Privacy & cookies
Last updated: 23 August 2026
Who we are
flamelens is operated by Kismet Software LLC, a Utah limited liability company doing business as flamelens (“we”, “us”). Questions about anything on this page: privacy@flamelens.dev.
The short version
- We do not keep your recording. A profile you upload is analysed and the file is deleted. What we keep is the report.
- The report contains your class and method names. That is what a profiler records, and it is what makes the report useful — but it does describe your codebase, so it is worth knowing.
- Free and student analyses contribute one anonymized finding to the public insights page. That is what the free tier costs. Paid plans do not, unless you switch it on.
- We do not sell anything to anyone. Not the reports, not the aggregates, not your email address.
- You can delete all of it from your account settings.
What we collect
Your account: email address, a bcrypt hash of your password (never the password), your plan, and — if you signed in with GitHub or Google — the account identifier they return. We send an emailed code at each login, so we also store the short-lived code and when it was used.
What you upload: a profiler recording. It is written to a temporary file, summarised, sent for analysis, and deleted. The raw recording is never stored.
The report we produce: ranked findings with their evidence. Because a profile is made of stack frames, this includes fully-qualified class and method names from your application — a report can therefore describe the shape of your codebase. Reports are visible only to your account and, if you are in an organization, to that organization.
If you pay: Stripe processes the payment. We never see or store your card number; we store the subscription state Stripe reports back.
How the site is used: see cookies, below.
What the free tier contributes
Every analysis produces one anonymized finding — a category, the library it was found in, and a count. Those roll up into the public insights page and are given free to the maintainers of the libraries concerned, so they can see what is actually slow in the wild.
The aggregate carries no reference to you, your account, or your organization. It is stored separately from anything that identifies you, and there is no path back from a public count to the report it came from. That is a property of how it is stored, not a promise about how we behave.
- Free and Student: always contribute, and cannot switch it off. This is what the free tier is paid with, and we would rather say so here than bury it.
- Pro and Enterprise: contribute only if you opt in. Off by default. Your organization's setting overrides the personal one.
- Self-hosted installations: never contribute, and it is not a setting. An on-premise install phoning home would be an incident, not a feature.
Your organization's own private landscape of findings is a separate thing entirely and is never published.
Who else processes your data
| Who | What for | What they see |
|---|---|---|
| Anthropic | producing the analysis | the summarised profile, including class and method names |
| Stripe | payments | your billing details; we never see the card |
| Our email provider | verification, login codes, alerts | your email address and the message |
| Google Analytics | which pages get visited | only if you accept the banner — see below |
| Our hosting provider | running the service | data at rest and in transit |
We do not sell data to anyone, and none of the above are permitted to use it for their own purposes.
Cookies
Essential cookies keep you signed in and protect forms against cross-site request forgery. The site does not work without them, so they are not optional and we do not ask.
Analytics cookies are set by Google Analytics only after you accept them in the banner. Until you do, consent is denied by default and no analytics cookie is written — that is enforced before the tag loads, not after. Choose “Reject” and none are ever set. Your choice is remembered in your browser's local storage, which is a preference rather than a tracker.
To change your mind, clear this site's data in your browser and the banner returns.
How long we keep things
Uploaded recordings: not kept — deleted as soon as the analysis finishes. Reports and your account: until you delete them. Unverified sign-ups are cleaned up automatically after seven days. Login codes expire in minutes.
Deleting your data
Deleting your account removes your reports, your findings, and the account itself. It is a real delete, not a flag. Two things deliberately survive it:
- The anonymized public aggregate, because it contains no reference to you and there is nothing in it to delete.
- Your organization's knowledge base, because those counts belong to the team rather than to you. An organization owner can erase the whole organization separately, with a typed-name confirmation.
To delete everything, use your account settings, or email privacy@flamelens.dev.
Your rights
Depending on where you live you may have the right to access, correct, export, or delete your personal data, and to object to some processing. Email privacy@flamelens.dev and we will action it. We do not charge for this and we will not make you explain why.
Children
flamelens is a developer tool and is not directed at children. We do not knowingly collect data from anyone under 13.
Changes
If this policy changes materially we will say so on this page and, for changes that affect what we do with data you have already given us, by email.
This policy describes what the service actually does. It is written for transparency and is not legal advice.