Data Use & Privacy

Last updated: May 2026

This page supplements our Privacy Policywith practical details about how Flitch Solutions Pty Ltd ABN 57 682 821 512 of 191 St Georges Terrace, Perth, WA 6000, Australia ("Flitch", "we", "us" or "our") handles your data when you use our AI dashboard creation platform.

1. Overview

Here's a quick summary of our data practices:

  • Your data stays yours: We never sell your data or use it for advertising.
  • No training on your data: AI providers do not train models on your content.
  • Encrypted at rest and in transit: Industry-standard encryption protects your data.
  • Delete anytime: Export or delete your data at any time.

2. What Data We Collect

Account Information

Email address and name. We use OAuth-only authentication (Google or Microsoft sign-in), so we never store your passwords. We receive basic profile information from your chosen authentication provider.

Your Prompts and Data

The text prompts you provide and data you upload or connect (data files such as CSV or Excel spreadsheets, database connections, cloud storage) to generate dashboards.

  • Uploaded files (CSV, Excel): Stored in encrypted cloud storage (Amazon S3). We store only metadata about your files (column names, data types, row counts) in our database, not the data itself.
  • Data extracted or generated on the Data page (Upload & extract from a PDF, document, or image; From a URL; Describe a dataset): The resulting dataset is stored in encrypted cloud storage (Amazon S3), the same as an uploaded file. For Upload & extract, the original source file is also stored in S3 and read to pull out its data. We keep only metadata (column names, data types, row counts) in our database. The dataset and any source file are deleted when you delete the dataset.
  • Connected data sources: Queried live from your data source when needed. We store connection credentials and metadata (column names, data types, row counts), not copies of your data.

Prompt Attachments

When creating or updating a dashboard you can attach images and GeoJSON map files. These guide how the dashboard is built; they are context, not data sources:

  • Images (screenshots, logos, style references): used as visual reference so the dashboard matches a target look or branding. Images are never charted.
  • GeoJSON: fetched when the dashboard loads and drawn as a map layer.
  • Retention: attachments are briefly held in a temporary upload area, and that copy is deleted within 24 hours. Images kept with the dashboard as project assets are deleted when the dashboard is deleted.

To turn a PDF, document, or spreadsheet into data, use Upload & extract on the Data page, which creates a dataset (see above). Documents are not attached to a prompt.

Generated Dashboards

The dashboards and code generated by our AI based on your prompts. These are stored in your account and belong to you.

Usage Information

Basic analytics about how you use the platform (features accessed, dashboards created) to help us improve the service. We do not track your activity across other websites.

3. How AI Processes Your Data

When you generate a dashboard, your prompts and relevant data context are sent to AI providers for processing. Here's how this works:

1

You submit a prompt

Your prompt, data metadata (column names and types), a sample of rows read from your data source at request time, and any attached images or GeoJSON map files are sent to our backend. Sample rows are read on demand and are not stored in our database.

2

AI generates your dashboard

We send the request to our AI providers (Anthropic, Google, Replicate) to generate dashboard code and assets. Attached images are processed using AI vision capabilities to match a target look or branding.

3

Request data is not retained

AI providers process the request and return results. They do not store your data or use it for training.

4

Dashboard saved to your account

The generated dashboard is stored in your account, where only you (and your team) can access it.

Important: We use API access to AI providers, which means your data is not used for model training. This is contractually guaranteed by our agreements with Anthropic, Google, and Replicate for API usage.

4. AI Providers We Use

We use the following third-party AI providers to process your requests:

Anthropic (Claude)

Used for dashboard generation, code planning, and intelligent assistance. During generation, Anthropic Claude (Opus model) receives your prompt, any attached images, and connected data samples for dashboard planning and code generation. It also reads files you connect on the Data page via Upload & extract to pull structured data out of them.

  • Location: United States
  • API data is not used for training
  • Anthropic retains API request logs for up to 7 days for abuse monitoring only
  • Privacy Policy: anthropic.com/privacy

Google (Gemini)

Used for code generation, data processing, and validation tasks. Google Gemini (Flash Lite model) receives attached images for intent classification to determine how to use them during generation.

  • Location: United States
  • API data is not used for training
  • Google retains paid API data for a limited period for policy monitoring only
  • Privacy Policy: policies.google.com/privacy

Replicate (Flux)

Used for generating custom dashboard icons and images.

5. Data Storage & Retention

Where Your Data Is Stored

  • Account data: Stored in our database hosted on Neon (PostgreSQL) in the United States.
  • Dashboards: Stored in our database, associated with your account.
  • Datasets (uploads, Upload & extract, From a URL, Describe a dataset): Stored in Amazon S3 (United States), encrypted at rest. Only metadata (column names, types, row counts) is stored in our database. For Upload & extract, the original source file is stored in S3 too. The dataset and any source file are deleted when you delete the dataset.
  • Prompt attachments: Images and GeoJSON attached during dashboard creation or update. Images kept with the dashboard are deleted when the dashboard is deleted. The temporary upload buffer is cleared within 24 hours.

How Long We Keep Data

  • Account data: While your account is active. After account closure, you have a 14-day grace period to cancel the deletion and recover your data, after which it is permanently deleted.
  • Dashboards: Until you delete them or close your account.
  • Usage logs: Up to 12 months for security and improvement purposes.
  • Payment records: 7 years as required by tax laws.

6. Your Controls

You have full control over your data:

Export Your Data

Download your dashboards and data at any time through the platform's export features.

Delete Your Data

Delete individual dashboards or request complete account deletion at any time.

Access Your Information

Request a copy of all personal information we hold about you.

Correct Your Information

Update your profile information or request corrections to any inaccurate data.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

7. Contact Us

If you have any questions about how we handle your data, please contact us:

Email: [email protected]

Address: 191 St Georges Terrace, Perth, WA 6000, Australia

For our complete privacy practices, please read our Privacy Policy.