This privacy policy explains how Commercial Office Service Filip Miernik ("Flexile", "we", "us") processes personal data when you visit flexile.io, create a Flexile account, or use the Flexile extension for Adobe After Effects. We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR").
The controller of your personal data is Commercial Office Service Filip Miernik, a business established in Poland, operating the Flexile product and the flexile.io website.
Contact for all privacy matters: contact@flexile.io.
We have not appointed a Data Protection Officer because we are not required to under Article 37 GDPR. Any question about this policy or your data can be sent to the address above.
We collect the following categories of personal data:
- Account data: first name, last name, email address, password (stored only as a salted hash), account status, role and preferred currency.
- Sign-in with Google: if you sign in with Google we receive your Google account identifier, email address, verified-email status and basic profile information (name, avatar) from Google.
- Licence and billing data: licence status, plan, trial usage and, when paid plans are active, your Stripe customer identifier, subscription identifier, invoices and payment status. We never receive or store your full card number; payments are processed by Stripe.
- Extension usage data: the tools you save to the cloud, your settings, usage counters (for example how many times a feature was used and when), progress in built-in tutorials, and the extension version you run.
- Technical and security data: IP address, browser and operating system information, request timestamps, error and diagnostic logs, and session tokens used to keep you signed in.
- Communication data: the content of messages you send us by email or through the contact form, and our replies.
- Website analytics data: pages viewed, referring page, approximate location derived from your IP address, device type, and interaction events, collected through cookies only with your consent.
Most of the data we process is provided directly by you when you:
- register a Flexile account or sign in with Google,
- download, install and use the Flexile extension in After Effects,
- save tools, presets or settings to your account,
- subscribe to a plan or manage billing in your dashboard,
- contact us by email or through the website,
- accept cookies in the cookie banner or use the website.
We also receive data indirectly from Google (when you sign in with Google) and from Stripe (payment and subscription status).
We process personal data for the following purposes and on the following legal bases:
- To create and operate your account, deliver the extension, validate your licence and keep you signed in (Article 6(1)(b) GDPR, performance of a contract).
- To process payments, issue invoices and manage subscriptions when paid plans are active (Article 6(1)(b) GDPR, performance of a contract, and Article 6(1)(c) GDPR, legal obligations in tax and accounting law).
- To send transactional emails such as account confirmation, password reset, licence and payment notifications (Article 6(1)(b) GDPR).
- To answer your questions and support requests (Article 6(1)(b) and 6(1)(f) GDPR, our legitimate interest in responding to people who contact us).
- To keep the service secure, prevent abuse, enforce the two-computers-per-account rule, rate-limit the API and diagnose errors (Article 6(1)(f) GDPR, our legitimate interest in the security and stability of the service).
- To understand how the extension is used through aggregated usage counters, so we can improve features and tutorials (Article 6(1)(f) GDPR, our legitimate interest in improving the product).
- To measure website traffic with analytics cookies (Article 6(1)(a) GDPR, your consent, which you can withdraw at any time in the cookie settings).
- To send product news and offers by email, only if you have opted in (Article 6(1)(a) GDPR, your consent).
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you.
We do not sell personal data. We share it only with service providers that process data on our behalf under data processing agreements, and only as far as necessary:
- Cloudflare, Inc. (hosting, content delivery, file storage, security). Cloudflare processes data in the EU and the United States.
- Neon, Inc. (managed database hosting for account and licence data).
- Stripe Payments Europe, Ltd. and Stripe, Inc. (payment processing, invoices, subscription management). Stripe is an independent controller for the payment data it collects; see the Stripe privacy policy.
- Google LLC (Sign in with Google, only if you choose that option).
- Twilio SendGrid and Loops (sending transactional and, with your consent, marketing email).
- PostHog, Inc. (website and product analytics, only after you accept analytics cookies).
We may also disclose personal data when required by law, to protect our rights, or in connection with a merger, acquisition or sale of assets, in which case we will inform you before your data becomes subject to a different privacy policy.
Some of the providers above are located in, or process data in, the United States. Where personal data leaves the European Economic Area we rely on an adequacy decision of the European Commission (including the EU-U.S. Data Privacy Framework where the provider is certified) or on the European Commission Standard Contractual Clauses, together with additional safeguards where needed. You can request a copy of the relevant safeguards by contacting us.
- Account, licence and extension usage data: for as long as your account exists. When you delete your account, or ask us to, we delete or anonymise this data within 30 days.
- Billing records and invoices: for the period required by Polish tax and accounting law, currently five years from the end of the tax year in which the transaction took place.
- Security and diagnostic logs: up to 12 months.
- Support correspondence: up to 24 months after the last contact.
- Analytics data: up to 12 months, or until you withdraw consent.
- Marketing consent records: until you withdraw consent, plus the time needed to prove that consent was given.
All traffic between your browser, the extension and our servers is encrypted with TLS. Passwords are stored as salted hashes and are never readable by us. Access to production systems is restricted to the people who operate the service and protected by strong authentication. Data sent to the extension is additionally encrypted at the application level.
We only send product news and offers by email if you have opted in. Every marketing email contains an unsubscribe link, and you can also withdraw your consent at any time by writing to contact@flexile.io. Transactional emails about your account, licence or payments are not marketing and are sent as part of the service.
Under the GDPR you have the following rights:
- The right to access: you can request a copy of the personal data we hold about you.
- The right to rectification: you can ask us to correct inaccurate data or complete incomplete data. You can change your name and email in your dashboard.
- The right to erasure: you can ask us to delete your personal data, subject to legal retention duties such as invoices.
- The right to restrict processing: you can ask us to restrict processing of your data under certain conditions.
- The right to object: you can object to processing based on our legitimate interests, and at any time to direct marketing.
- The right to data portability: you can ask us to transfer the data you provided to you or to another organisation in a structured, commonly used, machine-readable format.
- The right to withdraw consent: where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, email us at contact@flexile.io. If you make a request, we have one month to respond to you. We may ask you to confirm your identity before we act on a request.
Cookies are small text files placed on your device when you visit a website. flexile.io uses cookies and similar technologies (such as local storage) in the following categories:
- Necessary: required for the site and your dashboard to work, for example keeping you signed in, protecting forms against abuse and remembering your cookie choice. These cannot be switched off.
- Functional: remember preferences such as language or currency.
- Analytics: help us understand how visitors use the site (PostHog). Set only with your consent.
- Marketing: used to measure the effectiveness of campaigns. Set only with your consent. We currently do not run advertising cookies.
When you first visit the site you can accept all cookies, reject all non-necessary cookies, or customise your choice. You can change your choice at any time through the cookie settings link in the footer or by clearing cookies in your browser. If you disable cookies, some features of the website may not function as a result.
Flexile is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
flexile.io contains links to other websites and services, such as Adobe, Google, Stripe or our blog partners. This privacy policy applies only to flexile.io and the Flexile extension. If you follow a link to another website, read its privacy policy.
We review this policy regularly and publish updates on this page. Material changes will be announced by email to account holders or with a notice on the website. This policy was last updated on 17 September 2026.
If you have any questions about this policy, the data we hold about you, or you would like to exercise one of your rights, write to us at contact@flexile.io.
If you believe we have not handled your data properly, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live, work or where the alleged infringement took place. Our lead supervisory authority is the Polish President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl. We would appreciate the chance to address your concerns first, so please contact us before approaching the authority.