Privacy Policy
Last updated: August 2026
1. Introduction
Flowr ("we", "us", "our") explains here what personal data we hold, why, and who else processes it.
This covers both the website and the Flowr application. Where your organisation uses Flowr to manage its own projects, your organisation decides what goes into it; we process that data on its behalf.
2. If you only contact us
When you request early access or use the contact form, we collect:
- Your email address
- Your name, where you give it
- Your role, the number of projects you run and the tools you use today, where you give them
- The message you write and the plan a link carried, if any
3. If your organisation uses Flowr
A workspace holds the data your organisation puts into it. This includes personal data about the people who use it and the people it refers to:
- Account and sign-in identifiers, name and email address
- Which organisation you belong to, your access role, and the project responsibilities assigned to you
- Projects, plans, tasks, milestones, dependencies and stages
- Status reports and the narrative written in them, risks, issues, business cases, lessons and closure records
- Budgets, approved amounts and their approval history, rates, forecasts and calculated costs
- Timesheets, hours recorded against tasks, leave, and who submitted and approved them
- Resource assignments and capacity
- An audit history recording who changed what, and when
- Notification preferences, and billing identifiers held against your organisation
4. How we use it
- To operate the service your organisation subscribes to
- To authenticate you and enforce the access your organisation grants
- To bill your organisation and keep the records that requires
- To answer your questions and manage early access
- To diagnose faults, using error reports
5. Where it is processed
The Flowr application and its database run in Microsoft Azure, West Europe. Backups are point-in-time backups held in the same region.
Some processing necessarily happens with other providers, and not all of them are inside that boundary. We name them below rather than implying everything stays in one place.
6. Who else processes it
We use these providers. Each is listed with what reaches it:
- Microsoft Azure — hosting of the application and database, and their backups (West Europe)
- Clerk — sign-in and account identity: name, email and authentication identifiers
- Stripe — payments: billing contact and card details, which we never see or store ourselves
- Anthropic — AI assistance only, and only when a plan includes it and an administrator has not disabled it. See section 7
- Airtable — early-access and contact form submissions from this website
- Sentry — application error reports, which can include technical request context
7. Artificial intelligence
AI is optional, is included only on plans that list it, and an administrator can switch it off for the whole organisation. Supplying your own provider key changes who pays for the call; it does not change what is sent, and it does not unlock AI on a plan without it.
When a draft or a review is requested, Flowr sends the model the project information behind it: the project and portfolio name, the current stage, RAG statuses and the written commentary for this period and the previous one, milestone names and dates, and open risks and issues with their impact, status and named owner. Budget figures for the period are included where the request concerns them.
That means project narrative and the names of people who own risks and issues leave the Azure boundary when AI is used. If that is not acceptable to your organisation, an administrator can disable AI and no request will be made.
Flowr records the number of calls and the tokens they consumed, in order to apply the monthly allowance. Flowr does not store the prompt or the model's reply; a suggestion is stored only if somebody accepts it into a report, at which point it is part of that report like any other text.
What the provider does with a request under its own terms is governed by our agreement with that provider and is not something this page can assert on their behalf.
8. How long we keep it
Workspace data is kept for as long as your organisation has a workspace. Point-in-time database backups cover a rolling 7-day window; nothing older is recoverable from them.
You can export your organisation's data as JSON at any time.
Retention after cancellation, and the deletion of contact and early-access submissions, are not yet settled as published policy. We would rather say so than state a period we do not enforce. Ask us and we will tell you what happens today.
9. Your rights
Under the GDPR you can:
- Request access to your personal data
- Request correction or deletion
- Object to or restrict processing
- Request a copy in a portable form
- Withdraw consent where processing relies on it
Where your employer runs the workspace, ask them first — they decide what it contains. To exercise these rights with us directly, contact: contact@getflowr.app
10. Changes
We may update this policy. Changes are reflected on this page with the date above.
11. Contact
If you have any questions, contact us at: contact@getflowr.app
Read the Terms of Service alongside this.