Flarea

Privacy Policy

Last updated 22 July 2026 · LinkedOtter LLC · GDPR & CAN-SPAM aligned

Who we are

Flarea is operated by LinkedOtter LLC ("we", "us"), a New York limited liability company at 440 Kent Ave, Brooklyn, NY 11249. We provide a live-broadcast / webinar platform. This policy explains what personal data we process and your rights over it. For privacy questions, contact privacy@linkedotter.com.

What we collect

Account data (name, email, password hash via our auth provider). Event & registration data you or your attendees provide (name, email, optional company, consent records). Usage data (pages viewed, features used, device/browser, IP address, approximate location). Live-session data (transcripts, chat, reactions, recordings) when a host runs a show. Voice dictation (optional): if you use the in-app microphone command feature, your browser sends the captured audio to your browser vendor (e.g. Google, Microsoft, or Apple) to convert it to text — this is processed by your browser vendor under their terms and does not pass through our servers; it only runs when you press the microphone. Cookies and local storage for sign-in sessions, UI preferences, and — on pages carrying our analytics pixel — a first-party visitor identifier (see Cookies & local storage below).

How we use it

To provide the service (run events, send confirmations/reminders/replays, show analytics), secure and improve the platform, and meet legal obligations. We do not sell personal data. We do not use your private session content to train third-party models beyond what is needed to generate the features you invoke (e.g. AI summaries you request).

Legal bases (GDPR)

Performance of a contract (providing the service you signed up for), legitimate interests (security, product improvement, and business-to-business outreach to professional contacts — see Research data & personalized outreach pages, where we describe the balancing test and your right to object), consent (marketing emails, optional cookies — withdrawable anytime), and legal obligation.

Sub-processors

We rely on the following vendors, each under its own published data-processing terms: Vercel (application hosting & content delivery), Supabase (database, authentication & file storage), LiveKit (live audio/video transport & recording (egress)), Cloudflare R2 (recording & media object storage), OpenAI (ai features (transcription, copy, images, agent)), Resend (transactional & reminder email delivery), Google (Sign-In) (optional "sign in with google" authentication), Stripe (payment processing & billing for paid plans), ElevenLabs (text-to-speech for show audio (walk-on announcements, narration)), HubSpot (crm sync — only if a host connects their own hubspot account). Each processes data only for the function described. The current canonical list, with purpose, data category, and region, is at /subprocessors.

Hosts as controllers

When a host runs an event, the host is the data controller for their attendee list and we act as their processor. Hosts must have a lawful basis to contact the people they register or invite.

Research data & personalized outreach pages (not our account holders)

We maintain a research dataset of public professional voices (name, job title, employer, topic, region, public platforms, estimated audience reach), compiled from publicly available sources such as company websites and public professional profiles. We did not obtain this data from you. We do not sell it. We use it for two things: to suggest relevant speakers and guests to hosts, and to build personalized outreach pages — a page addressed to a specific company that may name people who work there, with their job title and employer, alongside an illustrative AI-generated image. Those pages are not listed in our directory or indexed by search engines, but they are reachable by anyone holding the link, and recipients are encouraged to share them. Our lawful basis is legitimate interests (business-to-business outreach about a product relevant to your professional role); we have carried out and documented a balancing test weighing that against your privacy, and we do not include special-category data, personal contact details, or anything about your private life. You can object at any time and we will stop — including removing any page naming you. Request removal, correction, objection, or a copy — with no account — at /find/remove or privacy@linkedotter.com; verified requests are actioned within 5 business days and removals are suppressed so they do not reappear.

Attendee profiles across hosts

If you register for a show yourself — directly on Flarea's own signup page, or through a one-click "you might also like" signup — we link that registration to a single cross-host Flarea profile keyed to your email, so you can see your own history and replays at /me and so we do not treat you as a brand-new person every time you register with a different host. Shortly after you register this way, we also proactively email you a one-click sign-in link so that profile becomes a real account you can log into at /me whenever you like — you only ever get this email once. If a host instead uploads or imports your contact details themselves (for example, from a CSV of an existing list) rather than you registering directly, we do not create this cross-host profile or account for you at all: your registration stays only with that one host's event, exactly as if this profile feature didn't exist. Either way, this profile/account is ours, not any individual host's: a host only ever sees their own events and their own attendees, never your activity on another host's shows, and having (or not having) this account never affects your ability to watch a replay you already have a link to — replay access never requires an account. You can export or permanently erase your profile yourself at any time from /me — no request needed.

Cookies & local storage

We use strictly-necessary cookies/local storage for authentication and saving UI preferences. Separately, hosts can place the Flarea analytics pixel on their own site: where it runs, it stores a first-party random visitor identifier in local storage so repeat visits from the same browser can be counted as one visitor, and reports page views back to the host whose site it is on. It honours the browser's Do-Not-Track signal, and hosts can configure it to stay dormant until their own consent banner grants permission. It is not a third-party advertising tracker, sets no cross-site cookie, and we do not use it to build advertising profiles. You can clear these in your browser; doing so may sign you out.

Retention

We keep account and event data while your account is active and as needed for legal/operational reasons, then delete or anonymize it. Recordings and transcripts can be deleted by the host at any time from the dashboard, and we are rolling out automatic per-plan deletion of expired recordings — until that is switched on, recordings are retained until a host deletes them or asks us to. Walk-on souvenirs you generate (the AI stage image and its shareable /stage page) are self-only and removed on request — email privacy@linkedotter.com with the link and we take the page and image down; we do not retain your original uploaded photo.

Your rights

Subject to your jurisdiction, you may request access, correction, deletion, portability, restriction, or objection, and you may withdraw consent. Attendees can self-serve export and deletion from their /me account; for any other request, email privacy@linkedotter.com and we will respond within the legally required time (we may first verify your identity). Every marketing email also has a one-click unsubscribe that feeds a global suppression list hosts cannot override; if you unsubscribe, we retain your email address on that suppression list after deletion, because it is the only way to keep honoring the opt-out — it is used for nothing else.

California privacy (CCPA/CPRA) — Do Not Sell or Share

We do not "sell" your personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA) — so there is nothing to opt out of in that specific sense. You may still submit a "Do Not Sell or Share My Personal Information" request to privacy@linkedotter.com and we will honor it. California residents also have the right to know, access, correct, and delete the personal information we hold about them, and not to be discriminated against for exercising these rights. For a Speaker Finder listing, you can remove or correct it with no account at /find/remove; for anything else, email privacy@linkedotter.com.

Security

TLS everywhere, encrypted media (DTLS-SRTP), Postgres Row-Level Security isolating each host's data, hashed passwords, scoped & revocable API keys. See our Security & Trust page.

Children

The service is not directed to children under 16; we do not knowingly collect their data.

Changes

We will post material changes here and update the date below.

Questions or a data request? Email privacy@linkedotter.com.

Privacy Policy — Flarea