Privacy Policy

Our privacy policy and how we use your data

Effective date: April 30, 2026

This Privacy Policy explains what personal information FlowDiff (“FlowDiff,” “we,” “us”) collects when you use our website and service (the “Service”), how we use that information, who we share it with, and the choices you have. FlowDiff is operated by [Your Company Name].

1. Information We Collect

Account information

When you sign up, we collect your email address and an authentication identifier issued by our auth provider. If you sign in with a third-party identity provider, we receive a unique identifier and basic profile information from that provider in accordance with the permissions you grant.

Billing information

If you subscribe to a paid plan, our payment processor (Stripe) collects your payment card details, billing address, and transaction history directly. FlowDiff stores a customer identifier and subscription status returned by Stripe; we do not store full card numbers or CVCs.

Service content

To run a comparison, you submit URLs (typically a staging and a production URL). We store those URLs, the metadata you assign to them (such as a website name or route label), and the outputs of each comparison: full-page screenshots, a pixel-difference image, the count and coordinates of changed regions, and capture dimensions. Whatever is publicly visible on the URLs you submit will be captured into screenshots stored against your account.

Usage data

We record how many comparisons you run within each billing period to enforce plan quotas. We also collect technical logs from server requests (IP address, user-agent, timestamps, error traces) to operate, secure, and debug the Service.

Cookies

We use cookies and similar local-storage technologies for authentication, session management, locale preference, and fraud prevention. See our Cookie Policy for details.

2. How We Use Information

  • To provide, operate, and maintain the Service.
  • To process subscriptions, billing, and provide customer support.
  • To enforce comparison quotas, plan limits, and other usage rules.
  • To detect, investigate, and prevent abuse, fraud, or violations of our Terms.
  • To improve the Service, debug issues, and develop new features.
  • To send transactional emails (account, billing, security) and, if you have opted in, product updates.
  • To comply with legal obligations and respond to lawful requests from authorities.

4. How We Share Information

We do not sell your personal information. We share it only with the following categories of recipients, and only as necessary to operate the Service:

  • Supabase — authentication and database hosting.
  • Cloudflare — object storage (R2) for screenshots and diff images, and content delivery.
  • Screenshot capture provider — a third-party service we use to render the URLs you submit and return full-page screenshots. Only the URLs and capture parameters are sent; no account information is shared.
  • Stripe — payment processing and subscription management.
  • Email service providers — for authentication, transactional, and (if applicable) product emails.
  • Hosting and infrastructure providers — for application hosting, logs, and error monitoring.
  • Professional advisors and authorities — where reasonably required for legal, accounting, or compliance purposes, or in connection with a corporate transaction (e.g. merger, acquisition, or sale of assets).

5. Data Retention

We retain account information for as long as your account is active. Comparison results, including screenshot and diff images, are retained according to your subscription plan (typically up to thirty days for older comparisons), or until you delete the underlying website or comparison from your account. Billing records are retained as required by tax and accounting law. Logs are retained for a limited period for security and debugging.

When you delete your account, we delete or anonymize your personal information within a reasonable period, except where we are required by law to retain it.

6. International Transfers

FlowDiff and our service providers may process your information in countries outside your country of residence, including the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for transfers of personal data out of the EEA, UK, or Switzerland.

7. Security

We use industry-standard administrative, technical, and physical safeguards to protect your information, including encryption in transit, scoped database row-level security, least-privilege access for our team, and authentication hardening. No system is perfectly secure, however; if you believe your account has been compromised, contact us immediately.

8. Your Rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal information; to object to or restrict certain processing; and to withdraw consent. To exercise these rights, email us at hello@flowdiff.app. We will respond within the timeframe required by applicable law. You may also lodge a complaint with your local data protection authority.

9. Children

The Service is not directed to children under the age of 13 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.

10. Third-Party Sites

The screenshots stored on your behalf are captured from URLs you provide. The content of those pages is governed by the privacy policies of the sites that publish them, not by FlowDiff. You are responsible for ensuring that you have the right to capture screenshots of any URL you submit.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the effective date above. If the changes are material, we will notify you by email or through the Service.

12. Contact

For privacy questions or to exercise your rights, contact us at hello@flowdiff.app.