Flare — Privacy Policy
Effective Date: September 2026 · Entity Responsible: Fig Studio LLC
We built Flare because we needed it ourselves. This policy explains clearly what data we collect, where it goes, and what we do with it.
TL;DR: your health data never leaves your device and there are no accounts. The little the app does send — purchase receipts, anonymous usage analytics, and App Store ad attribution — is never linked to your identity and never used to track you. The one exception is not in the app at all: if you choose to send us a story through this website, you are deliberately giving us something to publish. That is covered in Story submissions.
What We Collect
Stored Only on Your Device
These never leave your phone:
- Your symptom logs, check-ins, and severity ratings
- Medications, activities, and milestones you've recorded
- Your app preferences and settings
- A randomly generated install identifier — random, not your device's hardware ID — used to distinguish this installation for purchases and anonymous analytics. It is never linked to your identity.
Anonymous Usage Analytics
We use TelemetryDeck to collect anonymous usage signals — such as which screens are viewed and which features are used. TelemetryDeck does not collect personal data, device identifiers, or IP addresses. Signals cannot be traced back to individual users. For details, see telemetrydeck.com/privacy.
Purchases (RevenueCat)
Flare Pro purchases are made through Apple. To unlock Pro and keep it unlocked across reinstalls, purchase receipts and subscription status are validated through RevenueCat under the random install identifier described above. Purchase history contains no health data and is not linked to your identity. See revenuecat.com/privacy.
App Store Ad Attribution (Apple Ads)
If you found Flare through an ad on the App Store, Apple's AdServices framework provides a standard attribution token that tells us which campaign the install came from. This is campaign-level information — it contains no identity, is not cross-app tracking, and requires no App Tracking Transparency prompt under Apple's definitions. It is processed and retained by RevenueCat alongside purchase records, and we use it only to measure our own App Store advertising.
Weather Insights (Optional)
Weather insights are off by default and start only when you enable them. When you do:
- Your location is rounded to an approximate area — about 10 km — on your device before anything is stored.
- Only that approximate coordinate is sent to Apple WeatherKit to fetch weather. Your symptoms, ratings, and other health content are never sent — to Apple or anyone else.
- Weather data is kept as a local cache on your device and is excluded from backups.
- Turning Weather off deletes the saved area and the cache.
- iOS location permission stays under your control in Settings at all times.
Sleep Insights (Optional)
Sleep from Apple Health (optional). If you turn on Sleep insights, Flare reads your sleep records from Apple Health on your device. Flare reads sleep only, never writes to Health, and uses the data for one purpose: to compare your own symptom ratings on days after shorter nights with days after typical nights and show you the result. Sleep data stays on your device. It is not sent to us or to any third party, it is not stored in iCloud, and it is not included in your Flare backup, PDF or CSV exports, or analytics. Turning Sleep insights off in Settings deletes the sleep Flare has saved. You can withdraw Health access at any time in the Health app under Sharing.
Exporting Your Data (PDF, CSV, Image)
When you export a timeline or CSV, that file is generated entirely on your device and goes wherever you send it — your email, your doctor, your files. We never see it, receive it, or have access to it.
When you save a timeline image to your photo library, we request Photos access solely to write that image. We do not read your photo library.
Feedback
If you email us using the in-app feedback link, your message is composed and sent through your own mail client. We receive only what you choose to send. We don't store your email address or link it to your usage.
What We Don't Collect
- No account, email address, or login. The app never asks for one. (If you send us a story through this website, that is separate and deliberate — see Story submissions.)
- No location data, unless you enable Weather insights (approximate area only, sent only to Apple)
- No camera access
- Your health data is never sent to any server. The only things that leave your phone are: an approximate area to Apple Weather (only if you enable Weather), purchase receipts to Apple and RevenueCat, anonymous usage signals to TelemetryDeck, and Apple's ad-attribution token if you arrived through an App Store ad
- We never sell your data
- We never use your health data for advertising, and Flare shows no ads. (Campaign attribution measures our own App Store ads and is never linked to you.)
Story Submissions (this website)
Everything above describes the app. This section describes something different: the story form at flarelog.app/stories/submit, where people can send us a short account of what they live with. It is entirely optional, it has nothing to do with the app, and you never have to use it to use Flare.
If you send us a story, you are asking us to publish it. That is the point of the form, and it is the one place where we hold something you have written.
What the form collects
- Your story — required, up to 1,500 characters. This is intended for publication on flarelog.app/stories.
- A display name — optional. Leave it empty and your story appears as “Anonymous.” Most people do.
- What you live with — optional, chosen from a short list. Published alongside the story if you provide it.
- An email address — optional, and only if you want us to be able to contact you about your story. It is never published, never shared, and never used for a mailing list. If you leave it empty we have no way to reach you, and that is a perfectly reasonable choice.
What we do with it
- Nothing publishes automatically. Every submission waits in a private queue until a person at the studio reads it. We may lightly edit for length or clarity. We may also decline to publish.
- Submissions are stored on Cloudflare, our hosting provider, in a database that is not public.
- We record the time a story arrived. We do not store your IP address with your story. Our spam protection uses a one-way hash that is kept separately and expires within the hour, so a story cannot be traced back to an address.
- The form uses Cloudflare Turnstile to keep automated submissions out. It is invisible, there are no puzzles to solve, and it does not track you across sites.
Changing your mind
You can withdraw a story at any time, published or not, by writing to aminoli@figstudiollc.com. We will remove it from the site promptly and delete the submission. You do not have to explain why, and you do not need an account to ask.
When you send a story we show you a short removal code once. Keep it. Because most stories are anonymous, that code is how we know a removal request comes from the person who wrote the story rather than from someone who simply read it. If you gave us an email address, writing from that address does the same job. If you have lost both, write to us anyway and tell us which story is yours — we would rather remove a story on a reasonable request than leave someone stuck with words they regret.
A published story is public. Search engines and other people can copy or quote what is on a public page, and we cannot pull those copies back. That is worth knowing before you write something you would not want a colleague, an employer, or a family member to read. If in doubt, stay anonymous and leave out details that would identify you or anyone else.
Please write only about your own experience. If your story names another person — a doctor, a family member — we may remove or change that name before publishing.
The App Store Privacy Label
Flare's App Store listing discloses the following — every entry is not linked to your identity and not used for tracking:
- Coarse location — app functionality (Weather insights, optional and off by default)
- Purchase history — app functionality (unlocking and restoring Flare Pro)
- Device ID — analytics (the random install identifier)
- Product interaction — analytics (anonymous usage signals)
- Advertising data — analytics and our own marketing (Apple Ads campaign attribution)
Your Data, Your Control
Because there's no account and everything lives on-device, you're already in full control. To delete all your data, delete the app from your iPhone. There's nothing on our end to request removal of. You can also clear your data at any time from Settings inside the app.
A Note on Health Data
Flare is a personal logging tool, not a medical device. The symptom and medication data you record is yours — it lives in your app's private storage on your device and is never accessed by us or shared with anyone.
Children
Flare is not directed at children under the age of 13. We don't knowingly collect data from children.
Changes to This Policy
If we update this policy, we'll note the new effective date at the top. We'll make reasonable efforts to communicate major changes in the app.
Questions?
We're a small, independent studio and we're happy to answer any questions you have about your privacy.
aminoli@figstudiollc.com
Fig Studio LLC · figstudiollc.com