This Privacy Policy explains how Flowviant ("Flowviant", "we", "us") handles personal data when you visit flowviant.com or use the Flowviant application at app.flowviant.com (the "Service"). We keep the data we collect to what the Service needs to function, and we do not sell your personal data.
Information we collect
- Account data. When you sign up we create an account through our authentication provider, Clerk. This includes your name, email address, and — if you sign in with GitHub or Google — the basic profile and identifier from that provider.
- Billing data. Paid plans are processed by Stripe. Stripe collects and stores your payment details; we never receive or store full card numbers. We retain your subscription status, plan, seat count, and billing email.
- Content you create. Projects, canvases, epics, stories, tasks, sprints, comments, and any text you enter, including documents synced in real time for collaboration.
- Integration data. If you connect GitHub, we access repository metadata, file contents, commits, and pull requests for the repositories you authorize. If you configure Slack, we store the webhook URL you provide.
- AI prompts and context. Messages you send to the in-app assistant, and the project context needed to answer them.
- Inbound email. If you use the email-to-task feature, we process the emails sent to your project's ingest address to create work items.
- Usage and log data. Standard server logs (IP address, browser type, timestamps, and request metadata) generated when you use the Service.
How we use your data
- To provide, operate, and maintain the Service and your account.
- To process payments and manage subscriptions and entitlements.
- To power AI features you invoke — drafting plans, answering questions, and dispatching coding agents.
- To sync your GitHub activity to your project and send notifications you've configured.
- To secure the Service, prevent abuse, and debug problems.
- To communicate with you about the Service (transactional email).
AI processing
When you use AI features, the relevant prompt and project context are sent to a model provider to generate a response. Managed AI runs on Google's Gemini models. Coding agents run on Anthropic's Claude — when you connect your own agent, that processing happens under your own provider credentials and cost. We send only what is needed to fulfill your request and rely on these providers' API terms, under which your content is not used to train their foundation models.
Subprocessors
We share data with the following providers strictly to operate the Service:
| Provider | Purpose |
|---|---|
| Cloudflare | Application hosting, database (D1), object storage (R2), and inbound email routing |
| Clerk | Authentication and account management |
| Stripe | Subscription billing and payment processing |
| Google (Gemini) | Managed AI model inference |
| Anthropic (Claude) | Coding-agent model inference |
| GitHub | Repository integration (only when you connect it) |
| Slack | Outbound notifications (only when you configure it) |
Sharing and disclosure
We do not sell your personal data. We disclose data only to the subprocessors above, to your own organization's members per your project's access settings, when required by law, or in connection with a merger or acquisition (in which case we will notify you).
Data retention
We retain your account and content for as long as your account is active. When you delete a project or your account, we delete the associated content from our active systems; residual copies may persist in encrypted backups for a limited period before being overwritten. Log data is retained for a limited operational window.
Security
Data is encrypted in transit (TLS) and at rest on our infrastructure. For more on our practices, see our Security page.
International transfers
Our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for international transfers.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing (for example under the GDPR or the CCPA). You can manage most of your data directly in the app, or contact us to exercise these rights. We will not discriminate against you for doing so.
Cookies
We use only essential cookies required to keep you signed in (set by Clerk) and to process payments (set by Stripe). We do not use advertising or third-party tracking cookies. The marketing site loads fonts and icons from third-party CDNs, which may receive your IP address as part of serving those assets.
Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
Changes to this policy
We may update this policy from time to time. We will post the revised version here and update the "last updated" date above. Material changes will be communicated through the Service.
Contact
Questions or requests about privacy: [email protected].