Legal

Privacy Policy

How FLINT handles access requests, demo, device-signal, and operational data.

Effective date / August 2, 2026

Policy posture

No ad resale

We do not sell or share data for advertising.

Necessary controls

Cookies and local storage support security, consent, auth, and core workflows.

Fraud-model training

We use submitted verification data to train our own fraud-detection models that protect your agent. We never sell it or feed third-party models.

01

What we collect

For access requests submitted before August 2, 2026, we collected your work email address, company name, and role. These are stored in our access database and used to manage design partner follow-up.

We also captured a device fingerprint when you submitted the access form. This is a privacy-preserving device signal. It does not contain your name, email, or any directly identifying information. We use it to understand whether multiple submissions came from the same device, which helps us protect form integrity.

When you use the live verification demo, the same device fingerprint is captured as part of the demo's Environment Identity layer. This is for demonstration purposes only and is not retained beyond the session.

When an agent connects over MCP or the API to issue a passport or run a verification, we collect the data submitted for that purpose: agent name, optional controller, optional wallet address, and transaction context at verification time. Passports are signed and publicly resolvable by design. Verification records and the behavioral signals derived from them are retained as evidence and used to operate and improve FLINT's fraud-detection models.

We count selections of designated public calls to action in aggregate so we can understand which product paths are useful. These counters store the action name, public page path, and selected homepage persona when present. They do not store an IP address, user identifier, referrer, browser signature, or destination query string.

We collect standard server-side logs through our hosting provider (Vercel). These include IP addresses, browser type, and page request data, retained per Vercel's standard data practices.

02

How we use it

Historical access-request data (email, company, role) is used to evaluate design partner fit and communicate about FLINT product availability. We do not send marketing emails unrelated to FLINT. We do not sell or share this data with third parties for advertising purposes.

Device fingerprints are used internally to detect duplicate submissions and understand aggregate usage patterns. They are not linked to your personal identity without your knowledge.

Aggregate call-to-action counts are used to evaluate site navigation and product interest. They are not used for advertising or individual profiling.

We use the verification and behavioral data submitted to FLINT to train and improve our own fraud-detection and trust models. This is protective intelligence: it helps defend agents against takeover, diversion, and impersonation by bad actors. We do not sell this data, do not share raw identifiers, and do not use it to train third-party or general-purpose models.

03

Cookies and local storage

FLINT uses necessary cookies and local storage for authentication, security, abuse prevention, consent memory, and core product workflows. These controls are required for the site to operate and for FLINT to protect demo flows and signed verification records.

The cookie notice stores a local consent record so the site can remember that you have seen the necessary-controls notice. FLINT does not currently use third-party advertising cookies.

04

Third-party processors

Brevo handles email delivery and historical access-request contact management. Data sent to Brevo includes your email address, company, and role. Brevo's privacy policy governs how they process this data.

Notion is used as a lightweight database for historical access-request records. Entries include email, company, role, submission timestamp, and device fingerprint. Notion's privacy policy governs their data handling.

Fingerprint Pro provides device intelligence signals used in prior access-request intake and the live demo. Fingerprint's processing is governed by their privacy policy and data processing agreement. Fingerprint does not receive your email address or personal identifying information, only browser and device signals.

Vercel hosts the FLINT application and retains standard infrastructure logs per their data retention policies.

05

Data retention

Historical access-request records are retained until you request deletion or until the design partner process concludes, whichever comes first. Device fingerprints in our systems are retained alongside those records and deleted on the same schedule.

To request deletion of your data, email us at the address below. We will confirm deletion within 30 days.

06

Your rights

If you are located in the European Economic Area, the United Kingdom, or California, you have the right to access, correct, or delete the personal data we hold about you. You may also object to or restrict certain processing, and in some cases request portability of your data.

To exercise any of these rights, contact us at contact@flint.network. We do not require you to create an account or pay a fee to make a data request.

07

Security

FLINT is a fraud intelligence company. We take data security seriously as a matter of professional principle, not just compliance. Access-request data is stored in access-controlled systems. We do not store payment information. We do not log sensitive credentials.

No system is perfectly secure. If you believe your data has been involved in a security incident, contact us immediately at contact@flint.network.

08

Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated to affected users by email. The effective date at the top of this page reflects the most recent revision.

09

Contact

FLINT is operated by KillChain, Inc. For privacy questions or data requests, email contact@flint.network.

FLINT 2026