Privacy Policy
This policy explains what Flow Testing collects, why, who it is shared with, and the rights you have over it. It is written to be read, not to be skimmed past.
1. Who is responsible for your data
Flow Testing is operated by Francisco Gómez, an individual established in Colombia, acting as the data controller (responsable del tratamiento) for the personal data described in this policy.
Contact for any privacy matter, including the rights described in section 9: [email protected]. We answer from this address and it is the fastest route for a deletion or access request.
2. Which laws apply
- Colombia — Ley 1581 de 2012 and Decreto 1377 de 2013 (Habeas Data), supervised by the Superintendencia de Industria y Comercio (SIC).
- European Economic Area and UK — the GDPR and UK GDPR apply to the extent we offer the service to users located there, under Article 3(2) GDPR.
Where the two regimes differ, we apply whichever gives you the stronger protection.
3. What we collect
Account data
- Your email address and a one-way hash of your password — never the password itself.
- Email verification status and account creation date.
- If you sign in with Google: the email address, name, profile picture and Google account identifier contained in the Google ID token. We do not receive your Google password and request no access to your Gmail, Drive or Calendar.
Test content you create
- Projects, flows, nodes, assertions, element selectors and the target URLs you configure.
- Schedules and notification settings for recurring runs.
- Values you store in the secrets vault — typically credentials for the application you are testing. These are encrypted at rest and the plaintext value is never returned by our API once saved; only the secret's name and creation date are readable. Note that the vault protects the stored value and your flow definition, not the record of a run that used it — see the warning under "Run artifacts" below.
- If you use the AI features with your own key (BYOK), the API key you supply for Anthropic, OpenAI or a custom endpoint, stored encrypted.
Run artifacts
When a flow runs, Playwright produces traces, screenshots, video, console output and network logs. These are stored so you can debug the run in the trace viewer.
Read this part carefully. Run artifacts are a recording of your application as it was being driven. If you point a flow at a production system holding real user data, those screenshots, traces and network logs will contain that data — including personal data belonging to people who are not Flow Testing users.
Credentials appear in run artifacts in readable form. To type a credential into a real login form we have to decrypt it first, so the value is recorded in that run's artifacts — in the captured step parameters, in the page snapshot, and in the body of the request the page sent. A password field renders as dots on screen, but the characters are still present in the underlying recording, and a value in an ordinary text field is visible outright. Storing a credential in the secrets vault keeps it out of your flow definition, out of exported files and out of our database in readable form; it does not remove it from the recording of a run that used it. This is a consequence of driving a real browser against a real application. Use dedicated, low-privilege test accounts rather than real user or administrator credentials, and see section 11.
Usage and billing data
- Your plan, run count for the current period, and monthly usage history.
- A billing audit log of events such as
run_created,limit_reachedandlimit_exceeded_attempt, used to enforce plan limits and to resolve disputes. - Subscription status received from our payment provider. We do not receive or store your card number, CVV or full billing address — see section 6.
Product analytics
We use PostHog to understand how the product is actually used. The events we record are deliberately limited to product actions, not content: account signup and login, logout, flow created, flow deleted, flow run started, flow run completed, flow exported, flow imported, upgrade initiated and subscription cancelled. Each is linked to your user identifier so we can measure, for example, how many people reach a first successful run.
Alongside those events PostHog records technical context: browser and device type, operating system, referring page, and an approximate location derived from your IP address. We do not record the contents of your flows, your secrets or your run artifacts in analytics.
Technical data
- IP address and user agent, from server and CDN logs, used for security and abuse prevention.
- A session cookie that keeps you signed in.
4. What we never do
- We do not sell your personal data, and we never have.
- We do not share it with advertising networks or data brokers, and we run no ad tracking.
- We do not read your flows, secrets or run artifacts except where section 7 permits it.
- We do not use your test content to train our own machine-learning models.
5. Why we process it, and on what legal basis
| Purpose | Data used | GDPR legal basis |
|---|---|---|
| Provide the service — run your tests, store your flows, keep you signed in | Account, test content, secrets, run artifacts | Performance of a contract (Art. 6(1)(b)) |
| Enforce plan limits and take payment | Usage counters, billing audit log, subscription status | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention, debugging | IP, user agent, server logs | Legitimate interests (Art. 6(1)(f)) |
| Product analytics and improvement | PostHog events, device and approximate location | Legitimate interests (Art. 6(1)(f)), or consent where required |
| Service emails — verification, run reports, billing notices | Email address | Performance of a contract (Art. 6(1)(b)) |
| Meeting accounting and legal obligations | Billing records | Legal obligation (Art. 6(1)(c)) |
Under Colombian law, your authorisation for processing is given when you create an account and accept this policy, in line with Article 9 of Ley 1581 de 2012. You can withdraw it at any time by deleting your account, subject to the retention periods in section 8.
6. Who we share data with
We use a small number of providers to run the service. They process data on our instructions and only for the purpose listed.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare | Hosting the web front end, CDN, DDoS protection | IP address, request metadata |
| Lemon Squeezy | Payments and subscriptions, acting as merchant of record | Email, billing and card details collected directly by them |
| PostHog | Product analytics (US cloud region) | Product events, user identifier, device, approximate location |
| Google Sign-In, where you choose to use it | Google account identifier, email, name, profile picture | |
| Anthropic / OpenAI | AI test generation, planning and self-healing | Flow structure and page context sent to generate a suggestion |
Card details. Payments are handled by Lemon Squeezy as merchant of record. You enter your card on their checkout, not ours. We receive only the outcome — plan, status, renewal date — and never see your card number.
AI features. When you use an AI agent, the relevant flow structure and page context are sent to the model provider to produce a suggestion. If you supply your own API key, the request runs against your own account with that provider and is governed by your agreement with them. Avoid putting secrets or real personal data into prompts.
We may also disclose data where we are legally required to, or to protect our rights, but we will not hand over your data on an informal request.
7. International transfers
Flow Testing is operated from Colombia, which the European Commission has not issued an adequacy decision for, and our providers operate in several countries — PostHog in the United States, and others in the United States and the European Union. Your data will therefore be transferred outside your own country, including outside the EEA.
For transfers of EEA or UK personal data we rely on the Standard Contractual Clauses in our agreements with these providers, together with the safeguards they publish. For transfers out of Colombia we rely on your authorisation and on contractual guarantees as contemplated by Article 26 of Ley 1581 de 2012. You can ask us at [email protected] which safeguard applies to a specific provider.
We are in the process of documenting the exact hosting region for the API and for run-artifact storage. If the region matters for your compliance assessment, email us before you sign up and we will confirm it in writing rather than have you rely on a guess.
8. How long we keep it
- Run artifacts — traces, screenshots, video and logs are retained for 30 days from the run, then deleted. You can delete a run earlier yourself.
- Account and test content — kept while your account is open. On deletion, flows, projects, secrets and stored API keys are removed.
- Secrets and BYOK API keys — deleted when you delete the secret, or when the account is deleted.
- Billing records — retained as long as commercial and tax law requires, which can be several years after your account closes, even though the account itself is gone.
- Analytics events — retained on PostHog's standard retention schedule for our plan.
- Security logs — short-lived, generally weeks rather than months.
9. Your rights
Under the GDPR you have the right to access your data, correct it, have it deleted, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing relies on consent.
Under Ley 1581 de 2012 you have the right to know, update and correct your data, to ask for proof of the authorisation you gave, to be informed on request how your data has been used, to file a complaint with the SIC, and to ask for deletion where processing does not respect the law.
Email [email protected] to exercise any of these. We respond to a request to consult your data (consulta) within 10 business days and to a complaint or correction request (reclamo) within 15 business days, as Decreto 1377 de 2013 requires; where the GDPR's one-month deadline is shorter in a given case, we meet that instead. If we need to extend a deadline, we will tell you why before it expires.
If you are unhappy with how we handled your request you can complain to the SIC in Colombia, or to your national data protection authority if you are in the EEA or UK. We would rather you came to us first, but that route is yours regardless.
10. How we protect it
- All traffic is served over HTTPS.
- Passwords are stored as one-way hashes, never in a recoverable form.
- Vault secrets and BYOK API keys are encrypted at rest and write-only through the API. This is encryption at rest, not end-to-end encryption: we necessarily decrypt a secret in order to use it in a run, and the value then appears in that run's artifacts as described in section 3.
- Access to production data is limited to the operator and used only to run and repair the service.
No service can promise perfect security. If a breach affects your personal data we will notify you and the relevant authority without undue delay, and within 72 hours of becoming aware of it where the GDPR requires.
11. Your own responsibilities
When you test an application that holds other people's personal data, you are the controller of that data and we act as your processor. Practically, that means:
- Test against staging or seeded data wherever you can. Pointing a flow at production means real personal data ends up in run artifacts.
- Use dedicated, low-privilege test accounts created for testing — never real user or administrator credentials. Any credential a flow signs in with is readable by anyone who can open that run's artifacts.
- Use the secrets vault rather than typing credentials directly into a node. This keeps them out of your flow definition and out of anything you export or share, though not out of run artifacts.
- Delete a run you no longer need rather than waiting out the 30-day retention period, and rotate any credential you believe has been over-exposed.
- Only test systems you own or have written authorisation to test. This is also a condition of the Terms of Service.
- If you need a data processing agreement before using Flow Testing for this kind of data, email us and we will put one in place.
12. Cookies
We use a session cookie to keep you signed in, which the service cannot work without. PostHog sets its own cookies to recognise a returning user across sessions. We set no advertising or cross-site tracking cookies. You can block cookies in your browser, but the authenticated part of the app will not function without the session cookie.
13. Children
Flow Testing is a professional tool and is not directed at children. You must be at least 16 to create an account. If you believe a child has given us personal data, email us and we will delete it.
14. Changes to this policy
We will update this policy as the product changes. The date at the top always reflects the current version. If a change materially affects your rights or how we use your data, we will email you before it takes effect rather than change the page quietly.
15. Contact
Privacy questions, requests and complaints: [email protected]. A real person reads it.