Privacy Policy

Last updated: March 23, 2026

1. Introduction

Welcome to Auto Flow Pro, developed by Flow Automation ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Chrome extension and related services.

Important: We do not collect any personal data except your email address, which is used solely for authentication and license management purposes. We will never use your email for marketing, sell it to third parties, or use it for any purpose other than providing our service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect only your email address for authentication purposes. Your password is stored securely using industry-standard bcrypt hashing and is never stored in plain text. We do not collect your name, phone number, address, or any other personal information.

2.2 Device Information

For license validation and security purposes, we collect:

  • Device ID: A randomly generated unique identifier for your device
  • Operating System: Your OS name and version (e.g., Windows 10, macOS 14)
  • Screen Resolution: Your display resolution for analytics purposes
  • Browser Information: Browser type and version

This information is used solely to bind licenses to devices and prevent unauthorized sharing. We cannot identify you personally from this data.

2.3 Usage Data

We track the number of videos/images you generate daily to enforce usage limits for free tier users. This includes timestamps and basic metadata about your usage patterns. This data is stored locally on your device and on our servers only for quota enforcement.

2.4 License Information

If you purchase a PRO license, we store your license key and associate it with your email and device ID for validation purposes. No payment information is stored on our servers.

2.5 Technical Data

We collect minimal technical data for service operation:

  • Session Tokens: Temporary JWT tokens for authentication (expire after inactivity)
  • Error Logs: Anonymous error messages for debugging (no personal data included)
  • API Request Metadata: Timestamps and request types for rate limiting

We do not collect IP addresses for tracking purposes. Technical data is retained only as long as necessary for service operation.

2.6 Content You Create

We do NOT collect, store, or have access to:

  • Your prompts or text inputs
  • Images or videos you upload
  • Generated videos or images
  • Any content you create using the extension

All content remains on your device and Google's servers. We never see or store your creative work.

3. How We Use Your Information

We use the information we collect only for the following purposes:

  • Authentication: Your email is used solely to log you into your account
  • License Management: To validate PRO licenses and bind them to your device
  • Usage Limits: To enforce the 50 videos/day limit for free tier users
  • Security: To prevent unauthorized access and license sharing
  • Service Delivery: To provide and maintain the core functionality of the extension
  • Legal Compliance: To comply with applicable laws and regulations

We do NOT:

  • Send marketing or promotional emails
  • Share your email with third parties
  • Use your data for advertising purposes
  • Track your browsing activity outside of Google Flow pages
  • Analyze or access your creative content

4. Data Storage and Security

We implement industry-standard security measures to protect your data:

  • Passwords are hashed using bcrypt before storage
  • All data transmission is encrypted using HTTPS/TLS
  • Database access is restricted and monitored
  • Regular security audits and updates

5. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

  • With your explicit consent
  • To comply with legal obligations or court orders
  • To protect our rights, property, or safety
  • With service providers who assist in operating our service (under strict confidentiality agreements)

6. Your Rights

You have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your account and data
  • Opt-out of non-essential communications
  • Export your data in a portable format

To exercise these rights, please contact us at support@flowautomation.store

7. Cookies and Tracking

We use session-based authentication tokens (JWT) to maintain your login state. These tokens expire after a period of inactivity. We do not use persistent cookies for tracking purposes.

8. Third-Party Services

Our extension interacts with Google Flow (labs.google/fx/tools/flow) for video/image generation. We do not control Google's privacy practices. Please review Google's privacy policy for information about how they handle your data.

9. Children's Privacy

Our service is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

11. GDPR Compliance (For EU Residents)

If you are a resident of the European Union (EU) or European Economic Area (EEA), you have certain data protection rights under the General Data Protection Regulation (GDPR).

11.1 Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contractual Necessity: To provide our services and fulfill our contract with you
  • Legitimate Interests: To improve our services, prevent fraud, and ensure security
  • Legal Obligation: To comply with applicable laws and regulations
  • Consent: Where you have given explicit consent for specific processing activities

11.2 Your GDPR Rights

Under GDPR, you have the following rights:

  • Right to Access: Request copies of your personal data
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data
  • Right to Restrict Processing: Request limitation of how we use your data
  • Right to Data Portability: Request transfer of your data to another service
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time (where processing is based on consent)
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

11.3 How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at:

We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.

11.4 Data Transfers

Your data may be transferred to and processed in countries outside the EU/EEA. When we transfer data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.

11.5 Supervisory Authority

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local data protection supervisory authority. You can find your local authority at: https://edpb.europa.eu

12. Data Retention

We retain your information only for as long as necessary to provide our services:

  • Account Data: Retained while your account is active. Deleted within 30 days of account deletion.
  • Usage Data: Retained for 90 days for quota enforcement, then automatically deleted.
  • License Data: Retained for the lifetime of the license for validation purposes.
  • Device Information: Retained while license is active. Deleted when license is deactivated.

13. Cookies and Similar Technologies

We use minimal cookies and similar technologies to provide our service:

Essential Cookies

  • Session Tokens (JWT): Stored in browser localStorage to maintain your login state. These expire after a period of inactivity.
  • Settings Storage: Your extension preferences stored locally in Chrome's storage API.

What We Don't Use

We do NOT use tracking cookies, advertising cookies, or third-party analytics cookies. Your browsing activity is not tracked outside of Google Flow pages.

14. Contact Us

If you have any questions about this Privacy Policy, please contact Flow Automation: