Privacy Policy
Effective date: June 8, 2026 · Greylock Labs
1. What We Collect
When you use Flow, we collect the following categories of information:
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, GitHub username, display name, avatar URL | GitHub OAuth or email sign-up |
| Board content | Task titles, descriptions, comments, checklist items, file names | You and your team |
| Usage data | Task status changes, timeline events, presence heartbeats | Automatic |
| Technical data | IP address (in auth audit log), browser type, request timestamps | Automatic |
| Billing data | Stripe customer ID, subscription status, plan type | Stripe (no card numbers stored by us) |
Authentication is handled through GitHub OAuth or email and password. Password-based sign-in is managed entirely by our authentication provider (Supabase). Flow never receives or stores your raw password; the provider stores it as a salted hash. We do not store raw API tokens either; only SHA-256 hashes are retained.
2. How We Use Your Information
- Providing the Service: storing and serving your board data, authenticating users, routing notifications
- Billing: processing subscription payments and managing seat limits via Stripe
- Security: detecting abuse, investigating unauthorized access, maintaining auth audit logs
- Communication: sending @mention notifications to webhooks you configure; transactional emails if Resend is configured
- Improvement: understanding aggregate usage patterns (e.g. task counts, DAU) to improve the product
We do not use your board content to train AI models. We do not sell your data to third parties.
3. Third-Party Services
We use the following sub-processors to operate the Service:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database hosting (Postgres), authentication | All board data, auth tokens |
| Railway | Application hosting | Request logs, IP addresses |
| Stripe | Payment processing | Email, billing information |
| GitHub | OAuth authentication, PR/issue sync | OAuth token, repo metadata |
| Cloudflare | DNS, CDN/proxy, email routing | Request metadata, IP addresses, inbound email routing |
| Resend | Transactional & inbound email | Recipient email & name, message content |
Each provider has its own privacy policy governing their use of shared data.
4. Data Retention
- Board content (tasks, comments, decisions): retained indefinitely while your account is active; deleted within 30 days of account deletion
- Presence data: shown as offline after 10 minutes of inactivity; the record is overwritten by your next session and removed when your account is deleted
- Auth audit logs: retained for 90 days, then automatically purged
- Billing records: retained as required by law (typically 7 years for financial records)
- Platform audit log: administrative/security events (including the IP address at the time of an action such as account deletion) are retained for security and to meet our legal obligations
- Timeline events: if you delete your account while your organization continues (other members remain), the team's shared history (task activity, comments, and the actions taken) is retained as part of the organization's records and is not individually erased; the historical entries keep the identifier and any text associated with them at the time. When an entire organization is deleted, its timeline is deleted with it. Support correspondence and product feedback tied to a deleted organization are deleted along with it.
5. Your Rights (GDPR & CCPA)
If you are located in the European Economic Area, United Kingdom, or California, you have the following rights:
- Access: request a copy of the personal data we hold about you
- Correction: request correction of inaccurate personal data
- Deletion (Right to Erasure): request deletion of your personal data. You can exercise this right directly by deleting your account (see Section 6 below)
- Portability: request your data in a machine-readable format
- Restriction: request that we restrict processing of your data in certain circumstances
- Objection: object to processing based on legitimate interests
Our lawful basis for processing your data is contract performance (providing the Service you signed up for) and legitimate interests (security, fraud prevention, service improvement).
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
6. Account Deletion
You can delete your account at any time. Account deletion:
- Revokes all your API tokens immediately
- Removes your presence data
- Deletes tasks assigned to you
- Removes your person record (name, email, avatar) from our database
- Deletes your product feedback, and (when you delete your whole organization) its support correspondence with us
- If your organization continues without you, its shared timeline history (task activity, comments, and the actions taken) is retained as part of the team's records for audit purposes; if you delete the entire organization, its timeline is deleted with it
Org owners must transfer ownership or delete their organization before deleting their account. To delete your account, use the board settings or send a DELETE request to /api/flow/account with your authentication token.
7. Cookies & Session Data
Flow uses a single authentication session, stored by our authentication provider in your browser's local storage (not a cookie) during sign-in. It is strictly necessary to maintain your authenticated session. It is not used for advertising or tracking. Because no tracking or advertising cookies are used and the session is functionally required, no cookie consent banner is displayed.
No third-party tracking cookies, analytics pixels, or advertising technologies are used.
8. Security
We implement industry-standard security measures including: TLS encryption in transit, SHA-256 token hashing (raw tokens never stored), row-level security on all database tables, timing-safe token comparison, and per-actor write rate limiting. Authentication failures are logged for security monitoring.
No method of transmission over the internet is 100% secure. If you discover a security vulnerability, please disclose it responsibly to [email protected].
9. International Data Transfers
Flow is hosted in the United States (Railway, us-east-1 via Supabase). If you are located in the EEA or UK, your data is transferred to and processed in the United States. We rely on standard contractual clauses and our sub-processors' data processing agreements for these transfers.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on the Service. The "Effective date" at the top of this page indicates when the policy was last updated.
11. Contact
For privacy questions, data access requests, or deletion requests, contact us at [email protected]. We aim to respond within 30 days.