Privacy Policy
How we collect, use, and protect your personal information. Effective April 10, 2026.
FlowFrame Privacy Policy
Last Updated: April 10, 2026 Effective Date: September 2, 2026
Previous Version Effective Date: April 10, 2026
1. Introduction
This Privacy Policy ("Policy") explains how Data and Operations LLC ("Company," "we," "us," or "our") collects, uses, discloses, and otherwise processes personal information in connection with FlowFrame (the "Software"), a downloadable desktop application.
This Policy describes:
- The types of personal information we collect
- How we collect, use, and share your personal information
- The legal bases and purposes for processing your information
- Your rights regarding your personal information
- How to exercise those rights
- How we protect your information and how long we retain it
- How we handle international data transfers
This Policy applies to all users of the Software, regardless of geographic location. Certain sections contain jurisdiction-specific disclosures for users in:
- The European Union (EU), European Economic Area (EEA), and United Kingdom (UK), as required by the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and related national laws.
- The State of California, as required by the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), and related regulations.
By downloading, installing, or using the Software, or by otherwise providing personal information to us, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, you should not use the Software.
2. Key Terms and Definitions
- "Personal information" or "personal data" means information that identifies, relates to, describes, or is reasonably capable of being associated with a particular individual or household, whether collected online or offline.
- "Processing" means any operation performed on personal information, whether or not by automated means, such as collection, recording, organization, storage, use, disclosure, or destruction.
- "Data subject" or "consumer" means a natural person to whom personal information relates. Under GDPR this person is referred to as the "data subject"; under CCPA as the "consumer."
- "Controller" means the entity that determines the purposes and means of processing personal information. For this Policy, Data and Operations LLC is the controller.
- "Processor" means an entity that processes personal information on behalf of a controller, pursuant to a data processing agreement.
- "Service provider" or "contractor" (CCPA) means an entity that processes personal information on behalf of a business and is contractually restricted from using it for other purposes.
- "Sale" (CCPA) means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating personal information to a third party for monetary or other valuable consideration.
- "Sharing" (CCPA) means communicating personal information to a third party for cross-context behavioral advertising, whether or not for monetary consideration.
- "Sensitive personal information" (CCPA) means personal information that reveals racial or ethnic origin, religious beliefs, union membership, genetic data, biometric information, health information, sex life or sexual orientation, precise geolocation, government-issued identifiers, or account credentials.
- "Legitimate interests" (GDPR) means a lawful basis for processing under GDPR Article 6(1)(f), where processing is necessary for the legitimate interests of the controller, except where overridden by the data subject's rights and freedoms.
3. Personal Information We Collect
We collect personal information directly from you, automatically through your use of the Software, and from certain third parties.
3.1 Information Collected Directly from You
3.1.1 Download, Installation, and Activation
When you download, install, and activate the Software, we collect:
- Email address (required for trial activation and associated with paid licenses for license management and product communications)
- Device identifiers (such as a hashed hardware identifier) used for licensing and anti-piracy purposes
- Installation information (including installation timestamp, Software version, and basic platform data)
3.1.2 Purchases
When you purchase a license, payment-related personal information is collected and processed by our third-party payment processor, LemonSqueezy. This may include:
- Email address (and any alternative contact email you provide)
- Name (if you choose to provide it)
- Billing address (used for tax determination, payment verification, and fraud prevention)
- Payment card information (card number, expiration date, security code) collected directly by LemonSqueezy and not stored by us
- Transaction history (such as purchased products, amounts, currency, refunds, and chargebacks)
- IP address and related technical details used for fraud detection, tax calculation, and regulatory compliance
We do not directly collect or store your payment card number, expiration date, or security code. LemonSqueezy collects and stores such details in accordance with applicable payment security standards. We receive only the information necessary to fulfill your order, manage your license, provide support, and comply with accounting, tax, and legal obligations.
3.1.3 Support Requests and Feedback
When you contact us for support, to report a problem, or to provide feedback, we collect:
- Email address
- Name or username (if you choose to provide it)
- Content of your message (including any information you include in your description)
- Attachments (such as screenshots, diagnostic logs, or other files you provide)
- Metadata and records of our communications (such as timestamps and resolution status)
3.1.4 Marketing Communications
When you opt in to receive marketing communications or product updates, we collect:
- Email address
- Marketing preferences (types of content, frequency preferences, or opt-in categories)
- Marketing engagement data (whether and when you opened an email, clicked a link, or unsubscribed)
3.2 Information Collected Automatically
3.2.1 License Verification and Software Operation
When you use the Software, we automatically collect certain technical information necessary to operate and protect the Software:
- License key information (such as the license key, license type, status, and expiration date) necessary to verify that your use of the Software is authorized
- Device and system information (such as operating system name and version, processor architecture, and language or locale settings)
- Session data (such as timestamps associated with license verification requests and Software version in use)
The Software communicates with our servers for license verification and update checks. These communications are logged in our license infrastructure (hosted on Cloudflare) for security and fraud prevention purposes.
The Software does not collect usage analytics, feature telemetry, or behavioral data, with one narrow exception described below. All project content (videos, steps, media, settings) is stored locally on your machine and is never transmitted to our servers.
Milestone record (one per installation)
The first time an installation successfully exports a video, the Software sends a single record so we can tell whether people are able to complete a video at all. It is sent once per installation, not once per export, and repeat exports send nothing.
The record contains exactly six fields and nothing else:
| Field | What it is |
|---|---|
| Installation ID | An anonymous, irreversible identifier derived from a hashed machine identifier and the application data path. It is the same identifier already sent with license verification and cannot be reversed into your device, name, or location. |
| Milestone name | Always the literal value first_export. |
| Path | Either app or agent, indicating whether the export was started in the application or by an AI agent. |
| Application version | The version of the Software, e.g. 0.6.3. |
| Operating system | The OS name and processor architecture, e.g. darwin arm64. |
| Date | The calendar date only. No time of day is recorded. |
What this record cannot contain. It carries no project name, file name, file path, video content, narration text, media, duration, step count, export settings, or any count of how many videos you have made. Because only the first export is recorded, it cannot describe how often or when you use the Software.
How to turn it off. Open Settings → Privacy and switch off "Share that you finished a video." You can also set the environment variable FLOWFRAME_NO_MILESTONES=1 before launching. The setting is on by default; turning it off has no effect on any Software feature.
3.2.2 License Verification via Cloudflare
Our license verification infrastructure is hosted and protected using services provided by Cloudflare. When the Software verifies your license:
- Your license key, email address, and certain technical details (such as IP address, request timestamp, and Software version) are transmitted to our servers through Cloudflare for validation
- These communications are encrypted in transit using industry-standard security protocols (TLS 1.2 or later)
- Cloudflare may process your data as part of protecting and delivering network traffic, subject to contractual restrictions as a processor/service provider acting on our behalf
3.2.3 Technical and Server Logs
When the Software communicates with our servers, we automatically collect:
- IP address
- User agent or application identifier (indicating Software version and basic platform information)
- Request details (such as the endpoint called and request method)
- Timestamps for each request and response
- Response codes and diagnostic information
3.2.4 Cookies and Similar Technologies
As of the effective date of this Policy, we do not use cookies or similar tracking technologies within the Software. If we later implement cookies or similar technologies in the Software or related websites, we will update this Policy and, where legally required, present you with appropriate notices and consent mechanisms.
3.2.5 Location Data
We do not intentionally collect precise geolocation data. However, your IP address may allow us to infer a coarse location (such as country or region). We use this approximated location only for security, fraud prevention, legal compliance (such as tax calculation), and to present localized content where relevant.
3.3 Information Received from Third Parties
3.3.1 LemonSqueezy (Payment Processor)
When you purchase the Software through LemonSqueezy:
- We receive transaction-related information including your email address, name (if provided), billing country or address, purchased products, transaction identifiers, payment status, and limited fraud or chargeback indicators
- We use this information to manage your license, provide support, maintain records for tax and accounting obligations, and protect against fraud
3.3.2 Cloudflare (Infrastructure Provider)
In the course of Cloudflare's provision of infrastructure and security services:
- We receive log and analytics data (traffic metadata, performance metrics, and security alerts) that may include your IP address and certain technical information
- We use this information to operate, secure, and optimize our systems
3.3.3 Referral Partners and Affiliates
If you were referred to us by an affiliate or partner:
- We may receive limited referral information (such as a referral ID or campaign identifier)
- We do not receive sensitive data from affiliates; the data we receive is used for attribution and partner compensation
3.4 Third-Party AI Services (User-Directed)
FlowFrame allows you to connect your own API keys from third-party AI providers (such as OpenAI, Anthropic, or Google Gemini) to enable features like narration generation, quality scoring, and content drafting.
When you use these AI-powered features:
- Your project content (such as step text, instructions, and media descriptions) is sent directly from the Software on your machine to the AI provider you selected, using your own API key and account
- We do not receive, store, or have access to the content sent to these AI providers or their responses
- We do not have access to your API keys. API keys are stored locally on your machine using Electron's encrypted safeStorage and are never transmitted to our servers
- Each AI provider has its own privacy policy governing how they handle data sent to their APIs. We encourage you to review the privacy policies of any AI providers you connect:
We are not responsible for the data practices of third-party AI providers. Your use of these services is governed by your own agreement with each provider.
3.5 Local Data Storage
All FlowFrame project data, including videos, screenshots, step content, media files, and project settings, is stored locally on your machine (typically in ~/FlowframeProjects/). This data is never transmitted to our servers.
The Software also runs a local MCP (Model Context Protocol) server on localhost:3100 to enable integration with AI coding tools (such as Claude Code or Cursor). This server listens only on your local machine and does not expose data to the network.
4. How We Use Your Personal Information
We process personal information for the purposes described below. For EU/EEA/UK users, the legal bases for processing under GDPR and UK GDPR are detailed in Section 5.
4.1 Primary Purposes of Processing
4.1.1 License Management and Contract Performance
We process your personal information to:
- Verify, activate, and manage your Software license
- Provide you with access to the Software and any related updates
- Enforce license terms and usage restrictions, including detection and prevention of unauthorized use
- Communicate with you regarding your license status and material changes
4.1.2 Payment Processing and Order Fulfillment
We use transaction information received from LemonSqueezy to:
- Process purchases, refunds, and chargebacks
- Maintain invoices, receipts, and financial records
- Comply with accounting, tax, and financial reporting obligations
- Detect and prevent fraudulent transactions
4.1.3 Support and Customer Service
We process your personal information to:
- Respond to your inquiries, support requests, and bug reports
- Diagnose and resolve technical issues
- Maintain a history of support interactions for quality assurance and dispute resolution
- Improve our support operations and documentation
4.1.4 Security, Fraud Prevention, and Abuse Detection
We process personal information to:
- Secure our infrastructure and Software against unauthorized access, attacks, and abuse
- Detect and investigate suspicious activities or potentially fraudulent behavior (such as excessive concurrent activations)
- Enforce our rights, terms, and policies
4.1.5 Marketing and User Engagement
Subject to applicable laws and your preferences:
- We may send you marketing communications about new features, versions, or related products
- We may send you product-related announcements (such as security updates or changes to our terms), which may be sent even if you opt out of marketing
- We may invite you to participate in surveys, user research, or feedback programs
- You can opt out of marketing communications at any time as described in Section 9
4.1.6 Legal and Regulatory Compliance
We process personal information to:
- Comply with applicable laws, regulations, and legal processes
- Establish, exercise, or defend legal claims
- Maintain accurate business and financial records as required by law
4.1.7 Business Operations and Planning
We may use personal information as reasonably necessary for:
- Internal record-keeping and administrative functions
- Business continuity, disaster recovery, and data backup
- Evaluating or entering into corporate transactions (as described in Section 6)
4.2 Automated Decision-Making and Profiling
4.2.1 Automated License-Related Decisions
The Software and our systems may use automated logic to:
- Validate license keys and detect invalid or compromised keys
- Automatically flag or temporarily limit access where we detect activity that appears fraudulent or inconsistent with license terms
4.2.2 Significance of Such Decisions
Automated decisions related to license validity or fraud detection may:
- Restrict or temporarily suspend access to the Software
- Trigger additional verification steps or manual review
4.2.3 Human Review (EU/EEA/UK)
If an automated process results in a decision that significantly affects you (such as license suspension), you may request human review by contacting us at the details in Section 12. We will review the decision, consider any additional information you provide, and respond within a reasonable period.
4.2.4 Profiling
We may use limited profiling to detect anomalous patterns that may indicate fraud or security incidents. We do not engage in profiling that produces legal effects or similarly significant effects for you without appropriate safeguards.
5. Legal Bases for Processing (EU/EEA/UK Users)
For users in the EU, EEA, and UK, we process personal data only where we have a lawful basis under GDPR or UK GDPR:
- Performance of a contract (Article 6(1)(b))
- Compliance with a legal obligation (Article 6(1)(c))
- Legitimate interests (Article 6(1)(f))
- Consent (Article 6(1)(a))
5.1 Legal Basis Table
| Processing Activity | Legal Basis |
|---|---|
| License management and Software access | Performance of contract (Art. 6(1)(b)) |
| Payment processing and order fulfillment | Performance of contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) for tax/accounting |
| Support and customer service | Performance of contract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f)) |
| Security, fraud prevention, abuse detection | Legitimate interests (Art. 6(1)(f)); Legal obligation (Art. 6(1)(c)) where applicable |
| Marketing communications | Consent (Art. 6(1)(a)) for non-essential marketing; Performance of contract or legitimate interests for service communications |
| Legal and regulatory compliance | Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f)) for legal claims |
| Business operations and transfers | Legitimate interests (Art. 6(1)(f)) |
5.2 Legitimate Interests Balancing
Where we rely on legitimate interests, we have performed a balancing assessment. Our interests generally relate to:
- Securing our systems and protecting against fraud and misuse
- Conducting reasonable business operations and defending our legal rights
We consider:
- The nature and sensitivity of the data (we do not process sensitive categories)
- The context of collection (data collected in the context of your use of the Software)
- The impact on you (we minimize intrusion and provide transparency)
- The safeguards we apply (technical and organizational security measures, access controls, retention limits)
You have the right to object to processing based on legitimate interests, as described in Section 9.
6. How We Share Your Personal Information
We share personal information only as described below and only to the extent necessary for the stated purposes.
6.1 Processors and Service Providers
6.1.1 Cloudflare (Infrastructure and Security)
- Role: Processor under GDPR; service provider under CCPA
- Data shared: Network traffic involving our servers (including IP address, license verification requests, Software version, and related metadata)
- Purpose: Secure, performant hosting and network protection for our license servers
- Security: Data in transit is encrypted. We configure Cloudflare to retain only what is necessary
- International transfers: Standard Contractual Clauses and supplementary measures as described in Section 8
6.1.2 LemonSqueezy (Payment Processing)
- Role: Processor under GDPR; service provider under CCPA
- Data shared: Email address, name (if provided), billing address, and payment information. We receive transaction-level data excluding full payment card details
- Purpose: Processing payments, issuing invoices, handling refunds, and mitigating fraud
- Security: LemonSqueezy stores payment card information in compliance with relevant payment security standards. We do not store full card details
- International transfers: Standard Contractual Clauses and supplementary measures as described in Section 8
6.1.3 Email Service Providers
- Role: We use third-party email delivery providers to send transactional emails and, where applicable, marketing communications
- Data shared: Email address, name (if provided), message content, and engagement information
- Purpose: Reliable delivery of email communications and compliance with anti-spam requirements
6.1.4 Other Vendors and Professional Advisers
We may share personal information with IT, security, and infrastructure vendors; and auditors, accountants, lawyers, and other professional advisers. These parties are bound by confidentiality obligations and data protection agreements.
6.2 Legal and Regulatory Disclosures
We may disclose personal information to competent authorities, courts, or law enforcement when disclosure is:
- Required by applicable law, regulation, legal process, or governmental request
- Necessary to protect the rights, property, or safety of the Company, our users, or the public
- Necessary to detect, prevent, or address security, fraud, or technical issues
Where permitted by law, we will use commercially reasonable efforts to notify you before disclosing your personal information in response to a legal request.
6.3 Business Transfers
In connection with a corporate transaction (such as a merger, acquisition, or sale of assets), personal information may be transferred as part of the transaction. We will take reasonable steps to ensure that the recipient honors this Policy or provides substantially similar privacy protections.
6.4 Aggregated and Anonymized Information
We may create aggregated, de-identified, or anonymized data from personal information. Once data is anonymized so that it is no longer reasonably capable of identifying you, it is no longer personal information and we may use it for any lawful purpose.
6.5 No Sale or Sharing of Personal Information (CCPA)
For California users:
- We do not sell your personal information as defined in the CCPA
- We do not share your personal information for cross-context behavioral advertising as defined in the CCPA
- Our use of Cloudflare, LemonSqueezy, email providers, and similar vendors is limited to providing services on our behalf under contracts that restrict them from using personal information for their own purposes
7. Data Retention and Security
7.1 General Retention Principles
We retain personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected. When determining retention periods, we consider the amount, nature, and sensitivity of the information; the potential risk of harm; the purposes for processing; and applicable legal requirements.
After the applicable retention period expires, we will delete or anonymize your personal information. If deletion is not technically feasible (such as in backup systems), we will securely store and isolate it until deletion is possible.
7.2 Retention Schedule
| Data Category | Purpose | Retention Period |
|---|---|---|
| Licensing data (email, license key, device identifiers) | License management, access control, verification | Duration of license + 3 years after termination |
| Transaction and billing data | Accounting, tax compliance, fraud prevention | 7 to 10 years per applicable tax/accounting laws |
| Support communications | Customer service, quality assurance, dispute resolution | Up to 7 years from last communication |
| Server and security logs | System security, debugging, abuse detection | 30 to 365 days depending on log type |
| Marketing data | Managing marketing communications | Until unsubscribe + up to 2 years for compliance records |
7.3 Security Measures
We implement technical and organizational measures to protect personal information, including:
- Encryption of data in transit and, where appropriate, at rest
- Access controls and authentication mechanisms
- Network protections, firewalls, intrusion detection, and monitoring
- Secure development practices and vulnerability management
- Regular review of vendor security practices
While we strive to protect your personal information, no system can be guaranteed completely secure. You are responsible for keeping your license key confidential and promptly notifying us if you suspect unauthorized use of your license.
8. International Data Transfers
8.1 General
We may process and store personal information in countries other than your own, including the United States and other countries where our service providers maintain facilities.
8.2 Transfers from the EU/EEA/UK
When we transfer personal data to countries without an adequacy decision, we rely on:
- Standard Contractual Clauses adopted by the European Commission
- The UK International Data Transfer Addendum where applicable
- Technical measures such as encryption and data minimization
8.3 Government Access
Personal data transferred to the United States or other jurisdictions may be subject to lawful access requests. Our contracts with processors require them to notify us of government access requests where permitted and challenge disproportionate requests where appropriate.
8.4 More Information
If you are in the EU, EEA, or UK and would like more information about international transfers or a copy of the relevant Standard Contractual Clauses, contact us as described in Section 12.
9. Your Rights and Choices
9.1 GDPR and UK GDPR Rights (EU/EEA/UK Users)
If you are in the EU, EEA, or UK, you may have the following rights:
- Right of access: Obtain confirmation of whether we process your personal data and request a copy
- Right to rectification: Request correction of inaccurate or incomplete personal data
- Right to erasure: Request deletion in certain circumstances (when data is no longer necessary, you withdraw consent, or you successfully object)
- Right to restriction: Request that we restrict processing in certain situations
- Right to data portability: Request a copy of your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests; absolute right to object to direct marketing
- Right to withdraw consent: Withdraw consent at any time without affecting prior lawful processing
- Right to lodge a complaint: Lodge a complaint with your local supervisory authority
9.2 CCPA Rights (California Users)
If you are a California resident, you may have the following rights:
- Right to know/access: Request disclosure of categories and specific pieces of personal information collected
- Right to deletion: Request deletion, subject to certain exceptions
- Right to correct: Request correction of inaccurate personal information
- Right to non-discrimination: We will not discriminate against you for exercising your rights
- Right to opt out of sale or sharing: As noted in Section 6.5, we do not sell or share personal information
9.3 How to Exercise Your Rights
To exercise your rights, contact us using the details in Section 12. Please describe the right you wish to exercise and provide sufficient information for us to verify your identity. We will respond within the time periods required by applicable law (typically one month for GDPR, 45 days for CCPA).
9.4 Marketing Communications
- For EU/EEA/UK users, we obtain consent before sending non-essential marketing emails. You may withdraw consent at any time.
- You can opt out of marketing communications by clicking the unsubscribe link in any marketing email or contacting us.
- We may continue to send service-related messages (such as security updates or license notices) even if you opt out of marketing.
10. Cookies, Tracking, and Signals
- We do not currently use cookies or similar tracking technologies within the Software
- We evaluate Global Privacy Control (GPC) signals consistent with applicable law
- We do not interpret Do Not Track (DNT) signals as a universal opt-out, but you may exercise your rights through the mechanisms described in this Policy
11. Additional Information
11.1 Children's Privacy
The Software is not directed to children under 16. We do not knowingly collect personal information from children. If we become aware of inadvertent collection, we will delete such information promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
11.2 No Sensitive Personal Information
We do not intentionally collect special categories of data under GDPR or sensitive personal information under CCPA. Please do not provide such information in support communications.
12. Contact Information
Data Controller: Data and Operations LLC 2436 Keesling St. Bellingham, WA 98225 USA
Privacy Contact: Email: [email protected]
13. Changes to This Policy
We may update this Policy to reflect changes in our practices or legal requirements. When we make material changes:
- We will revise the "Last Updated" date at the top
- Where required or where changes are significant, we will provide additional notice within the Software or via email
Your continued use of the Software after the effective date of an updated Policy indicates your acknowledgment of the changes.
14. Summary of Key Points
- Data collected: Email address, device identifiers, license key information, and limited billing and transaction details (via LemonSqueezy). We do not collect usage analytics, feature telemetry, or behavioral data, except for a single one-per-installation milestone record described in Section 3.2.1, which you can switch off in Settings → Privacy. We do not collect payment card numbers directly.
- Local-first: All project content (videos, steps, media) stays on your machine. API keys are stored locally with encryption and never transmitted to us.
- AI services: When you use AI features, your content goes directly to the AI provider you selected, using your own API key. We have no access to this data.
- Uses: License management, payment processing, support, security, and (with consent where required) marketing.
- Sharing: Service providers (Cloudflare, LemonSqueezy, email providers) only. We do not sell or share personal information for advertising.
- International transfers: We may transfer data to the United States using safeguards such as Standard Contractual Clauses.
- Retention: We retain personal information only as long as necessary, then delete or anonymize it.
- Your rights: Depending on your location, you may have rights of access, rectification, deletion, restriction, objection, portability, and the right to withdraw consent and lodge complaints.