Super Flows

Privacy policy

Last updated 5 October 2026.

This policy explains what Super Flows collects when you use https://superflows.app, why, and what control you have over it. Super Flows is the data controller for your account data. For the data your workflows move between your apps, your organization is the controller and we process it on its behalf.

What we collect

Account data. Your name, email address and a hash of your password, plus the organizations you belong to and your role in each.

Workflow data. The projects, workflows, agents, skills and databases your organization creates, every run with each step's input and output, and the events your connected apps send to trigger workflows. This can include content from those apps, such as a message, an email or a spreadsheet row, when a workflow handles it.

Connected apps. Apps are connected through Super Connect, which stores the OAuth tokens. Super Flows stores only a reference to each connection. If your organization adds its own AI provider key, we store it encrypted.

Billing data. Stripe handles payment. We never see your card number; we keep your Stripe customer id, plan and invoice status.

Technical data. Server logs with IP address, browser type and the request made, and traces of AI steps for debugging. We do not use analytics or advertising trackers, and the only cookie is the one that keeps you signed in.

How we use it

To run your workflows, show you what each step did, send account and notification emails, enforce plan limits, bill your subscription, keep the service secure and answer support requests. AI steps send the step's instructions and inputs to the model your workflow selects. We do not sell personal data and we do not use your content to train models.

Who processes data for us

Cloudflare hosts the service, its database and email delivery. Stripe processes payments. Super Connect holds your app connections and relays their events. Vercel AI Gateway and Cloudflare Workers AI route AI requests to the model provider your workflow chooses. Langfuse stores traces of AI steps. Each receives only what it needs to do its job.

How long we keep it

Account and workflow data stay until you delete them or your organization is deleted. App events are deleted 30 days after they arrive. Server logs and traces are kept for a limited period for debugging. Deleting your organization removes its data from the live service; backups expire on their own shortly after.

Your rights

You can read and change your account details in Settings and export workflow data through the API. To access, correct or delete personal data, or to object to how it is processed, email us and we will answer within 30 days. If you are in the EU or UK you may also complain to your local data protection authority.

Changes

If this policy changes in a way that matters, we email account owners before the change takes effect. The date at the top shows the current version.

Contact

Email noreply@superflows.app with any questions about this policy.