designFlow
Home Privacy Terms
Legal · Privacy

Privacy Policy

This Policy explains what data designFlow processes, why it is needed, which service providers may receive it, and how you can control or delete it.

Effective and last updated: 4 September 2026

The short version

Your project content remains yours. AI features are optional and require permission in the app before selected content is sent for AI processing. You can withdraw that permission, and you can initiate deletion of your account in the mobile app.

Contents 1. Scope and controller 2. Our data roles 3. Data we process 4. Purposes and grounds 5. AI processing 6. Service providers 7. Sharing and transfers 8. Retention and deletion 9. Security 10. Your rights 11. Children 12. Changes 13. Contact

1. Scope and controller

This Privacy Policy applies to the designFlow websites, web application and designFlow mobile applications for iOS and Android (together, the “Service”). It applies to the English and Spanish interfaces of the Service until a separate Spanish translation is published.

The operator and data controller for account administration and operation of the Service is Individual Entrepreneur Anna Aleksandrovna Maksimova, OGRNIP 319508100325484 (“designFlow”, “we”, “us”).

This Policy is informational. Acceptance of the Terms of Use does not replace any separate consent required by law or requested inside the app.

2. Our data roles

For account, security, support, billing status and product-operation data, designFlow determines why and how the data is processed and acts as the controller.

When a professional user uploads information about clients, contractors, employees or other people into a private project workspace, that user decides what to collect and why. In that context, the user may be the controller and designFlow processes the content to provide the Service. Users must have an appropriate legal basis and give any notices required before uploading another person’s data.

3. Data we process

Account and contact data

  • name, email address, internal user identifier and profile image;
  • authentication information, one-time login codes, session and security records;
  • support messages and account-deletion requests.

Workspace and project content

  • project names and textual addresses, visits, notes, tasks, issues, tags, responsible persons and due dates;
  • photos, videos, audio recordings, documents and other files you choose to upload;
  • comments, transcripts, recognised text, article numbers, prices, QR or barcode content, AI-generated summaries and suggested tasks;
  • reports and private sharing links generated at your request.

Technical and usage data

  • device and app version, operating system, language, timestamps and synchronization state;
  • IP address, request metadata, security events and server logs;
  • crash reports, performance information and diagnostic breadcrumbs. We do not intentionally enable advertising tracking or collect IDFA for the Service.

Website data

Our websites may process IP address, browser and device information, page interactions, referrer data, form submissions and cookies or similar technologies. The international landing page uses Google Tag Manager to operate configured measurement tools. Browser controls and any consent controls presented on the website can be used to limit optional cookies.

Commercial records

If you use a paid plan, we may process plan status, entitlement, invoice and payment-status records needed to administer the Service. Full payment-card details are handled by the payment provider used at checkout and are not requested by the mobile app.

4. Why we process data

Depending on the data and applicable law, processing is necessary to perform our agreement with you, comply with legal obligations, pursue legitimate interests such as security and service reliability, or is based on your consent.

We use data to:

  • create and secure accounts, authenticate users and maintain sessions;
  • store, synchronize and display projects and files across authorized devices;
  • create client reports and private sharing links at your request;
  • provide optional AI functions described below;
  • respond to support, privacy and deletion requests;
  • prevent abuse, investigate failures and keep the Service reliable;
  • administer plans, entitlements and records required by tax, accounting or other applicable law;
  • understand aggregate website and product performance and improve the Service.

We do not sell personal data and do not use project content for third-party advertising.

5. Optional AI processing

AI features are disabled until the user grants permission in the app. Refusing or withdrawing AI permission does not prevent use of the Service’s basic non-AI functions.

If AI is enabled, content selected by the user may be processed to:

  • transcribe voice notes and audio tracks from videos;
  • recognise visible text, article numbers, dimensions, prices, QR codes and barcodes in photographs;
  • suggest or classify tasks and issues;
  • answer questions using relevant project context;
  • generate a concise visit summary for a report.

This processing may include selected audio, video, photographs, text and relevant project context. The content may be transmitted to the AI and speech-processing providers listed in Section 6. designFlow does not use AI to make decisions that produce legal or similarly significant effects about individuals.

AI output may be incomplete or incorrect. Transcripts and generated comments can be reviewed and edited by the user before they are relied upon or shared.

Withdrawing AI permission: withdrawing permission stops new optional AI requests from the app. It does not automatically remove original project content or results already saved in the workspace. Those can be edited or deleted separately, or removed through account deletion.

6. Service providers

We use service providers only for functions needed to operate the Service. Depending on the feature and current technical configuration, recipients may include:

  • Timeweb Cloud — infrastructure and object storage for uploaded files.
  • Yandex Cloud SpeechKit — transcription of audio selected for speech recognition.
  • Cloud.ru Foundation Models — text and image AI processing.
  • OpenAI — certain image or vision processing routed through the configured AI platform when that model is selected.
  • Google email services — delivery of login codes, security, support and deletion notifications.
  • Sentry — crash, performance and diagnostic monitoring. Default personal-data collection is limited where technically available.
  • Google Tag Manager and configured website measurement services — operation and measurement of the public website.

Providers can change when infrastructure changes. We require providers to handle data only for the contracted purpose and subject to applicable confidentiality, security and data-protection obligations.

7. Sharing and international transfers

We disclose data to service providers described above, to authorized members of your workspace, to a recipient when you intentionally create or send a private report link, and when disclosure is required by law or necessary to protect rights and security.

Some providers may process data in Russia, the United States or other countries where they or their subprocessors operate. Those countries may apply different data-protection rules. Where applicable law requires it, we rely on an available transfer mechanism and appropriate contractual or organizational safeguards.

We do not make private project content publicly searchable. Anyone who receives an active report link may be able to view the linked report, so users must share links carefully.

8. Retention and account deletion

Account data and project content are generally retained while the account is active and for as long as needed to provide the Service. Security logs, support records, transaction records and backups may be kept for a limited additional period where necessary for security, dispute resolution, accounting or legal obligations.

A user can initiate deletion in Profile → Delete account in the mobile app. The app asks the user to confirm the email address. After acceptance, access and sessions are revoked, local app data is cleared and the server places the account into the deletion process. The underlying account and associated project data are normally processed for deletion within 2–3 business days. We send a completion notice when processing finishes.

Deletion covers the account and associated projects, visits, notes, tasks, issues, media, derived files and AI history, except records we must retain under law or need to establish, exercise or defend legal claims. Residual copies may remain temporarily in protected backups until the applicable backup cycle overwrites them.

The same email address may be used to create a new account after a deletion request. The new account is assigned a new identity and is not given access to the deleted account’s projects.

9. Security

We use organizational and technical safeguards intended to protect data against unauthorized access, alteration, loss and disclosure. These include authenticated access, transport encryption, access controls, credential revocation and isolation of local data by account. No system can guarantee absolute security; please protect your device, email account and access links and notify us if you suspect unauthorized use.

10. Your choices and rights

Subject to applicable law, you may ask to access, correct, receive, restrict the use of, object to processing of, or delete your personal data. Where processing is based on consent, you may withdraw it without affecting processing that was lawful before withdrawal. You may also lodge a complaint with the competent data-protection authority.

You may manage AI permission in the app and initiate account deletion in Profile. For other requests, contact us using Section 13. We may ask for information needed to verify your identity and protect the account from unauthorized requests.

11. Children

The Service is designed for professional project work and is not directed to children. A parent or legal guardian who believes a child has provided personal data without appropriate authorization should contact us so that we can investigate and take appropriate action.

12. Changes to this Policy

We may update this Policy when the Service, providers or legal requirements change. The current version and effective date will remain available at this URL. If a change requires a new consent, we will request it separately rather than treating continued use as consent.

13. Contact

Controller: Individual Entrepreneur Anna Aleksandrovna Maksimova
OGRNIP: 319508100325484
Privacy requests: info@designflow.su
Product support: support@designflow.online

designFlow
Home Privacy Terms Support

© 2026 designFlow