1. Scope and controller
This Privacy Policy applies to the designFlow websites, web application and designFlow mobile applications for iOS and Android (together, the “Service”). It applies to the English and Spanish interfaces of the Service until a separate Spanish translation is published.
The operator and data controller for account administration and operation of the Service is Individual Entrepreneur Anna Aleksandrovna Maksimova, OGRNIP 319508100325484 (“designFlow”, “we”, “us”).
This Policy is informational. Acceptance of the Terms of Use does not replace any separate consent required by law or requested inside the app.
2. Our data roles
For account, security, support, billing status and product-operation data, designFlow determines why and how the data is processed and acts as the controller.
When a professional user uploads information about clients, contractors, employees or other people into a private project workspace, that user decides what to collect and why. In that context, the user may be the controller and designFlow processes the content to provide the Service. Users must have an appropriate legal basis and give any notices required before uploading another person’s data.
3. Data we process
Account and contact data
- name, email address, internal user identifier and profile image;
- authentication information, one-time login codes, session and security records;
- support messages and account-deletion requests.
Workspace and project content
- project names and textual addresses, visits, notes, tasks, issues, tags, responsible persons and due dates;
- photos, videos, audio recordings, documents and other files you choose to upload;
- comments, transcripts, recognised text, article numbers, prices, QR or barcode content, AI-generated summaries and suggested tasks;
- reports and private sharing links generated at your request.
Technical and usage data
- device and app version, operating system, language, timestamps and synchronization state;
- IP address, request metadata, security events and server logs;
- crash reports, performance information and diagnostic breadcrumbs. We do not intentionally enable advertising tracking or collect IDFA for the Service.
Website data
Our websites may process IP address, browser and device information, page interactions, referrer data, form submissions and cookies or similar technologies. The international landing page uses Google Tag Manager to operate configured measurement tools. Browser controls and any consent controls presented on the website can be used to limit optional cookies.
Commercial records
If you use a paid plan, we may process plan status, entitlement, invoice and payment-status records needed to administer the Service. Full payment-card details are handled by the payment provider used at checkout and are not requested by the mobile app.
4. Why we process data
Depending on the data and applicable law, processing is necessary to perform our agreement with you, comply with legal obligations, pursue legitimate interests such as security and service reliability, or is based on your consent.
We use data to:
- create and secure accounts, authenticate users and maintain sessions;
- store, synchronize and display projects and files across authorized devices;
- create client reports and private sharing links at your request;
- provide optional AI functions described below;
- respond to support, privacy and deletion requests;
- prevent abuse, investigate failures and keep the Service reliable;
- administer plans, entitlements and records required by tax, accounting or other applicable law;
- understand aggregate website and product performance and improve the Service.
We do not sell personal data and do not use project content for third-party advertising.
5. Optional AI processing
AI features are disabled until the user grants permission in the app. Refusing or withdrawing AI permission does not prevent use of the Service’s basic non-AI functions.
If AI is enabled, content selected by the user may be processed to:
- transcribe voice notes and audio tracks from videos;
- recognise visible text, article numbers, dimensions, prices, QR codes and barcodes in photographs;
- suggest or classify tasks and issues;
- answer questions using relevant project context;
- generate a concise visit summary for a report.
This processing may include selected audio, video, photographs, text and relevant project context. The content may be transmitted to the AI and speech-processing providers listed in Section 6. designFlow does not use AI to make decisions that produce legal or similarly significant effects about individuals.
AI output may be incomplete or incorrect. Transcripts and generated comments can be reviewed and edited by the user before they are relied upon or shared.
6. Service providers
We use service providers only for functions needed to operate the Service. Depending on the feature and current technical configuration, recipients may include:
- Timeweb Cloud — infrastructure and object storage for uploaded files.
- Yandex Cloud SpeechKit — transcription of audio selected for speech recognition.
- Cloud.ru Foundation Models — text and image AI processing.
- OpenAI — certain image or vision processing routed through the configured AI platform when that model is selected.
- Google email services — delivery of login codes, security, support and deletion notifications.
- Sentry — crash, performance and diagnostic monitoring. Default personal-data collection is limited where technically available.
- Google Tag Manager and configured website measurement services — operation and measurement of the public website.
Providers can change when infrastructure changes. We require providers to handle data only for the contracted purpose and subject to applicable confidentiality, security and data-protection obligations.
8. Retention and account deletion
Account data and project content are generally retained while the account is active and for as long as needed to provide the Service. Security logs, support records, transaction records and backups may be kept for a limited additional period where necessary for security, dispute resolution, accounting or legal obligations.
A user can initiate deletion in Profile → Delete account in the mobile app. The app asks the user to confirm the email address. After acceptance, access and sessions are revoked, local app data is cleared and the server places the account into the deletion process. The underlying account and associated project data are normally processed for deletion within 2–3 business days. We send a completion notice when processing finishes.
Deletion covers the account and associated projects, visits, notes, tasks, issues, media, derived files and AI history, except records we must retain under law or need to establish, exercise or defend legal claims. Residual copies may remain temporarily in protected backups until the applicable backup cycle overwrites them.
The same email address may be used to create a new account after a deletion request. The new account is assigned a new identity and is not given access to the deleted account’s projects.
9. Security
We use organizational and technical safeguards intended to protect data against unauthorized access, alteration, loss and disclosure. These include authenticated access, transport encryption, access controls, credential revocation and isolation of local data by account. No system can guarantee absolute security; please protect your device, email account and access links and notify us if you suspect unauthorized use.
10. Your choices and rights
Subject to applicable law, you may ask to access, correct, receive, restrict the use of, object to processing of, or delete your personal data. Where processing is based on consent, you may withdraw it without affecting processing that was lawful before withdrawal. You may also lodge a complaint with the competent data-protection authority.
You may manage AI permission in the app and initiate account deletion in Profile. For other requests, contact us using Section 13. We may ask for information needed to verify your identity and protect the account from unauthorized requests.
11. Children
The Service is designed for professional project work and is not directed to children. A parent or legal guardian who believes a child has provided personal data without appropriate authorization should contact us so that we can investigate and take appropriate action.
12. Changes to this Policy
We may update this Policy when the Service, providers or legal requirements change. The current version and effective date will remain available at this URL. If a change requires a new consent, we will request it separately rather than treating continued use as consent.
13. Contact
Controller: Individual Entrepreneur Anna Aleksandrovna Maksimova
OGRNIP: 319508100325484
Privacy requests: info@designflow.su
Product support: support@designflow.online