Privacy Policy
Last updated: 21 September 2026
This policy explains what personal data Flowinco(“we”, “us”) collects, why we collect it, who we share it with, and what rights you have. It applies to the Flowinco website and web application.
1. Who is responsible for your data
The data controller is Bahadır Yıldırım, an individual sole proprietor established in Türkiye. You can reach us at privacy@flowinco.com for any privacy question or request.
2. What data we collect
2.1 Account data
Authentication is handled by Clerk. When you sign up we store your email address, display name and profile image URL, plus the workspace (organization) you belong to and your role in it. We never receive or store your password — Clerk handles credentials.
2.2 Content you create
Everything you put into the product: projects, boards, tasks and their descriptions, comments, documents, labels, custom fields, cycles, attachments (file name and stored file), automation rules and activity history. This content may contain personal data if you choose to put it there — for example when you mention a colleague or describe a customer.
2.3 Integration data
If you connect an integration, we store the access tokens and the minimum identifying data needed to operate it: GitHub App installation and selected repositories; Google account email and calendar sync state; Jira account connection; Slack webhook URL. Integrations are optional and can be disconnected at any time from workspace settings.
2.4 Billing data
Payments are processed by Lemon Squeezy, which acts as Merchant of Record. We do not receive or store your card details. We store only your plan, subscription status and billing period, plus usage counters used to enforce plan limits.
2.5 Technical and diagnostic data
We use Sentry for error monitoring. When something breaks, Sentry may receive technical context such as your browser, the page you were on and a stack trace, which can include your user or workspace identifier. We use this only to diagnose faults.
3. AI features and what happens to your content
This is the part most people care about, so we are explicit about it.
- When you use an AI feature (task creation from plain text, the assistant, the coding agent, document generation), the relevant content — typically your prompt plus the tasks, comments or documents needed for context — is sent to Anthropic’s Claude API to produce a response.
- Anthropic processes this content as a service provider in order to return a result. Your content is not used by us to train any AI model.
- AI features are off by default. They only work once a workspace admin supplies an Anthropic API key. If no key is set, no content is ever sent to Anthropic.
- If your workspace supplies its own API key, that key is encrypted at rest with AES-256-GCM before being stored, and is never shown back in full or exposed to the browser.
- If you connect the coding agent, task content you explicitly send is published to your own GitHub repositoryas an issue, and is then subject to GitHub’s terms and your repository’s visibility settings. Do not send content you would not want in that repository.
AI output can be wrong. Do not rely on it as the sole basis for a decision that matters.
4. Why we process your data (legal bases)
| Purpose | Legal basis |
|---|---|
| Providing the service, storing your content, authentication | Performance of a contract |
| Processing payments and enforcing plan limits | Performance of a contract |
| Running AI features you invoke | Performance of a contract |
| Operating integrations you connect | Consent (you connect them; you can disconnect them) |
| Error monitoring, security and abuse prevention | Legitimate interest in a reliable, secure service |
| Audit logs of administrative actions | Legitimate interest in workspace accountability |
5. Who we share data with
We do not sell your data and we do not share it for advertising. We use the following processors, each only for the purpose listed:
| Processor | Purpose | Location |
|---|---|---|
| Clerk | Authentication and workspace membership | USA |
| Vercel | Application hosting and file attachment storage | EU (Frankfurt) / USA |
| Neon | Database hosting | EU |
| Anthropic | AI features, only when enabled | USA |
| Lemon Squeezy | Payments, as Merchant of Record | USA |
| Sentry | Error monitoring | USA / EU |
| GitHub, Google, Atlassian, Slack | Only the integrations you explicitly connect | USA |
Transfers outside your country rely on the processors’ Standard Contractual Clauses or equivalent safeguards. We may also disclose data where we are legally required to do so.
6. How long we keep data
- Your content is kept as long as your workspace exists.
- Deleting a workspace deletes its projects, tasks, documents, comments and integration connections from our database.
- Audit logs are kept for the life of the workspace, so admins can review past administrative actions.
- Backups may retain deleted data for a short period before rotating out.
- Billing records are retained by Lemon Squeezy as required by tax and accounting law.
7. Security
Data is transmitted over HTTPS and stored on managed infrastructure. Every request is scoped to your workspace, so one workspace cannot read another’s data. API keys are encrypted at rest with AES-256-GCM. Sensitive actions — API keys, access tokens, integrations — are restricted to workspace admins. Uploaded files are restricted by type to block executable and script content.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected users and any required authority without undue delay.
8. Your rights
Under GDPR and Turkey’s KVKK (Law No. 6698) you may request access to your data, correction of inaccurate data, deletion, restriction of or objection to processing, a portable copy, and withdrawal of consent for integrations. Email privacy@flowinco.com and we will respond within 30 days.
If you are dissatisfied you may complain to your local data protection authority — in Turkey, the Personal Data Protection Authority (KVKK Kurumu).
9. Workspaces and roles
If you joined a workspace created by your employer or team, that workspace controls its content: admins can see the tasks, comments and documents inside it, manage members, and delete the workspace. For content you create inside someone else’s workspace, direct access and deletion requests to that workspace’s admin first.
10. Children
Flowinco is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
11. Cookies
We use only what the product needs to function: session cookies set by Clerk to keep you signed in, and local storage for preferences such as theme and board settings. We do not use advertising or cross-site tracking cookies.
12. Changes to this policy
We may update this policy as the product changes. The date at the top always reflects the current version, and we will notify you in the application before any material change takes effect.