Privacy Policy
Last updated: 2 October 2026
This is a working draft, not legal advice, and it has not been reviewed by a lawyer. Every highlighted item in brackets must be replaced with the real details before this page is published.
This policy explains what personal data FlowCraft collects, why, who it is shared with, and the choices you have. Ankit Jodhani ("we", "us"), trading as FlowCraft, is the controller of your personal data. Contact us about privacy at [Privacy contact email].
1. What we collect
Account data
Your name, email address, a securely hashed password or the identity you sign in with (for example Google), verification codes, sign-in sessions and your settings.
Your content
The projects you create, the files you upload (images, fonts, animations and other assets), project thumbnails, and your Weave conversation history for each project.
Weave usage
When you use Weave we process your request, the page it works on and any files you attach, and we record usage details such as the time, the amount of processing used and its cost, so we can apply your monthly allowance and keep the service reliable.
Billing data
Payments are handled by Paddle, our merchant of record. Paddle collects your payment details; we never see or store your full card number. Paddle tells us your subscription status, your country, and the details of your transactions and invoices.
Technical data
Your IP address, browser and device type, and server logs of requests and errors, which we use for security, rate limiting and fixing problems.
2. Cookies
We use one essential cookie to keep you signed in. It is required for the service to work. We do not use advertising cookies. We do not use analytics or tracking tools. When you pay, Paddle's checkout may set its own cookies under Paddle's privacy policy.
3. How we use it, and our legal bases
- To provide FlowCraft: your account, saving and syncing your projects, exports, and Weave. Legal basis: performance of our contract with you.
- To bill for Pro, together with Paddle. Legal basis: contract, and our legal obligations for tax and accounting.
- To keep the service secure: preventing abuse and fraud, enforcing usage limits. Legal basis: our legitimate interest in a safe, reliable service.
- To email you verification codes and important account and billing messages. Legal basis: contract. We send product news only if you agree, and you can opt out at any time.
- To support you when you contact us. Legal basis: contract and legitimate interest.
We do not sell your personal data.
4. Who we share it with
- Amazon Web Services hosts the service, its database and your uploaded files, and sends our email. Data is stored in the United States (US East, Northern Virginia).
- Paddle processes payments, tax and invoices as our merchant of record, and is responsible for the payment data it collects under its own privacy policy.
- AI model providers process your Weave requests, the page content and any attached files to generate a response: currently Google (the Gemini API) and OpenRouter, which passes a request on to the provider of the model it routes to. We send only what is needed for the request. Each provider handles requests under its own API terms and privacy policy.
- Authorities, when the law requires it, or to protect the rights and safety of our users and the public.
5. International transfers
Our providers may process data outside your country. Where data leaves the UK or the European Economic Area, we rely on safeguards such as the European Commission's Standard Contractual Clauses.
6. How long we keep it
- Account data and content: for as long as your account is open.
- After you delete your account: removed from the live service at once, and from backups within 30 days, when the last backup that contains them expires.
- Weave usage records: kept while your account is open, to show your monthly allowance, and deleted with it.
- Billing records: as long as tax and accounting law requires.
- Server logs: events and errors only, never your project content; rotated automatically and kept for a limited time.
7. Your rights
Depending on where you live, you can ask to access, correct, export or delete your personal data, to restrict or object to how we use it, and to withdraw consent you have given. Many of these you can do yourself: Settings lets you edit your profile, export all of your projects and delete your account. For anything else, write to [Privacy contact email]. You can also complain to your data protection authority.
8. Security
Connections are encrypted with HTTPS. Access to data is limited to what each part of the service needs, every request checks that you own what it touches, and keys for outside services are encrypted at rest. No system is perfectly secure; if a breach affects your data we will tell you as the law requires.
9. Children
FlowCraft is not meant for children under 16, and we do not knowingly collect their data.
10. Changes
We will post any changes here and update the date above. If a change matters, we will tell you by email or in the app before it takes effect.
11. Contact
Ankit Jodhani
Email: [Privacy contact email]