Legal

Privacy Policy

Last updated 7 June 2026


RestFlags ("RestFlags", "we", "us", or "our") is a feature-flag, targeting and experimentation platform operated by Etariosk. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it. It applies to the RestFlags dashboard at restflags.com, the public flag-evaluation API at /api/v1, and the related marketing pages (together, the "Service").

By creating an account or using the Service you acknowledge the practices described here. If you do not agree, please do not use the Service.

Controller and processor

RestFlags plays two distinct roles depending on the data involved:

  • As a controller — for data about our own users: the account holders and team members who sign in to the dashboard. We decide why and how this data is processed, and this Policy governs it.
  • As a processor — for the end-user evaluation context your application sends to the flag API (the user object and any attributes inside it). Here you are the controller and we process that data on your behalf and on your instructions, under our Terms & Conditions. You are responsible for having a lawful basis to send us that data and for telling your own users about it.

Data we collect

Account and profile data

We use Google and GitHub Sign-In (via Firebase Authentication) as our login methods. When you sign in with one of these providers we receive and store:

  • your name,
  • your email address,
  • your profile photo URL from that provider, and
  • a stable Firebase user identifier.

We also record account-management metadata such as your account creation date, last login time, workspace memberships, and assigned roles.

Workspace and configuration data

When you use the dashboard we store the configuration you create: workspace names and slugs, feature-flag definitions, variations, targeting rules, segments, experiments, prerequisites, alerts, webhooks, and billing contact details. This is the operational content of the Service.

End-user evaluation context (processed on your behalf)

When your application calls the flag API, you send a user object containing a user identifier (user.id) and any attributes you choose to include (for example plan, country, or email) so that targeting rules can be evaluated. We process this context to return an evaluation result and, for analytics and experiments, we store evaluation and conversion events that reference the user key. We do not control what attributes you send — please send only what your targeting actually needs, and avoid sensitive categories of data.

Usage, technical and security data

To operate, secure and bill the Service we collect:

  • API usage — per-account request counts (the basis for billing) and per-evaluation events recording flag key, environment, served variant, result, HTTP status, latency, region, and the SDK string.
  • IP addresses — the IP of the actor who makes a change (recorded in the workspace audit log); where you configure an API-key IP allowlist, the IP of API callers (checked against that allowlist); and the IP of callers to the flag API, processed transiently in memory to enforce per-IP rate limits and prevent abuse (not stored as part of this rate-limiting).
  • Audit records — an immutable, hash-chained log of meaningful changes in your workspace, including the acting user and timestamp.
  • Error and diagnostic data — if error monitoring is enabled, technical error reports may be sent to our monitoring provider.

Cookies and similar technologies

We use strictly necessary cookies, plus optional analytics cookies that load only if you accept them. We do not use advertising cookies.

Strictly necessary (always active):

  • A Firebase session cookie (HttpOnly, and Secure in production) keeps you signed in for up to five days.
  • An rf_workspace cookie remembers which workspace you are currently viewing.
  • A small entry in your browser's local storage records your cookie-consent choice so we do not have to ask again.

Optional analytics (set only after you accept the cookie banner):

  • Firebase Analytics (Google Analytics) sets cookies and identifiers to measure how the Service is used so we can improve it. Nothing is set until you consent, and you can change or withdraw consent at any time via Cookie preferences in the site footer. We do not use this data for advertising.

How we use your data

We use personal data to:

  • authenticate you and keep your account secure;
  • provide, maintain and operate the dashboard and flag API;
  • evaluate feature flags and run experiments as you have configured them;
  • measure usage and calculate billing;
  • with your consent, measure general usage of the Service through analytics to understand and improve it;
  • maintain the audit log and detect, investigate and prevent abuse, fraud and security incidents;
  • send service communications, including workspace invitations and free-plan usage-limit notices to your billing contact; and
  • comply with our legal obligations.

We do not sell your personal data, and we do not use it for behavioural advertising.

Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on:

  • Performance of a contract — to provide the Service you signed up for;
  • Legitimate interests — to secure the Service, prevent abuse, and improve reliability, balanced against your rights;
  • Legal obligation — to meet accounting, tax and other legal requirements; and
  • Consent — where specifically requested, which you may withdraw at any time.

How we share your data

We share personal data only with service providers ("subprocessors") who help us run the Service, each bound by contractual confidentiality and data-protection obligations:

SubprocessorPurpose
Google (Firebase)Authentication, Google Sign-In, database, analytics
GitHubAuthentication (GitHub Sign-In)
DigitalOceanCloud hosting
SentryError and performance monitoring (if enabled)
Email/SMTP providerDelivery of workspace invitation emails (if enabled)

We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety and security of RestFlags, our users, or the public. If RestFlags is involved in a merger, acquisition or asset sale, data may be transferred as part of that transaction, subject to this Policy.

International transfers

Our providers may process data in countries outside your own, including the United States. Where we transfer personal data internationally we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, where required.

Data retention

We retain account and configuration data for as long as your account is active. Usage and evaluation events are retained to support metrics, experiments and billing. Audit-log entries are retained as a tamper-evident record for security and compliance purposes. When you close your account we delete or anonymise personal data within a reasonable period, except where we must retain it to meet legal, accounting or security obligations. Because of the cascading design of our database, deleting an account removes its workspaces and their associated data.

Security

We take measures designed to protect personal data, including:

  • encryption of traffic in transit (TLS);
  • storing only a hash of every API key secret and Firebase session — never the raw secret;
  • an immutable, cryptographically hash-chained audit log that makes tampering detectable;
  • role-based access controls and least-privilege API key scopes;
  • per-IP and per-API-key rate limiting on the public API to mitigate abuse; and
  • network isolation, with a single hardened public entrypoint and a redundant flag-serving service for resilience.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. If you are in California, you have rights under the CCPA/CPRA including access, deletion, and the right not to be discriminated against for exercising them; note that we do not sell or share personal data as those terms are defined under that law. To exercise any right, contact us at contact@restflags.com. We may need to verify your identity before responding, and we will respond within the time required by applicable law.

If we process data as a processor on your behalf, please direct end-user requests to the customer who controls that data; we will assist that customer as required.

Children

The Service is not directed to children and is intended for use by businesses and their staff. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

Changes to this Policy

We may update this Policy from time to time. When we make material changes we will update the "Last updated" date below and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

Contact

Questions about this Policy or your personal data can be sent to Etariosk at contact@restflags.com.