Privacy

Your work stays yours.

FlairDirector is designed around local capture and editing. This policy explains the limited information that leaves your device when you choose to activate a license, join the waitlist, or send a support report.

Last updated August 3, 2026

Local projects and captures

Recordings, screenshots, project files, edits, captions, and exports are created and stored on your device. FlairDirector does not automatically upload project contents, media, filenames, clipboard contents, keystrokes, camera data, or microphone data to the FlairDirector feedback service.

License activation

If you activate a paid license, the app sends the license key, active device instance identifier, and the checkout email you enter directly to Lemon Squeezy over HTTPS to activate and validate the license. The raw key is stored in your operating system credential vault, not in an editable app configuration file.

When a licensed user sends a support report, the raw key and active instance identifier are sent over HTTPS to the private FlairDirector feedback service only so that service can validate them with Lemon Squeezy. The feedback service does not store or log the raw key. It stores stable identifiers returned by Lemon Squeezy, such as customer, order, license-key, product, variant, and instance IDs.

In-app feedback and crash reports

Nothing is sent automatically. When you choose to report a problem or request a feature, we receive:

  • the report text you enter and a private report ID;
  • a validated customer reference, or a random installation ID for trial users;
  • app/build, install channel, Windows architecture/version, WebView2, FFmpeg, display scaling, and backend metadata;
  • your contact email only when you provide it and allow follow-up; and
  • only the screenshot or privacy-safe diagnostics report you explicitly select.

Reports are private and are not automatically posted to GitHub or a public roadmap. Report text, optional contact information, and customer/install references are retained for up to 12 months. Optional screenshots and diagnostics attachments are retained for up to 30 days. Abuse controls use the validated customer or random installation ID; an IP address may be one-way hashed with a private salt as a secondary signal, and the raw IP address is not stored in the feedback database.

Local diagnostics

FlairDirector keeps bounded structured logs locally for up to seven days, with a 20 MB total limit. Prepared diagnostics reports are also removed locally after seven days. Central redaction removes license secrets, full email addresses, Windows paths and usernames, filenames, URLs, window titles, typed or clipboard text, project data, and arbitrary server response bodies. A report includes at most 2 MB or 2,000 recent events.

A small session marker distinguishes a normal exit from a probable unexpected shutdown. On the next launch, the app may offer a one-time, dismissible crash report. It does not create or send a native crash dump.

Waitlist

If you join the website waitlist, we collect the email address you submit plus basic source, referrer, and campaign fields used to understand the signup. Cloudflare Turnstile processes a security token to prevent automated abuse. We use this information for the early-access and product updates you requested.

Service providers

Cloudflare hosts the private feedback API, D1 report database, R2 attachments, website, and abuse protection. Lemon Squeezy processes checkout and license validation. Microsoft may process Store delivery and updates. Those providers handle information under their own terms and privacy notices.

Your choices

  • Do not attach diagnostics or a screenshot unless you want them reviewed.
  • Leave contact permission off to avoid storing a report contact email.
  • Dismiss an unexpected-shutdown offer without preparing or sending a report.
  • Request access to or deletion of a support report by providing its report ID.

For a privacy request, contact FlairBytes, LLC through flairbytes.comand include the relevant FlairDirector report ID when available.

Security, children, and changes

We use HTTPS, private Cloudflare storage, strict payload limits, and data minimization to protect support information. No system is perfectly secure. FlairDirector is not directed to children under 13, and we do not knowingly collect their personal information. We may update this policy as the product changes; the date above will identify the current version.