Version 1 — 31 August 2026
Privacy policy.
FlashInsight surveys simulated respondents, not real people. We therefore collect no survey responses from human beings, and we build no file of research participants. The personal data we process is our customers': account, billing, and the technical logs needed to run the service.
1. Who is responsible
PALOMABEN, société civile, 6 rue Métayer, 95540 Méry-sur-Oise, France, registered with the Pontoise Trade and Companies Register under number 507 457 034. For any question, or to exercise your rights: contact@flashinsight.io
2. The data we process
Account data. Name, email address, encrypted password, organisation, role. Billing data. Credit purchases, transaction history, information required for invoicing. We store no card details: payments are processed by Stripe. Technical data. Connection logs, IP address, browser technical data — what is needed to run and secure the service. We do not measure your use of the platform. No analytics tool tracks what you do in the application, or what you exchange there. The audience measurement described in section 10 concerns the public pages of the site only, before any sign-in. Content you upload. Documents, visuals or text submitted as stimulus material, and data you provide to calibrate a population. What we do not process. Simulated profiles correspond to no real person: they are built from published statistical distributions and are not personal data.
3. Why, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the service, managing your account and studies | Performance of the contract |
| Invoicing and managing credits | Performance of the contract, and legal obligation for accounting |
| Securing the service and preventing misuse | Legitimate interest |
| Improving the service and fixing faults | Legitimate interest |
| Sending you commercial information | Consent, withdrawable at any time |
| Meeting a legal obligation or an authority's request | Legal obligation |
4. Your content is used for your study only
The documents and data you upload are used to produce your study. They are shared with no other customer. They are not used to train or fine-tune any artificial intelligence model — not for you, and not for anyone else. What we control. Every call we make to a model carries a setting that explicitly refuses data collection. That setting is covered by our automated tests: it is not an intention, it is a control executed on every call. What is not in our hands. Whether that refusal is honoured by the provider and by the model suppliers it calls is governed by their contractual terms. We select them on that undertaking and we check their terms — but it is not ours to enforce, and we do not claim otherwise.
We deliberately separate two things throughout this page, because they are not equivalent. What we do is a control — verifiable in our own system, and dependent on no one else. What a provider does on their side is a contractual undertaking — we select them on it and we check their terms, but we do not execute it for them. We tell you which of the two applies, every time.
5. How long we keep it
At the end of these periods, data is deleted or anonymised.
| Data | Retention |
|---|---|
| Account, studies and uploaded content | For the term of the contract, then 30 days |
| Technical and security logs | 6 months |
| Accounting and invoicing records | 10 years — legal obligation, we cannot delete them earlier |
| Sales contacts with no follow-up | 3 years after the last exchange |
The thirty days following the end of the relationship give you time to export your studies. After that, we delete your content from our active systems and can no longer return it to you. Our backups follow their own cycle and are overwritten in turn; we do not use them to reconstruct deleted content. Earlier deletion can be requested at any time. We carry it out by hand, on written request: we have no automatic button, and we would rather say so than let it be assumed. The GDPR provides for cases where we must retain data despite your request — accounting records, compliance with a legal obligation, or the establishment and defence of legal claims. We will tell you which apply, if any do. What we keep beyond that. We retain measurements of how our method performs — reliability scores, validation metrics, technical indicators — used to improve it. They contain no verbatim, no concept or question wording, no result attributable to a study, and nothing identifying a customer or a brand. They are designed to relate to no one, and we never use them to reconstruct a study.
6. Who has access
These are the providers currently configured. We date this list because it describes a state, not an architecture: it can change, and this page changes with it.
| Provider | Role | Where | Nature |
|---|---|---|---|
| Vercel Inc. | Application hosting | US company; execution configured from Paris | Configuration |
| Supabase | Database and authentication | AWS, Ireland (eu-west-1) | Configuration |
| Language model access layer | Routing requests to the model chosen for the study | Inside or outside the European Union depending on the model chosen — see section 7 | Configuration, interchangeable |
| Stripe | Payments | Processes card details, which we never see | Structural |
| Google Analytics | Audience measurement on public pages only | US company | Configuration — see section 10 |
We sell no data and disclose none to third parties for commercial purposes. One point we owe you in honesty. Several of these providers are US companies, and their own terms allow them, in certain cases, to process data outside the European Union — including for services whose main infrastructure sits in Europe. We choose European regions where they are offered, and we cannot guarantee that no data will ever be processed outside. Such processing is governed by the mechanisms in Chapter V of the GDPR.
7. Transfers outside the European Union
We would rather be precise here than reassuring. What stays in Europe. Your account data, your billing and your content at rest are stored in Ireland. The application runs from Paris. We are tied to no model and no provider. This is a design choice, and a structural one: we regularly test several models, we have changed models more than once, and the method has never had to change with them. The model access point is a configuration setting — it can be a third-party routing service, a European provider, or a locally run model. Moving between them is a setting, not a rebuild. Where processing takes place. Depending on the study and the model chosen, content may be processed inside the European Union or outside it, in particular in the United States. On request, before a study begins, we tell you where it will take place and through which services. What travels, and what does not. What is sent to the model is the study content: stimulus material, questions, population definitions. Your account data, your billing and your technical logs are never sent to a model. They are stored in Ireland — but see the note at the end of section 6: our payment and hosting providers are US companies, and their terms allow them to process certain data outside the Union. What this makes possible. Because the access point is a setting rather than a dependency, we can adapt a study's set-up to a localisation requirement without redesigning it. Why this usually involves no personal data at all. Our respondents are simulated: there is no real person behind a profile, so there is no respondent personal data to transfer. What circulates is your professional material — a concept, an advertisement, a questionnaire. In the normal course of a study it therefore contains no personal data. It can contain some if you upload some: a name, a photograph, a testimonial. That is the case addressed just below, and you keep control of it. The case where it would. If you upload a document containing personal data, it would follow that same path. Our terms ask you not to, and you keep control: you decide what you upload. Should it occur, those transfers are governed by the mechanisms provided for in Chapter V of the GDPR, and your content is never used to train a model. If your internal policy prohibits any processing outside the European Union, tell us before we start: we adapt the study set-up.
8. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability, under the conditions and limits set by the GDPR, and the right to withdraw your consent at any time. We handle these requests by hand. We have no self-service tool, and at our current volume we see no need for one — but it does mean a request goes through an exchange with us, not through a button. Write to us at contact@flashinsight.io. We respond within one month. You may also lodge a complaint with the CNIL — https://www.cnil.fr — if you consider your rights are not respected.
9. Security
Traffic is encrypted in transit. Each organisation's data is isolated from others at database level, not merely by the interface. Access is restricted to those who need it — to date, one person. What we do. We run occasional security audits targeted at specific surfaces of our system. We measure before, we fix, we measure after, and we keep the test scripts so they can be replayed. The most recent one addressed whether an uploaded document could hijack a simulated respondent's behaviour: eight attempts out of eight succeeded before, none succeeds after the fix. What we do not have, and we would rather say so: no continuous testing programme, no audit by an independent third party, no certification. No system is infallible and we do not claim otherwise. We undertake to inform you without delay of any incident affecting your data.
10. Cookies
Necessary cookies for the service to work: sign-in, security, and remembering your display language. These do not require your consent. Analytics. We use Google Analytics on the public pages of the site only — never inside the application, where your study data lives. By default this measurement is anonymous and uses no cookies: we know a page was viewed, we do not know by whom, and nothing is stored on your device. A banner invites you, on your first visit, to allow fuller measurement, which does use cookies. If you refuse, measurement stays anonymous and cookie-free — it does not stop, and it does not follow you. You can change your choice at any time. We use no advertising cookies and resell no browsing data.
11. Changes
This policy may change. Any substantial modification will be notified to you, and the version date at the top of the page shows the last update.