← flow-graph.com

Subprocessors

Effective: July 2026 · Contact: help@flow-graph.com · Security: security.txt

The short version: FlowGraph is local-first — most customer data never becomes processed data. Your graphs, documents, and models stay on your device until you explicitly use a cloud feature. The subprocessors below only see data for the cloud features you turn on.

Current subprocessors

SubprocessorPurposeWhat it processes
Cloudflare, Inc.Hosting, edge delivery, Workers, D1, R2, Durable ObjectsAccount identity, shared-document sync data, audit logs (only when you sign in and use cloud features)
Stripe, Inc.Subscription billing and paymentsBilling email and payment details (only for paid plans; card data is held by Stripe, never by us)
Resend, Inc.Transactional email (invites, notifications, sign-in links)Recipient email address and message content (only when you invite teammates or enable notifications)
Your chosen AI provider(s)AI planning and generation, under bring-your-own-key (BYOK)Only the prompt content you send — routed with your key to the provider you chose (Anthropic, OpenAI, Google, or a local model). We never proxy or resell your inference unless you explicitly configure our proxy.

Data residency & retention

Cloud data is processed on Cloudflare's global network. Audit-log retention windows are configurable by workspace owners on Enterprise plans; older rows are archived to object storage and disclosed in the admin console. A lapsed workspace keeps read access to everything it created — nothing is held hostage.

Changes

We will update this page before a new subprocessor begins processing customer data. For a data processing agreement (DPA) or questions, email help@flow-graph.com.

Privacy Policy · Terms · flow-graph.com