1. Who is responsible for your data

Flow Testing is operated by Francisco Gómez, an individual established in Colombia, acting as the data controller (responsable del tratamiento) for the personal data described in this policy.

Contact for any privacy matter, including the rights described in section 9: [email protected]. We answer from this address and it is the fastest route for a deletion or access request.

2. Which laws apply

  • Colombia — Ley 1581 de 2012 and Decreto 1377 de 2013 (Habeas Data), supervised by the Superintendencia de Industria y Comercio (SIC).
  • European Economic Area and UK — the GDPR and UK GDPR apply to the extent we offer the service to users located there, under Article 3(2) GDPR.

Where the two regimes differ, we apply whichever gives you the stronger protection.

3. What we collect

Account data

  • Your email address and a one-way hash of your password — never the password itself.
  • Email verification status and account creation date.
  • If you sign in with Google: the email address, name, profile picture and Google account identifier contained in the Google ID token. We do not receive your Google password and request no access to your Gmail, Drive or Calendar.

Test content you create

  • Projects, flows, nodes, assertions, element selectors and the target URLs you configure.
  • Schedules and notification settings for recurring runs.
  • Values you store in the secrets vault — typically credentials for the application you are testing. These are encrypted at rest and the plaintext value is never returned by our API once saved; only the secret's name and creation date are readable. Note that the vault protects the stored value and your flow definition, not the record of a run that used it — see the warning under "Run artifacts" below.
  • If you use the AI features with your own key (BYOK), the API key you supply for Anthropic, OpenAI or a custom endpoint, stored encrypted.

Run artifacts

When a flow runs, Playwright produces traces, screenshots, video, console output and network logs. These are stored so you can debug the run in the trace viewer.

Read this part carefully. Run artifacts are a recording of your application as it was being driven. If you point a flow at a production system holding real user data, those screenshots, traces and network logs will contain that data — including personal data belonging to people who are not Flow Testing users.

Credentials appear in run artifacts in readable form. To type a credential into a real login form we have to decrypt it first, so the value is recorded in that run's artifacts — in the captured step parameters, in the page snapshot, and in the body of the request the page sent. A password field renders as dots on screen, but the characters are still present in the underlying recording, and a value in an ordinary text field is visible outright. Storing a credential in the secrets vault keeps it out of your flow definition, out of exported files and out of our database in readable form; it does not remove it from the recording of a run that used it. This is a consequence of driving a real browser against a real application. Use dedicated, low-privilege test accounts rather than real user or administrator credentials, and see section 11.

Usage and billing data

  • Your plan, run count for the current period, and monthly usage history.
  • A billing audit log of events such as run_created, limit_reached and limit_exceeded_attempt, used to enforce plan limits and to resolve disputes.
  • Subscription status received from our payment provider. We do not receive or store your card number, CVV or full billing address — see section 6.

Product analytics

We use PostHog to understand how the product is actually used. The events we record are deliberately limited to product actions, not content: account signup and login, logout, flow created, flow deleted, flow run started, flow run completed, flow exported, flow imported, upgrade initiated and subscription cancelled. Each is linked to your user identifier so we can measure, for example, how many people reach a first successful run.

Alongside those events PostHog records technical context: browser and device type, operating system, referring page, and an approximate location derived from your IP address. We do not record the contents of your flows, your secrets or your run artifacts in analytics.

Technical data

  • IP address and user agent, from server and CDN logs, used for security and abuse prevention.
  • A session cookie that keeps you signed in.

4. What we never do

  • We do not sell your personal data, and we never have.
  • We do not share it with advertising networks or data brokers, and we run no ad tracking.
  • We do not read your flows, secrets or run artifacts except where section 7 permits it.
  • We do not use your test content to train our own machine-learning models.

5. Why we process it, and on what legal basis

Under Colombian law, your authorisation for processing is given when you create an account and accept this policy, in line with Article 9 of Ley 1581 de 2012. You can withdraw it at any time by deleting your account, subject to the retention periods in section 8.

6. Who we share data with

We use a small number of providers to run the service. They process data on our instructions and only for the purpose listed.

Card details. Payments are handled by Lemon Squeezy as merchant of record. You enter your card on their checkout, not ours. We receive only the outcome — plan, status, renewal date — and never see your card number.

AI features. When you use an AI agent, the relevant flow structure and page context are sent to the model provider to produce a suggestion. If you supply your own API key, the request runs against your own account with that provider and is governed by your agreement with them. Avoid putting secrets or real personal data into prompts.

We may also disclose data where we are legally required to, or to protect our rights, but we will not hand over your data on an informal request.

7. International transfers

Flow Testing is operated from Colombia, which the European Commission has not issued an adequacy decision for, and our providers operate in several countries — PostHog in the United States, and others in the United States and the European Union. Your data will therefore be transferred outside your own country, including outside the EEA.

For transfers of EEA or UK personal data we rely on the Standard Contractual Clauses in our agreements with these providers, together with the safeguards they publish. For transfers out of Colombia we rely on your authorisation and on contractual guarantees as contemplated by Article 26 of Ley 1581 de 2012. You can ask us at [email protected] which safeguard applies to a specific provider.

We are in the process of documenting the exact hosting region for the API and for run-artifact storage. If the region matters for your compliance assessment, email us before you sign up and we will confirm it in writing rather than have you rely on a guess.

8. How long we keep it

  • Run artifacts — traces, screenshots, video and logs are retained for 30 days from the run, then deleted. You can delete a run earlier yourself.
  • Account and test content — kept while your account is open. On deletion, flows, projects, secrets and stored API keys are removed.
  • Secrets and BYOK API keys — deleted when you delete the secret, or when the account is deleted.
  • Billing records — retained as long as commercial and tax law requires, which can be several years after your account closes, even though the account itself is gone.
  • Analytics events — retained on PostHog's standard retention schedule for our plan.
  • Security logs — short-lived, generally weeks rather than months.

9. Your rights

Under the GDPR you have the right to access your data, correct it, have it deleted, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing relies on consent.

Under Ley 1581 de 2012 you have the right to know, update and correct your data, to ask for proof of the authorisation you gave, to be informed on request how your data has been used, to file a complaint with the SIC, and to ask for deletion where processing does not respect the law.

Email [email protected] to exercise any of these. We respond to a request to consult your data (consulta) within 10 business days and to a complaint or correction request (reclamo) within 15 business days, as Decreto 1377 de 2013 requires; where the GDPR's one-month deadline is shorter in a given case, we meet that instead. If we need to extend a deadline, we will tell you why before it expires.

If you are unhappy with how we handled your request you can complain to the SIC in Colombia, or to your national data protection authority if you are in the EEA or UK. We would rather you came to us first, but that route is yours regardless.

10. How we protect it

  • All traffic is served over HTTPS.
  • Passwords are stored as one-way hashes, never in a recoverable form.
  • Vault secrets and BYOK API keys are encrypted at rest and write-only through the API. This is encryption at rest, not end-to-end encryption: we necessarily decrypt a secret in order to use it in a run, and the value then appears in that run's artifacts as described in section 3.
  • Access to production data is limited to the operator and used only to run and repair the service.

No service can promise perfect security. If a breach affects your personal data we will notify you and the relevant authority without undue delay, and within 72 hours of becoming aware of it where the GDPR requires.

11. Your own responsibilities

When you test an application that holds other people's personal data, you are the controller of that data and we act as your processor. Practically, that means:

  • Test against staging or seeded data wherever you can. Pointing a flow at production means real personal data ends up in run artifacts.
  • Use dedicated, low-privilege test accounts created for testing — never real user or administrator credentials. Any credential a flow signs in with is readable by anyone who can open that run's artifacts.
  • Use the secrets vault rather than typing credentials directly into a node. This keeps them out of your flow definition and out of anything you export or share, though not out of run artifacts.
  • Delete a run you no longer need rather than waiting out the 30-day retention period, and rotate any credential you believe has been over-exposed.
  • Only test systems you own or have written authorisation to test. This is also a condition of the Terms of Service.
  • If you need a data processing agreement before using Flow Testing for this kind of data, email us and we will put one in place.

12. Cookies

We use a session cookie to keep you signed in, which the service cannot work without. PostHog sets its own cookies to recognise a returning user across sessions. We set no advertising or cross-site tracking cookies. You can block cookies in your browser, but the authenticated part of the app will not function without the session cookie.

13. Children

Flow Testing is a professional tool and is not directed at children. You must be at least 16 to create an account. If you believe a child has given us personal data, email us and we will delete it.

14. Changes to this policy

We will update this policy as the product changes. The date at the top always reflects the current version. If a change materially affects your rights or how we use your data, we will email you before it takes effect rather than change the page quietly.

15. Contact

Privacy questions, requests and complaints: [email protected]. A real person reads it.