FLOW
Privacy Policy
Last updated: September 8, 2026
Persura Labs LLC operates FLOW (www.myflow.fyi). This page says what FLOW collects, why, and how to
remove it — in plain language.
What we collect
- Account: your email address and, if you sign in with Google, the name on that account.
- Workspace content: report data you upload from PDF, Excel, or CSV, plus any structured data FLOW extracts from a report photo when Photo processing has been explicitly enabled for your workspace — typically team and rep names with performance figures. The photo itself is not stored in your workspace. This is your data; you control who is in your workspace.
- Reviewed Facts: selected source excerpts and locations, measurement definitions, values, reporting dates, review history and a file fingerprint. Original files are read on your device; saving Facts sends the selected evidence to your workspace. Active owners, admins and members can access Facts; the invited rep role cannot access this feature.
- Preferences: theme and similar settings, stored in your browser (localStorage), not on our servers.
- Usage analytics: only if analytics is enabled for the site, we record named product events (e.g. "demo opened") and pageviews to improve FLOW. DOM autocapture and session replay are disabled, and signed-in users are identified only by an opaque account ID.
- Diagnostics: only if error monitoring is enabled, we collect crash reports, app/browser and device type, app version, and limited performance traces. We remove email, name, report text, form input, click text, URL query strings, cookies, and authorization headers before sending.
What we don't do
- We don't sell your data.
- We don't use your reports to advertise to you or anyone else.
- We don't show your workspace to anyone you haven't invited. Isolation is enforced in the database, including line-level restriction for members given the "rep" role.
Who processes it for us
FLOW runs on a small set of service providers, each processing data only to provide the service:
- Supabase — database, authentication, and storage.
- Vercel — hosting and serverless functions.
- Anthropic — Photo processing is not generally available in the public beta. A report photo can be processed only if a FLOW operator makes the capability available, a workspace owner or admin explicitly enables it for that workspace, and the user then chooses Process photo on the per-upload disclosure that names employee names and performance data. Anthropic receives the photo only to extract the report. Under Anthropic's standard commercial API policy, inputs and outputs are deleted from its backend within 30 days (except for documented legal, safety, or separately agreed retention) and are not used to train its models by default. See Anthropic's retention policy and training policy.
- Google Fonts — your browser connects to Google to retrieve font files used only to display and deliver FLOW pages. Report and user content is not sent to Google.
- Stripe — payments, only if paid plans are active for your account. We never see full card numbers.
- PostHog — product analytics, only if analytics is enabled.
- Sentry — crash and performance diagnostics, only if monitoring is enabled.
Local PDF, Excel, and CSV reading and the arithmetic debrief do not send their contents to Anthropic. Optional AI explanations of reviewed Facts use a separate control from Photo processing: when FLOW makes the feature available, an owner or admin enables it for the workspace, and the requesting user accepts the disclosure for that request, FLOW sends saved reviewed values, measurement dates, metric definitions and person or group labels to Anthropic. Fact revision identifiers connect suggestions to the saved measurements. Original files and retained source excerpts are not sent through this explanation feature. AI chooses a review focus from the saved facts. FLOW supplies the prepared question, proposed verification step and exact figures; the model does not write those statements. Suggestions require human review and are not forecasts. Anthropic's standard commercial API retention and training policies linked above also apply to these requests.
How long we keep it
Workspace reports stay until you (or a workspace owner/admin) delete them, or the workspace
itself is deleted. You can delete dashboard imports from Settings. Workspace owners and admins can delete a fact report from Facts.
Deleting a fact report removes its retained source excerpts and associated fact content. Content-free revision markers may remain to prevent an older value from reappearing after a correction is deleted. Independently sourced corrections remain with their own reports.
FLOW does not persist generated explanations. Processing settings, changes and limited request counters are retained to enforce access and usage limits. Deleting content in FLOW does not undo a provider request already made while processing was authorized; Anthropic's retention policy applies to that request.
Deleting your account
Settings → delete account removes your sign-in and your memberships. If you created a workspace,
it (and its reports) is deleted with your account once no other members remain — FLOW blocks the
deletion and tells you if teammates would lose their workspace.
Your rights
You can ask us to export or erase the personal data we hold about you:
sales@myflow.fyi. We answer as quickly as we can.
Changes
If this policy changes in a way that matters, we'll note the new date at the top and, for
significant changes, tell you in the product.