Privacy Policy
Last updated: August 10, 2026
1. Overview
We take your privacy seriously. This Privacy Policy describes how UseONE, LLC ("we", "us", "Company") collects, uses, stores, and protects your personal information when you use:
• https://notionflare.com and related subdomains — primarily the NotionFlare creator SaaS (Notion as CMS, Knowledge Base / RAG, Telegram bots, distribution, billing, and documentation); • Mobile applications we publish under the NotionFlare / HexAstral / related brands on the Apple App Store and Google Play; • Related APIs, newsletters, contact / feedback forms, and support channels.
Where an app-specific privacy page differs for a HexAstral or other mobile product, that app-specific page controls for that app. This Policy is intended to meet applicable data-protection laws and store privacy expectations.
2. Information We Collect
2.1 Information you provide • Account identifiers: name, email, profile photo, and OAuth identifiers when you sign in with Google, GitHub, Apple, Notion, or similar providers. • Content you create or connect: blog posts, media uploads, Notion workspace tokens you authorize, distribution settings, and similar creator data. • Newsletter subscription email and confirmation status. • Contact and feedback submissions (name or email and message body when you use /contact or in-product feedback). • Purchase and entitlement information when you buy subscriptions or in-app products (processed by Apple, Google, Stripe, and/or RevenueCat — we receive receipts / entitlement state, not full card numbers). • Support messages you send us.
2.2 Telegram & Knowledge Base (when you enable these features) • Telegram bot tokens and webhook secrets you configure. • Linking codes and chat / group links (Telegram chat IDs, optional chat titles, Telegram user IDs of users who interact with your bot). • Queries sent to your bot (for example /ask) and related command text needed to answer. • We process group or private chat content only as needed to operate the bot features you enable; we do not sell Telegram message data.
2.3 What Knowledge Base / /ask does not collect or access NotionFlare is a knowledge base over content you sync from Notion (and related surfaces you control). Unless you deliberately put that data into Notion pages (or other content you sync), we do not scrape, import, or look up: • Telegram member profiles, contact lists, private chat history, or other group membership privacy data beyond what is required to run the bot commands you enable; • Orders, payments, subscriptions, CRM records, sales pipelines, or similar business systems outside Notion; • Any third-party database you have not connected through a supported integration that you authorize.
If you import personal data, customer data, or business records into Notion and sync them to the Service, you are the controller of that content for privacy purposes; we process it as a service provider to operate indexing and /ask. You are responsible for lawful basis, notices, and any risk arising from that import.
2.4 Automatically collected information • Device and browser metadata (approximate location from IP, locale, time zone). • App / site usage logs for reliability, abuse prevention, and product improvement. • Crash diagnostics. • Cloudflare Turnstile / similar bot-protection signals on anonymous forms (feedback, newsletter). • Push notification tokens if you enable notifications in a mobile app.
2.5 Advertising & attribution • We do not sell personal information. • We do not use IDFA / advertising IDs for cross-app advertising tracking as a business model. • We do not build advertising profiles to sell to third parties. • When we run paid acquisition (for example Meta, Google, Xiaohongshu 聚光, or Bilibili ads), we may load advertising pixels or tags and send conversion events (such as sign-up or purchase) to those platforms, including click identifiers from the ad landing URL and hashed email where the platform supports enhanced matching. These tools only run when the corresponding configuration is enabled.
3. How We Use Information
We use personal information to: • Provide and secure the Service (accounts, Notion sync, publishing, media hosting, Knowledge Base search, Telegram bots, distribution); • Index private and public content you sync for retrieval-augmented generation (RAG) so you (Dashboard test) and authorized Telegram group channels can ask questions about your posts — private posts are stored in our database/KV and vector index but are never listed on the public blog, site search, RSS, or sitemap; • When you enable “Include my Public posts in platform discovery” under Settings → Preferences, index those public posts so they may be retrieved by NotionFlare’s official Telegram demo / platform discovery experience; • Process subscriptions and restore purchases; • Send transactional / service email (account security, important service notices, and — if we enable them — quota or billing-related service notices about your account); • Send newsletter / product email only when you subscribe (double opt-in). You can unsubscribe at any time. Newsletter messages are optional marketing communications, separate from transactional mail; • Respond to feedback and support requests; • Improve reliability and prevent fraud / abuse; • Measure advertising attribution and conversion for ads we run (sign-up / purchase callbacks to ad platforms when enabled). This is not the same as sending you marketing email; • Comply with law and App Store / Play policies.
We do not sell or rent your personal information.
4. AI, RAG & Third-Party Processors
Some features send limited inputs to third-party processors under contract, which may include: • Cloudflare (Workers, R2, D1, Workers AI, Vectorize, Turnstile, Queues); • Stripe (web billing, where used); • Apple / Google (sign-in and in-app purchases); • RevenueCat (mobile entitlement validation, where used); • Amazon SES or an internal mailer service for transactional email and (when you opt in) newsletter delivery; • Notion (only if you connect your Notion account); • Telegram (only if you connect a bot — messages and commands are processed via Telegram's API under Telegram's terms); • Advertising platforms we use for acquisition when configured (for example Meta, Google, Xiaohongshu, Bilibili), limited to pixel/tag loads and conversion callbacks.
Knowledge Base / RAG: subject to your plan quotas, we create embeddings (vector representations) of your private and public posts and store them in Cloudflare Vectorize (or equivalent) so questions can retrieve relevant chunks and generate answers with Workers AI. Free plans may use Dashboard Try /ask with a capped personal index; Telegram / Discord / Slack /ask and Image OCR require a paid plan (Pro or Business) unless otherwise stated on Pricing. Private posts remain off the public site (including titles and authors in Command-K) but may be retrieved by your linked IM groups (when enabled on your plan) and by your own Dashboard Ask test.
Answers are generated from indexed content you synced. They are not a substitute for live CRM, billing, or messaging-platform lookups.
Image OCR (optional, Pro or Business): if you enable “Index images (OCR) in Knowledge Base” under Settings → Preferences, we may send images you synced to R2 (via media proxy) to Workers AI vision models to extract text for indexing. OCR is subject to separate daily and monthly quotas tied to your plan, is off by default, and may be inaccurate. You can disable the preference at any time; subsequent rebuilds stop injecting OCR text into the vector index.
AI auto-cover (optional, Business): for posts that have no cover image, we may generate a cover with Workers AI and store it in R2. Auto-cover is subject to separate daily and monthly quotas. When the quota is exhausted, posts still sync and publish without an auto-generated cover. Free and Pro plans do not receive AI auto-cover. Prefer a Notion page cover or Featured Image when you can. Cover generation may be inaccurate or stylistically unsuitable; you may replace or remove generated covers.
Platform discovery / official demo RAG: Public posts appear on your public blog. They are included in NotionFlare’s shared platform knowledge base (for example the official Telegram demo /ask) only if you turn on the preference under Settings → Preferences. You can turn it off at any time; we then stop treating new retrievals as in-corpus and update embeddings as soon as practical. Private and draft posts are never included in the platform corpus.
Interactive AI Studio image generation (web chat and Telegram /image) has been discontinued. Historical conversation / generation metadata may be retained only as needed for abuse prevention and then deleted with your account.
We instruct AI providers not to use your content to train public models where the product contract allows that control. AI output may be inaccurate and is not professional advice.
5. Cookies & Local Storage
We use cookies and similar technologies that are necessary or helpful to operate the Service, including: • Authentication / session cookies for signed-in users; • Cloudflare Turnstile challenge tokens on anonymous forms (feedback, newsletter subscribe) — verified server-side, not stored as a long-lived login cookie; • Preference cookies (locale, sidebar UI state, and similar); • Security and rate-limiting signals tied to your IP or session; • First-party attribution cookies (for example nf_utm_*, nf_xhs_click_id, nf_bili_track_id, nf_fbclid, nf_gclid) that remember how you arrived from a campaign so we can attribute sign-up or purchase; • When advertising is configured, third-party advertising pixels/tags (for example Meta Pixel, Google gtag) that may set their own cookies.
We do not sell personal information or build ad profiles for resale. For a short summary see our Cookie Policy at https://notionflare.com/legal/cookie-policy. You can control cookies through your browser settings; disabling necessary cookies may break sign-in or security features.
6. Storage, Security & Retention
• Primary infrastructure runs on Cloudflare's edge network. • Data in transit uses TLS. • Access is limited by role and least privilege. • After account deletion requests (via Settings or email), we delete or anonymize personal account data within 30 days, except where we must retain records for legal, tax, or fraud-prevention reasons. In-product deletion usually completes within 24 hours. • Operational logs are retained for a limited period for security and debugging (typically up to 90 days unless a longer period is required for an ongoing investigation). Cloudflare platform log retention is configured in the Cloudflare Dashboard. • Ask insight events (question text, short answer preview, IM message references, and button/reaction feedback) are retained for about 90 days and then deleted by a daily scheduled job. • RAG embeddings and indexed chunks are removed or orphaned when the underlying posts are archived/deleted or your Knowledge Base access ends, subject to normal processing delays. After a plan downgrade, a cleanup job removes indexed posts beyond the Free (or lower) indexed-post cap. • Historical AI Studio conversation / generation records (if any) and feedback submissions are retained while your account is active and deleted or anonymized with account deletion, unless we must keep them for abuse prevention. • Telegram, Discord, and Slack Ask bindings and any user-held bot credentials are deleted when you disconnect the integration or delete your account. Shared platform bot tokens operated by NotionFlare are not per-user credentials.
7. Your Rights
Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to withdraw consent where processing is consent-based.
You can download an account data export and request deletion from Dashboard → Settings. You may also email privacy@notionflare.com. We aim to respond within 15 business days.
8. Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided data, contact privacy@notionflare.com and we will delete it.
9. International Transfers
We may process data in the United States and other regions where Cloudflare or our subprocessors operate. Where required, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses).
10. Changes
We may update this Policy. Material changes will be reflected by updating the "Last updated" date on this page and, where appropriate, an in-product notice. Continued use after the effective date constitutes acceptance of the updated Policy.
11. Contact
Privacy inquiries: privacy@notionflare.com Controller: UseONE, LLC Website: https://notionflare.com