D-ALabs LLC (“D-ALabs”, “we”, “us”) runs Flasklings: the CLI, the desktop app and agent plugin, flaskling.com and app.flasklings.com. This policy explains what personal information we process, why, for how long, who helps us process it, and what your rights are. It follows the Personal Information Protection Act of the Republic of Korea.
The short version
- Flasklings works without an account, and what the CLI and the app record stays on your computer.
- We never collect your prompts, code, file contents, commands, tool input or output, your agent’s replies, or the names and paths of your projects.
- With an account, we keep what we need to sign you in and to run your pets, growth, essence, rankings and purchases. Your activity reaches us only as daily totals.
- Nothing is public until you publish your profile, and you choose what it shows.
- We don’t sell personal information, show ads, or use analytics or tracking tools.
1. What stays on your computer
To show your pet’s state, the CLI and the agent plugin read a few details from your coding agent’s events: event and tool names, model names, token counts and a session ID, which they hash. Everything else in an event is dropped as soon as it’s read.
They keep the following in the .flaskling folder in your home directory:
- a random install ID;
- each session’s activity times, token usage and folder name (not its full path), for 7 days;
- daily totals, your pets, essence and items, until you remove them;
- the number of commits you authored. Commit hashes are used only so a commit isn’t counted twice. Commit messages and changes are never read.
Usage-limit percentages are shown on screen and never stored. None of this leaves your computer unless you connect it to an account.
2. What we process, why and for how long
When you create an account or connect a device, we process the information below. We process it to provide the Service you signed up for, and, for your public profile and rankings, because you chose to turn them on.
| Information | Why | How long |
|---|---|---|
| GitHub sign-in Your GitHub user ID and username. We ask GitHub for no permissions, so we don’t get your email address, and we never store your GitHub access token. | To sign you in and suggest a handle | Until you delete your account |
| Email sign-in (once available) Your email address. | To sign you in and send sign-in links | Until you delete your account. A sign-in link expires after 15 minutes and its record is removed a day later |
| Sessions and devices Sign-in sessions, stored only as one-way hashes, and for each connected device its name, permissions and when it was last seen. | To keep you signed in and let you manage your devices | A session lasts 14 days and is removed a day after it ends. A device stays until you revoke it |
| Profile and game data Your handle and past handles, display name, time zone and its changes, pets with their names and looks, items, and your essence balance and history. | To run your pets, growth, essence and the store | Until you delete your account. A past handle redirects to the new one for 30 days |
| Daily totals from connected devices For each day and coding agent: work time, time with a session open, completed turns, the number of commits you authored, and token counts by model. | For growth and essence, and for rankings if you opt in | Until you delete your account |
| Live status (if you use it) A keyed hash that stands for the session, the coding agent, its state and the time. | To show a session’s state on your other devices | Less than 24 hours, and removed when you revoke the device |
| Purchases (once on sale) Order, item, amount, currency and payment status. Card details stay with the payment provider. | To deliver items, handle refunds and meet our legal duties | As Korean e-commerce law requires: 5 years for contract, cancellation, payment and delivery records, and 3 years for complaint and dispute records |
| Security records A one-way hash of your IP address, used only for rate limiting, and an account activity log (sign-ins, device and privacy changes, exports, deletion) under a pseudonymous ID with no email, handle or IP address. | To prevent abuse and to show you your account’s activity | IP hashes: about a day. Activity log: 90 days |
Our servers’ request logs record only the route, result and timing of each request, not your IP address, your account or what you sent. We delete information without delay once its period ends.
3. What we never collect
- Prompts, code, file contents or commands
- Tool input or output, or your agent’s replies
- Project or repository names and paths
- Commit messages or changes
- Your coding agent’s own session IDs
- Your GitHub access token, or your email address from GitHub
Our server rejects uploads that contain fields it doesn’t expect, and model names that look like paths, web addresses or keys.
4. What other people can see
- Nothing, until you publish your profile. Signing up or connecting a device is never consent to publish, and you can unpublish at any time.
- A published profile shows your handle, display name, pets (their kind, look, name and stage), collection, achievements and streak. Your pets and their stages are always shown. Your activity heatmap, arena record and usage appear only if you turn each one on.
- If you join the rankings, others see your rank or band, handle, display name and main pet, never your figures.
- In the arena, others’ pets challenge a snapshot of your pet: its kind, element, stats and looks.
- Your email address, GitHub ID, devices, projects and session times are never shown to anyone. If this policy changes what a profile shows, your profile becomes private until you confirm again.
5. Sharing and the companies that help us
We don’t sell personal information or give it to anyone else, except where the law requires it, for example under a court order.
These companies process personal information on our behalf:
| Company | What they do | Where |
|---|---|---|
| Cloudflare, Inc. | Hosts flaskling.com and app.flasklings.com and carries all traffic to them, including your IP address | United States, with servers in many countries |
| Supabase, Inc. | Hosts our database | Stored in Seoul, Republic of Korea |
When you sign in with GitHub, GitHub, Inc. handles the sign-in under its own privacy statement. Before email sign-in or paid purchases open, we’ll add the email provider and the payment provider to this list, with what they process.
Transfers outside Korea
Each time you use flaskling.com or app.flasklings.com, your connection, including your IP address and the requests you send, passes through the network of Cloudflare, Inc. (United States, privacyquestions@cloudflare.com), which has servers in many countries. This is needed to deliver the websites, and Cloudflare keeps request logs only for a short time under its own terms. You can avoid it by using the CLI and the app without an account, but the websites can’t work without it.
6. Cookies
app.flasklings.com sets two cookies, both needed for sign-in. flaskling.com sets none.
| Cookie | Purpose | Expires |
|---|---|---|
__Host-flaskling_session | Keeps you signed in | 14 days |
__Host-flaskling_oauth_state | Protects GitHub sign-in against forgery | 10 minutes |
We don’t use analytics, advertising or tracking cookies. You can block cookies in your browser, but then you can’t sign in.
7. Your rights
You can ask to see, correct or delete your personal information, ask us to stop processing it, and withdraw your consent. You can do much of this yourself in Settings:
- Export everything we hold about your account, up to 3 times a day. The file is deleted after 24 hours.
- Change your handle, display name and pet names.
- Publish or unpublish your profile, and turn rankings and each profile section on or off.
- See your account’s activity log and revoke devices.
- Delete your account.
For anything else, contact our privacy officer (section 11). We’ll reply within 10 days. Someone you authorize, such as a legal representative, can make a request for you. If the law requires us to keep some information, we’ll tell you what and why.
8. Deleting your account
When you delete your account in Settings, all access to it ends at once, your public profile and rankings are removed, and your account data is deleted. There’s no undo. Signing up again creates a new account.
After deletion we keep only:
- two log entries that record the deletion, re-keyed so they can’t be linked to you;
- a record that the deletion ran, for 30 days, or 90 days if it failed and has to be retried;
- purchase records the law requires us to keep, for the periods in section 2, stored apart from other data.
Copies in database backups disappear as the backups expire. If we ever restore a backup, we delete deleted accounts again before using it. We delete electronic files so they can’t be recovered, and we don’t keep personal information on paper.
9. How we protect it
- All connections use HTTPS, and sign-in cookies can’t be read by scripts on the page.
- Sign-in tokens and IP addresses are stored only as one-way hashes. GitHub tokens are never stored.
- Logs leave out IP addresses, account IDs and what you sent.
- Only the people who run the Service can access its production systems.
10. Children
Flasklings isn’t meant for children under 14, and you must be 14 or older to create an account. If we learn that we hold personal information of a child under 14 without a guardian’s consent, we delete it.
11. Privacy officer
Our privacy officer is Jeseok Lee, CEO. Contact them with any question, request or complaint about your personal information at info@d-alabs.com or +82-10-2983-3375.
12. Getting help elsewhere
If you need help beyond us, you can contact these Korean bodies:
- Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
- Personal Information Infringement Report Center (KISA): 118, privacy.kisa.or.kr
- Supreme Prosecutors’ Office, cybercrime investigation: 1301, www.spo.go.kr
- Korean National Police Agency, cyber bureau: 182, ecrm.police.go.kr
13. Changes to this policy
We’ll post changes here with the new effective date, and tell account holders in the dashboard, at least 7 days before they take effect, or at least 30 days before for changes that significantly affect your rights.
14. Contact
See Customer Support, or contact us:
- D-ALabs LLC, CEO Jeseok Lee
- #1140, Wirye Hyosung Harrington Tower, 190 Wirye-daero, Hanam-si, Gyeonggi-do, Republic of Korea
- Business Registration No. 547-87-03375
- Email info@d-alabs.com · Phone +82-10-2983-3375