Flowinco logoFlowinco

Privacy Policy

Last updated: 21 September 2026

This policy explains what personal data Flowinco(“we”, “us”) collects, why we collect it, who we share it with, and what rights you have. It applies to the Flowinco website and web application.

1. Who is responsible for your data

The data controller is Bahadır Yıldırım, an individual sole proprietor established in Türkiye. You can reach us at privacy@flowinco.com for any privacy question or request.

2. What data we collect

2.1 Account data

Authentication is handled by Clerk. When you sign up we store your email address, display name and profile image URL, plus the workspace (organization) you belong to and your role in it. We never receive or store your password — Clerk handles credentials.

2.2 Content you create

Everything you put into the product: projects, boards, tasks and their descriptions, comments, documents, labels, custom fields, cycles, attachments (file name and stored file), automation rules and activity history. This content may contain personal data if you choose to put it there — for example when you mention a colleague or describe a customer.

2.3 Integration data

If you connect an integration, we store the access tokens and the minimum identifying data needed to operate it: GitHub App installation and selected repositories; Google account email and calendar sync state; Jira account connection; Slack webhook URL. Integrations are optional and can be disconnected at any time from workspace settings.

2.4 Billing data

Payments are processed by Lemon Squeezy, which acts as Merchant of Record. We do not receive or store your card details. We store only your plan, subscription status and billing period, plus usage counters used to enforce plan limits.

2.5 Technical and diagnostic data

We use Sentry for error monitoring. When something breaks, Sentry may receive technical context such as your browser, the page you were on and a stack trace, which can include your user or workspace identifier. We use this only to diagnose faults.

3. AI features and what happens to your content

This is the part most people care about, so we are explicit about it.

  • When you use an AI feature (task creation from plain text, the assistant, the coding agent, document generation), the relevant content — typically your prompt plus the tasks, comments or documents needed for context — is sent to Anthropic’s Claude API to produce a response.
  • Anthropic processes this content as a service provider in order to return a result. Your content is not used by us to train any AI model.
  • AI features are off by default. They only work once a workspace admin supplies an Anthropic API key. If no key is set, no content is ever sent to Anthropic.
  • If your workspace supplies its own API key, that key is encrypted at rest with AES-256-GCM before being stored, and is never shown back in full or exposed to the browser.
  • If you connect the coding agent, task content you explicitly send is published to your own GitHub repositoryas an issue, and is then subject to GitHub’s terms and your repository’s visibility settings. Do not send content you would not want in that repository.

AI output can be wrong. Do not rely on it as the sole basis for a decision that matters.

4. Why we process your data (legal bases)

PurposeLegal basis
Providing the service, storing your content, authenticationPerformance of a contract
Processing payments and enforcing plan limitsPerformance of a contract
Running AI features you invokePerformance of a contract
Operating integrations you connectConsent (you connect them; you can disconnect them)
Error monitoring, security and abuse preventionLegitimate interest in a reliable, secure service
Audit logs of administrative actionsLegitimate interest in workspace accountability

5. Who we share data with

We do not sell your data and we do not share it for advertising. We use the following processors, each only for the purpose listed:

ProcessorPurposeLocation
ClerkAuthentication and workspace membershipUSA
VercelApplication hosting and file attachment storageEU (Frankfurt) / USA
NeonDatabase hostingEU
AnthropicAI features, only when enabledUSA
Lemon SqueezyPayments, as Merchant of RecordUSA
SentryError monitoringUSA / EU
GitHub, Google, Atlassian, SlackOnly the integrations you explicitly connectUSA

Transfers outside your country rely on the processors’ Standard Contractual Clauses or equivalent safeguards. We may also disclose data where we are legally required to do so.

6. How long we keep data

  • Your content is kept as long as your workspace exists.
  • Deleting a workspace deletes its projects, tasks, documents, comments and integration connections from our database.
  • Audit logs are kept for the life of the workspace, so admins can review past administrative actions.
  • Backups may retain deleted data for a short period before rotating out.
  • Billing records are retained by Lemon Squeezy as required by tax and accounting law.

7. Security

Data is transmitted over HTTPS and stored on managed infrastructure. Every request is scoped to your workspace, so one workspace cannot read another’s data. API keys are encrypted at rest with AES-256-GCM. Sensitive actions — API keys, access tokens, integrations — are restricted to workspace admins. Uploaded files are restricted by type to block executable and script content.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected users and any required authority without undue delay.

8. Your rights

Under GDPR and Turkey’s KVKK (Law No. 6698) you may request access to your data, correction of inaccurate data, deletion, restriction of or objection to processing, a portable copy, and withdrawal of consent for integrations. Email privacy@flowinco.com and we will respond within 30 days.

If you are dissatisfied you may complain to your local data protection authority — in Turkey, the Personal Data Protection Authority (KVKK Kurumu).

9. Workspaces and roles

If you joined a workspace created by your employer or team, that workspace controls its content: admins can see the tasks, comments and documents inside it, manage members, and delete the workspace. For content you create inside someone else’s workspace, direct access and deletion requests to that workspace’s admin first.

10. Children

Flowinco is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.

11. Cookies

We use only what the product needs to function: session cookies set by Clerk to keep you signed in, and local storage for preferences such as theme and board settings. We do not use advertising or cross-site tracking cookies.

12. Changes to this policy

We may update this policy as the product changes. The date at the top always reflects the current version, and we will notify you in the application before any material change takes effect.