Privacy Policy
Last updated: May 2026
This Privacy Policy describes how Flitch Solutions Pty Ltd ABN 57 682 821 512 of 191 St Georges Terrace, Perth, WA 6000, Australia ("Flitch", "we", "us" or "our") collects, uses, and discloses your personal information when you visit our website at flitch.io, use our AI dashboard creation platform, or otherwise interact with us. This policy is designed to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Information We Collect
We collect the following kinds of personal information:
Information You Provide Directly
- Account Information: Name and email address when you sign in via Google or Microsoft OAuth.
- Profile Information: Company name, job title, and other details you choose to provide.
- Payment Information: Billing address and payment details (processed securely by Stripe; we do not store card numbers).
- Communications: Information you provide when contacting us for support or feedback.
Information Collected Automatically
- Usage Data: Information about how you use our services, including dashboards created, features accessed, and interaction patterns.
- Device Information: IP address, browser type, operating system, device identifiers, and screen resolution.
- Log Data: Server logs including access times, pages viewed, and referring URLs.
Information from Third Parties
- Authentication Providers: If you sign in via Google or Microsoft, we receive your name and email address from those services.
- Data Connections: When you connect external data sources (databases, spreadsheets), we access only the data you authorise for dashboard creation.
User Content
- Data Files: CSV files, Excel spreadsheets, and files you turn into data on the Data page via Upload & extract (PDFs, documents, images). The dataset is stored in encrypted cloud storage (Amazon S3). Only metadata (column names, data types, row counts) is stored in our database. For Upload & extract, the original source file is stored in S3 too and read to pull out its data. The dataset and any source file are deleted when you delete the dataset.
- Data Connections: Data accessed through connections you configure (databases, cloud storage, APIs). Connected data is queried live and not copied to our database. We store connection credentials and metadata only.
- Prompts and Instructions: Text prompts you provide to generate dashboards.
- Prompt Attachments: Images and GeoJSON map files attached during dashboard creation or update, used as visual and map context (not data). Images kept with the dashboard persist until the dashboard is deleted. The temporary upload buffer is cleared within 24 hours. To turn a document into data, use Upload & extract on the Data page.
Sensitive Information: We do not intentionally collect sensitive information (such as health information, racial or ethnic origin, political opinions, or biometric data). If your uploaded data contains sensitive information, you are responsible for ensuring you have appropriate consent and legal basis to share that data with us.
2. How We Collect and Store Information
Collection Methods
- Direct collection: Through account registration forms, support communications, and service usage.
- Automated collection: Through cookies, server logs, and analytics tools when you use our platform.
- Third-party collection: Through authentication providers (Google, Microsoft) when you choose to sign in with those services.
Storage and Security
Your personal information is stored on secure servers provided by Amazon Web Services (AWS) located primarily in the United States. We implement industry-standard security measures including:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls and authentication requirements
- Regular security assessments and monitoring
- OAuth-only authentication (no password storage)
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, and improve our AI dashboard creation platform.
- Account Management: To create and manage your account, process transactions, and provide customer support.
- AI Processing: To process your prompts and data through AI models to generate dashboards (see Section 4 for details).
- Communications: To send you technical notices, updates, security alerts, and administrative messages.
- Analytics and Session Replay: To understand how users interact with our services and diagnose issues. This includes page views, feature usage, and recordings of user interactions with sensitive content (data tables, chat messages, connection details) masked. For visitors in the EU, UK, EEA, and Switzerland, analytics and session replay only run with your explicit consent via our cookie banner.
- Security: To detect, investigate, and prevent fraudulent transactions, abuse, and other harmful activities.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
4. AI and Automated Decision-Making
Our platform uses artificial intelligence to generate dashboards based on your prompts and data. This section explains how AI processes your information in accordance with APP 1.7-1.9.
How AI Is Used
- Dashboard Generation: AI models process your text prompts and uploaded data to generate dashboard code, visualisations, and layouts.
- Content Suggestions: AI may suggest chart types, colour schemes, or data transformations based on your data.
- Error Correction: AI assists in identifying and fixing issues in generated code.
Information Used by AI
- Text prompts you provide describing desired dashboards
- Data structure metadata (column names, types, row counts) from your uploaded files or connected sources. A sample of rows is read at generation time and sent to AI providers as part of the request, but is not stored in our database.
- Your preferences and selected options during dashboard creation
AI Model Providers
We use the following third-party AI providers to process your requests:
- Anthropic (Claude): United States
- Google (Gemini): United States
Your prompts and data context are sent to these providers for processing. We do not permit these providers to use your data for training their models. Processed data is not retained by AI providers beyond the immediate request.
Decisions Made by AI
AI systems make the following types of decisions during dashboard generation:
- Selection of appropriate chart types and visualisations
- Layout and design choices for dashboard components
- Data transformation and aggregation approaches
- Code structure and implementation patterns
These decisions relate to content generation and do not affect your legal rights, access to services, or account standing. You retain full control to modify, regenerate, or reject AI-generated content.
6. International Data Transfers
We are likely to disclose personal information to overseas recipients. Your information may be transferred to and processed in the following countries:
- United States: Our primary infrastructure (AWS), payment processing (Stripe), AI providers (Anthropic, Google), and other service providers are located in the United States.
Before disclosing personal information to overseas recipients, we take reasonable steps to ensure that the recipient does not breach the Australian Privacy Principles. This includes:
- Entering into contractual arrangements that require recipients to handle personal information in accordance with the APPs
- Selecting service providers with robust privacy and security practices
- Conducting due diligence on recipient privacy practices
By using our services, you acknowledge that your personal information may be transferred to and processed in countries outside Australia, which may have different data protection laws than Australia.
7. Data Security
We implement appropriate technical and operational measures to protect your personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Our security measures include:
- Encryption of data in transit using TLS/SSL
- Encryption of sensitive data at rest
- Secure authentication, with multi-factor authentication available through Google and Microsoft sign-in
- Regular security assessments and vulnerability testing
- Access controls limiting employee access to personal information
- Secure development practices and code review processes
- Incident response procedures
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.
8. Data Breach Notification
In accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988, if we experience a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable
- Notify affected individuals as soon as practicable
- Provide information about the breach, including the type of information involved and recommended steps individuals should take
We maintain incident response procedures to assess and respond to potential data breaches within the required timeframes.
9. Retention of Data
We retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy:
- Account Information: Retained while your account is active. After account closure, you have a 14-day grace period to cancel the deletion and recover your data, after which it is permanently deleted.
- Dashboard Data: Retained while your account is active. You may delete individual dashboards at any time.
- Usage Logs: Generally retained for up to 12 months for security and analytics purposes.
- Payment Records: Retained as required by tax and accounting laws (typically 7 years).
- Support Communications: Retained for a reasonable period to provide ongoing support and improve our services.
When personal information is no longer needed, we will take reasonable steps to destroy or de-identify it.
10. Your Rights
Under the Australian Privacy Principles, you have the following rights regarding your personal information:
- Access: You may request access to the personal information we hold about you. We will respond to your request within a reasonable period (generally 30 days).
- Correction: You may request that we correct any personal information that is inaccurate, out-of-date, incomplete, irrelevant, or misleading.
- Deletion: You may request deletion of your account and associated personal information, subject to our legal obligations to retain certain records.
- Data Export: You may export your dashboards and data through our platform's export features.
- Opt-out: You may opt out of marketing communications at any time by clicking the unsubscribe link in our emails or contacting us.
To exercise these rights, please contact us using the details in Section 13. We may need to verify your identity before processing your request. In some circumstances, we may refuse a request, such as where granting access would unreasonably impact another person's privacy or where we are required by law to retain information.
11. Complaints
If you believe we have breached the Australian Privacy Principles or mishandled your personal information, you may lodge a complaint with us.
How to Lodge a Complaint
Please contact our Privacy Officer:
- Email: [email protected]
- Subject Line: Privacy Complaint
- Address: 191 St Georges Terrace, Perth, WA 6000, Australia
Our Complaint Handling Process
- We will acknowledge receipt of your complaint within 5 business days.
- We will investigate your complaint and aim to respond within 30 days.
- If we need more time, we will let you know and explain why.
- We will inform you of the outcome and any actions we have taken.
External Complaints
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Email: [email protected]
- Address: GPO Box 5218, Sydney NSW 2001
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we may also notify you by email. We encourage you to review this Privacy Policy periodically.
13. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your rights, or want to access or correct your personal information, please contact us: