The short version

Your story stays yours

Flared contains sensitive health and wellbeing information. We use it only to provide and protect the features you choose. It is private by default and is shared with a support person only when you choose the person, information and action involved.

We do not sell personal information, provide it to data brokers or use health information for targeted advertising. Flared is a reflection and communication tool, not an emergency, diagnostic or medical service.

Who we are

Flared is operated by A.J. Brough & S.W. Brough (ABN 25 653 810 683), a partnership based in New South Wales 2155, Australia. In this policy, “Flared”, “we”, “us” and “our” mean that partnership.

This policy applies to the Flared website, web app and native apps. It explains how we handle personal information under Australian privacy law, including the Australian Privacy Principles and applicable New South Wales health privacy requirements.

Information we collect

  • Account information: sign-in identity, display name, email address when provided and an optional profile picture.
  • Health and wellbeing information you choose to enter: Entries, symptoms, wellbeing state, cycle context, Flares, notes, food and medication context, support needs, Health Profile choices, appointment preparation, Summaries and timestamps.
  • Support Circle information: names and contact details you enter, invitations, sharing permissions, support requests and responses.
  • Billing information: plan, entitlement, Stripe customer and subscription identifiers, billing interval, renewal or cancellation status and payment status. Stripe collects payment-card details directly; Flared does not receive or store your full card number.
  • Technical, security and support information: records needed to authenticate requests, protect accounts, diagnose faults, deliver email and respond when you contact us.

Optional website email updates

Added 17 September 2026. You can choose to receive Flared news, practical resources and product updates without creating an app account. We collect your email address, your consent choice and wording/version, request and confirmation times, subscription status and random link tokens. We also temporarily keep a hashed network identifier and request counts to limit misuse.

The form has an unticked consent choice. We send a confirmation email after you submit it and only activate your subscription when you confirm. Your email subscription is separate from app accounts, Health Profiles and private reflections. We do not use your health information to select or personalise marketing emails. Creating an account or buying Premium does not subscribe you.

We store the mailing list separately in Amazon DynamoDB in Sydney and use Amazon Simple Email Service in Sydney to deliver confirmation, welcome and optional update emails. Email may be routed or stored outside Australia by your email provider. AWS delivery and security processing may also involve its global systems. We do not sell or rent the mailing list or include advertising pixels or open-tracking pixels in these emails.

Confirmation links expire after 48 hours. Unconfirmed requests are scheduled for deletion after seven days; automatic expiry deletion may take a few additional days. We keep an active subscription while you remain subscribed. Unsubscribing stops future updates and removes the email address from the active subscription record immediately. We retain limited consent and withdrawal evidence, a hashed email identifier and the unsubscribe token for up to three years to honour your choice and handle complaints. Network rate-limit records are scheduled to expire after two hours. Encrypted recovery backups can retain deleted records for up to 35 days.

Every update email includes a free unsubscribe link. You do not need an account or password to use it. You can also email hello@flared.cloud to unsubscribe or ask to access, correct or delete subscriber information. Unsubscribing does not delete your app account, cancel Premium or stop necessary account and support messages. If you later sign up again, fresh confirmation is required.

See the email collection notice for a short explanation at sign-up.

What Flared does not collect

Flared does not provide a feature for uploading doctor letters, pathology or imaging results, medical reports or other health documents. Please do not send those documents to our support email. The only image upload currently supported is an optional profile picture.

How we collect and use information

We collect information directly from you when you create an account, complete an Entry, configure support, prepare a Summary, manage billing or contact us. We may also receive identity information from a sign-in provider, responses from a support person you invited and subscription events from Stripe.

We use information to authenticate accounts, provide the Timeline and other features, generate descriptive Insights and Summaries, deliver support communications you initiate, manage subscriptions, respond to enquiries, prevent misuse, maintain security and improve reliability.

We do not currently use advertising pixels or third-party behavioural analytics in the signed-in Flared product. We will not introduce tracking that collects or infers health information without first assessing the privacy impact, updating this policy and obtaining consent where required.

Insights, Summaries and plan access

Flared uses structured rules to turn the information you enter into descriptive Insights and Summaries. They may identify associations or changes, but they do not prove cause, diagnose a condition, recommend treatment or make decisions about your legal rights.

Free and Premium plans may provide different time windows for viewing or calculating Insights. Changing plan changes that access window; it does not delete the underlying Entries in your Timeline. Subscription access may update automatically when Stripe reports a billing-status change.

Sharing and disclosure

Health information is private by default. When you use a support feature, you choose the intended recipient and the categories of information they may see. A Summary is downloaded or shared only when you take that action.

If you send information by email or text, download it, take a screenshot or share it outside Flared, the recipient or destination may keep a separate copy. Removing access inside Flared cannot recall those external copies.

We disclose only what is reasonably necessary to service providers that operate Flared, advisers or contractors bound by appropriate confidentiality, a buyer or successor subject to privacy safeguards, or authorities where disclosure is required or permitted by law or needed to address a serious safety or security threat.

We do not sell or rent personal information, provide it to data brokers or use health information to train general-purpose public AI models.

Service providers and overseas processing

  • Amazon Web Services: application hosting, authentication, databases, private profile-picture storage and email delivery.
  • Stripe: hosted checkout, subscription management, billing portal, payment processing and fraud prevention.
  • Apple, Google or Meta: identity information when you choose the corresponding sign-in option.

Flared’s primary application data is hosted in the AWS Sydney region. Because our payment and optional sign-in providers operate internationally, they may process personal information in Australia, the United States, India, Ireland and other countries listed in their own privacy information. Overseas privacy protections may differ from Australian law. We take reasonable steps when selecting and configuring providers and remain accountable where Australian law requires.

Storage and security

Flared uses Amazon Cognito for authentication, Amazon DynamoDB for profile and Timeline data and a private Amazon S3 bucket for optional profile pictures. We use encrypted connections, encryption at rest, account-scoped API access, restricted administrative access, logging and other operational safeguards appropriate to the sensitivity of the information.

No internet service can promise absolute security. If a data breach occurs, we will contain and assess it and notify affected people and regulators where required by the Notifiable Data Breaches scheme or other applicable law.

Retention and deletion

We keep personal information while your account is active and while it is reasonably needed to provide Flared, meet legal obligations, resolve disputes, prevent fraud and protect the service. We do not delete Timeline Entries merely because an Insight is outside the access window for your current plan.

After we verify a deletion request, we aim to close the account and remove its information from active Flared product systems within 30 days. Limited billing, security, dispute or health records may need to be retained where law requires or permits. If New South Wales health-record retention requirements apply to Flared, health information collected when a person is 16 or 17 may need to be kept until they turn 25. Health information collected from other users may need to be kept for at least seven years from the last occasion the relevant health service was provided. We may ask for the minimum age information needed to calculate a legally required retention period. Retained information is restricted to the required purpose and deleted or de-identified when the retention period ends.

Deleted information may remain in encrypted disaster-recovery backups for up to 35 days before ageing out. Those backups are not used for ordinary product access and a verified deletion must be reapplied if a backup is restored. External copies previously shared by a User cannot be recalled.

See our data deletion instructions.

Access, correction and choices

You can update many account and Health Profile details inside Flared. You may also ask to access personal information we hold about you or correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.

There is no charge to make a request. Email hello@flared.cloud. We may need to verify your identity. We aim to respond within 30 days. If we cannot fulfil a request, we will explain why and the available complaint options, except where the law prevents us from doing so.

Privacy questions and complaints

Email hello@flared.cloud and explain what happened and how you would like us to help. We will investigate fairly and aim to respond within 30 days.

If you are not satisfied, you may contact the Office of the Australian Information Commissioner. New South Wales health privacy matters may also be raised with the NSW Information and Privacy Commission.

Changes and contact

We may update this policy as Flared or the law changes. We will publish the new date here and, where a change materially affects how we handle information, provide notice in Flared or by email before it takes effect where practicable.

Privacy contact: hello@flared.cloud
A.J. Brough & S.W. Brough
ABN 25 653 810 683
New South Wales 2155, Australia