Skip to main content
Platform Review
PricingSign in
FlowManual assessment

FlowManual procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for FlowManual
TopicPlan or tierRiskTheir wordsSource
Data retentionAll applicable tierslow Your data is retained until you delete it or request account deletion. Deleted data is removed within 30 days.Captured 2026-07-20Open source →Finding permalink →
Data retentionAll applicable tiersunknown We maintain an audit log of document analysis calls that includes: timestamp, user ID, document ID, operation type, bytes transmitted, and a keyed HMAC-SHA-256 hash of the prompt (when an audit key is configured). Full prompt text is never stored. This log is visible only to you at /admin/security and is used to maintain an audit trail of analysis usage.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown We use Resend to send service-related emails such as account confirmation, sign-in verification codes, and material changes to this policy. Resend processes the recipient email address and message contents on our behalf under a data processing agreement.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown We have no marketing or advertising vendors. The hosted service at flowmanual.com uses one privacy-preserving analytics provider (PostHog) to understand product usage: which features are used, how far new accounts get in setup, and where errors happen. These are server-side event counts tied to an account identifier. They never include document content, filenames, or client and vendor names, and we do not use analytics cookies or session recording (see Cookies below).Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown For accounts on flowmanual.com, the application, the database, and uploaded files are hosted on DigitalOcean. Files are kept on an encrypted volume. DigitalOcean processes this data on our behalf under a data processing agreement.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown If you sign in with Google, Google authenticates you and shares your name and email address with us. This is governed by Google’s Privacy Policy .Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown You can connect accounts you already hold with third-party services (Microsoft OneDrive and SharePoint, Google Drive, Procore, Dropbox, Egnyte, Docusign, and Autodesk Construction Cloud) to import PDF documents into your projects. Connectors are off by default, and connections go through each provider’s own sign-in and consent screen, so we never see or store your password for that service. The provider issues access tokens, which we store encrypted with AES-256-GCM and use only to list the folders, files, or completed agreements you browse and to download the specific files you choose to import. Imported files are then stored and protected exactly like files you upload directly. We request read-only access wherever the provider supports it, we never change or delete anything in your connected account, and nothing is scanned in the background: browsing, importing, and manual re-scans run only when you start them. You can disconnect a provider at any time, which deletes the stored tokens, and you can also revoke FlowManual’s access from the provider’s own security settings. Our use of data received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown We share data with the following processors only as necessary to provide the service:Captured 2026-07-20Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.