The short version
Your story stays yours
Flared contains sensitive health and wellbeing information. We use it only to provide and protect the features you choose. It is private by default and is shared with a support person only when you choose the person, information and action involved.
We do not sell personal information, provide it to data brokers or use health information for targeted advertising. Flared is a reflection and communication tool, not an emergency, diagnostic or medical service.
Who we are
Flared is operated by A.J. Brough & S.W. Brough (ABN 25 653 810 683), a partnership based in New South Wales 2155, Australia. In this policy, “Flared”, “we”, “us” and “our” mean that partnership.
This policy applies to the Flared website, web app and native apps. It explains how we handle personal information under Australian privacy law, including the Australian Privacy Principles and applicable New South Wales health privacy requirements.
Age and consent
Flared accounts are available only to people aged 16 and over. This applies both to people using a Health Profile and to support people. Public information pages may be viewed without an account, but a person under 16 must not create or use a Flared account. A parent or guardian must not create an account on their behalf or enter that person’s health information into their own Health Profile.
Before any signed-in account holder can use Flared, we ask them to make an unticked declaration that they are at least 16 and separately acknowledge the privacy collection notice. We record the age threshold, declaration, acknowledgement, applicable version and server time. We do not routinely collect dates of birth or identity documents for this purpose.
Before a User creates or continues a Health Profile, we ask for a separate, unticked express consent to collect and handle the health and wellbeing information they choose to provide. Providing health information is voluntary, but Health Profile features cannot operate without this consent.
These controls rely on honest self-declaration. If we learn or reasonably suspect that an account holder is under 16, we may block access while we investigate and close the account and delete associated information under our deletion process, except for any limited information we must retain by law.
You can stop adding health information at any time. You can also withdraw consent for future handling by contacting us, although this may require closure of your account and does not undo handling already permitted by law or information we must retain.
Information we collect
- Account information: sign-in identity, display name, email address when provided and an optional profile picture.
- Health and wellbeing information you choose to enter: Entries, symptoms, wellbeing state, cycle context, Flares, notes, food and medication context, support needs, Health Profile choices, appointment preparation, Summaries and timestamps.
- Support Circle information: names and contact details you enter, invitations, sharing permissions, support requests and responses.
- Billing information: plan, entitlement, Stripe customer and subscription identifiers, billing interval, renewal or cancellation status and payment status. Stripe collects payment-card details directly; Flared does not receive or store your full card number.
- Technical, security and support information: records needed to authenticate requests, protect accounts, diagnose faults, deliver email and respond when you contact us.
What Flared does not collect
Flared does not provide a feature for uploading doctor letters, pathology or imaging results, medical reports or other health documents. Please do not send those documents to our support email. The only image upload currently supported is an optional profile picture.
How we collect and use information
We collect information directly from you when you create an account, complete an Entry, configure support, prepare a Summary, manage billing or contact us. We may also receive identity information from a sign-in provider, responses from a support person you invited and subscription events from Stripe.
We use information to authenticate accounts, provide the Timeline and other features, generate descriptive Insights and Summaries, deliver support communications you initiate, manage subscriptions, respond to enquiries, prevent misuse, maintain security and improve reliability.
We do not currently use advertising pixels or third-party behavioural analytics in the signed-in Flared product. We will not introduce tracking that collects or infers health information without first assessing the privacy impact, updating this policy and obtaining consent where required.
Insights, Summaries and plan access
Flared uses structured rules to turn the information you enter into descriptive Insights and Summaries. They may identify associations or changes, but they do not prove cause, diagnose a condition, recommend treatment or make decisions about your legal rights.
Free and Premium plans may provide different time windows for viewing or calculating Insights. Changing plan changes that access window; it does not delete the underlying Entries in your Timeline. Subscription access may update automatically when Stripe reports a billing-status change.
Sharing and disclosure
Health information is private by default. When you use a support feature, you choose the intended recipient and the categories of information they may see. A Summary is downloaded or shared only when you take that action.
If you send information by email or text, download it, take a screenshot or share it outside Flared, the recipient or destination may keep a separate copy. Removing access inside Flared cannot recall those external copies.
We disclose only what is reasonably necessary to service providers that operate Flared, advisers or contractors bound by appropriate confidentiality, a buyer or successor subject to privacy safeguards, or authorities where disclosure is required or permitted by law or needed to address a serious safety or security threat.
We do not sell or rent personal information, provide it to data brokers or use health information to train general-purpose public AI models.
Service providers and overseas processing
- Amazon Web Services: application hosting, authentication, databases, private profile-picture storage and email delivery.
- Stripe: hosted checkout, subscription management, billing portal, payment processing and fraud prevention.
- Apple, Google or Meta: identity information when you choose the corresponding sign-in option.
Flared’s primary application data is hosted in the AWS Sydney region. Because our payment and optional sign-in providers operate internationally, they may process personal information in Australia, the United States, India, Ireland and other countries listed in their own privacy information. Overseas privacy protections may differ from Australian law. We take reasonable steps when selecting and configuring providers and remain accountable where Australian law requires.
Storage and security
Flared uses Amazon Cognito for authentication, Amazon DynamoDB for profile and Timeline data and a private Amazon S3 bucket for optional profile pictures. We use encrypted connections, encryption at rest, account-scoped API access, restricted administrative access, logging and other operational safeguards appropriate to the sensitivity of the information.
No internet service can promise absolute security. If a data breach occurs, we will contain and assess it and notify affected people and regulators where required by the Notifiable Data Breaches scheme or other applicable law.
Retention and deletion
We keep personal information while your account is active and while it is reasonably needed to provide Flared, meet legal obligations, resolve disputes, prevent fraud and protect the service. We do not delete Timeline Entries merely because an Insight is outside the access window for your current plan.
After we verify a deletion request, we aim to close the account and remove its information from active Flared product systems within 30 days. Limited billing, security, dispute or health records may need to be retained where law requires or permits. If New South Wales health-record retention requirements apply to Flared, health information collected when a person is 16 or 17 may need to be kept until they turn 25. Health information collected from other users may need to be kept for at least seven years from the last occasion the relevant health service was provided. We may ask for the minimum age information needed to calculate a legally required retention period. Retained information is restricted to the required purpose and deleted or de-identified when the retention period ends.
Deleted information may remain in encrypted disaster-recovery backups for up to 35 days before ageing out. Those backups are not used for ordinary product access and a verified deletion must be reapplied if a backup is restored. External copies previously shared by a User cannot be recalled.
See our data deletion instructions.
Access, correction and choices
You can update many account and Health Profile details inside Flared. You may also ask to access personal information we hold about you or correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
There is no charge to make a request. Email hello@flared.cloud. We may need to verify your identity. We aim to respond within 30 days. If we cannot fulfil a request, we will explain why and the available complaint options, except where the law prevents us from doing so.
Privacy questions and complaints
Email hello@flared.cloud and explain what happened and how you would like us to help. We will investigate fairly and aim to respond within 30 days.
If you are not satisfied, you may contact the Office of the Australian Information Commissioner. New South Wales health privacy matters may also be raised with the NSW Information and Privacy Commission.
Changes and contact
We may update this policy as Flared or the law changes. We will publish the new date here and, where a change materially affects how we handle information, provide notice in Flared or by email before it takes effect where practicable.
Privacy contact: hello@flared.cloud
A.J. Brough & S.W. Brough
ABN 25 653 810 683
New South Wales 2155, Australia