Legal

Privacy Policy

Last updated: 25 July 2026

Note on entity. Veflow is currently operated by its founder pending registration of a dedicated legal entity. The "data controller" named in this policy will be updated to that entity once registration is complete. Existing users will be notified of the change in writing.

Local mode: your code stays on your device

When you run agents in Veflow's local / bring-your-own-agent mode (the desktop app on your own Claude, Codex, or Copilot subscription), your source code, diffs, and terminal activity are processed on your own machine and are not transmitted to or stored by Veflow. In that mode we sync only session metadata — repository and branch names, timestamps, and run status. The processing described below about code and agent conversations applies to managed / cloud runs, which you choose explicitly. See our Trust Center for the full data-flow.

1. Who we are

Veflow is an agent workspace that helps developers and teams plan, build, and ship software using AI agents. This Privacy Policy explains how Veflow collects, uses, shares, and protects your personal data when you use our website at veflow.ai or our application at app.veflow.ai.

2. Data we collect

We collect the following categories of personal data:

  • Account data. Email address, display name, authentication identifiers from the OAuth providers you use to sign in (such as GitHub or Google).
  • Integration data. OAuth access and refresh tokens for the third-party services you connect (GitHub, Linear, Jira, ClickUp). We store these encrypted at rest and use them only to perform actions you have authorised.
  • Workspace content. Tasks, comments, agent prompts, agent outputs, code diffs, repository contents fetched on your behalf, and the full conversational thread between you and our AI agents.
  • Billing data. Subscription tier, billing status, and the customer identifier issued by our payment processor (Creem). Veflow does not store full credit-card numbers — those are held by Creem and its sub-processors.
  • Usage and telemetry. Pages visited, features used, credit consumption, error reports, IP address, and approximate location derived from IP. We collect this to operate, secure, and improve the service.
  • Communications. Messages you send us via the contact form, email, or support channels, and our replies.

3. How we use your data

We use personal data to:

  • Provide, maintain, and improve the Veflow service;
  • Execute the actions you instruct agents to perform on connected integrations;
  • Process payments, prevent fraud, and comply with tax and accounting obligations;
  • Communicate with you about your account, security, and material service changes;
  • Detect and prevent abuse, security incidents, and violations of our Terms;
  • Comply with applicable legal obligations.

4. Legal bases (EEA / UK users)

For users in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR: performance of a contract (for delivering the service), legitimate interests (for security, abuse prevention, and product analytics), consent (where required, such as for optional cookies), and legal obligations (such as tax and bookkeeping).

5. Sub-processors

To deliver Veflow, we share data with the following sub-processors. We choose providers that publish their own privacy and security commitments and we configure them to limit data sharing to what is necessary.

Sub-processorPurposeRegion
SupabaseDatabase, authentication, file storageUnited States
CloudflareEdge delivery, Workers, Containers, DDoS protectionGlobal edge
AnthropicLLM inference for AI agents (managed runs)United States
OpenAILLM inference for AI agents, where selected (managed runs)United States
ExpoPush notifications to the mobile app (device token only)United States
CreemPayments, billing, tax (Merchant of Record)Global
ResendTransactional emailUnited States
GitHub, Linear, Jira, ClickUp, GoogleOAuth and integration providers (only when you connect them)Varies

Product analytics (OpenPanel) and error monitoring (GlitchTip) run on infrastructure we operate ourselves — that data is not shared with a third-party analytics or monitoring vendor. We may add or replace sub-processors over time; material changes will be reflected in this policy.

6. AI model providers

When you instruct a Veflow agent in a managed run, the content of your prompt and any context the agent gathers (including selected code from connected repositories) is sent to the AI provider for that run — Anthropic or, where selected, OpenAI — for inference over an encrypted connection. Per those providers' API terms, content sent through the API is not used to train their models. In local / bring-your-own-agent mode, inference runs against your own provider subscription from your machine and does not pass through Veflow at all.

7. International transfers

Veflow is operated from the United States, and our infrastructure and sub-processors are located in the United States and on global edge networks. If you access Veflow from outside the United States — including the European Economic Area or the United Kingdom — your data will be transferred to and processed in the United States, whose data-protection laws may differ from yours. Where required by applicable law, we rely on Standard Contractual Clauses or equivalent safeguards for these international transfers.

8. Data retention

We keep account data and workspace content for as long as your account is active and for a reasonable period afterwards to allow for reactivation, dispute resolution, and legal compliance. After permanent deletion is requested, we will delete or irreversibly anonymise your data within thirty days, subject to retention required by law (such as for tax records).

9. Your rights

Depending on where you live, you may have rights under the GDPR (EEA / UK), CCPA / CPRA (California), or similar laws. These typically include the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Delete your data (subject to legal retention exceptions);
  • Restrict or object to certain processing;
  • Receive a portable copy of your data;
  • Withdraw consent at any time (where consent is the legal basis);
  • Lodge a complaint with your local data-protection authority.

To exercise any of these rights, email privacy@veflow.ai. We respond within thirty days.

10. Cookies and analytics

We use a small number of strictly-necessary cookies to keep you signed in and remember your language preference. For usage analytics, we run a self-hosted instance of OpenPanel on our own infrastructure. Event data stays on servers we control — it is never shared with or sent to any third-party analytics vendor. We do not sell your personal data to advertisers, and we do not use third-party advertising cookies. If your browser sends a Do Not Track signal, analytics are disabled entirely.

11. Children

Veflow is not intended for use by anyone under sixteen. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Security

We use industry-standard measures to protect your data: encryption in transit (TLS) and at rest, scoped access controls for our team, encrypted storage of OAuth tokens, and continuous monitoring for security events. No security control is perfect — please use a strong, unique password and notify us promptly if you suspect a compromise.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email to the address on your account at least fourteen days before they take effect, or by a prominent notice in the Veflow application.

14. Contact

Questions about this policy or your data? Email privacy@veflow.ai or use the contact form on our website.