FlowIcon

Legal

Privacy Policy

This page names the data FlowIcon actually stores today — not a generic list that would fit any application.

Effective 17 August 2026

01

Data that is stored

Most of the data is there because you entered it. The rest exists because the service cannot run without it.

  • Account. Your email address, plus the display name and photo you set yourself (or the ones Google/GitHub send if you sign in that way). There is never a password, because FlowIcon does not use them.
  • Session. One session token and its expiry, stored in the database and copied into a cookie in your browser. It lasts 30 days. Since 17 August 2026 the IP address used at sign-in is stored alongside the session — once, never refreshed — so you can recognise a device that is not yours on Settings → Devices and sessions and end it. Browser, operating system, and location are not stored.
  • Document contents. The title, every drawing element, styles, the preview image, and any image files you upload to the canvas.
  • Workspace. The name, the slug, the member list with their roles, and the email addresses you invite — including invitations that haven't been accepted.
  • Audit records. Important workspace actions (inviting members, changing roles, deleting documents) are recorded with a timestamp, IP address, and browser identifier. This is what lets a workspace owner trace what happened to their data.
  • Rate limiting. Email addresses and IP addresses are held briefly in Redis to count sign-in attempts and invitation emails. Those records expire on their own within minutes to hours.
02

What is not done

  • There are no trackers, ad pixels, or third-party analytics on any page. Not a single external script is loaded.
  • Data is not sold, rented, or traded.
  • Your document contents are not used to train any model.
  • There is no advertising profile, and no cookies beyond the ones needed to keep a session signed in.
03

Who else processes it

Some parts of the service run on other people's infrastructure. They receive only the data their part needs.

  • An email provider, to send sign-in links and invitations. What is sent is the destination address and the message body.
  • An object storage provider, for image files and document previews.
  • Google or GitHub, only if you choose to sign in through one of them.
  • The hosting provider where the application and database run.
04

How long it is kept

  • A discarded document goes to Trash and can still be restored; its contents are not gone from the database until permanently deleted.
  • Deleting a workspace also deletes its projects, documents, memberships, and invitations.
  • A session ends on its own after 30 days, or immediately when you sign out.
  • Audit records deliberately outlive the objects they refer to — that is precisely their purpose as a trail.
05

Your rights over your data

Some of this is available through the interface, some isn't. What isn't is stated plainly here rather than promised.

  • Viewing. Your account data appears on the Account settings page, and all document contents can be opened at any time.
  • Changing. Document titles and workspace names can be changed. Changing your account name and photo is not available yet.
  • Downloading. Every document can be downloaded as PNG, SVG, or PDF through the Export button in the editor header.
  • Deleting. Documents and workspaces can be deleted yourself. Deleting an account together with all of its data is not available yet through the interface.
06

Protections in force

What is named here is what already runs, not what is planned.

  • Every data request is checked against workspace membership in the same layer that fetches the data, so a document belonging to another workspace produces a not-found page — not a message that leaks its existence.
  • Image files and previews are not directly reachable; their links are signed and expire.
  • Sign-in attempts and invitation emails are rate limited, and the limiter closes rather than opens when the limiting system itself is in trouble.
  • The session token is never exposed to JavaScript on the page.

No system is immune. If a breach affects your data, notice will be sent to your account email address.

07

Changes and contact

Meaningful changes will be announced by email before they take effect. During the build period, reaching us is the same as reaching the developer — see the docs section and the Terms of Service.