Account and purchase
For sign-in, recovery, trial verification and purchase, Flash Route processes email and account, order, payment and access state, the selected plan and term. For a trial, email is verified with a one-time code and bound to the account; ordinary email sign-in does not start a trial. Flash Route does not receive full card details; they are processed by the payment provider shown at checkout.
Device and installation
Flash Route processes random installation and device identifiers, device name, platform, Chrome and extension version, and session state. To protect the one-time trial, the server issues an opaque signed installation attestation; an installation can receive a trial only once. It is stored locally and in Chrome Sync only when Chrome synchronisation is enabled. Flash Route does not require a phone number or use invasive browser fingerprinting for a trial.
Selective routing
The extension stores selected services, connection state and short-lived route credentials. Domains of selected services are processed to apply the route. Until a new or changed disclosure is accepted, selected services are blocked locally and are not sent through Flash Route nodes; the saved session and credentials are not used for proxy authentication. After consent, the network edge and infrastructure necessarily see transient IP addresses and connection metadata for delivery, authorisation, security and abuse prevention.
First successful route
After the first selected-service request successfully completes through an authorised route, the extension stores locally once only the service ID, UTC timestamp and the fixed route class authorized_selected_service. The record contains no URL, page content, request ID or credentials. Active correlation records bind Chrome's request ID to the current route generation and owned proxy endpoint until the terminal request event or browser session ends; this is not a separate store with an independent count or time limit. Only rejected terminal tombstones are bounded to at most 128 records with a 60-second TTL. The correlation contains no visited URL, page content, cookies or credentials. During bounded recovery, the extension checks a fixed selected-service endpoint with a HEAD request and random nonce, without credentials or a body; it does not repeat the failed user's URL, is valid for at most 30 seconds and is bounded by the recovery deadline, and remains a local observation rather than proof of server-side acceptance or independent egress. The user can clear the local first-route record by clearing extension data or removing the extension.
Data not read
Flash Route does not read page or chat content, password fields or other form data, user files, or browsing history. Flash Route access data — account tokens and short-lived proxy credentials — is processed separately only to operate the account and route.
Processors
Data is shared only with processor categories needed for the feature: Flash Route infrastructure and VPS/hosting, the email provider for one-time codes, the payment provider during purchase, and Google Chrome Sync when the user enables synchronisation. They do not receive it for unrelated advertising.
Retention
Short-lived OTPs, sessions and routing credentials are limited by their own expiry and are deleted or replaced on expiry, logout or revocation. The local extension log is capped at 100 events and a support report at 20. Aggregate site analytics is retained for a configured 7 to 366 days. Account, licence, device, payment, refund, security-audit, support and backup records are kept only to the extent necessary for active access and applicable accounting, dispute, security and recovery purposes.
Operational logs
Infrastructure logs may contain a transient IP, request target and error metadata. They are not used to create browsing histories. Nginx keeps up to 14 daily rotations, container logs are size-bounded, proxy access logging is disabled, and journald is capped at 14 days and 512 MB.
Usage observation
Limited technical usage observation may be enabled on individual nodes for verification: for a completed network event, a node temporarily records an opaque reference, time, and transferred-byte volume. These technical records are periodically removed by time and size. Only aggregate counters for completed events and byte volume for a licence in hourly windows are sent to the Flash Route central server. This technical observation may be incomplete or absent; it is not a complete traffic log, a current rate, a user count, or open-connection count. It is not used for quotas, automatic sanctions, or access decisions.
Licence and node binding
An operational binding between a licence and a node, using an opaque reference, verifies that an aggregate belongs to that licence. It contains no URL, page content, messages, browsing history, payment details, or credentials. The binding metadata is retained separately within the licence record's retention and is not traffic history. On the central server, aggregate counter windows are retained for 24 hours by default, configurable up to seven days.
Website analytics
The website uses only an anonymous aggregate visit counter: no cookies, fingerprinting, email addresses, stored IP addresses, browsing history or advertising profiles. Browser storage is used only for the language choice and campaign parameters during the current session.
Contact
Privacy questions: support@flashroute.app.