Privacy Policy
How PreFlight handles product data, credentials, and account information.
Privacy Policy
Effective: July 25, 2026
This Privacy Policy explains how PreFlight ("we", "us", or "our") handles personal information when you use getpreflight.dev, our applications, and related services (the "Service"). It does not change the Terms of Service, Acceptable Use Policy, or Disclaimer.
Information we collect
We collect information you provide or that is generated while you use the Service:
- Account information: email address, display name, and authentication identifiers supplied through Clerk.
- Workspace information: project names, integration configuration, monitoring preferences, team membership, and billing details.
- Operational results: pass/fail statuses, response times, safe error codes, timestamps, readiness scores, and reports generated by the Service.
- Credentials: API keys and secrets you choose to provide for integration checks.
- Usage and device information: feature interactions, page views, session metadata, and aggregate performance metrics used to operate and improve the Service.
We do not ask you to upload source code, row-level database contents, or your end users' personal information. Do not submit information that is unnecessary for an authorized integration check.
How we use information
We use information to provide and secure the Service; run the checks, alerts, reports, and automations you request; administer accounts and billing; communicate about the Service; troubleshoot and improve reliability; and comply with applicable law. We use credentials only to perform the authorized health checks for the integrations you configure.
Credential handling
When you save an API key or secret, PreFlight encrypts it with AES-256 envelope encryption before storage. The full value is not returned to the browser or included in an API response, report, or export after saving. Account API keys used for CI or automation are shown once at creation and then stored as hashed values with short prefixes for identification. Keys are scoped to individual projects; rotating a key in one project does not affect another.
How we share information
We share information only as needed to provide the Service: with the service providers that support authentication, database and application hosting, transactional email, payment processing, and error monitoring; when you direct a connection or report to another service; to comply with law; or to protect the Service, our users, or others. We do not sell personal information or use advertising cookies. A current list of sub-processors is available on request.
Retention and deletion
- Check results and monitoring history: retained for your plan period (free plans: 7 days; paid plans: up to 30 days) unless deleted sooner.
- Account and workspace records: retained while your account is active; associated data is removed within 30 days after account deletion, except where retention is needed for billing disputes, fraud prevention, or legal obligations.
- Encrypted credentials: deleted when you remove the integration or delete its project.
Your choices and rights
You can export check history and project data, delete projects and integrations, or delete your account in Settings. You may also request access, correction, export, or deletion by emailing privacy@getpreflight.dev. Where applicable law provides additional rights, including for EU/EEA residents, we will respond as required and may need to verify your request.
Cookies, analytics, and security
PreFlight uses essential cookies for authentication and session management. Vercel Analytics and Speed Insights measure aggregate page views and Core Web Vitals without cookies or browser storage for tracking. We protect data in transit with TLS 1.2+ and at rest with encryption, restrict workspace access to authorized members using row-level security, and keep provider secrets out of logs, error reports, and client rendering after initial save. No security measure is absolute; use the Service only in accordance with our Acceptable Use Policy.
International processing and changes
Our service providers may process information in countries other than yours. Where required, we use appropriate safeguards for those transfers. We will post changes here with a new effective date and, for material changes, notify active workspace owners through the product.
Contact
Questions about this policy or your information? Email privacy@getpreflight.dev.
See also: Terms of Service · Acceptable Use Policy · Disclaimer
