Privacy Policy
Local mode: your code stays on your device
1. Who we are
Veflow is an agent workspace that helps developers and teams plan, build, and ship software using AI agents. This Privacy Policy explains how Veflow collects, uses, shares, and protects your personal data when you use our website at veflow.ai or our application at app.veflow.ai.
2. Data we collect
We collect the following categories of personal data:
- Account data. Email address, display name, authentication identifiers from the OAuth providers you use to sign in (such as GitHub or Google).
- Integration data. OAuth access and refresh tokens for the third-party services you connect (GitHub, Linear, Jira, ClickUp). We store these encrypted at rest and use them only to perform actions you have authorised.
- Workspace content. Tasks, comments, agent prompts, agent outputs, code diffs, repository contents fetched on your behalf, and the full conversational thread between you and our AI agents.
- Billing data. Subscription tier, billing status, and the customer identifier issued by our payment processor (Creem). Veflow does not store full credit-card numbers — those are held by Creem and its sub-processors.
- Usage and telemetry. Pages visited, features used, credit consumption, error reports, IP address, and approximate location derived from IP. We collect this to operate, secure, and improve the service.
- Communications. Messages you send us via the contact form, email, or support channels, and our replies.
3. How we use your data
We use personal data to:
- Provide, maintain, and improve the Veflow service;
- Execute the actions you instruct agents to perform on connected integrations;
- Process payments, prevent fraud, and comply with tax and accounting obligations;
- Communicate with you about your account, security, and material service changes;
- Detect and prevent abuse, security incidents, and violations of our Terms;
- Comply with applicable legal obligations.
4. Legal bases (EEA / UK users)
For users in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR: performance of a contract (for delivering the service), legitimate interests (for security, abuse prevention, and product analytics), consent (where required, such as for optional cookies), and legal obligations (such as tax and bookkeeping).
5. Sub-processors
To deliver Veflow, we share data with the following sub-processors. We choose providers that publish their own privacy and security commitments and we configure them to limit data sharing to what is necessary.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Cloudflare | Edge delivery, Workers, Containers, DDoS protection | Global edge |
| Anthropic | LLM inference for AI agents (managed runs) | United States |
| OpenAI | LLM inference for AI agents, where selected (managed runs) | United States |
| Expo | Push notifications to the mobile app (device token only) | United States |
| Creem | Payments, billing, tax (Merchant of Record) | Global |
| Resend | Transactional email | United States |
| GitHub, Linear, Jira, ClickUp, Google | OAuth and integration providers (only when you connect them) | Varies |
Product analytics (OpenPanel) and error monitoring (GlitchTip) run on infrastructure we operate ourselves — that data is not shared with a third-party analytics or monitoring vendor. We may add or replace sub-processors over time; material changes will be reflected in this policy.
6. AI model providers
When you instruct a Veflow agent in a managed run, the content of your prompt and any context the agent gathers (including selected code from connected repositories) is sent to the AI provider for that run — Anthropic or, where selected, OpenAI — for inference over an encrypted connection. Per those providers' API terms, content sent through the API is not used to train their models. In local / bring-your-own-agent mode, inference runs against your own provider subscription from your machine and does not pass through Veflow at all.
7. International transfers
Veflow is operated from the United States, and our infrastructure and sub-processors are located in the United States and on global edge networks. If you access Veflow from outside the United States — including the European Economic Area or the United Kingdom — your data will be transferred to and processed in the United States, whose data-protection laws may differ from yours. Where required by applicable law, we rely on Standard Contractual Clauses or equivalent safeguards for these international transfers.
8. Data retention
We keep account data and workspace content for as long as your account is active and for a reasonable period afterwards to allow for reactivation, dispute resolution, and legal compliance. After permanent deletion is requested, we will delete or irreversibly anonymise your data within thirty days, subject to retention required by law (such as for tax records).
9. Your rights
Depending on where you live, you may have rights under the GDPR (EEA / UK), CCPA / CPRA (California), or similar laws. These typically include the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Delete your data (subject to legal retention exceptions);
- Restrict or object to certain processing;
- Receive a portable copy of your data;
- Withdraw consent at any time (where consent is the legal basis);
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email privacy@veflow.ai. We respond within thirty days.
10. Cookies and analytics
We use a small number of strictly-necessary cookies to keep you signed in and remember your language preference. For usage analytics, we run a self-hosted instance of OpenPanel on our own infrastructure. Event data stays on servers we control — it is never shared with or sent to any third-party analytics vendor. We do not sell your personal data to advertisers, and we do not use third-party advertising cookies. If your browser sends a Do Not Track signal, analytics are disabled entirely.
11. Children
Veflow is not intended for use by anyone under sixteen. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Security
We use industry-standard measures to protect your data: encryption in transit (TLS) and at rest, scoped access controls for our team, encrypted storage of OAuth tokens, and continuous monitoring for security events. No security control is perfect — please use a strong, unique password and notify us promptly if you suspect a compromise.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to the address on your account at least fourteen days before they take effect, or by a prominent notice in the Veflow application.
14. Contact
Questions about this policy or your data? Email privacy@veflow.ai or use the contact form on our website.