Privacy notice
Last updated 10 October 2026
Draft for review. The bracketed details are still to be filled in, and this text has not yet been reviewed by counsel.
This notice explains what personal data FlarePath collects, why, and what you can do about it. The controller of your personal data is [CoralComp's registered company name], trading as CoralComp, [Registered office address]. Privacy contact: [privacy contact email address].
FlarePath is built on the public record of the US National Transportation Safety Board. Names and details of people that appear in that record are shown as the NTSB published them; we add nothing to them.
What we collect and why
| Data | Why | Legal basis |
|---|---|---|
| Your account: name, email address, a one-way hash of your password, your workspace and role, and the IP address you signed up from | To create and run your account and let your workspace administrators manage it; the sign-up address only limits how many accounts one address can request in an hour | Contract; legitimate interests (preventing abuse) |
| Your content: Casebook notes, bookmarks and share links | To keep them for you and show them to your workspace | Contract |
| Sign-in sessions: a random session token, stored as a hash; the browser and IP address it signed in from; when it was last used | To keep you signed in (until the browser closes and for 12 hours at most, or for 30 days if you choose to stay signed in), to show you where you are signed in so you can sign out other devices, and to end sessions when an account is disabled | Contract |
| Plan requests and their notes; the plan your workspace is on | To give you the plan you asked for | Contract |
| Payment records Paddle sends us: your name, email, country, the plan and its status. Never card numbers | To switch your plan on, renew it or end it | Contract; legal obligation (accounting) |
| Two-factor sign-in, if you turn it on: your authenticator secret, encrypted with a key kept apart from the database, and your recovery codes as one-way hashes | To check the codes you sign in with | Contract; legitimate interests (security) |
| Password reset requests: the account, when it was asked for and the IP address asking | To send you a reset link, and to stop the form being abused (a few requests an hour) | Contract; legitimate interests |
| Account activity: sign-ins, failed attempts and security changes on your account, each with the time, browser and IP address, and for sign-ins a one-way hash of the browser's device identifier | To show you on your Account page what happened on your account, and to email you when it signs in from a browser it has not used before (you can turn these emails off) | Legitimate interests (security) |
| Technical logs: your IP address, browser, pages requested and times | To keep the service secure and working, and to investigate misuse | Legitimate interests |
We do not sell personal data, use it for advertising, or use your content to train any model.
Who receives it
- Paddle.com, our reseller and the Merchant of Record for card orders. Paddle collects your payment details directly at checkout and processes them as an independent controller under its own privacy notice; we never see card numbers.
- Amazon Web Services, which hosts FlarePath in its US East (N. Virginia) region, as our processor.
- Google Workspace, our email provider, which sends password-reset emails and account, security and plan emails (requests to join and their outcome, removals, new sign-ins, password and two-factor changes, role changes, account deletion, and, to workspace administrators, plan changes and reminders) to the address on the account, as our processor.
- Google Fonts: the printable brief and casebook pages load their fonts from Google, which receives your IP address when you open one.
- Professional advisers (lawyers, accountants) where needed, and authorities where the law requires.
- Your workspace administrators, who see the members and notes of their workspace, and are told by email when someone asks to join, when another administrator makes a new invite code, and when a member deletes their account; the workspace owner is also told when an administrator changes someone’s role or removes them.
- FlarePath’s administrators, who are told your name, email and workspace name when you ask for a new workspace, so they can approve it.
Where it is kept
Your data is stored in the United States. Where you are in the UK or the European Economic Area, transfers rely on the European Commission’s standard contractual clauses (and the UK addendum) in our agreement with the host, or on an adequacy decision where one applies.
How long we keep it
- Account: while it is open. You can delete it yourself at any time from your Account page; it is deleted at once, and from backups within 14 days.
- Your content: notes belong to your workspace. When you delete your account, the notes you wrote stay with the workspace without your name; when the last member leaves, or the owner deletes the workspace, the workspace and all its notes are deleted at once (and, when the owner deletes it, every account in it, each told by email), and from backups within 14 days.
- Sessions: until you sign out, or they expire: 12 hours, or 30 days if you chose to stay signed in.
- Account activity: 90 days.
- Password reset links: they stop working after one hour or one use; the request records are kept for 90 days.
- Technical logs: kept only while they fit in a fixed, rolling space, usually a few weeks.
- Payment records: as long as tax and accounting law requires.
Cookies
FlarePath sets only the cookies it needs to work and keep your account safe: pc.session, which keeps you signed in (deleted when the browser closes, unless you chose to stay signed in for 30 days), pc.user, which lets the page show the account you are signed in with, and pc.device, a random identifier for your browser, kept 400 days, so we can tell you when your account is used from a browser it has not used before. There are no analytics or advertising cookies. Paddle’s checkout sets its own cookies when you pay.
Your rights
Depending on where you live, you may have the right to see the personal data we hold about you, to have it corrected or erased (you can delete your account yourself from your Account page), to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where we rely on consent. In the UK and EEA you may also complain to your data protection authority. In India, under the Digital Personal Data Protection Act 2023, you may access, correct and erase your data, seek grievance redressal from us, and nominate someone to act for you. Write to [privacy contact email address]; we answer within one month.
Security
Passwords are stored only as salted one-way hashes. Connections are encrypted, the database and backups sit on encrypted disks, and access to the servers is limited to named administrators. Each workspace’s notes are kept apart from every other workspace’s.
Children and changes
FlarePath is not intended for anyone under 18. We will post any change to this notice here, with a new date, and tell account holders in the service of any material change.