Flutterfrog

Security

Security and data handling.

This page is written for the person whose job is to say no. It states what is true today, what we commit to per engagement, and — at the bottom — what we do not claim.

Where your data sits

Client deployments are single-tenant — your own instance and your own storage, not a shared database with row-level separation. We deploy in the region you nominate; the default is Mumbai.

The underlying infrastructure is Google Cloud Platform. Google’s own certifications cover Google’s infrastructure, not our application — we mention it because it is relevant to your assessment, not because it transfers to us. Data is encrypted in transit and at rest.

Who can reach it

Access is limited to named individuals working on your engagement, each under a written confidentiality agreement. Credentials are never committed to source control. Audit logging of access and production activity is included in enterprise deployments, and we will tell you exactly what is and is not logged before you load anything.

You choose the boundary. Material you do not want in the system stays out of it, or stays on your own machines — and that is a configuration decision, not a request you have to make.

AI models and your content

We use commercial API terms only, never consumer tiers. The distinction matters: consumer products and paid API terms carry materially different commitments about what happens to submitted content.

Your content is not used to train models. We will point you to the specific clause in the relevant provider’s terms rather than ask you to take our word for it.

International transfers

We are an Indian company, so we will state the position rather than wait to be asked. India does not currently hold a UK or EU adequacy decision. Where personal data is transferred to, or accessed from, India, the appropriate safeguard under Article 46 applies — the ICO’s International Data Transfer Agreement, or EU Standard Contractual Clauses with the UK Addendum. We will sign either.

In many engagements the question is narrower than it first appears, because the data itself stays in your region and only named personnel have access. We are happy to work through that distinction with your data protection lead.

Sub-processors

The parties below may process data on our behalf. The definitive list for your engagement is issued in writing before anything is loaded, and we notify you in advance of any addition.

PartyPurposeRegion
Google Cloud Platform (incl. Firebase)Hosting, database, application runtimeMumbai (asia-south1) by default; alternative regions on request
AnthropicLanguage models, on commercial API termsRegional endpoint selected per engagement
Google (Gemini API)Image generation, on commercial API termsRegional endpoint selected per engagement
HostingerOutbound notification email only — never client contentEU

Ownership, retention and deletion

Your knowledge is held as plain text files that you already have a copy of — not rows in a database only we can read. There is no export process, because there is nothing to export.

Deletion on exit is a contract term rather than a policy commitment. Retention periods are set by you, in writing, before anything is loaded.

Incident response

As an Indian body corporate we are subject to the CERT-In Directions of April 2022, which carry a six-hour reporting duty for specified incidents — among the tightest in the world. Our commitment to you is notification without undue delay, with what we know at the time, followed by a written account once the position is established.

What we do not claim

We are a small company, and we would rather you learn that here than discover it in procurement.

  • We are not SOC 2 or ISO 27001 certified. Both require an independent audit we have not undertaken. If your process requires one, tell us early and we will price it into the engagement honestly rather than claim it.
  • We do not display a “GDPR compliant” badge. No meaningful certification scheme stands behind those. What we will do is answer every question on this page in writing, under contract.
  • We do not present our host’s certifications as our own. Running on certified infrastructure is not the same as being certified, and any vendor implying otherwise is worth a second look.

What we offer instead: a completed security questionnaire returned within one working day, a data processing agreement, the sub-processor list above, and a direct conversation with the person who built the system rather than an account manager.

Security review

Send us your questionnaire, your DPA, or your questions. We answer in writing, and we answer “no” where the answer is no.

gokul@theflutterfrog.com · Contact form