Privacy Policy
Flashlight processes your phone number to verify sign-in and deliver messages, and your name and email to manage your account. Twilio handles SMS verification. Sendblue handles assistant messaging. Conversation content and app connection tokens are encrypted in the hosted backend; Hermes processes requests using Tinfoil inference. Connected apps are accessed after your authorization. Flashlight web sign-in sessions use secure, HTTP-only cookies and expire after 30 days. You can disconnect apps, ask Flashlight to forget saved memories, or send DELETE MY HISTORY to remove earlier backend conversation rows. Copies held on your phone and by providers are separate. For account deletion or pilot support, contact the person who invited you.
If you add a store login to Vault, its username and password are encrypted in Flashlight’s backend. When you ask to connect that store, Flashlight can enter those details into its sign-in page through our hosted browser provider. Passwords are kept out of assistant prompts and are not returned to your account page. You can remove saved credentials in Vault. Deleting a Vault credential does not sign out an existing merchant session. To remove saved merchant sessions and Vault logins together, text Flashlight “forget saved logins.” Merchants can also expire sessions. Flashlight does not collect payment-card details in Vault.
Back to sign in