Privacy Policy
Last updated 10 August 2026
FlowDocs extracts structured data from documents you upload. That means we handle your files and what we read out of them. This page explains exactly what we collect, where it goes — including the third-party AI services your documents pass through — how long we keep it, and how to get it back or delete it.
What we collect
We hold four kinds of data:
Account information. Your email address, your name if you provide one, and which workspaces you belong to and with what role. Authentication is handled by Supabase Auth.
Documents you upload. The file itself and its original filename. Files may be up to 25 MB and 300 pages.
Extracted data. The field values our pipeline reads out of your documents, the field templates you define, detected headings, and any exports you generate.
Operational records. Usage counts, rate-limit events, and administrative audit entries — used to enforce plan limits, keep the service available, and investigate problems.
If you send us a message through our contact form, we keep that message and any file you attach to it so we can reply.
How your documents are processed
This is the section most worth reading. Processing a document can involve sending it to third-party AI services, and what gets sent depends on the document.
Text-based PDFs are parsed on our own infrastructure. If we can read the text directly out of the PDF, that text is never sent to an OCR provider.
Scanned PDFs and images are sent to Mistral AI for OCR. When a PDF yields almost no readable text, or when you upload an image, the file itself is transmitted to Mistral’s OCR service so the text can be recovered.
Field extraction is performed by OpenAI. Once we have the document’s text, that text — up to roughly 80,000 characters per document — is sent to OpenAI along with the field names you asked for. The original file is not sent to OpenAI; the text read from it is.
Mistral and OpenAI are independent companies and process this data under their own terms and privacy policies, which govern their own retention and use of what they receive. We do not control those practices, and we make no representation here about whether they retain your content or use it to train models — please read their policies directly if that matters to you.
Where your data is stored
Documents, extracted data and account records are stored with Supabase (PostgreSQL database, object storage and authentication), hosted in the Asia Pacific (Singapore) region.
The application is hosted on Vercel, which serves it from a global network; requests may be routed through infrastructure outside your country.
Data is transmitted over TLS.
Email and inbound documents
Transactional email — sign-in links, notifications and similar — is sent through Resend.
Notification emails deliberately do not contain your extracted values. They tell you that an extraction finished and link you back into FlowDocs, where you must be signed in to see the data. That keeps your documents’ contents out of your inbox and out of email delivery logs.
Where document-by-email is enabled, inbound mail is routed through Cloudflare before reaching our pipeline.
Sending your data somewhere else
If you configure a webhook, we send your extraction results to the URL you specify, signed so your server can verify they came from us. Once delivered, that data is in your systems and this policy no longer governs it.
If you connect a Google account to write results into Google Sheets, we request only the drive.file scope. That scope limits us to files our application creates or that you explicitly select for us. We use it solely to create a spreadsheet and append your extraction results to it. We do not read, list, modify or delete any other file in your Google Drive, and we do not use Google user data for advertising, for training AI models, or for any purpose other than delivering your results to the sheet you asked for. We do not sell Google user data or transfer it to third parties except as needed to provide this feature. You can disconnect the Google account at any time from your automation settings, which revokes our access. FlowDocs’ use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How long we keep things
Deleting a document moves it to Trash, where you can restore it. Items in Trash are permanently purged after 60 days. You can also delete permanently at any time, which removes the stored file and its extracted records.
Account and workspace records are kept while your account is open. Operational records such as usage counts and audit entries are kept for service integrity and may outlive an individual document.
Your choices
Export. You can export extracted data as CSV from the application at any time.
Delete. You can delete individual documents and their extracted data from the application. To delete your account and everything in it, contact us and we will action it.
Access and correction. Contact us and we will tell you what we hold about you, or correct it.
Note that deleting data from FlowDocs does not by itself remove copies that a third-party processor may hold under its own retention policy, or data already delivered to a webhook or spreadsheet you configured.
Security
Access to your workspace’s data is enforced in the database itself, so one workspace cannot read another’s. API keys are stored hashed and shown to you only once at creation. Webhook payloads are signed, and webhook destinations are validated to prevent them being pointed at internal infrastructure.
No system is perfectly secure. If you believe you have found a vulnerability, please contact us.
Children
FlowDocs is a business product and is not directed at children.
Changes
If we change how we handle your data — particularly if we add or change a processor that receives your documents — we will update this page and its date.
Contact
Questions about this policy, or a request about your data, can be sent through our contact form.