flash[:notice] Security

as david said, the flash is stored in the session.

there's another quirkiness of the flash that you should be aware, though:

the action that receives the flash is the request immediately following the one that populated the flash. that means that in quasi-parallel requests (e.g. user opens many tabs) or in multiple refreshes, the flash may go to an undesired page.