Back to the site

Legal

Privacy.

Updated 14 September 2026 · Flare Studio, Israel

In short

01What is collected

The brief (Start a project): what we are building, budget range, timing, your description, name, phone and email. Stored in a table called leads.

The course waitlist (Tell me when it opens): your email only. Stored in a separate table called course_waitlist. The same email is kept once.

With both, the server also records your IP address, the time, and the browser identifier — for security and to block automated submissions. Those two technical fields are cleared automatically after 30 days. Browsing the site collects nothing.

02Why

The brief: to read it, come back to you, and prepare a proposal. The waitlist: to send you one email when the course opens, and nothing else until then. Neither list is sold, shared or used to market anything of anyone else's.

03Where it lives and who touches it

Both tables sit in a database hosted by Supabase (EU/US cloud), reachable only by the site's server — not from the browser. When a brief or a waitlist signup arrives, a notification with its contents is sent to the studio's private Telegram chat via Telegram's Bot API, so it is read the same day. When the course opens, the waitlist email is sent through Resend. Each of these providers processes the data for the studio only, under their own privacy terms.

Your browser also keeps a local copy of a brief you sent (localStorage). That copy never leaves your device and you can clear it with your browser data.

04How long

A brief is kept while there is a conversation or a project, and no longer than 24 months after the last contact. A waitlist email is kept until the course-opening email goes out, or until you ask for it to go. Technical fields (IP, browser) go after 30 days regardless.

05Your rights

Under Israel's Protection of Privacy Law 5741-1981 you can see what is stored about you, correct it, or have it deleted. Ask on WhatsApp · 050-683-0231. Deletion is done by hand within a few days and confirmed back to you.

06Security

HTTPS everywhere, server-side validation, rate limiting per address, a honeypot against bots, and database access that is closed to the public API entirely. No security is absolute, but nothing here is reachable from a browser.

07Changes

This page may change. The date at the top is the last edit.

— Flare Studio · Built to Ship