Your data stays yours
flowgen reads your website, public sources and the documents you choose to connect, and writes content your team approves. This page describes how that data is isolated, protected, retained and deleted. It is a summary of practice, not a certification claim.
SOC 2 readiness program in progress · no certification is claimedHow customer data is handled
Data privacy
flowgen processes the data needed to run your workspace: your website content, the documents you connect, the questions you track and the AI responses collected for them. Personal data handling is described in the privacy policy.
Customer data isolation
Each customer workspace is logically isolated. Verified facts, drafts, reports and connected sources belong to one workspace and are never shared across customers.
Encryption
Data is encrypted in transit using TLS and at rest using the storage provider’s encryption. Credentials for connected services are stored encrypted and are never shown back in full.
Access controls
Workspace members have roles, and publishing requires an approver role. Access by flowgen staff for support is limited, logged and granted only when a customer asks for help.
Data retention
Collected AI responses and reports are retained for the period set by your plan so that before-and-after comparisons remain possible. Retention periods can be shortened on request.
AI provider data handling
flowgen sends questions and, when drafting, the verified facts needed for a draft to the AI providers used in your workspace, under their API terms. Which providers are used is listed in the subprocessor list.
Model training policy
flowgen does not use customer workspace content to train models of its own. Provider terms governing API data are listed with each subprocessor.
Human approval workflows
Nothing is published to a connected channel without approval by a workspace member with the approver role. Automation prepares; people approve; flowgen executes.
Audit logs
Approvals, publications, fact changes and connection changes are logged with the user and time, and the log is available to workspace administrators.
Data deletion
Customers can delete connected sources, facts, drafts and whole workspaces. Deleted data is removed from active systems promptly and from backups on the backup rotation schedule.
Subprocessors
Hosting, storage, email and AI providers that process customer data are listed in the subprocessor list, available on request, with the purpose of each.
Vulnerability reporting
Security researchers can report issues through the vulnerability reporting page. Reports are acknowledged and tracked to resolution.
Need the detailed documentation?
Security questionnaires, the subprocessor list and data processing terms are available on request.