FlowIn

Privacy Policy

FlowIn is built to hold almost nothing. If you never buy anything, it holds nothing about you at all. Here is the whole list, either way.

In effect 25 July 2026

Who controls your data

H M SOUTO CONSULTORIA E TECNOLOGIA LTDAsupport@4io.ai

What we process

FlowIn has no accounts, no sign-up and no password. If you are only browsing or using the free templates, there are two things we handle at all:

  • The description you write. It is sent to a third-party large language model provider to generate your flow, and it is used for nothing else.
  • Your IP address. Held briefly in server memory to limit how many generations one visitor can trigger. This is abuse control — it stops one script running up the bill for everyone. It is never written to a database and disappears when the process recycles.

What we keep when you buy a pass

A purchase is the one thing FlowIn has to remember, because a pass you paid for has to still work tomorrow. Buying is also the only way anything about you is written down.

  • What our payment provider told us. When you buy, Creem sends us a record of the sale and we store it exactly as received. It contains your email address, the order, and the access key issued to you. We keep it verbatim rather than picking it apart, so that what we believe you bought can always be checked against what the seller actually said.
  • The pass itself. Which access key is valid, which pass it is, and when it ends. This record is keyed by the access key, not by your name or your email.
  • Fair-use counts. How many flows that access key has generated this hour, day and month, so the fair-use limits on the pricing page mean something. Counts only — never what you generated.

Your card details never reach us. Creem is the merchant of record: the payment happens on their page, under their systems, and we are told the outcome and nothing more.

What we never store

Your descriptions and the flows made from them are never saved. Not on a free template, not on a paid generation, not for a day, not for an hour. They are passed to the model, drawn for you, and gone. Nothing in our database can be traced back to what you wrote — the purchase records above contain no descriptions and no flows.

  • Your descriptions never appear in our logs. When something goes wrong, our error handler deliberately records only the type of error, never its message, because an error message can echo fragments of the request that caused it.
  • Shared flow links never reach us. When you share a flow, the whole diagram is packed into the part of the link after the #. Browsers do not send that part to any server, so a shared link is readable by whoever you send it to and invisible to us. There is nothing for us to store, expire, or hand over.
  • We run no analytics and set no tracking cookies. There is no advertising network, no session recording, and no third-party script watching you use the page.

Cookies and local storage

FlowIn sets no cookies at all. It stores three things in your browser, and only three:

  • flowin-theme — whether you chose the light or dark theme. It never leaves your device.
  • flowin-access-key— the access key from your receipt, if you pasted one in, so you do not have to paste it again. It is sent back to us with each generation for the single purpose of checking that your pass is still valid. Clearing it, or pressing “Forget this key”, removes it immediately.
  • flowin-pending-description — if you write a description and are asked to buy a pass, the text you wrote is kept here so it is still waiting for you when you come back from the payment page. This copy never leaves your device, it is deleted as soon as your flow is generated, and it expires on its own after a day.

Because both are strictly functional and there is no tracking of any kind, no cookie consent banner is required — which is why you have not seen one.

Who else is involved

  • Third-party large language model providers — receive your description to generate the flow. More than one may be used: at busy moments a generation is served by a second, slower provider instead of the usual one. Their handling is governed by their own terms, and the specific providers we use are available on request at the support address below.
  • Vercel — hosts FlowIn and serves the pages.
  • Creem — sells and invoices paid access as merchant of record, and handles payment details.
  • Supabase — hosts the database that holds the purchase records described above. Nothing else is stored there.

These providers process data in the United States and elsewhere. Where FlowIn transfers personal data out of Brazil, it does so on the basis of the contractual safeguards those providers offer.

How long we keep things

  • Descriptions and flows — not kept at all.
  • IP addresses — minutes, in server memory only.
  • Fair-use counts — for the window they count, and they are not linked to anything you generated.
  • Purchase records — for as long as tax and accounting law requires us to keep them. These are records of a sale, so we are obliged to retain them and cannot delete them on request; you can still ask for a copy of yours, or for the access key itself to be invalidated.

Your rights

Under Brazil’s LGPD — and, if you are in the UK or EU, under the GDPR — you can ask for access to your personal data, correction of it, deletion of it, a portable copy, and information about who we share it with. You can also object to processing we base on a legitimate interest, which for us is only the abuse control described above.

In practice most of these requests will have a short answer. For descriptions and flows we hold nothing to give you, correct, or delete. If you have bought a pass, the record of that purchase is what we hold, and the one limit is the one above: a sale we are legally required to keep on file cannot be erased on request, though anything else about it can be corrected and the pass itself can be ended. Write to support@4io.ai and we will respond within three business days.

Children

FlowIn is not directed at children and we do not knowingly process the data of anyone under 16.

Changes to this policy

The date at the top of this page shows when it last changed. If we ever begin storing something we do not store today, this page changes before that starts, not after.

Contact

Privacy questions and rights requests go to support@4io.ai. See also our Terms of Service and Acceptable Use Policy.