← Back to home

Privacy Policy

How Flowviant collects, uses, and protects your data.

Last updated June 25, 2026

This Privacy Policy explains how Flowviant ("Flowviant", "we", "us") handles personal data when you visit flowviant.com or use the Flowviant application at app.flowviant.com (the "Service"). We keep the data we collect to what the Service needs to function, and we do not sell your personal data.

Information we collect

  • Account data. When you sign up we create an account through our authentication provider, Clerk. This includes your name, email address, and — if you sign in with GitHub or Google — the basic profile and identifier from that provider.
  • Billing data. Paid plans are processed by Stripe. Stripe collects and stores your payment details; we never receive or store full card numbers. We retain your subscription status, plan, seat count, and billing email.
  • Content you create. Projects, canvases, epics, stories, tasks, sprints, comments, and any text you enter, including documents synced in real time for collaboration.
  • Integration data. If you connect GitHub, we access repository metadata, file contents, commits, and pull requests for the repositories you authorize. If you configure Slack, we store the webhook URL you provide.
  • AI prompts and context. Messages you send to the in-app assistant, and the project context needed to answer them.
  • Inbound email. If you use the email-to-task feature, we process the emails sent to your project's ingest address to create work items.
  • Usage and log data. Standard server logs (IP address, browser type, timestamps, and request metadata) generated when you use the Service.

How we use your data

  • To provide, operate, and maintain the Service and your account.
  • To process payments and manage subscriptions and entitlements.
  • To power AI features you invoke — drafting plans, answering questions, and dispatching coding agents.
  • To sync your GitHub activity to your project and send notifications you've configured.
  • To secure the Service, prevent abuse, and debug problems.
  • To communicate with you about the Service (transactional email).

AI processing

When you use AI features, the relevant prompt and project context are sent to a model provider to generate a response. Managed AI runs on Google's Gemini models. Coding agents run on Anthropic's Claude — when you connect your own agent, that processing happens under your own provider credentials and cost. We send only what is needed to fulfill your request and rely on these providers' API terms, under which your content is not used to train their foundation models.

Subprocessors

We share data with the following providers strictly to operate the Service:

ProviderPurpose
CloudflareApplication hosting, database (D1), object storage (R2), and inbound email routing
ClerkAuthentication and account management
StripeSubscription billing and payment processing
Google (Gemini)Managed AI model inference
Anthropic (Claude)Coding-agent model inference
GitHubRepository integration (only when you connect it)
SlackOutbound notifications (only when you configure it)

Sharing and disclosure

We do not sell your personal data. We disclose data only to the subprocessors above, to your own organization's members per your project's access settings, when required by law, or in connection with a merger or acquisition (in which case we will notify you).

Data retention

We retain your account and content for as long as your account is active. When you delete a project or your account, we delete the associated content from our active systems; residual copies may persist in encrypted backups for a limited period before being overwritten. Log data is retained for a limited operational window.

Security

Data is encrypted in transit (TLS) and at rest on our infrastructure. For more on our practices, see our Security page.

International transfers

Our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for international transfers.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing (for example under the GDPR or the CCPA). You can manage most of your data directly in the app, or contact us to exercise these rights. We will not discriminate against you for doing so.

Cookies

We use only essential cookies required to keep you signed in (set by Clerk) and to process payments (set by Stripe). We do not use advertising or third-party tracking cookies. The marketing site loads fonts and icons from third-party CDNs, which may receive your IP address as part of serving those assets.

Children

The Service is not directed to children under 16, and we do not knowingly collect their data.

Changes to this policy

We may update this policy from time to time. We will post the revised version here and update the "last updated" date above. Material changes will be communicated through the Service.

Contact

Questions or requests about privacy: [email protected].