Skip to main content

Privacy Policy

Last updated: August 10, 2026

Who we are

FlareSight (flaresight.org) helps you find startups that recently raised money, built on public SEC filings and other public sources. It is operated by W Holdings LLC, 5155 Blue Diamond Road, Suite 102-2353, Las Vegas, NV 89139, United States. W Holdings LLC is the data controller, which means it is the business legally responsible for the personal data described in this policy. Questions about this policy or your data: support@flaresight.org.

This policy covers two groups of people: visitors and account holders, and the founders and executives whose business contact details appear in FlareSight, most of whom never signed up. If you are in the second group, the sections "Contact details about people who never signed up" and "Your rights" are written for you too.

What we collect

Account data. Your email address, and a scrambled (hashed) version of your password that cannot be turned back into the original. The password itself goes from your browser to Supabase, the service that runs our logins. If you sign in with Google, we receive your Google account email address and name instead.

Payment data. Payments run through Stripe. You type your card details into Stripe's payment page, not into FlareSight, and we do not store card numbers. We keep your Stripe customer reference and your subscription status.

Usage data. Which pages you visit and which features you use, collected with a tool called PostHog. When you are logged in, this is tied to your account, including your email address and plan. It is not anonymous. The cookie section below explains when this tool is allowed to run at all. PostHog does not record your screen.

Things you write. Your profile bio (the "about me" text used for drafting outreach), your watchlist names, feedback you send us, and any note you leave if you cancel.

How you found us. When you first arrive, we set a small first-party cookie called fs_attribution (a cookie is a small piece of text your browser stores for us). It holds the page you came from, campaign tags in the link, ad click identifiers, and the page you landed on. It expires after 90 days. If you sign up, we keep that snapshot with your account so we know which marketing works.

Error reports. When something breaks in your browser, a tool called Sentry sends us the error details, information about your browser and device, and a replay of what was on your screen in the moments around the error. It does not record your whole session, only the window around an error.

Server logs. Like almost every website, our hosting provider Vercel keeps technical logs of each request, including your IP address (the network address of your device). Vercel also collects page-speed measurements from your browser so we can see how fast the site loads.

Public company data. We collect information about companies from public sources such as SEC EDGAR filings and company websites. Contact details connected to those companies are covered next.

Contact details about people who never signed up

FlareSight shows business contact information for founders and executives, and most of those people are not FlareSight users. Plainly: we may hold your name, role, and work email address even though you never gave them to us. Here is where that comes from:

  • Names and roles come from public SEC Form D filings, where the company itself listed them.
  • When one of our users asks to "reveal" a contact, we send the person's name and company website address to lookup services (Hunter, with Findymail as backup) to find a work email address, and to a checking service (NeverBounce) to confirm the address works.
  • We store what was found so we do not have to look it up twice, and we log each lookup attempt, including the name searched and whether anything was found.

Under privacy law this is still personal data, even though it is work contact information tied to a public filing. The rights in this policy apply to it, you do not need an account to use them, and the "Your rights" section explains exactly what happens when you ask us to remove your details, including one limitation we have not solved yet.

How we use data

  • To run your account and the product
  • To take payments and manage subscriptions
  • To send email (the "Email" section explains which kinds, and your choices)
  • To understand how the product is used and improve it
  • To measure whether our advertising works
  • To draft outreach text when you ask for it (the "AI" section names exactly what is sent)
  • To find and check business contact details when a user asks for a reveal
  • To prevent abuse and keep the service secure (our rate limiter counts requests per account or IP address)
  • To meet legal obligations

We do not sell personal data for money. California law defines "selling" and "sharing" more broadly than that, and sending browsing data to advertising platforms can count as sharing there. The cookie section describes exactly what we send to those platforms, and we treat the Global Privacy Control browser signal as an opt-out everywhere in the world.

If you are in the EU, EEA or UK, the legal grounds we rely on are, in plain terms: the contract with you (running your account and taking payment), your consent (analytics and advertising cookies, and optional email for accounts created after we added the signup choice), our legitimate interests (keeping the service secure, and making contact details from public filings searchable), and legal obligations. You can object to processing based on legitimate interests; the "Your rights" section says how to reach us.

Who receives data

We use other companies to run parts of the service. The full list, with what each one does, what it receives, and where it processes data, is at flaresight.org/subprocessors, and we update it whenever we add or remove a provider.

In summary: Supabase (logins and database), Vercel (hosting), Stripe (payments), Resend (email delivery), Sentry (error reports), PostHog (product analytics), Google, Meta, LinkedIn and X (analytics and advertising measurement, only as the cookie section allows), Anthropic and Perplexity (AI, described next), Hunter, Findymail and NeverBounce (contact lookup and checking), Serper (finding company websites), Apollo and Clearbit (company data and logos), Upstash (abuse prevention), and Slack (an internal alert to our own team when someone cancels).

We may also disclose data if the law requires it or to protect our legal rights.

AI

Two features use AI services.

Outreach drafts. When you click to generate an email opener, we send Anthropic (the maker of the Claude models): the contact's first name and job title, the company's name, city, sector, funding stage and amount, and your own "about me" text. Anthropic returns a short draft, which is shown only to you. Nothing is sent to the contact, by us or by the AI.

Company research. Our data pipeline sends company names and text from public company websites to Anthropic (to write short company descriptions), and company names and websites to Perplexity (to research missing facts such as a company's website or sector). No names of people and no contact details are included in either.

FlareSight does not train AI models on your data.

Cookies, analytics and advertising

We advertise FlareSight, and we measure those ads. Five outside tools are involved: Google Analytics, the Meta pixel (for Facebook and Instagram ads), the LinkedIn Insight Tag, the X pixel, and PostHog (our product analytics). A pixel is a small piece of code that tells its platform your browser visited our page, along with cookie identifiers the platform uses to recognise the browser. The platforms use this to show us which ads led to signups, and they may use it for their own purposes as described in their own policies.

Cookies we set ourselves (first-party):

  • Login cookies from Supabase, so you stay signed in. Essential, always on.
  • fs_attribution, how you found us. Expires after 90 days.
  • fs_consent, which remembers your cookie choice. Expires after 12 months.

If you are in the EU, the wider European Economic Area, or the UK: the first time you visit, a banner asks whether we may use analytics and advertising cookies. Accept and Decline are presented as equal buttons, and declining is one click. Until you choose, none of the five tools above load: the code that runs them is not added to the page at all. If we cannot tell which country you are in, we treat you as if consent were required. Your choice is remembered for 12 months. To change it, delete cookies for flaresight.org in your browser and the banner will ask again.

Everywhere else: the five tools load by default, without a banner.

Global Privacy Control, honoured everywhere. If your browser sends the Global Privacy Control signal (a browser setting that tells websites not to share your data; Firefox and Brave can send it automatically), we treat it as a no and load none of the five tools, wherever you are in the world. The one exception: if you explicitly click Accept on our banner, that later, deliberate choice wins over the browser-wide default.

Email

Emails your account needs. Receipts, billing notices, security and password messages, and legal notices are sent to every account and cannot be turned off while you have an account. If an address hard-bounces or reports us as spam, we stop sending to it.

Optional emails. Onboarding tips, usage summaries, watchlist digests, and product news are optional.

  • New accounts choose at signup: the form has a box, unticked by default, asking whether you want these emails. If you leave it unticked, we do not send them.
  • Accounts created before that choice existed (August 2026) receive them until turned off.
  • Every optional email can be switched off in one click from the email itself, without logging in.

We record whether an email was delivered, bounced, or reported as spam. We do not store whether you opened an email, and nothing in FlareSight uses that information. Resend, the service that sends our email, may still collect delivery and engagement information on our behalf, so it is listed on our subprocessor page.

How long we keep data

While you have an account: for as long as the account exists.

When you delete your account (you can do this yourself from your account page): your login record and the data linked to it, including watchlists, alerts and reveal history, are deleted immediately, and we cancel any active subscription. Three operational records can survive that moment: our log of emails sent to you, feedback you submitted, and any cancellation note. A cleanup job runs every day and, once such a record is more than 30 days old and no longer linked to any account, deletes the feedback, removes your email address from the email log (the record that an email was sent is kept, without the address), and erases the text of the cancellation note (the reason category is kept, your words are not). Because the job runs daily against a 30 day threshold, the longest any of these details can survive after account deletion is 31 days.

Contact details about people who never signed up: there is currently no automatic time limit on this data. We keep it until the person asks us to remove it, and we are reviewing whether to set a fixed retention period. We say this plainly because publishing a number we do not enforce would be worse than admitting there is not one yet.

Cookies: fs_attribution expires after 90 days, fs_consent after 12 months.

Payments: Stripe keeps its own records of past transactions under its own legal obligations, even after your account is deleted.

Server logs: held by our hosting provider Vercel as part of running the service.

Where data is processed

FlareSight is hosted in the United States (our primary server region is San Francisco), and most of the providers on the subprocessor page process data in the United States. A few providers' processing regions are still being confirmed, and that page marks those as "Not yet confirmed" rather than guessing.

If you use FlareSight from the EU, EEA, UK or anywhere else outside the United States, your data is transferred to and processed in the United States.

Your rights

You can ask us to:

  • show you the personal data we hold about you (access)
  • correct it
  • delete it
  • give it to you in a machine-readable format (portability)

If you are in the EU, EEA or UK, you can also object to or restrict certain processing, and you have the right to complain to your data protection authority. In the UK that is the Information Commissioner's Office; every EU and EEA country has an equivalent, and you can complain to the one where you live.

How to ask. Email support@flaresight.org, or use the form at flaresight.org/eu. The form works whether or not you have an account: it has an option for people who never signed up. Both routes create a request that a real person reads and acts on; nothing is deleted automatically at the moment you submit. We respond within 30 days, and we may need to check you are who you say you are before releasing or deleting anything.

If you never signed up. For example, a founder whose work email FlareSight looked up: every request above is open to you, and you do not need an account. If you ask us to remove your contact details, we delete the copies we hold. One honest limitation: our product finds work emails through outside lookup services when a user requests it, and we do not yet keep a list of people who have asked not to appear, so a future lookup could find the same publicly available information again. We are treating that as a gap to close, and you can write to us again if it happens.

Children

FlareSight is a business research tool. It is not directed at children under 16, and we do not knowingly collect data from children.

Changes to this policy

When we make a material change, we will say so by email or with a notice on the site before it takes effect, and update the date at the top. We will not treat your continued use as agreement to something you never saw.

How this policy was written

Every factual claim in this policy was checked against FlareSight's actual code on August 10, 2026, and the evidence for each claim is recorded internally. The subprocessor list is re-reviewed whenever a provider is added or removed. If you believe any statement here does not match what the product actually does, email support@flaresight.org and we will check the code again.

Contact

support@flaresight.org, or by post: W Holdings LLC, 5155 Blue Diamond Road, Suite 102-2353, Las Vegas, NV 89139, United States.