FlowsparkAzərbaycan versiyası

Privacy Policy

Last updated: September 22, 2026

1. Who operates this service

Flowspark is operated by ToorStyle LLC, Republic of Azerbaijan ("we", "Flowspark"). This document explains what personal data we collect when you use the service, how it is processed, and what rights you have.

2. What data we collect

When you create an account and use the service, we collect:

  • Registration data — your email address, name (optional), and password (never stored in plain text — see §7).
  • Profile data — the timezone your browser reports (so schedules and notifications fire at the correct local time).
  • Prompts you write — the plain-language text you enter to create or edit an automation.
  • Automations you build — the title, description, and the technical definition of the steps your workflow performs.
  • Connections (credentials) — API keys, tokens, and similar secrets you provide to connect third-party services (Gmail, Slack, Google Sheets, etc.).
  • Execution metadata — when your automation ran and whether it succeeded (unlike the connected-service data described in §6, this is only status/timing, never the actual content).

3. Why we collect it

  • To create your account, recognize you, and let you sign in.
  • To turn the prompt you write into a real, working automation (the core function of the service — see §5, this requires sending the prompt text to our AI provider).
  • To carry out, on behalf of the services you connect, the exact steps YOU configured.
  • To protect your account and detect misuse (security audit logs).
  • To contact you (verification codes, password resets).

4. Legal basis (GDPR)

We process your data under the following legal bases (General Data Protection Regulation, Article 6):

  • Performance of a contract (6(1)(b)) — all core processing needed to create your account and deliver the service (registration, prompt-to-automation, connections).
  • Legitimate interest (6(1)(f)) — security audit logging and misuse prevention.
  • Consent (6(1)(a)) — when you grant OAuth permission while connecting a third-party service (Gmail, Google Sheets, etc.).

5. Where data is stored and who it is shared with

Your data is stored and processed through the following infrastructure providers:

  • Vercel (fra1 — Frankfurt) — runs the application's server-side code.
  • Neon (Frankfurt) — our database (account, automations, encrypted connections).
  • Hetzner (Germany) — the n8n engine that actually executes your automations.
  • Anthropic (USA) — the TEXT of the prompt you write (only that text, never your connection secrets) is sent for automation generation.
  • Resend — ONLY your email address (to send verification codes / password resets), nothing else.

Because Anthropic is located in the USA, this involves a transfer of data outside your country — the transfer to the USA is carried out subject to appropriate safeguards.

6. Data from connected services

Data coming from services you connect (Gmail, Google Sheets, Slack, etc. — e.g. email content, spreadsheet rows) is processed ONLY to carry out the exact steps of the automation YOU configured — it is never read, stored, or analyzed for any other purpose.

  • This data is kept in execution history for at most 7 days, then deleted.
  • It is never sold.
  • It is never used for advertising.
  • It is never repurposed beyond the automation you configured.

7. Encryption

  • Your connection secrets (API keys, tokens) are encrypted with AES-256-GCM.
  • Your password is hashed with Argon2id — the plain text is never stored.
  • Verification/password-reset codes are stored as SHA-256 hashes and expire after 10 minutes.
  • All connections (browser↔server, server↔database) are encrypted in transit with TLS.

8. Retention periods

  • Account data — until you delete your account (see §9).
  • Connected-service execution data — at most 7 days (see §6).
  • Security audit logs — retained even after account deletion, but anonymized (see §9).
  • Verification/password-reset codes — 10 minutes.

9. Deleting your account

You can permanently delete your account at any time via Settings → "Delete Account". When you do:

  • All your workflows and connections in n8n (including OAuth tokens) are deleted.
  • Your account, automations, and connections are permanently removed from our database.
  • Security audit records (e.g. "registered", "account deleted") are RETAINED (date, action type), but your email address in those records is kept ONLY as an irreversible hash (SHA-256) — it is never visible in plain text anywhere.

Note: permission you granted to services like Google or Slack may still appear in that service's own settings (e.g. Google's "Connected apps" list) even though it becomes unusable on our end — we recommend also revoking access directly in that service's settings for a complete revocation.

10. Your rights

Under the GDPR, you have the right to:

  • Access your data.
  • Correct inaccurate or outdated data.
  • Request erasure of your data (see §9 — you can do this yourself).
  • Restrict or object to processing.
  • Receive your data in a portable format.
  • Lodge a complaint with the data protection authority responsible for your country of residence.

11. Cookies

We only use cookies that are strictly necessary for you to sign in (session, CSRF protection, post-login redirect) — no analytics, tracking, or advertising cookies are used.

12. Children

Our service is not intended for individuals under the age of 16 (the GDPR's default age threshold). If we become aware that a user is under 16, we will delete their account.

13. Google API Services User Data Policy

When you connect a Google account (Gmail, Google Sheets, etc.), the following official disclosure applies, as required by Google:

Flowspark’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

14. Changes to this policy

We may update this policy from time to time. If we make a material change, we will notify you at your account email address. Continued use of the service constitutes acceptance of the updated policy.

15. Contact

For privacy-related questions or requests: sananismayilovs82@gmail.com