Privacy

This website

This page collects nothing beyond what you type into the migration form: your email address and, if you share it, a rough item count. When you send that form, it also carries the page you arrived from and any campaign tag in the link you clicked, so that it is possible to tell which post or page brought you here. Nothing is read or sent unless you submit the form, nothing is stored in your browser, and none of it is used to identify you anywhere else. That information is used to set up your account and send your import link. It is not sold, shared, or added to any marketing list.

Hosting is provided by Cloudflare Pages, which keeps standard aggregate traffic metrics. When the link you followed carries a campaign tag (the ?ref= part), the site adds one to that day's count for the tag; the count is the only thing stored, with nothing about you attached to it. There are no analytics scripts, no advertising pixels, and no cookies set by this site.

Your inventory data, once you have an account, belongs to you: you can export all of it as CSV at any time, including after your subscription ends.

The app

What follows covers the FlatStock app itself, which is a different thing from this page.

Your account is an email address and a password. They are held by Supabase, our database and authentication provider, and are used to sign you in and to send you the occasional message you asked for, such as a confirmation or a password reset. The address also gets the notices the law asks for about a subscription: a receipt when it starts and, on a yearly plan, a reminder before it renews. And if you turn off renewal, it gets one email from the person who builds FlatStock, asking what was missing. That email is sent once, carries no offer, and is never followed up. Nothing else.

Your inventory is items, folders, quantities, notes, photos and the check-out ledger. It is written to your own phone first and then synced to your account's own rows in a Supabase database, so it is there on your other devices. Photos go to Supabase Storage for the same reason. We do not read it, sell it, share it, or train anything on it.

Purchases are handled by Apple or by Google when you subscribe inside the app, and by Stripe when you subscribe in your browser. RevenueCat, our subscription service, records which subscription is active and an identifier for the device, which is how the app knows whether your subscription is live. No card details ever reach us on any of the three, because they never leave the payment provider. The terms say who takes the money where.

When you arrive from one of our own links or ads, the campaign tag in that link travels with you to the sign-up page and is stored once against your account, so we can tell which post, page or advert brought you. Our ads add a click identifier of their own to the link, and it is kept in the same single row. Once an account exists we hand that identifier back to the advertising network to say the click became an account, and nothing else: no email address, no name, nothing you typed. It is a fact about the click, not about you, it is written once and never revised, and it goes away with the account.

There is no analytics, no advertising pixel and no tracking of you across the web, in the app or on this site. That is a fact about what is in the build rather than a statement of intent: there is no analytics script, no advertising tag and no cookie anywhere in either, the measurement described above happens on our own server from what the link itself carried, and the only third-party component in the app is the one that talks to the store about your subscription.

Leaving. The full CSV export works at any time, including after a subscription ends. When you want the account and everything in it gone, Settings has Delete account and it is permanent. How deletion works, and what is kept.

Questions: [email protected]. A person reads it.