feature by complai

Privacy Policy

flmnt LLC Last updated July 31, 2026

1. Scope

This policy describes how flmnt LLC ("flmnt", "we") handles personal data when you use the Feature service and this website. For personal data contained in the content customers submit to the service (specs, evidence, workspace data), the customer is the controller and we process it on their behalf under our Data Processing Addendum. For the data described below — your account, billing, and usage data — flmnt is the controller.

Contact for anything in this policy: privacy@mmmnt.ai.

2. Data we collect

  • Account data. Your email address and authentication credentials. Passwords are handled by our identity infrastructure and stored only in hashed form. If you sign in through Google, GitHub, or GitLab, we receive your email address and an account identifier from that provider.
  • Workspace and service data. The workspaces you belong to, your role in them, and the content you and your team submit — specifications, contracts, runs, and the attestation records the evidence ledger derives from them.
  • Billing data. Your subscription plan, interval, seat count, and billing status. Payments are processed by Stripe; we do not receive or store your full card number.
  • Usage and security data. Sign-in events (including IP address and device information used to flag unfamiliar sign-ins), API request logs, and enforcement events such as reaching a plan limit.
  • Preferences and communications. Your notification settings, the email address notifications are delivered to, and messages you send us.

We do not collect data from data brokers, and this website runs no analytics or tracking.

3. How we use data

  • To provide, secure, and operate the service — accounts, workspaces, the evidence ledger, billing, and support.
  • To send security notices (unfamiliar sign-ins, credential and email changes) and service notices (plan-limit enforcement, payment problems, membership changes). These are always sent because they protect your account.
  • To send optional notifications you can switch off in your account settings (for example, weekly digests and activity notices).
  • To comply with legal obligations, and to establish or defend legal claims.

We do not sell personal data, and we do not use it for advertising.

4. Legal bases (GDPR)

Where the GDPR or UK GDPR applies, we rely on:

  • Contract — providing the service you signed up for, including billing.
  • Legitimate interests — securing accounts, preventing abuse, and preserving the integrity and continuity of the tamper-evident evidence ledger.
  • Legal obligation — tax, accounting, and responses to lawful requests.
  • Consent — optional notification emails, withdrawable at any time in your notification settings.

5. Who we share data with

We share personal data only with the service providers that run the service (see the subprocessor list in the Data Processing Addendum): Amazon Web Services (hosting, storage, and email delivery, in the US), Stripe (payments), and Vercel (hosting for this website). If you sign in through an identity provider, that provider processes your sign-in under its own privacy policy. We may disclose data if required by law, or in connection with a merger or acquisition (in which case this policy continues to apply until amended with notice).

6. International transfers

We are a US company and process data in the United States. Where we receive personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the Standard Contractual Clauses.

7. Retention

  • Account data — for the life of your account.
  • Account deletion — you can delete your account from your settings. Deletion has a 7-day cooling-off period during which you can cancel it; after that, personal data is erased.
  • Evidence ledger — attestation records are hash-chained, and the ledger's audit value depends on its continuity. After erasure, retained attestation records carry only opaque identifiers; the personal data that linked them to you is removed.
  • Suppression list — if you opt out of email or an address hard-bounces, we keep that address on a suppression list so we do not email it again.
  • Billing records — as long as tax and accounting law requires.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to the processing of your personal data. Much of this is self-service: you can edit your email address in your profile, change notification settings, generate a signed export of your data (download links expire after 8 days — fetch them promptly), and delete your account. For anything else, email privacy@mmmnt.ai; we will verify the request against your account email and respond within the time the applicable law allows.

If you are in the EEA or UK, you may also lodge a complaint with your supervisory authority. We will never discriminate against you for exercising a privacy right.

9. California residents (CCPA/CPRA)

In the last 12 months we have collected the categories described in Section 2: identifiers (email, account IDs), commercial information (subscription records), internet activity (usage and security logs), and professional information you choose to include in workspace content. We collect them from you, your identity provider, and Stripe; we use them for the purposes in Section 3; and we disclose them only to the service providers in Section 5.

We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done either in the preceding 12 months. We do not use sensitive personal information for purposes requiring a right to limit. You have the rights to know, correct, and delete, exercisable as described in Section 8, in person or through an authorized agent.

10. Cookies and similar technologies

This website sets no cookies and runs no analytics or advertising trackers. The Feature application (the dashboard, on its own subdomain) uses only what is strictly necessary to keep you signed in: an authentication session, and browser session storage that remembers which workspace you are viewing until the tab closes or you sign out. Because we use nothing that requires consent, there is no cookie banner; blocking this storage in your browser simply prevents sign-in.

Signing in through Google, GitHub, or GitLab happens on that provider's own site, where the provider's cookies and policies apply; checkout and billing pages hosted by Stripe likewise set Stripe's own cookies under Stripe's policy. If we ever introduce cookies beyond the strictly necessary ones (for example, analytics), we will update this policy first and add a consent mechanism where the law requires one.

11. Security

Data is encrypted in transit; access to production systems is restricted by role and least privilege; and the evidence ledger itself is tamper-evident — its hash chain makes alteration detectable. No system is perfectly secure; if a breach affects your personal data we will notify you as the law requires.

12. Children

The service is for businesses and professionals and is not directed to children under 18. We do not knowingly collect their data; if you believe a child has an account, contact privacy@mmmnt.ai.

13. Changes

We will post updates to this policy here and, for material changes, notify you by email or in the service before they take effect.

14. Contact

flmnt LLC · privacy@mmmnt.ai