Privacy Policy

Effective date: June 8, 2026  ·  Greylock Labs

1. What We Collect

When you use Flow, we collect the following categories of information:

CategoryExamplesSource
Account dataEmail address, GitHub username, display name, avatar URLGitHub OAuth or email sign-up
Board contentTask titles, descriptions, comments, checklist items, file namesYou and your team
Usage dataTask status changes, timeline events, presence heartbeatsAutomatic
Technical dataIP address (in auth audit log), browser type, request timestampsAutomatic
Billing dataStripe customer ID, subscription status, plan typeStripe (no card numbers stored by us)

Authentication is handled through GitHub OAuth or email and password. Password-based sign-in is managed entirely by our authentication provider (Supabase). Flow never receives or stores your raw password; the provider stores it as a salted hash. We do not store raw API tokens either; only SHA-256 hashes are retained.

2. How We Use Your Information

We do not use your board content to train AI models. We do not sell your data to third parties.

3. Third-Party Services

We use the following sub-processors to operate the Service:

ProviderPurposeData shared
SupabaseDatabase hosting (Postgres), authenticationAll board data, auth tokens
RailwayApplication hostingRequest logs, IP addresses
StripePayment processingEmail, billing information
GitHubOAuth authentication, PR/issue syncOAuth token, repo metadata
CloudflareDNS, CDN/proxy, email routingRequest metadata, IP addresses, inbound email routing
ResendTransactional & inbound emailRecipient email & name, message content

Each provider has its own privacy policy governing their use of shared data.

4. Data Retention

5. Your Rights (GDPR & CCPA)

If you are located in the European Economic Area, United Kingdom, or California, you have the following rights:

Our lawful basis for processing your data is contract performance (providing the Service you signed up for) and legitimate interests (security, fraud prevention, service improvement).

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

6. Account Deletion

You can delete your account at any time. Account deletion:

Org owners must transfer ownership or delete their organization before deleting their account. To delete your account, use the board settings or send a DELETE request to /api/flow/account with your authentication token.

7. Cookies & Session Data

Flow uses a single authentication session, stored by our authentication provider in your browser's local storage (not a cookie) during sign-in. It is strictly necessary to maintain your authenticated session. It is not used for advertising or tracking. Because no tracking or advertising cookies are used and the session is functionally required, no cookie consent banner is displayed.

No third-party tracking cookies, analytics pixels, or advertising technologies are used.

8. Security

We implement industry-standard security measures including: TLS encryption in transit, SHA-256 token hashing (raw tokens never stored), row-level security on all database tables, timing-safe token comparison, and per-actor write rate limiting. Authentication failures are logged for security monitoring.

No method of transmission over the internet is 100% secure. If you discover a security vulnerability, please disclose it responsibly to [email protected].

9. International Data Transfers

Flow is hosted in the United States (Railway, us-east-1 via Supabase). If you are located in the EEA or UK, your data is transferred to and processed in the United States. We rely on standard contractual clauses and our sub-processors' data processing agreements for these transfers.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on the Service. The "Effective date" at the top of this page indicates when the policy was last updated.

11. Contact

For privacy questions, data access requests, or deletion requests, contact us at [email protected]. We aim to respond within 30 days.