← flow-graph.com

Subprocessors

Effective: August 11, 2026 · Contact: help@flow-graph.com · Security: security.txt

The short version: FlowGraph is local-first — most customer data never becomes processed data. Your graphs, documents, and models stay on your device until you explicitly use a cloud feature. The subprocessors below only see data for the cloud features you turn on.

Current subprocessors

SubprocessorPurposeWhat it processes
Cloudflare, Inc.Hosting, edge delivery, Workers, D1, R2, Durable ObjectsAccount identity; private/shared document data and revision metadata when cloud protection or sharing is used; content-free activation events; audit records
Stripe, Inc.Card-backed trials, subscription billing, and paymentsBilling email, card/payment details, and subscription status (card data is held by Stripe, never by us)
Resend, Inc.Transactional email (invites, notifications, sign-in links)Recipient email address and message content (only when you invite teammates or enable notifications)
OpenRouter and the model provider selected by FlowGraphThe one-map hosted Free Preview and other explicitly labeled hosted AIThe goal/prompt and generated response for the AI action you invoke; no unrelated vault content
Your chosen AI provider(s)AI planning and generation under BYOK, Codex, or a local/provider connectionOnly the content you send through that route, under that provider's terms. Local-model processing can remain on your machine.

Data residency & retention

Cloud data is processed on Cloudflare's global network. Audit-log retention windows are configurable by workspace owners on Enterprise plans; older rows are archived to object storage and disclosed in the admin console. A lapsed workspace keeps read access to everything it created — nothing is held hostage.

Changes

We will update this page before a new subprocessor begins processing customer data. For a data processing agreement (DPA) or questions, email help@flow-graph.com.

Privacy Policy · Terms · flow-graph.com