Privacy

Dated 6 September 2026. This page describes current handling on usefulflows.com.

Public pages

Public pages present the studio, tools, and legal text. UsefulFlows does not sell personal data or use advertising pixels. Public Traffic adds one to daily totals for the page path, tool if any, referring site host (not the full URL), UTC hour, and — when the host sends a two-letter country code with the request — that country. A hashed session id is kept only until UTC midnight so a session is counted once, then deleted. IP addresses, query strings, cities, coordinates, and form fields are not stored. A short-lived in-memory count of recent country codes (about five minutes) exists only on the serving process for the owner dashboard and is not written to the database. Day totals older than 90 days are deleted.

Enquiries

The contact form stores name, email, optional organisation and service focus, and the outcome you describe. You acknowledge a 90-day retention period on the form. Submissions land in the owner enquiry inbox and are deleted after 90 days. An enquiry starts a conversation. It is not a quote.

Browser-local tools

Most catalogue tools keep input in the browser. They are not uploaded, stored by UsefulFlows, or sent to AI. Opening a tool page may add one to Traffic totals; the text or files you paste are not part of those totals.

Public Trust Check

This page is an exception. Traffic logging is off. The HaGeZi TIF Mini threat list is downloaded directly from GitHub and searched in your browser. GitHub receives your IP address but not the domain you are checking. The feed is not processed or stored by a UsefulFlows backend.

When you select Check, your browser sends the hostname to Cloudflare DNS and the registration domain to RDAP.org and its referred registry. Those providers see your IP address. The URL path, query and fragment stay in this page; no target site is visited. Results and checklist entries are held in memory and clear on refresh. Reputation-source links open only when you select them.

Sign-in and Workspace

Workspace is invitation-only. Continue with Google is the federated sign-in on the live site. Invited people may also create a UsefulFlows password stored on this site; that password is not a Gmail password. Signing in at an email that has not been invited does not grant access. A signed-in session uses an HttpOnly cookie on usefulflows.com. The identity record stores a UsefulFlows user id, name, and email. Google passwords are not stored here. If you create a UsefulFlows password, it is stored hashed. Workspace may also hold monitoring sources you add (a name and a public URL, plus check hashes), membership emails with first sign-in and last Workspace activity for the owner, and member tool records such as a handoff pack you choose to keep.

Providers

Hosting and the database run this site. Google is used only as a sign-in provider for invited people. The contact form does not send mail; it writes to the enquiry inbox. Webmaster and sales addresses on the site are ordinary mailto links.

Security and choices

Transmission and storage have ordinary limits. You may contact webmaster@usefulflows.com about access, correction, or deletion requests. Changes to this page will update the date above.

Contact · Home