Menu

Flowwyn privacy

Privacy Policy

This draft privacy page explains how Flowwyn V1 treats account data, uploaded files, generated outputs, workflow metadata, billing metadata, and support data.

Data Flowwyn may process

  • Account data such as your email address and authentication identifiers.
  • Uploaded files and generated outputs for workflow runs.
  • Workflow run metadata, usage events, output artifact metadata, and safe operational logs.
  • Payment and order metadata needed to process point packs and support billing questions.
  • Support or contact information you provide when asking for help.

How data is used

  • To authenticate users and show owner-scoped pages.
  • To run hosted workflows, enforce usage limits, record workflow history, and provide owner-only downloads.
  • To process payment status, point grants, refunds, fraud checks, support, tax, accounting, and legal obligations.
  • To troubleshoot product issues while avoiding raw CSV content, secrets, and payment secrets in user-facing logs.

Access and sharing boundaries

  • Uploaded files and generated outputs are intended to use private storage and owner-only access.
  • V1 creators do not see user inputs or generated outputs.
  • Payment secrets, raw provider secrets, service-role keys, and webhook secrets must not be exposed to the browser.
  • Flowwyn does not sell personal data to advertisers.
  • V1 does not send workflow inputs to external API providers or AI providers unless a future feature explicitly introduces that behavior.

Retention and deletion

  • Input and output retention should be limited or configurable and should not be treated as indefinite storage.
  • Account, order, ledger, payment, and audit records may be retained for fraud prevention, support, tax, accounting, and legal reasons.
  • Deletion and privacy requests can be sent through support until a dedicated privacy contact is configured.

Security note

Flowwyn uses product and database boundaries such as RLS, private storage, and owner-scoped downloads, but no system can promise absolute security.

This page avoids making certification claims such as SOC 2, ISO, HIPAA, GDPR, or CCPA readiness.

Related pages