AutoFlow Pro / Auto Flow Privacy Policy
This policy covers the AutoFlow Pro and Auto Flow Chrome extensions distributed by the ergophobian Chrome Web Store publisher (collectively, “Auto Flow,” “we,” “our,” or “us”). It explains the data the extension accesses, where processing occurs, why data is used, and the choices available to users.
1. Auto Flow’s Single Purpose
Auto Flow helps a user organize, run, monitor, reconcile, and download user-directed image and video generation workflows in Google Flow from a Chrome side panel. Related authentication, licensing, reliability, gallery, Agent Mode, and user-enabled local bridge functions exist only to support that purpose.
2. Data the Extension Handles
The extension handles only data reasonably necessary for features the user chooses to use:
- Personally identifiable information: the email address entered for OTP sign-in.
- Authentication information: one-time verification codes while entered, and Supabase access/refresh tokens stored in extension storage to keep the user signed in. We do not receive the reviewer mailbox password or the user’s Google password.
- Financial and subscription information: product, plan, license status, Stripe customer/subscription/price identifiers, subscription period dates, cancellation state, and billing-portal state. Payment-card details are entered directly with Stripe and are not received or stored by Auto Flow.
- Website content and workflow data: prompts, reference images selected by the user, generated images/videos, media URLs, project identifiers, task settings, model/mode choices, status data, and download/file-naming metadata.
- Personal communications: chat-style prompts, instructions, and responses processed when the user chooses Agent Mode or another conversational Google Flow feature.
- Limited web-page information: URLs, titles, tab IDs, and project IDs for supported Google Flow pages. Auto Flow does not build or sell a general browsing-history profile and does not inspect unrelated sites.
- User activity and diagnostics: user-requested queue actions, prompt counts, task ID, mode, submit path, source, idempotency key, timestamps, bounded operational logs, download status, and a one-way device fingerprint derived from extension/browser characteristics for entitlement enforcement, abuse prevention, and reliability.
- Local extension configuration: settings, queue/task state, project bindings, cached reference metadata and blobs, gallery/download records, and user-enabled bridge settings.
Auto Flow does not intentionally collect health information, precise geolocation, contacts, or unrelated browsing history. Normal internet requests expose network metadata such as an IP address to the receiving service; Auto Flow does not use that metadata to infer or track precise location.
3. Where Processing Occurs
On the user’s device
- Settings, queues, cached references, task state, project bindings, logs, and download records are primarily stored in Chrome extension storage or IndexedDB.
- The extension reads and changes supported Google Flow page content only after the user accepts the in-product privacy notice and invokes or enables the relevant workflow.
- User-enabled CLI, MCP, PatchWork, WebSocket, or native-messaging connections operate through approved pages or local loopback services and require their own pairing/approval controls.
External services
- Google Flow / Google: receives prompts, references, Agent messages, project actions, and media requests the user directs to Google Flow. Google controls Google accounts, models, quotas, safety systems, generated content, and its own retention.
- Supabase: provides OTP authentication, session management, licensing, account records, bounded product-usage enforcement, and backend database/functions.
- Stripe: provides checkout, subscription lifecycle, fraud controls, receipts, and the Customer Portal. Auto Flow receives subscription and entitlement metadata, not full card details.
- Resend: delivers OTP and necessary transactional account/service-continuity messages. Email addresses are not provided for third-party advertising.
- Cloudflare R2: serves declared product/static assets. User reference images and generated media are not uploaded to this asset bucket by the extension.
- GitHub Pages: hosts the Auto Flow website and this policy; ordinary website request logs may be processed under GitHub’s policies.
These providers receive only data reasonably necessary for their function. Their independent services are also governed by their own terms and privacy policies.
4. How Data Is Used
- Perform user-directed Google Flow automation, queueing, monitoring, reconciliation, and downloads.
- Authenticate users and restore the correct free, paid, or manual entitlement.
- Provide checkout, subscription management, cancellation, receipts, and service-continuity notices.
- Persist settings and recover user-directed workflows.
- Prevent duplicate submissions, enforce product limits, detect abuse, diagnose failures, and maintain security and reliability.
- Respond to support, privacy, security, or legal requests.
5. Prohibited Uses and Transfers
Auto Flow does not:
- sell, rent, license, or exchange user data for value;
- transfer user data to data brokers, information resellers, or advertising networks;
- use or transfer user data for personalized, retargeted, or interest-based advertising;
- use or transfer user data for purposes unrelated to Auto Flow’s disclosed single purpose; or
- use or transfer user data to determine creditworthiness, credit eligibility, insurance eligibility, or for lending purposes.
Data may be transferred only to provide the user-requested functionality described above, to service providers acting for that functionality, to protect against fraud or security threats, when required by law, or as otherwise permitted by the Chrome Web Store User Data Policy with any required consent.
6. Human Access
We do not permit humans to read user workflow content except when the user gives explicit consent for support, when access is necessary to investigate abuse or a security incident, when required by law, or when the data has been aggregated and anonymized for permitted internal reliability operations. Users should remove sensitive information before voluntarily sharing diagnostics with support.
7. Chrome Permissions
sidePanel: displays the product interface.tabs,scripting, and supported host permissions: find and operate only supported Google Flow tabs and user-approved PatchWork/local integrations.cookiesandbrowsingData: perform explicit Google Flow session-maintenance/recovery actions; not inspect or erase unrelated browsing history.storageandunlimitedStorage: retain settings, queue state, references, and long-running project records locally.alarms: refresh authentication and supervise user-started work while the service worker sleeps.downloads: save and validate media the user requests.debugger: temporarily attach to the selected Google Flow tab for bounded structural automation and request/acceptance proof, then detach.nativeMessaging: provide an optional, user-enabled legacy local bridge. The normal local bridge uses loopback WebSocket transport.
8. Consent and User Choices
- On first use, Auto Flow displays a prominent notice describing handled data and external services. The extension remains inactive unless the user selects Agree and continue.
- Selecting Decline leaves workflow access, authentication, licensing, and bridge processing disabled.
- Users can avoid account-linked features by not signing in, disable optional bridge integrations, clear extension storage/IndexedDB and download records, or uninstall the extension.
- If data practices materially change, Auto Flow will update this notice and request consent again before the changed handling begins.
9. Email Communications
We may send OTP codes, security notices, receipts, subscription/license notices, support replies, and material service-continuity or privacy-policy updates. These are transactional messages needed to operate the account or service. We do not send promotional marketing email without any consent required by applicable law, and opting out of marketing does not block necessary authentication, billing, security, or service messages.
10. Retention and Deletion
- Local data: remains until the user clears extension data, removes individual records through available controls, or uninstalls the extension.
- Authentication sessions: remain until expiration, sign-out, revocation, or deletion.
- Account, license, subscription, and usage-enforcement records: remain while needed to provide access and are then retained only as reasonably necessary for billing records, fraud/abuse prevention, dispute resolution, security, and legal obligations.
- Operational diagnostics: are retained only as long as reasonably necessary to investigate reliability or security and are minimized where practical.
- Provider records: Google, Supabase, Stripe, Resend, Cloudflare, and GitHub apply their own retention obligations to data they process.
To request access, correction, or deletion of backend account data, email partnerships@somnicoremedia.com with “Auto Flow Privacy” in the subject. We may need to verify the request and may retain records where legally required.
11. Security
External service traffic uses HTTPS/WSS or equivalent modern encrypted transport. Local bridge traffic is limited to loopback interfaces and protected by origin, pairing, registration, and capability checks. Authentication tokens are stored in extension storage and are not intentionally exposed to web pages. Payment-card information is handled by Stripe. Access to backend systems is restricted. No internet or storage system can be guaranteed 100% secure.
12. Children
Auto Flow is not directed to children under 13, and we do not knowingly collect personal data from children under 13.
13. Changes to This Policy
We may update this policy to reflect product, legal, or security changes. The effective date will be updated here. Material changes to extension data practices will also be disclosed in the product, and fresh consent will be requested before new handling begins when required.
14. Contact
Privacy requests: partnerships@somnicoremedia.com
Product and support information: https://ergophobia.info/autoflow/faq.html