⚡ Report Flow ← Back to home

Privacy Policy

Last updated: June 2026

Report Flow ("we", "our", or "us") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data when you use the Report Flow service (the "Service").

1. Information We Collect

We collect the following categories of information:

  • Account information: your username, display name, email address, and role when you create an account or accept a team invitation.
  • Credentials: login credentials you choose to store for use in automated workflows. These are encrypted at rest and are never transmitted in plain text.
  • Workflow definitions: the steps, selectors, and configuration you record to automate browser tasks.
  • Schedule configuration: the frequency, timing, and notification settings for scheduled workflow runs.
  • Run logs and error reports: timestamped records of each workflow execution, including success or failure status, error messages, and optional screenshots captured at the time of failure. Screenshots are stored temporarily to assist with troubleshooting and are never shared outside your account.
  • Agent telemetry: anonymous diagnostic events (such as unrecognized page elements or slow-loading frames) emitted by the local agent during workflow execution. These events help us improve reliability and are associated with your account only for support purposes.
  • Audit log: a record of changes made to your account, workflows, schedules, and billing settings, including the user who made each change and the timestamp.
  • Billing information: payment is processed by Stripe. We do not store credit card numbers; Stripe handles all payment data under their own privacy policy.
  • Agent heartbeat data: the local Report Flow Agent periodically sends a check-in timestamp and version number to confirm it is running. No browsing activity or file contents are transmitted.

2. How We Use Your Information

  • To provide, operate, and maintain the Service.
  • To authenticate you and secure your account.
  • To invite team members and manage user seats under your subscription.
  • To execute automated workflows on your behalf via the local agent running on your Windows machine.
  • To send invitation emails when you invite a colleague to join your workspace. Invitation emails are sent via Resend and contain only the information necessary to accept the invitation.
  • To send notifications about workflow results (only if you configure notification email addresses).
  • To process payments, manage your subscription plan, and handle plan upgrades or downgrades through Stripe.
  • To diagnose errors, review flagged support issues, and improve the reliability of the Service using agent telemetry and error reports.
  • To maintain an audit trail of changes to your account and workspace for accountability and compliance purposes.

3. Data Storage and Security

Account data, workflow definitions, schedules, run logs, telemetry events, and audit records are stored in a cloud database hosted on Supabase and served via Render. All data is transmitted over HTTPS. Stored credentials are encrypted before being written to the database.

Downloaded report files produced by your workflows are saved directly to your local Windows machine and are never uploaded to our servers.

Per-user settings — including your plan, agent last-seen timestamp, and billing license — are stored as part of your user record and are not shared with other users in your workspace.

4. Data Sharing

We do not sell or rent your personal information. We share data only with the following service providers as necessary to operate the Service:

  • Stripe — payment processing, subscription management, and billing portal.
  • Render — cloud hosting for the web application.
  • Supabase — managed PostgreSQL database and file storage.
  • Resend — transactional email delivery for team invitations.

We may disclose information if required by law or to protect the rights, property, or safety of our users or the public.

5. Data Retention

We retain your account data for as long as your account is active. Run logs are retained until you delete them from the View Logs page. Agent telemetry events and audit log entries are retained for operational and compliance purposes and may be pruned periodically. You may request deletion of your account and associated data by contacting us.

6. Team Accounts and Invitations

If you are invited to join a Report Flow workspace, we will receive your email address and the display name you provide when accepting the invitation. The inviting user's name is included in the invitation email. Pending invitations expire after 7 days and are permanently deleted if not accepted.

7. Your Rights

Depending on your location, you may have the right to access, correct, or delete personal data we hold about you, or to object to certain processing. To exercise these rights, please contact us using the information below.

8. Children's Privacy

The Service is not directed at children under the age of 13. We do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date above. Continued use of the Service after changes constitutes acceptance of the revised policy.

10. Contact Us

If you have questions about this Privacy Policy, please contact us at:
support@report-flow.ai

Report Flow  ·  Runs on your machine, your data stays yours
Privacy Policy  ·  Terms of Service