Privacy Policy

How FlexQueries collects, uses, shares, and protects personal information.

Last updated: July 25, 2026

This Privacy Policy explains how CYBRCOAST LLC, a Delaware limited liability company doing business as FlexQueries ("FlexQueries," "we," "us," or "our"), collects, uses, shares, and protects personal information when you use our hosted websites, applications, APIs, MCP server, support, and related services (collectively, the "Service").

This policy covers the FlexQueries-hosted Service.

1. Information we collect

Information you provide

  • Account and organization data: name, email address, authentication details, organization membership, preferences, and account settings.
  • Billing data: credit balance, purchases, automatic-reload settings, billing status, transaction identifiers, and limited payment-method details supplied by our billing provider. We do not receive or store full payment-card numbers.
  • Project and research data: project names, websites, domains, URLs, keywords, prompts, saved searches, tags, rank trackers, audit settings, files, and other content you submit.
  • Connected-service data: information you ask us to retrieve from Google Search Console or another integration, along with encrypted authorization tokens needed to maintain the connection.
  • Communications: support messages, feedback, and other correspondence.

Information collected automatically

  • Usage and diagnostic data: features used, request timing, credit usage, application events, errors, browser and device type, approximate region based on IP address, and security logs.
  • Marketing-site analytics: page views, referrers, campaign parameters, and general device information.
  • Attribution data: when you arrive through an identified Reddit campaign, we may store the campaign, referrer, landing page, and Reddit click identifier and report signup or purchase conversion events.
  • Cookies and local storage: session, security, preference, analytics opt-out, and campaign-attribution values. The Service does not require third-party advertising cookies to provide its core functionality.

Information from third parties

We receive information from authentication, billing, analytics, email, connected-integration, and data providers. We also receive public or licensed SEO and web data in response to requests you initiate.

2. How we use information

We use personal information to:

  • create, authenticate, and administer accounts and organizations;
  • provide projects, research, monitoring, reports, integrations, APIs, and MCP tools;
  • submit requested inputs to data and AI providers and return their results;
  • calculate, display, and debit the account balance for paid actions;
  • send account, security, billing, support, and monitoring communications;
  • operate, troubleshoot, secure, and improve the Service;
  • prevent fraud, abuse, unauthorized access, and violations of our Terms;
  • understand feature adoption and marketing performance;
  • comply with law and enforce agreements; and
  • establish, exercise, or defend legal claims.

Where applicable law requires a legal basis, we process information as needed to perform our contract with you, comply with legal obligations, pursue legitimate interests such as security and product improvement, and obtain consent where required. You may withdraw consent for future processing at any time, but that does not affect processing already completed.

3. How we share information

We do not sell personal information for money. We share information only as described below:

  • Cloud and infrastructure providers, including Cloudflare, that host, deliver, store, and protect the Service.
  • SEO and web-data providers, including DataForSEO, when you run a feature that requires their data.
  • Connected services, including Google, when you authorize an integration such as Search Console.
  • AI providers, including OpenAI, when you choose an AI-assisted feature. The prompt and context required for that request are sent to the provider.
  • Billing and payment providers, including Stripe, to administer checkout, saved payment methods, payments, automatic reloads, and refunds.
  • Email and support providers, including SendGrid, to deliver messages and manage communications.
  • Analytics providers, including PostHog for hosted-product analytics and Plausible for marketing-site analytics. Product analytics respects supported browser Do Not Track signals and your in-app analytics preference.
  • Advertising measurement providers, including Reddit, only when campaign attribution is present and conversion measurement is enabled.
  • Professional advisers and authorities when reasonably necessary for legal, security, audit, compliance, or claims purposes.
  • A successor or transaction participant in connection with a merger, financing, reorganization, acquisition, insolvency, or sale of assets, subject to appropriate confidentiality protections.

Providers process information under their own agreements and policies. The specific provider used for a feature can change as the Service evolves.

We may disclose aggregated or de-identified information that cannot reasonably be linked to you. We do not use private project content to train a general purpose AI model operated by FlexQueries.

4. Your choices and rights

Depending on where you live, you may have the right to request access to, correction of, deletion of, or a portable copy of personal information; object to or restrict certain processing; withdraw consent; or appeal a denied request. You may also have the right not to be discriminated against for exercising a privacy right.

You can:

  • update account and organization information in the Service;
  • connect or disconnect integrations;
  • disable hosted-product analytics in Settings → Analytics;
  • enable a supported browser Do Not Track signal;
  • email support@flexqueries.com to make a privacy request.

We may need to verify your identity and authority before completing a request. Some information may be retained where permitted or required for security, fraud prevention, billing, legal compliance, backups, or legal claims. If we cannot fulfill a request, we will explain why when required.

We do not knowingly sell personal information. If our practices change in a way that gives rise to a legally defined sale or sharing right, we will provide the required notice and opt-out mechanism. We honor legally required browser-based opt-out signals where they apply.

You may lodge a complaint with your local data-protection or consumer-protection authority.

5. Data retention

We keep personal information for as long as reasonably necessary to provide the Service, maintain your account, fulfill the purposes described in this policy, and meet legal, accounting, fraud-prevention, security, and dispute-resolution requirements.

Retention depends on the type of data. For example, active project data is generally kept while the account is active; transaction records may be kept longer for tax and accounting obligations; and short-lived logs and cached provider results are removed or overwritten on operational schedules. Deleted information may remain temporarily in restricted backups until those backups expire.

6. Security

We use administrative, technical, and organizational safeguards designed for the nature of the information we process. These include access controls, encrypted network transport, protected production secrets, encrypted connected OAuth tokens, project and organization scoping, input validation, and logging and monitoring.

No system is completely secure. You are responsible for using a strong, unique password, protecting connected accounts and devices, and notifying us promptly of suspected unauthorized access.

7. International data transfers

FlexQueries and its providers may process information in the United States and other countries that may have different data-protection laws. Where required, we use recognized transfer mechanisms and contractual protections.

8. Children's privacy

The Service is not directed to children under 13, and hosted accounts are limited to people who can enter a binding contract. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and delete it where required.

The Service may link to third-party websites. Their privacy practices are their own.

10. Changes to this policy

We may update this policy to reflect changes to the Service, providers, or law. We will post the revised policy and update the date above. If a change materially affects how we use existing personal information, we will provide additional notice where required.

11. Contact

For privacy questions or requests, email support@flexqueries.com.