This page is the practical companion to the Privacy Policy. It explains, without the legal phrasing, what flowss collects, where your work goes and who else can see part of it, what stays only in your browser, how long each kind of record is kept, and every control you have — switching off usage measurement, downloading everything held about you, managing email, and asking for corrections or deletion. Where this page and the policy differ, the policy is the binding text; where you need the mechanisms behind these promises, see Security at flowss.
At a glance
| Question | Short answer |
|---|---|
| Who is responsible? | Voranox Inc., the Canadian company that operates flowss. Requests are handled under PIPEDA, and where the GDPR or a similar law gives you more, the stronger rule applies. |
| Do you train AI on my work? | No. |
| Do you sell my data? | No. No third-party analytics, ad trackers or cross-site tracking either. |
| Is my work synced to your servers? | Yes, automatically, whenever you are signed in. There is no opt-out today. |
| Is usage measurement anonymous? | Yes: a random per-browser id, a short list of event names, no IP address, no account link. You can switch it off. |
| Are feedback and crash reports anonymous? | Not when you are signed in — they carry your account. |
| Where does my AI prompt go? | To the AI provider serving that one call. Automatic repair sends a failing diagram without asking unless you switch it off. |
| Can I download everything you hold? | Yes, yourself, from Account → Your data → Download my data. |
| Can I delete my account? | Self-service deletion is temporarily paused. Request deletion through the support form. |
| How long do you keep things? | Usage events, crash reports and agent-run records: 90 days. Your account and work: while the account exists. Full table below. |
| How do I ask a privacy question? | Email hello@flowss.ai. We answer within 30 days. |
Who is responsible for your data
flowss is operated by Voranox Inc., which is accountable for the personal information described here — the data controller, in GDPR terms. Privacy questions, data requests and complaints go to hello@flowss.ai, a monitored mailbox read by the people who build flowss; the contact page has a Privacy and your data card that opens an email with the subject already set.
Because Voranox Inc. is a Canadian company, requests are handled under PIPEDA. If you are not satisfied with an answer, you can complain to the Office of the Privacy Commissioner of Canada. Being outside Canada does not remove your rights: where the GDPR or a comparable law gives you more, flowss applies the stronger one.
flowss runs on infrastructure in more than one region. By using the service you consent to your data being processed there; where local law requires it, flowss relies on standard contractual clauses. If your work must stay in one jurisdiction, ask before you upload it — data-residency options are listed for Enterprise as "At GA" on the pricing page and are not available today.
What flowss collects
| Category | What it contains | When it is collected |
|---|---|---|
| Account | Email, display name and avatar (from GitHub or Google if you sign in that way) | When you create an account |
| Your work | The source of every diagram, every studio's documents, your Vault snapshots, projects you own | Continuously while you are signed in |
| Study | Decks and cards, review history (one row per card or concept reviewed, with your rating and how long you took), course progress and Study preferences | While you are signed in. Pictures on cards are not synced and stay on the device where you added them |
| Waitlist sign-ups | Your email, the plan you asked about, the exact wording on screen when you signed up, and the date | When you join a waitlist. Kept because Canada's anti-spam law (CASL) requires proof of consent |
| Usage measurement | Anonymous product events keyed to a random browser id (details below) | Unless you switch it off |
| Feedback | Your message and the page you sent it from; your account id and email if you were signed in | When you use Feedback |
| Support requests | Your account email, topic, subject, message, where it was sent from, its status and delivery times | When you send a request from the contact page |
| Email delivery records | Send and delivery-event identifiers, timestamps, delivery status, and hashes used to match a send to its delivery report — no message body or subject | When delivery tracking is enabled |
| Crash reports | Error message, stack trace, whether it happened in the browser or on the server, the page path (never the full address), the build, your browser's user-agent string, and your account id if signed in | When something crashes |
| Agent runs | The first 280 characters of what you asked, the tools the agent called, how the run ended and the points it cost | Each time you run a studio's agent, such as the flowss Studio Agent |
| Security log | Account and billing events (API keys, saved AI keys, plan changes, point top-ups, waitlist joins); your IP address and browser string when the event came from your own request | When those events happen |
| Billing | Your subscription status and plan. Card details are held by Stripe, never by flowss | If you subscribe |
What flowss does not do
- Train AI models on your diagrams.
- Sell or rent your data.
- Use third-party analytics, advertising trackers or cross-site tracking of any kind.
- Read your synced diagrams except to render them back to you.
- Store your AI provider key in plain text, or log it.
- Collect referrers, campaign tags or other acquisition data, or join anonymous usage to billing accounts.
- Add you to a mailing list because you wrote to support.
Where your work lives
flowss saves your work in two places at once:
- Your browser. Every studio writes your work to this browser's own storage as you go.
- Your account. While you are signed in, your whole workspace — the source of each figure, every studio's open document and your Vault snapshots — is pushed to our database about a second after each edit, again every 20 seconds, and when you leave the page. That is what restores your work on another device.
There is no switch to stop the second copy: every studio needs an account, and every signed-in workspace syncs. Until a cloud save succeeds, the browser may hold the only copy — an expired session, a network problem or a rejected save can interrupt backup — so check the sync status and keep exports of important work. The details are in Cloud sync, offline work and devices.
Some things stay only in your browser and are never uploaded:
| Kept only in this browser | Notes |
|---|---|
| Your personalisation profile | The name used for greetings, your role and accent colour |
| Your usage record | Counters, recent items and active days used to tune suggestions |
| What ⌘K has learned | The times the command palette's first suggestion was not the one you took |
| Document readiness history | The record shown under "How your documents have gone" in Settings |
| An AI key kept in the browser | The default way to hold your own key; see below |
| The random usage-measurement id and your opt-out choice | See "Usage measurement" |
You can see every item stored under the glyph prefix, with its size, in a studio's Settings → Personalization & privacy → What stays here, and what we store.
AI features and your data
When you use an AI feature, your prompt and the relevant part of the diagram are sent to the AI provider handling the request, and that provider's own policy covers that leg of the call.
| Situation | Provider that receives it |
|---|---|
| Hosted AI (your plan's AI points) | Anthropic or OpenAI |
| Your own key | The provider you chose: Anthropic, OpenAI, Google, DeepSeek, Alibaba (Qwen), Zhipu (GLM), Moonshot (Kimi) or Mistral. The platform's own key never routes to the last six |
| The flowss Support Agent on the support page, if you opt in | Anthropic — one general question of up to 500 characters (see "Feedback, support and crash reports") |
flowss does not keep the prompt or the answer after returning it to you, with one exception: each agent run keeps a short record — the first 280 characters of what you typed, the tools it called, how it ended and the points it cost — so your account page can show you what ran. It never holds the model's reasoning, your diagram or your key, and it is deleted after 90 days.
Automatic repair is the one AI feature that runs without being asked. It is on by default: when a diagram fails to render, its whole source and the error are sent to the AI provider and the editor is updated with the fix (you can undo it). To stop it, open the Studio's Settings (from its menu or by typing "Settings" in the command palette) → Personalization & privacy → Repair broken diagrams automatically and choose Turn auto-repair off. With it off, the card reads "Off — a diagram that fails to render stays exactly as you wrote it, and the error is reported instead." The choice is stored in this browser, so repeat it on each browser you use.
Converting to LaTeX/TikZ is an AI feature, not a compiler. The diagram source goes to the AI provider, which writes the LaTeX; nothing on flowss runs LaTeX. You compile the output yourself.
Your own AI key
On Starter and above you can bring your own key. By default it stays in your browser's storage and is attached to each AI request; our server holds it in memory for that one request and never writes it down. If you choose Save key on your account page, it is encrypted with AES-256-GCM and only the ciphertext is stored, with the first 8 characters kept readable so you can see which key is saved. Delete it from the same panel at any time. In both modes the request to your provider is made from our server. See Bring your own AI key.
Who else can see part of your data
Running flowss means relying on other companies for parts of the job. This table lists who receives what. "Your browser" means your browser contacts them directly, so they also see your IP address; "our server" means flowss relays the request, so they see our address instead of yours.
| Who | Why | What they receive | How |
|---|---|---|---|
| Supabase | Database, sign-in and file storage | Your account and your synced workspace | Our server and your browser |
| Our hosting provider | Serves every page and API call | Every request, including its full address — a share or embed link carries the whole diagram in its address | Your browser |
| Stripe | Payments | Your billing details; checkout is hosted by Stripe | Your browser and our server |
| AI providers (see above) | The AI features you use | The prompt and diagram context for that call; your key if you brought one | Our server |
| GitHub, Google | Optional sign-in | The usual sign-in exchange | Your browser |
| Cloudflare Turnstile | Bot protection on sign-in forms, when switched on | A challenge token and the IP address that solved it | Your browser |
| Our email provider | Sending account and service email | Your address and the message | Our server |
| Iconify | Online icon search in the Studio, Weave and Science icon pickers | The words you type into the icon search box and the id of each online icon you preview or place — no diagram content | Our server |
| PlantUML render server | Drawing PlantUML diagrams | The PlantUML source, at render time | Our server |
| Kroki | Drawing Bytefield, Structurizr DSL, SVGBob (ASCII), ERD, Excalidraw, WireViz, Ditaa (ASCII), Symbolator (HDL), Network (nwdiag), Packet diagrams (packetdiag) and Pikchr | That diagram's source, at render time; we relay it and neither store nor log it | Our server |
| RCSB PDB | Protein structures for the 3D Molecules engine's fetch: form | The four-character structure id you asked for | Your browser |
| Hosts named in your own document | A Vega or Plotly spec can point at an external data address, and a Markdown, HTML or SVG document can embed an outside picture. Your browser fetches it only if flowss's security policy allows that host — for example the jsDelivr sample data that two shipped map templates use, or an Iconify icon image | Whatever the document asks for | Your browser |
| OpenAlex | Evidence literature search and DOI lookups | Your search words or the DOIs you paste — no diagram content and no account identity | Our server |
| GitHub, GitLab, Bitbucket, Codeberg | Importing a file by link, and diagrams kept in step with a repository | The repository or file address you bind or import. Where the optional GitHub App is set up and you install it on a repository, it also reads that repository and can open pull requests on it | Our server or your browser |
| A rate-limit counter service | Shared daily limits | A counter keyed by IP address, by account id, or by a hash of an email address — no request content | Our server |
| Sentry | Crash reports, only when configured | An error message and stack trace from the server | Our server |
Every other diagram engine draws in your browser or on our own server, with no third party involved. DBML database schemas, for example, are drawn locally. Study's read-aloud voice is currently switched off, so its speech model is not downloaded and Hugging Face receives nothing.
Share links and embeds
A share link or embed link carries the compressed diagram inside the link itself. We do not host a copy, index it or record who opened it, but the link's contents reach our servers every time it is opened — our server decodes it to build the page title and the link preview — and it can appear in our hosting provider's request logs. Anyone holding the link holds the diagram. See Sharing and permissions.
Exports
Copy and download of a diagram's source never leave your browser. Image and PDF exports are produced in your browser too; if your browser cannot rasterise a very large PNG, the export falls back to our server's rasteriser, which returns the image without storing it. A PlantUML export is rendered by the PlantUML server. Each export records one usage event with the format and the engine, and nothing of the diagram itself. See Exporting your work.
Usage measurement
flowss measures product use with its own first-party events — there is no third-party analytics SDK anywhere in the product. A usage event contains only:
| Field | Detail |
|---|---|
| A random browser id | Generated in your browser on first use and kept in its storage. Not derived from your account, email, IP address or device. Clearing site data gives you a new one |
| An event name | From a fixed short list: opening a workstation, a successful render, an export, a hand-off, a Vault save, a feedback submission, a page-speed measurement and similar |
| A workstation id | Which studio it happened in, for example studio — never an address |
| A small set of properties | Up to 900 characters of approved categories and numbers, such as which engine rendered or which export format you chose. Search words, document titles and other free text are discarded before collection |
| A timestamp |
flowss does not store your IP address, browser string, referrer, full address or any query string with these events, and they are never linked to your account. Diagram source, notes and file contents are never sent. The requests carry no account cookies and no referrer, and the server discards any batch that arrives with either. Page-speed measurements from these events are what the public status page summarises.
Switching it off
- Open the Privacy Policy and scroll to section 4.
- Find Anonymous usage measurement on this browser. Its status line reads "On. No account identifiers or content are collected." while it is on.
- Choose Turn usage measurement off. The status changes to "Off. New events and pending events are discarded."
The choice applies to that browser and you can reverse it with Turn usage measurement on. It "does not subscribe you to email". If your browser sends Do-Not-Track or Global Privacy Control, measurement is already off, the status reads "Off — your browser privacy signal is respected.", and the button is disabled; the server honours those signals as well. You, or an IT administrator, can also switch it off permanently on a browser by setting glyph:telemetry:disabled to 1 in its local storage. Turning it off discards events that were still waiting to be sent.
Feedback, support and crash reports
Feedback
Feedback at the foot of the Flow Dock (⌘J) sends a message of up to 2,000 characters with the page path you sent it from. If you are signed in, your account id and email are attached so we can reply — signed-in feedback is identifiable, not anonymous. To send something anonymously, sign out first (the Flow Dock is still available on the Library page when you are signed out). Feedback carries no usage-measurement id and is kept until we have acted on it.
Support requests
A request sent from Send a private support request on the contact page is stored in our database and a receipt is sent to your account email. It is visible to you and to authorised support staff, included in your account export and removed with your account. Copies of emails held by our email provider and the support mailbox follow those services' own retention. Do not include passwords, API keys, payment card details or confidential project content.
The help assistant
The help page at /support first matches your question to reviewed flowss guidance on your own device. If AI help is available and you are signed in, you can tick "Use the flowss Support Agent to select a help topic…" to send one general question of up to 500 characters to Anthropic, which only picks a help topic. No account identifiers, email addresses, projects, tickets, conversation history or saved keys are sent; questions are not saved and do not go into usage measurement. Questions that look like they contain credentials, an email address or a card number, that mention a security problem, or that ask for a person are never sent — the page says "This question is better handled privately by a person. Nothing was sent to the AI provider." When AI help is switched off for the service, the page says so and all matching happens in your browser.
Optional voice input ("Enable local voice for this visit") needs your consent on each visit, uses only on-device English speech recognition, stops after 30 seconds, and never records or uploads audio. The transcript stays in the box for you to review, and reaches Anthropic only if you also opted into AI help and submit it.
Crash reports
When something crashes, the report described in the table above is recorded so it can be fixed. Stack traces can incidentally contain identifiers from what you were doing at the time. Reports are used only to find and fix bugs — never for analytics, profiling, marketing or automated decisions — are readable only by the server, and are deleted after 90 days. A copy also reaches our hosting provider's server logs, and the error-monitoring service when one is configured; those copies age out on their own schedules.
Cookies and browser storage
flowss uses only cookies that are strictly necessary: the session cookie that keeps you signed in, a short-lived cookie (one hour) that ties an emailed link or a GitHub or Google sign-in to the browser that started it, and cookies that remember your preferences. There are no analytics or advertising cookies; if that ever changes, you will be asked first with a consent banner.
Most of what flowss keeps on your device is in browser storage rather than cookies: your local copy of your work, personalisation, the usage-measurement id and, by default, your own AI key. Signing out clears your personalisation, any AI key kept in the browser and the cached plan and points, but leaves documents untouched.
| Kind of email | Can you switch it off? |
|---|---|
| Service messages — security notices, receipts, sign-in and confirmation emails, anything you asked for | No. "Those are not marketing and cannot be switched off." |
| Product news — "Launches, new workstations, pricing changes." | Yes |
| Getting-started emails — "A few short nudges in your first week." | Yes |
Every commercial email has an Email preferences link and a one-click unsubscribe; neither needs you to sign in. The preferences page lets you Unsubscribe from or Resubscribe to each list. Your unsubscribe and spam-complaint records are kept indefinitely against your address, so we never mail you again by mistake — even after an account is deleted.
How long things are kept
| Record | Kept for |
|---|---|
| Usage events | 90 days, deleted by a nightly job. It removes up to 50,000 rows per night, so after a backlog some can survive a few days longer |
| Crash reports | 90 days, nightly. Copies in our hosting provider's logs and any error-monitoring service follow their own schedules |
| Agent-run records | 90 days, nightly, and deleted with your account |
| Your account and synced work | As long as your account exists |
| Support requests | As long as your account exists. Copies already delivered to mailboxes follow those services' schedules |
| Email delivery records, when enabled | 14 days, with expired records deleted hourly. A copy can remain in database backups until those expire |
| Database backups | Taken daily and kept for our database provider's backup retention period. Anything deleted from the live database — a diagram or a whole account — remains in earlier backups until they age out |
| Feedback | Until we have acted on it. Account deletion blanks every identifier on it; ask if you want the text gone too |
| Security log | While it has value for account-security and billing questions. Account deletion unlinks entries and strips payment-processor ids |
| Unsubscribe and spam-complaint records | Indefinitely, against the address alone |
| Invoices held by Stripe | As long as tax and accounting law requires |
Warning: cloud sync is not a backup service. flowss does not offer point-in-time recovery or a restore guarantee. Keep your own exports of anything you cannot afford to lose.
Your rights and controls
Download everything flowss holds about you
- Sign in and open your account page.
- Scroll to Your data (or go to /account#account-data).
- Under Export everything, choose Download my data. The button reads "Building your file…" while it works.
- The file downloads, named like
flowss-account-export-2026-10-04.json, and the panel confirms "Downloaded" with the file name.
The file holds every row in our account-data inventory attributed to your account or email address, table by table, each with a sentence saying what it is — including the tables that hold nothing, and the full contents of research atlases you own. Nobody reviews or approves the request first. Three kinds of thing are held back, and the file says so where it happens:
| Held back | Why |
|---|---|
| Live secrets | An API key appears as its prefix, never its hash; a saved AI key as its provider and prefix, never its ciphertext; an unaccepted invitation without its join token |
| Another person's identifier | An invitation sent to you records who sent it, which identifies them, not you |
| Rows belonging to a project rather than to you | The diagram data of a project you can open but do not own, and a repository link's sync history. Your side — membership, role, comments, activity entries — is included |
Email delivery records are listed separately in the export's privacy-review notice, because one record can refer to several recipients. Email hello@flowss.ai for an individually redacted copy or an erasure review.
You can export every diagram from the studio it lives in as well — SVG, PNG, PDF, TikZ and JSON source, and the JSON round-trips back in. See Exporting your work.
Delete your account
Self-service account deletion is temporarily unavailable while protection for shared work is improved. On the account page, Account deletion says so and offers three links: Contact support about deletion, Export my data and Manage billing.
- Download your data first (above). A completed deletion cannot be undone, and deleted accounts are not restored from backups.
- Use the support form with the topic Privacy, or email
hello@flowss.ai, to request deletion. Say whether you own shared projects, teams or classes, or made an earlier deletion request that did not finish. - Cancel your subscription separately with Manage billing if you want it stopped now. Sending a request does not delete your account or cancel your subscription.
Support reviews each request and confirms the outcome; a request is not confirmation that erasure has happened. The intended erasure process, which support follows when it resumes, works like this:
| Step or rule | What happens |
|---|---|
| Billing first | Every live subscription on your payment record is cancelled before anything is erased; if one cannot be cancelled, the deletion stops |
| Removed | Your profile and ability to sign in; your cloud workspace and every diagram; projects, teams and research atlases nobody else belongs to; your API keys and saved AI key; your plan, points and purchases; your comments, coursework submissions, usage counters, agent-run history, crash reports and the log of emails sent to you |
| Kept, unlinked from you | Security-log entries (with payment ids stripped), feedback text, invitations you sent, coursework you set on a class, project activity entries emptied of your name and preview text, and risk-of-bias judgements in an atlas others still use |
| Shared research atlases | Handed on, not deleted: unless someone already holds the owner role, a remaining member is promoted to owner first. Your own screening decisions and entity links in it are removed |
| Refused | A project or team with other members stops the deletion until you transfer ownership or remove the members; a class you teach that still has students needs support's help |
| Afterwards | A record of the deletion itself is kept, identifying you only by a one-way fingerprint of your account id |
The full lists, with the reason for each item kept, are in section 11 of the Privacy Policy.
Correct, object, or erase something specific
Email hello@flowss.ai to:
- correct anything flowss holds about you;
- ask for something the erasure process keeps to be deleted — the text of a feedback message, for instance;
- object to, or ask flowss to stop, any of the collection described here.
flowss answers within 30 days and confirms when it is done. Usage measurement you can switch off yourself, as described above.
Privacy controls in Settings
The Studio's Settings → Personalization & privacy holds the controls for what lives in your browser:
| Control | What it does |
|---|---|
| Your name (used for greetings), role chips and Accent vibe | Set or change the on-device profile. "Role tunes recommendations only"; click a role again to clear it |
| Repair broken diagrams automatically — Turn auto-repair off / Turn auto-repair on | Stops (or restarts) failing diagrams being sent to AI automatically |
| What ⌘K has learned — Forget my N corrections (N is the number learned; shown only when there is something to forget) | Clears what the command palette has learned from your choices |
| How your documents have gone — Forget this history (shown only when something is recorded) | Clears the readiness history kept on this device |
| What stays here, and what we store | Lists every item this browser holds under the glyph prefix, with its size |
| Export my data | Downloads your on-device personalisation (profile, usage counters, recent items, active days) as flow-systems-intelligence.json |
| Erase personalization | The button turns into Really erase? (with Cancel beside it); press it again to remove your profile, usage history, learned corrections and readiness history. The panel notes that "documents and API keys are not touched." |
Children
flowss is not directed at children under 13, and does not knowingly collect data from them. You must be at least 13, and old enough to form a binding contract where you live, to use it. Teachers running classes should read Classrooms, cohorts and assignments.
Changes to these practices
Material changes to the Privacy Policy are announced at least 14 days before they take effect. The date the policy was last updated is shown at the top of /privacy.
Tips
- Sign out before sending feedback if you want it to be anonymous.
- Switch off automatic repair if you work on material that must not reach an AI provider, and avoid AI features for that work altogether.
- For confidential diagrams, prefer engines that draw locally over PlantUML and the Kroki-backed engines.
- Invite named people into a project rather than sending share links, which carry the whole diagram.
- Download your account data once in a while; it is the most complete copy of what flowss holds about you.
- Keep your own AI key in the browser unless you need it on several devices.
Limits and known constraints
- Cloud sync cannot be switched off while you are signed in, and there is no anonymous studio.
- Self-service account deletion is paused; deletion goes through support.
- Deleted data remains in daily database backups until they age out; there is no point-in-time recovery.
- There is no signed data-processing agreement, BAA or HIPAA/FERPA commitment. Do not upload identifiable patient data, student records or anything a data agreement governs.
- No data-residency choice is available.
- Your own AI key passes through our server on every AI request.
- Some engines send diagram source to an outside render service, and share links send the diagram to our servers each time they are opened.
- Pictures on Study cards are not synced between devices.
- Email delivery records are not included automatically in the account export, and they are not removed with account data; they expire on their own 14-day schedule.
- Usage-measurement, auto-repair and personalisation choices are stored per browser; set them again on each browser you use.
Troubleshooting
| What you see | What it means | What to do |
|---|---|---|
| "Sign in first." when exporting | Your session ended | Sign in again and retry |
| "Too many account operations today. Try again tomorrow." | The daily limit on account operations was reached | Try again after midnight UTC |
| "The server returned an empty file — nothing was downloaded." | The export did not produce a file | Retry; if it repeats, contact support |
| "Export failed (code)." | The export could not be built | Retry later; contact support with the code if it persists |
| "Off — your browser privacy signal is respected." with the button disabled | Do-Not-Track or Global Privacy Control is on in your browser | Nothing to do: measurement is already off |
| "Browser storage could not save this change. …" | Your browser blocked storage | The choice applies to this page; check again after reloading, or allow site storage |
| "This preferences link is not valid" | The link in the email was cut short or is very old | Use the link in a more recent email |
| "This link manages one list only" | The link came from a single-list unsubscribe | Use Email preferences from a recent commercial email |
| "Self-service account deletion is temporarily unavailable …" | Deletion is paused | Use Contact support about deletion |
| "We couldn't check the request limits just now, so we haven't run this. Nothing has been charged — please try again in a moment." when exporting | The daily-limit check could not run, so the export was not built | Try again in about 30 seconds |
| "Say a little more — the message was empty." | Feedback was sent with no text | Type a message, then Send feedback |
| "Couldn't save your feedback right now — please try again." | The feedback could not be stored | Retry, or email hello@flowss.ai |
| "Feedback limit reached (N/day). Please try again tomorrow." | Too much feedback from your network today | Email hello@flowss.ai instead |
| "This question is better handled privately by a person. Nothing was sent to the AI provider." | The help question looked like it held a credential, an address or card number, mentioned a security problem, or asked for a person | Use Contact a person and the private support form |
