Skip to content

Privacy Policy

Please read this document before using freecashflow.ai. It reflects how the service currently operates; we keep it up to date as the service develops and post any material change on this page. Last updated: 2026-07-28.

1. Controller and contact

freecashflow.ai ("we") is the controller responsible for the personal data described in this policy. For privacy questions or to exercise your rights, contact us at [email protected].

2. Personal data we process

Account data: email, display name, language preference, and a one-way password hash. Your content: the specifications, uploaded databases and generated workbooks you create. Usage records: build counts, storage bytes and similar operational metrics. Waitlist data, if you join: email, locale, plan interest, an optional note, and a daily-rotating, non-reversible IP hash for abuse control. Payment method, if you add one during the beta: only a masked reference — card brand and last four digits — never the full card number or security code. Analytics: first-party, cookieless counts of page paths and clicks, with no visitor identifiers or profiles.

3. Purposes and legal bases

We process account data and your content to perform our contract with you (to operate your account and provide the Service). We rely on our legitimate interests for security, abuse prevention, aggregate analytics and product improvement, balanced against your rights. We rely on your consent for the single waitlist launch email, which you can withdraw at any time. We process some data to comply with legal obligations, such as retention required by law. These bases correspond to GDPR Article 6 and LGPD Article 7.

4. Cookies and analytics

The public site sets no cookies. The application uses only strictly necessary cookies to keep you signed in. Our analytics are first-party and cookieless — no third-party tags, advertising pixels or cross-site tracking — so no consent banner is required, and we honour "Do Not Track". Introducing any third-party tag in future would change this and would be disclosed here first.

5. Sharing and subprocessors

We do not sell or rent personal data and do not share it for advertising. We share data only with processors that act on our instructions under contract: Resend (transactional email delivery), Cloudflare (DNS, CDN and edge security), and Amazon Web Services (application hosting). Each processes only what its function requires.

6. International transfers

Our infrastructure runs in the United States (hosting) and in Brazil and global edge locations (email and CDN), so your data may be processed outside your country. Where required, transfers are protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses and equivalent LGPD mechanisms.

7. Retention

We keep account content until you delete it or your account, after which it is permanently purged following a short grace window (7 days by default). Raw usage events are kept for about 13 months, audit records for at least 12 months, and waitlist entries until the launch email is sent and you convert or unsubscribe, with unconfirmed entries expiring. Abuse-control IP hashes rotate daily and cannot be reversed to an address.

8. Your rights

Subject to applicable law, you may request confirmation of processing, access, correction, deletion or anonymisation, portability, information about sharing, and restriction of or objection to certain processing; you may withdraw consent and lodge a complaint with your data-protection authority (in Brazil, the ANPD; in the EU/UK, your supervisory authority). Where US state laws apply, you have rights to know, delete, correct, and opt out of the "sale" or "sharing" of personal data — which we do not do. Deletion and export are self-service in the application; other requests go to [email protected] and are answered within the timeframes set by the LGPD and GDPR.

9. Security

We protect data in transit with TLS, store passwords only as salted hashes, keep only a masked reference to any payment card, restrict administrative access, and log administrative actions. No method of transmission or storage is completely secure, but we work to protect your data and will notify affected users and authorities of a breach as required by law.

10. Children

The Service is not directed to children and is intended for users aged 18 and over. We do not knowingly collect personal data from children; if you believe a child has provided data, contact us and we will delete it.

11. Changes and contact

We will post any change to this policy on this page and announce material changes before they take effect. Questions or requests: [email protected].