Privacy Policy
Last updated: 17 July 2026
FlowMesh ("FlowMesh", "we", "us", "our") is operated by a sole trader based in the United Kingdom. We are the data controller for the personal data described below. This policy explains what we collect, why, and your rights. Questions or requests: support@flowmesh-ai.com.
Our promise in one line: the work you do inside the FlowMesh desktop app — your prompts, files, workflows, and the data you process — stays on your device, and we don't collect it. The only exception is when you choose to call a third-party AI provider with your own key, which sends that content directly to that provider (see 1.7). What we collect is limited to running our website, verifying your licence, metering usage, and handling billing and support.
1. Information we collect
1.1 Website analytics. When you visit our website or download the app, we record your IP address, browser/user-agent, approximate location derived from your IP (country, region, city), a session identifier, the page or download, and the referring site.
1.2 Account, licence & purchase data. When you buy or activate a licence: your email address, licence key, plan/tier, subscription status, and billing identifiers from our payment processor. We do not store your card details — Stripe handles payments.
1.3 Device & activation data. A device identifier ("machine ID"), your device name, and basic operating-system information (platform, version, architecture), plus a log of activation/validation events (which may include device ID, device name, OS, and IP).
1.4 Sign-in identity. If you sign in with Google, GitHub, or Microsoft, we receive and store your email address, the provider you used, and your device identifier. We never receive your social password.
1.5 Usage metering. The app reports counts of certain actions to enforce plan limits (AI interactions, knowledge-tool calls, image/video generations) per month, tied to your licence or device ID. These are counts only — not the content of those actions.
1.6 What we do NOT collect. We do not collect the content of your workflows, prompts, documents, code, or any data you process in the app. That stays on your device.
1.7 AI providers you connect (your own keys). When you use FlowMesh's AI features with your own third-party API keys, the prompts, files, and other content you send them are sent directly to the AI provider you choose (for example OpenAI, Google, xAI, or Stability AI). That content travels from your device to the provider under your own key; it does not pass through, and is not received or stored on, any FlowMesh server. Where you build a knowledge base, the content you add is also stored in the vector database you configure (for example Chroma) under your own key, and remains there until you delete it. The provider's own privacy and content policies apply to what you send them.
2. How we use your information
To provide and secure the service; verify your licence and enforce plan limits; process payments and manage subscriptions/trials; send service emails (licence key, payment notices, trial reminders); understand and improve our website and product; prevent fraud and abuse; and comply with our legal obligations.
3. Legal bases (UK GDPR / EU GDPR)
We rely on: performance of a contract (providing the service you purchased); legitimate interests (securing and improving the service, basic analytics); consent (where required, e.g. non-essential cookies); and legal obligation (e.g. keeping tax records).
4. Who we share data with (our sub-processors)
We share data only with providers that help us run FlowMesh, under contract. We do not sell your personal data.
- Stripe — payments & billing
- Supabase — database & hosting
- Resend — transactional email
- Netlify — website hosting
- GitHub — app downloads and OAuth sign-in
- Google / Microsoft — OAuth sign-in (when you choose them)
5. International transfers
Because our providers and users are global, your data may be processed outside your country, including outside the UK/EEA. Where that happens, our providers rely on appropriate safeguards (such as Standard Contractual Clauses / UK equivalents) to protect it.
6. How long we keep it
- Website analytics: up to 18 months, then deleted.
- Identity & usage data (sign-in identity, usage counts, licence-event logs): for the life of your account + 90 days.
- Financial records (purchases, and licence records reduced to what's needed): 7 years, to meet UK tax/accounting obligations.
7. Your rights
Under UK/EU GDPR (and similar laws such as California's CCPA/CPRA), you may have the right to access, receive a copy (portability), correct, delete, or object to our use of your personal data, and to withdraw consent.
- Self-serve: request a copy of your data or deletion at /legal/data-request.
- By email: support@flowmesh-ai.com.
We respond within the time the law requires (generally within 30 days). We may retain certain financial records where the law requires (see §6). You can also complain to your data-protection regulator — in the UK, the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
Our website uses a session identifier and basic analytics. Where required by UK/EU rules, we ask for your consent to non-essential analytics. The desktop app does not use web cookies for tracking.
9. Security
We restrict access to personal data to our secured systems and our providers' infrastructure. No system is 100% secure, but we take reasonable measures to protect your data.
10. Children
FlowMesh is not directed to children under 16, and we do not knowingly collect their personal data. This under-16 age relates to data-protection consent only. Separately, our content rules prohibit sexual or indecent imagery of anyone under 18 — see our Acceptable Use Policy.
11. Changes
We may update this policy; we'll post the new "Last updated" date here and, for material changes, take reasonable steps to notify you.
12. Contact
FlowMesh — support@flowmesh-ai.com.