fraudulent transactions, abuse, and other harmful activities.
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes.

4. AI and Automated Decision-Making

Our platform uses artificial intelligence to generate dashboards based on your prompts and data. This section explains how AI processes your information in accordance with APP 1.7-1.9.

How AI Is Used

  • Dashboard Generation: AI models process your text prompts and uploaded data to generate dashboard code, visualisations, and layouts.
  • Content Suggestions: AI may suggest chart types, colour schemes, or data transformations based on your data.
  • Error Correction: AI assists in identifying and fixing issues in generated code.

Information Used by AI

  • Text prompts you provide describing desired dashboards
  • Data structure metadata (column names, types, row counts) from your uploaded files or connected sources. A sample of rows is read at generation time and sent to AI providers as part of the request, but is not stored in our database.
  • Your preferences and selected options during dashboard creation

AI Model Providers

We use the following third-party AI providers to process your requests:

  • Anthropic (Claude): United States
  • Google (Gemini): United States

Your prompts and data context are sent to these providers for processing. We do not permit these providers to use your data for training their models. Processed data is not retained by AI providers beyond the immediate request.

Decisions Made by AI

AI systems make the following types of decisions during dashboard generation:

  • Selection of appropriate chart types and visualisations
  • Layout and design choices for dashboard components
  • Data transformation and aggregation approaches
  • Code structure and implementation patterns

These decisions relate to content generation and do not affect your legal rights, access to services, or account standing. You retain full control to modify, regenerate, or reject AI-generated content.

5. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

Service Providers

We share information with third-party service providers who perform services on our behalf:

  • Amazon Web Services (AWS): Cloud infrastructure and hosting (United States)
  • Stripe: Payment processing (United States)
  • Anthropic: AI model services (United States)
  • Google: AI model services and authentication (United States)
  • Microsoft: Authentication services (United States)
  • Resend: Email delivery services (United States)
  • Neon: Database services (United States)
  • PostHog: Product analytics and session replay (United States)
  • Sentry: Error monitoring and session replay (United States)
  • Modal: Sandbox compute for dashboard previews (United States)
  • Railway: Hosting for published dashboards on view.flitch.io (United States)
  • Cloudflare: Content delivery, DNS, and web application firewall (United States)
  • Vercel: Application hosting and edge infrastructure (United States)

Other Disclosures

  • Legal Requirements: When required by law, court order, or governmental authority, or to respond to legal process.
  • Protection of Rights: To protect the rights, property, or safety of Flitch, our users, or others.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with appropriate safeguards for your data.
  • With Your Consent: In other ways with your explicit consent or at your direction.
  • Team Members: If you are part of a team account, certain information may be visible to team administrators.

6. International Data Transfers

We are likely to disclose personal information to overseas recipients. Your information may be transferred to and processed in the following countries:

  • United States: Our primary infrastructure (AWS), payment processing (Stripe), AI providers (Anthropic, Google), and other service providers are located in the United States.

Before disclosing personal information to overseas recipients, we take reasonable steps to ensure that the recipient does not breach the Australian Privacy Principles. This includes:

  • Entering into contractual arrangements that require recipients to handle personal information in accordance with the APPs
  • Selecting service providers with robust privacy and security practices
  • Conducting due diligence on recipient privacy practices

By using our services, you acknowledge that your personal information may be transferred to and processed in countries outside Australia, which may have different data protection laws than Australia.

7. Data Security

We implement appropriate technical and operational measures to protect your personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Our security measures include:

  • Encryption of data in transit using TLS/SSL
  • Encryption of sensitive data at rest
  • Secure authentication, with multi-factor authentication available through Google and Microsoft sign-in
  • Regular security assessments and vulnerability testing
  • Access controls limiting employee access to personal information
  • Secure development practices and code review processes
  • Incident response procedures

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.

8. Data Breach Notification

In accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988, if we experience a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:

  • Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable
  • Notify affected individuals as soon as practicable
  • Provide information about the breach, including the type of information involved and recommended steps individuals should take

We maintain incident response procedures to assess and respond to potential data breaches within the required timeframes.

9. Retention of Data

We retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy:

  • Account Information: Retained while your account is active. After account closure, you have a 14-day grace period to cancel the deletion and recover your data, after which it is permanently deleted.
  • Dashboard Data: Retained while your account is active. You may delete individual dashboards at any time.
  • Usage Logs: Generally retained for up to 12 months for security and analytics purposes.
  • Payment Records: Retained as required by tax and accounting laws (typically 7 years).
  • Support Communications: Retained for a reasonable period to provide ongoing support and improve our services.

When personal information is no longer needed, we will take reasonable steps to destroy or de-identify it.

10. Your Rights

Under the Australian Privacy Principles, you have the following rights regarding your personal information:

  • Access: You may request access to the personal information we hold about you. We will respond to your request within a reasonable period (generally 30 days).
  • Correction: You may request that we correct any personal information that is inaccurate, out-of-date, incomplete, irrelevant, or misleading.
  • Deletion: You may request deletion of your account and associated personal information, subject to our legal obligations to retain certain records.
  • Data Export: You may export your dashboards and data through our platform's export features.
  • Opt-out: You may opt out of marketing communications at any time by clicking the unsubscribe link in our emails or contacting us.

To exercise these rights, please contact us using the details in Section 13. We may need to verify your identity before processing your request. In some circumstances, we may refuse a request, such as where granting access would unreasonably impact another person's privacy or where we are required by law to retain information.

11. Complaints

If you believe we have breached the Australian Privacy Principles or mishandled your personal information, you may lodge a complaint with us.

How to Lodge a Complaint

Please contact our Privacy Officer:

  • Email: [email protected]
  • Subject Line: Privacy Complaint
  • Address: 191 St Georges Terrace, Perth, WA 6000, Australia

Our Complaint Handling Process

  1. We will acknowledge receipt of your complaint within 5 business days.
  2. We will investigate your complaint and aim to respond within 30 days.
  3. If we need more time, we will let you know and explain why.
  4. We will inform you of the outcome and any actions we have taken.

External Complaints

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we may also notify you by email. We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your rights, or want to access or correct your personal information, please contact us:

Privacy Officer

Email: [email protected]

Address: 191 St Georges Terrace, Perth, WA 6000, Australia