This policy covers flowviant.com, the Flowviant app at app.flowviant.com (the "Service"),
the Flowviant daemon (flowviant) that runs on your own machine, and the Windows
app, Flowviant Machines. "Flowviant", "we" and "us" mean the people who run them. We don't
sell your data.
The short version
- Your code stays on your machine. Flowviant has no copy of your repository and no access to your git host.
- The AI that works your cards is your own coding CLI (Claude Code, Codex or Antigravity), running on your machine under your own login. Flowviant never receives that login.
- We keep your account, your projects' boards and conversations, and what your machine reports about its work.
- On your own machine, the only model Flowviant pays for is the review quiz, on Google Gemini, and only on projects that turn it on.
- Deleting a project deletes everything in it.
Your account
- Signing in. You sign in with a code or a link we email you, or with Google or GitHub. There are no passwords.
- What we keep. Your name, email address, profile picture (the address of your Google or GitHub picture, or a picture you upload) and your notification settings.
- Sessions. Each signed-in session records when it expires and the IP address and browser it signed in from. A session lasts 60 days and renews while you use it.
- Google and GitHub sign-in. We store the provider's id for your account. The tokens a provider hands back at sign-in are not kept: Flowviant never reaches into your Google or GitHub account.
- Abuse limits. Signing in and connecting a machine keep short-lived counters keyed by your account or IP address.
What Flowviant keeps for a project
- The project. Its name and description, the repository name you link, its settings, its members and their roles, and invite links (only a hash of each).
- Cards. Each card's title, brief, criteria, type, comments and references; the notes agents file on it; and, for commits attached to it, the subject line, author name, date and line counts.
- Agents. The plan you accepted, which cards each agent holds, its model and effort, its branch name, its commits (hash, subject, author name), line counts, the result of the project's check command (with up to 4,000 characters of its output) and how many tokens it used.
- Turns. A card's conversation is kept with the project, including every message a person sent, the agent's answers and questions, send-back notes, the pre-review and its trace (narration and tool calls, with file paths, commands and a few lines of each edit). The running account is cleared when the agent ends. Turn facts such as timings, the model, token counts and commits stay. The commands CLIs run on the machine are kept for 30 days.
- Terminal tabs. A tab's transcript (up to 400 messages) is kept while the tab is open and removed when you close it. The prompt and final answer of each of its turns are deleted with it; only the counts stay.
- Artifacts. Files a turn writes under
.flowviant/artifacts/are uploaded so you can see them. They are deleted when the tab closes or the agent ends, unless you keep them in the Library. - The Library and Instructions. Work you keep, and the files and instructions you give the project. Kept until you delete them, and copied to your machine so your CLI can read them.
- Attachments. Files and pictures you add to a conversation. They are deleted when the agent ends or the tab closes; files added as a note on a card stay with the card.
- Commit diffs. A commit's changes, fetched from your machine only when somebody opens that commit, then kept with the project.
- Wiki notes. The notes about your codebase that your CLI writes for the Wiki.
- New task chats. Their messages and answers, and the cards your CLI proposes before you add them to the board, are kept with the project.
- Usage. Token counts per project, split by where they were spent and by CLI. Never money.
- Notifications and read marks. What you were notified about, and which cards you have read.
What your machine sends
The daemon reports to api.flowviant.com, under a credential for one project. It sends:
- Which machine it is. Its hostname, the path of the checkout it serves, the daemon's version, its process id and start time, a public key that identifies the box, and the operating-system user it runs as with that user's home folder.
- What it can run. Which CLIs are installed; for Claude Code, whether it is signed in, when that login expires and its plan type; the names (never the values) of environment variables that carry a CLI login; the models and skills each CLI reports; the names of MCP connectors that are not connected (connected ones stay on the machine); and each CLI's plan-limit readings, such as "62% used, resets at 3pm".
- Its load. Memory, cores, load and disk, used to pace work and shown in the app. These are held in memory, not stored.
- Your repository's state. Branches, worktrees, commits ahead of the base branch and changed-file line counts; for commits agents make, the hash, subject, author name and date, never the author's email.
- Listening ports. For each server listening in the checkout: the port, whether it listens only on this machine, and the first two words of its command.
- An environment comparison. For the
.envfiles at the checkout's root: each variable's name and an 8-character fingerprint of its value, salted with the project's id, so you can tell whether two machines agree. A value never leaves the machine. - Each turn. Your CLI's answer, its narration and tool calls, the commands it ran, how many tokens it used and the model it ran on.
- Claude Code sessions you run yourself in the repository. Their id, title, branch and when they were last active. Never their transcript.
- Diffs, only on request. A commit's patch (up to 256 KB), when somebody opens that commit.
Before sending any text, the daemon redacts the values in your .env files and
your deploy environment, and its own credential. Besides Flowviant, the daemon updates itself
from Flowviant's download host (or from npm, if you installed it with npm), downloads GitHub's
gh and Cloudflare's cloudflared from GitHub when it needs them, and
pushes to your git remote with your own git credentials.
What stays on your machine
- Your code. The daemon uploads no part of your repository except artifacts a turn writes, commits somebody opens, and Wiki notes. What your CLI says during a turn is relayed as it is, though, and it can quote code: its answers, the commands it runs, a few lines of each edit and the check command's output.
- Environment values. Only names and salted fingerprints are sent.
- Your CLI logins. Claude Code, Codex and Antigravity talk to their makers from your machine, under your login and on your plan. Flowviant never receives those credentials. From Claude Code's login the daemon reads only its expiry times and plan type.
- The machine credential. It is kept in
~/.flowviant/credentials.json, readable only by you, and it works only with Flowviant.
The one model Flowviant pays for: the review quiz
A project's owner can require a short quiz before work merges. It is off until the owner
turns it on. When it is required, approving an agent's work or shipping a Terminal branch
asks Google's Gemini API (gemini-3.5-flash) to write three questions about the
change.
It sends:
- the machine's counts: commits ahead, files changed, lines added and removed;
- whether the project's check passed, with up to 2,000 characters of its output;
- the branch name;
- for up to 20 cards: the title, the agent's delivery note (up to 1,200 characters) and the "done when" criteria;
- for a Terminal ship, the changed files' paths and line counts;
- up to four diff excerpts (up to 6,000 characters each), only for commits somebody has already opened.
Commit messages and author details are not sent, and the whole request is capped. We keep the questions, their answers and how many attempts were made. Your own answers are graded and not stored. No other model runs on Flowviant's servers. Hosted machines are described below.
Hosted machines (not offered yet)
Hosted machines aren't offered yet. When they are, a hosted machine runs in a cloud account Flowviant holds, your repository is copied onto it, and the AI on it runs under Flowviant's own API accounts with Anthropic and OpenAI. Your code, your prompts and the AI's answers go to them under our account. Before hosted machines start, this page will name the cloud provider and say how long a hosted machine's data is kept. None of this applies to your own machine.
Previews
Previews are off until a project's owner allows them. With them on, a member can share a
dev server that is already running on the project's machine. A viewer's browser connects to
Flowviant's preview address (<name>.flowviant.dev), which forwards to a
Cloudflare tunnel the daemon opened, which reaches the dev server through the daemon's own
gate. The forwarder keeps no copy of the pages.
We store the share's port, name, tunnel address, who asked for it, who may view it, and its times. A share's password is shown to the person who shared it once, then kept only as a hash. When a share ends (after 8 hours at most), its tunnel address, password hash and signing secret are erased. Members sign in to view it. A share can also be opened with a revocable tester link, or to anyone who has its link if the owner chooses.
Tickets from Sentry, Monday and webhooks
A project's owner can give Sentry, Monday or any tool that sends a JSON webhook an address that turns what it sends into a card. We store only a hash of the address's secret. Of each delivery we keep what becomes the ticket: a title, a link and up to 12,000 characters of text (for a Sentry alert: the rule, level, environment, tags, release, the exception and its in-app stack frames with their lines of code, and the request address). The rest of the payload is not kept. The project's machine drafts the card with your own CLI. Nothing is sent back to the tool. Tickets are kept until the address or the project is deleted.
Email and notifications
- Email is sent through Resend: sign-in codes and links, and the notifications you haven't turned off (an agent's question or delivery, for example), which carry a title and a short excerpt.
- Push notifications, if you allow them in your browser, go through your browser's push service (Google's, Mozilla's or Apple's), encrypted to your browser. They carry a title, a short excerpt and a link.
- Each has its own switch in Account settings › Notifications.
Payments
Flowviant does not charge yet. When paid plans start, Stripe will process payments. We will keep your Stripe customer and subscription ids, plan, status, number of collaborators and billing dates, and never your card number.
The Windows app
- On its own, it only checks for updates. A minute after it starts, then hourly, and when you open its window or tray card if it hasn't checked in the last ten minutes, it downloads
https://api.flowviant.com/dl/desktop/latest.json. That request carries nothing about you or your projects. A newer version is downloaded in the background and installed only when nothing is running on this computer, or when you press Restart now. - Everything else follows a press. Connecting a project opens app.flowviant.com in your browser; from then on the daemon it runs talks to api.flowviant.com. The setup checklist runs Windows' own
wsl --install(from Microsoft), Anthropic's Claude Code installer inside WSL, and Anthropic's sign-in page. - What it installs in WSL. The daemon, at
~/.flowviant/bin/flowviant. Connecting a project keeps that project's login in~/.flowviant. - What it keeps on Windows. The projects it serves and its log, in its own app folders. It starts when you sign in to Windows only if you turn on Start Flowviant when I sign in to Windows. Its notifications are about the machine only, shown by Windows, and sent nowhere.
The code signing policy has the rest, including how to uninstall it.
Cookies and your browser
- Cookies. A sign-in session cookie; a cookie that remembers which way you last signed in; short-lived cookies during Google or GitHub sign-in; and, when you open a preview, cookies that let you into that preview. No advertising or tracking cookies.
- Browser storage. The app keeps a copy of your projects' boards, and a few preferences such as a collapsed column, in your browser so it opens quickly.
- Error reports. When the app hits an error, it sends a report to Sentry: the error, its stack trace and the page address, with invite links removed. It doesn't send your IP address, cookies, request headers, query strings or the values in memory.
- This website loads nothing from third parties: its fonts and icons are served from flowviant.com.
Who can see what
- A project's members (owners and editors) can see everything in it: the board, agents and their conversations, the Library, previews and the machines list. Its owners can also see the commands CLIs ran on its machine in the last 30 days, and whose session ran them.
- The app shows a Terminal tab only to the person who opened it. Its transcript is sent only to that person's browser. Every project member can read and continue a New task chat.
- Anyone who holds one of these links can open it: a preview open to anyone with the link, a tester link, or an artifact link (valid for 15 minutes). An invite link lets its holder join the project.
- We share data only with the providers below, to run the Service, or when the law requires it.
Keeping and deleting
We keep your account and projects while they exist. Some things go sooner, as said above: Terminal transcripts, artifacts, attachments, the commands CLIs ran (30 days), preview secrets and sign-in codes (5 minutes).
- Deleting a project (its owner, in Project settings) deletes everything in it: the board, conversations and turns, the Library, artifacts and attachments, diffs, previews and machine records. If any part can't be deleted, the project stays and says so, rather than half-disappearing.
- Deleting your account (Account settings › Danger) deletes your account and the projects you own. It can't go ahead while you have a paid subscription or own a project other people are in: cancel the subscription, and transfer the project or remove them, first. It also removes your browser's push notification subscriptions and our record of the billing events Stripe sent us about you; Stripe keeps its own records of your customer account.
- Backups. Our database provider keeps a point-in-time history for up to 30 days, after which deleted data is gone.
- Logs. Our request logs record the method, the path (with secrets removed), the status and the timing, not your IP address. Cloudflare keeps them for its standard period.
Who processes data for us
| Provider | What for |
|---|---|
| Cloudflare | Hosting the app, its database and files; the preview forwarder and tunnels; this website |
| The review quiz (Gemini API), on projects that require it; Google sign-in, if you use it | |
| GitHub | GitHub sign-in, if you use it |
| Resend | |
| Sentry | Error reports from the app |
| Stripe | Payments, once paid plans start |
| Hosted machines (not offered yet) | A cloud provider, Anthropic and OpenAI, named here before they start |
| Your browser's push service | Push notifications, if you allow them |
Anthropic, OpenAI and Google also make the coding CLIs you choose to run, but those run for you, under your own account and their makers' terms, not for Flowviant.
Security
Everything travels over TLS, and Cloudflare encrypts the database and files at rest. More on the Security page.
Your rights
Depending on where you live (for example under the GDPR or the CCPA), you can ask to see, correct, export or delete your personal data, or object to how it's used. You can change or delete most of it in the app; for the rest, write to us. Our providers may process data in the United States and other countries; where the law requires it, we rely on safeguards such as Standard Contractual Clauses.
Children
Flowviant is not meant for children under 16, and we don't knowingly collect their data.
Changes
When this policy changes, we update it here and change the date at the top. We'll tell you in the app about changes that matter.
Contact
Privacy questions and requests: privacy@flowviant.com. Security issues: security@flowviant.com.