Last updated: 27 July 2026 · Effective: 27 July 2026
This policy explains what Flowral collects, why, who else sees it, and what you can do about it. We've tried to describe the system as it actually is rather than in generalities.
The short version: we collect what's needed to run your workspace and bill you, we don't sell anything to anyone, we don't use your project content for advertising, and we don't train AI models on it.
The data controller is LEGAL ENTITY NAME, REGISTERED ADDRESS, COUNTRY. Contact: hello@wiink.io. Our data protection contact is DPO NAME / EMAIL, or "not required — see below".
The distinction matters for who you go to about what:
| Category | What exactly | Where it comes from |
|---|---|---|
| Account | Name, email address, profile picture, sign-in provider | You, or the provider you sign in with (Google, Microsoft, WIINK) |
| Credentials | If you use a password, a salted hash — never the password itself | You |
| Workspace | Workspace name and logo, membership and roles, invitations you send | You and your teammates |
| Project content | Flows, tasks, sub-tasks, dependencies, notes, tags, comments, completion state | You and your teammates |
| Attachments | Files you upload to tasks and comments | You |
| Activity | A log of changes — who did what, and when | Generated as you use the app |
| Sessions | A session identifier stored in your browser to keep you signed in | Generated at sign-in |
| Billing | Subscription status, seat count, renewal date, and identifiers issued by Stripe | Stripe |
| Technical | Server logs, including IP address and error diagnostics | Generated automatically |
We never see your card details. Payment pages are hosted by Stripe; card numbers go to Stripe directly and never touch our servers. We store only the customer and subscription identifiers Stripe gives us.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the Service — running your workspace, storing your flows | Performance of a contract |
| Authentication and keeping accounts secure | Performance of a contract; legitimate interests (security) |
| Taking payment and issuing invoices | Performance of a contract; legal obligation (tax records) |
| Transactional email — invites, sharing notices, billing notices | Performance of a contract |
| Diagnosing faults and preventing abuse | Legitimate interests (a working, secure service) |
| Product updates and marketing email | Consent — and you can withdraw it at any time |
What we don't do: we don't sell personal data, we don't share it with advertisers, we don't use your project content to train machine-learning models, and we don't profile you for automated decisions with legal effects.
We use a small number of service providers ("sub-processors"). Each is bound by contract to protect your data and use it only on our instructions.
| Provider | What they do | Data involved |
|---|---|---|
| Stripe | Payments, invoicing, tax calculation | Name, email, billing address, card details (held by Stripe), tax ID |
| Amazon Web Services | File storage (S3, EU — Ireland) and transactional email (SES) | Attachments you upload; recipient address and content of transactional emails |
| Google · Microsoft · WIINK | Optional single sign-on, only if you choose that method | Your name, email and profile picture, released by them to us at sign-in |
| HOSTING PROVIDER | Application and database hosting | All of the above at rest |
We may also disclose data where legally required — a valid court order, for example — or to establish or defend legal claims. If a business transfer ever occurred, we would tell you before your data became subject to a different policy.
Your data is stored in PRIMARY DATA LOCATION, e.g. the EU (Ireland). Some providers may process data outside the EEA; where that happens we rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
Downgrading from Pro to Free deletes nothing. A failed payment deletes nothing.
No system is perfectly secure. If a breach affects your personal data and is likely to put your rights at risk, we will notify the relevant supervisory authority within 72 hours and tell you without undue delay.
If you're in the EEA or UK, you have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent where consent is the basis.
Email hello@wiink.io and we'll respond within one month. If we're acting as a processor for a workspace you don't own, we'll forward your request to that workspace's owner and support them in answering it.
You also have the right to complain to your local data protection authority — in COUNTRY, that is SUPERVISORY AUTHORITY.
Flowral is deliberately light here. We use no advertising cookies and no third-party analytics trackers.
Because we set no non-essential cookies, there's no consent banner to click through. If that ever changes, we'll ask first.
A flow can be shared with someone outside the workspace. If you're a guest, we hold your name and email so access can be granted and the person who invited you can see who has access. Guests see only the flows shared with them. The workspace owner controls that sharing — including revoking it.
Flowral is a tool for work and is not directed at children. We don't knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we'll delete it.
We'll update this policy as the product changes. The "last updated" date at the top always reflects the current version, and for material changes we'll notify you by email or in the app before they take effect.
Privacy questions, or to exercise any right above: hello@wiink.io, or write to LEGAL ENTITY NAME, REGISTERED ADDRESS.