Legal
Privacy Policy
What we collect, why, who we share it with, and how to get it out. The shortest version of this we could write without leaving anything important out.
Last updated July 15, 2026.
The short version
We collect the minimum we need to run Flowcorder: your account info, the URLs and prompts you send us, the videos and scripts we generate for you, and basic product analytics. If you use Cast to publish to social platforms, we also store the account connections you authorize and the content and metrics that flow through them. We don’t sell your data. We don’t train models on your inputs or outputs without an explicit opt-in. You can export or delete your data anytime from Studio.
1. What we collect
Account data: name, email, hashed password (or OAuth provider ID), team membership, billing details handled by Stripe.
Project data: the URLs you point Flowcorder at, your natural-language prompts, generated capture scripts, screenshots, and rendered videos.
Usage data: renders run, minutes of compute consumed, error logs, IP address, browser/OS, and timestamps.
Cookies: a session cookie for auth and a small set of strictly-necessary cookies. We do not use third-party advertising cookies.
2. Why we collect it
To run the service (generate videos, store your projects, bill you), to keep it healthy (debugging, abuse prevention, capacity planning), and to communicate with you about your account. That’s the list.
3. AI providers and your inputs
Flowcorder calls third-party AI providers (Anthropic and others) to turn your prompts into capture scripts. Your prompts and the page context Flowcorder collects to plan the script are sent to those providers under their zero-retention or short-retention policies. We do not use your inputs or outputs to train Flowcorder’s own models, and we have configured our providers not to train on them either. If we ever offer a training opt-in, it will be opt-in, off by default, and worth something to you.
4. Connected social accounts (Cast)
If you use Cast to publish to social platforms, you explicitly connect one or more accounts (for example Instagram or TikTok) via each platform’s official OAuth flow. When you do, we receive and store: access and refresh tokens (encrypted at rest — we never store your platform password), your account identifier and handle (to show which account is connected), the media and captions you choose to publish, and the insights the platform returns for content you posted (views, likes, comments, saves, reach, watch time).
We use these tokens for one purpose: to act on your behalf on that platform exactly as you instruct — publishing or scheduling the content you send, and reading back its metrics. We never post without your instruction, never share your tokens, and never use your connected-account data to train models. You can disconnect any account at any time from Studio, which revokes the stored tokens; see “Deleting your data” below.
5. Who we share data with
Sub-processors only: Cloudflare (hosting, storage, and edge compute), Anthropic and other AI providers (inference), Stripe (payments), Resend or similar (transactional email), and Sentry or similar (error reporting). When you use Cast, the content, captions, and requests you choose to publish are transmitted to the social platform you selected — Meta Platforms (Instagram), TikTok, and others you connect — and are then governed by that platform’s own terms and privacy policy. Each sub-processor is bound by a data-processing agreement. The current list lives at flowcorder.com/subprocessors and we’ll notify customers before adding new ones. We also disclose data when legally compelled, and we’ll tell you unless we’re prohibited from doing so.
6. Where data lives
Primary storage is on Cloudflare’s global infrastructure. Inference traffic may be routed to provider regions in the US and EU. If you have data-residency requirements, talk to us about an Enterprise plan.
7. How long we keep things
Account data is kept while your account is active and for 30 days after deletion (so we can restore it if you change your mind). Generated videos and scripts persist until you delete them or close the account. Connected-account tokens are kept only while the connection is active and are erased when you disconnect or delete your account. Published-content metrics are retained with the associated post until you delete it. Logs and usage telemetry are retained for 90 days. Billing records are kept for 7 years to satisfy tax law.
8. Your rights
You can access, export, correct, and delete your data from Studio. If you’re in the EU, UK, California, or anywhere with similar laws, you have additional rights under GDPR / UK GDPR / CCPA — including the right to object, restrict processing, and lodge a complaint with your local supervisory authority. Email privacy@flowcorder.com and we’ll handle the request within 30 days. We don’t sell personal information and we don’t engage in cross-context behavioral advertising.
9. Security
Data in transit is TLS 1.2+. Data at rest is encrypted by our cloud providers. Access is least-privilege, audited, and limited to the engineers who need it to keep the service running. If we ever have a breach affecting your data, we’ll notify you without undue delay and within the windows required by applicable law. Report suspected vulnerabilities to security@flowcorder.com.
10. Children
Flowcorder is not intended for users under 16. We don’t knowingly collect data from children.
11. Deleting your data
You can delete your data at any time. Disconnecting a social account from Studio immediately revokes and erases the stored access and refresh tokens for that account. Deleting your Flowcorder account removes your profile, media, connected-account tokens, and published-content records within 30 days (billing records excepted, per section 7).
You can also request deletion without logging in — including via the deletion instructions each platform surfaces — by visiting flowcorder.com/data-deletion or emailing privacy@flowcorder.com. We confirm completion by email.
12. Changes to this policy
We’ll post material changes in Studio and email account owners at least 14 days before they take effect. The “last updated” date at the top of this page always reflects the current version.
13. Contact
Privacy questions, requests, or complaints: privacy@flowcorder.com. A real human will read it.
See also
The legal terms of using the service live in our Terms of Service. Source-code rights live in our License.