Privacy policy
Last updated 22 September 2026
Flows is a workflow automation service operated by an independent developer in Sri Lanka. This policy explains what we collect, why, how long we keep it, and the choices you have. We wrote it to be read, not skimmed.
1. Who we are
Flows (create-your-flows.nishy.space) is operated by Nishy, based in Sri Lanka. You can reach us at hello@flows.nishy.space. We are the data controller for account and billing data, and a processor for the data that passes through your workflows.
2. What we collect
Account data: your name and email address, provided through our sign-in provider Clerk, and the workspace name you choose.
Connected app credentials: when you connect Slack, Google or another service, the provider gives us an access token scoped to the permissions you approve. We never receive or store your passwords.
Workflow data: the definitions you create and the data that flows through them when a run executes, such as a form submission or a row you append to a sheet. Run inputs and outputs are stored so you can inspect what happened.
Usage data: page views on our website (path, referrer, country, device type, and a random visitor identifier stored in your browser), sign-in sessions, and product events needed to enforce plan limits. We do not use third-party advertising trackers.
Billing data: handled by Polar, our merchant of record. We store your plan, subscription status and order totals. We never see your full card number.
3. How we use it
To run the workflows you build, on your instruction, using the accounts you connected.
To send you the alerts you asked for: failed runs, trial reminders and billing notices, by email or SMS.
To power the AI assistant that drafts workflows and explains failures. Your prompt and the relevant run data are sent to Anthropic's Claude API for that request only. Anthropic does not train on this data under our agreement.
To operate, secure and improve the service, including detecting abuse and measuring which pages and features are used.
4. Google user data
If you connect a Google account, Flows requests access only to the scopes needed for the actions you use: Google Sheets (to append rows you specify) and Gmail send (to send emails you compose in a workflow). We read your email address to label the connection.
Flows' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with your explicit consent for support, for security purposes, or where required by law.
You can revoke Flows' access at any time from your Google Account permissions page or by removing the connection in Flows, which deletes the stored token.
5. How we protect it
Connected app tokens are encrypted at rest with AES-256-GCM using a key that never leaves our servers. All traffic uses TLS. Access to production systems is limited to the operator.
Your workflows run on Vercel and your data is stored in Neon (PostgreSQL), both in the United States. Email is sent through Resend, SMS through Twilio, sign-in is handled by Clerk, and AI steps call Anthropic's Claude API. Each provider processes data under its own privacy terms. If you are outside the United States, this means your data is processed there.
6. How long we keep it
Account and workspace data: for as long as your workspace exists. Run history, including the data each step produced: 90 days. Notifications: 180 days. Website usage data and sign-in records: 13 months. Connected app tokens: until you disconnect the app or delete your workspace.
These limits are enforced by an automated job that runs every night and deletes anything past them. The figures above are read directly from the same settings that job uses, so this page cannot fall out of step with what actually happens.
You can delete your workspace yourself at any time from Settings. It happens immediately rather than within the 30 days we commit to: every workflow, run, notification and connected app token is destroyed, any subscription is cancelled, and for a personal workspace your sign-in account is removed too. Paid invoices are kept for tax and accounting with your name and email stripped out.
7. Sharing
We share data only with the providers named above, strictly to run the service, and with the third-party apps you choose to connect, on your instruction. We do not sell personal data. We may disclose data if required by law.
8. Your rights
You can export everything we hold as a JSON file, and delete your workspace entirely, from the Settings page. Neither needs you to contact us or wait. The export leaves out your connected app tokens on purpose, because handing back a decrypted credential would create a risk rather than remove one.
If you are in the EU or UK you have rights under GDPR including to object to processing and to lodge a complaint with a supervisory authority. For anything the Settings page does not cover, email hello@flows.nishy.space and we respond within 30 days.
9. Cookies
We use strictly necessary cookies from Clerk to keep you signed in. Our own analytics uses a random identifier in your browser's local storage rather than a cookie. We do not use advertising cookies.
10. Changes
We will update this page and change the date above when the policy changes. For material changes we will email account holders.