Legal · 02

Privacy Policy

What OpFlow collects, why, who helps us run it, and what you can ask of us. Opscend LLC is the company behind OpFlow.

Effective October 4, 2026Opscend LLC · Chicago, IllinoisQuestions · [email protected]
The short version
  • We collect what it takes to run your workspace: your account, the workflows you build, the data that moves through runs, and your billing status.
  • Your workspace data is yours. We process it for you. We do not sell it and we do not use it for advertising.
  • We do not use your workspace content to train AI models.
  • The keys and tokens for your connected apps are encrypted at rest.
  • A short list of providers helps us run OpFlow. They are named below.
  • Ask for your data, a correction or deletion any time: [email protected].

01Who we are

OpFlow is provided by Opscend LLC, an Illinois limited liability company based in Chicago (Opscend, we, us). This policy covers flow.opscend.net, the OpFlow app, its API and MCP server, and the site assistant. It works together with our Terms of Service.

There are two roles. For your account and billing details we decide why and how they are used. For the data in your workspace, which can include personal data about your own customers and contacts, you decide, and we process it on your behalf as your service provider.

02What we collect

AccountName, email, sign-in details (a password is stored as a hash, never readable), the business name you enter, and your role in a workspace.
Waitlist and requestsName, email, the plan you were interested in, and an optional note.
Workspace contentWorkflows, agents, folders, schedules, webhook addresses, and run history including each step's input and output.
Connected-app credentialsThe API keys and sign-in tokens you provide for connected apps. Stored encrypted.
BillingPlan, subscription status, invoice references and the Stripe customer ID. Card details go to Stripe. We never see or store a full card number.
Assistant and AIWhat you type to the assistant, the agent builder and AI steps, and the replies. For visitors who chat with the site assistant: the conversation and any email they leave.
Problem reportsYour description, the page address, browser and window size, and an optional screenshot. Only the OpFlow team can read them, and you.
TechnicalIP address, browser and device type, request and error logs, and an audit trail of administrative actions in a workspace.

03How we use it

  • Run OpFlow for you: sign you in, run your workflows and show their history.
  • Bill you and handle plan limits, including the emails at 80 % and 100 % of your run limit.
  • Keep the Service secure and stop abuse, including rate limits on the site assistant.
  • Answer your questions and fix problems you report.
  • Understand how OpFlow is doing, using counts and errors rather than the contents of your data.
  • Meet legal duties.

We do not sell personal information, we do not share it for advertising, and OpFlow has no advertising or third-party analytics scripts.

04Who helps us run OpFlow

These providers handle data for us, only to provide their service:

SupabaseDatabase, sign-in and file storage. Hosted in the United States (us-west-1).
CloudflareHosting, edge computing and our network.
StripePayments, subscriptions and invoices.
AnthropicAI model provider for the assistant, the agent builder and agents.
Lovable AI gatewayRoutes AI requests to model providers when an AI step uses the built-in model.
Google WorkspaceSends our own emails to you, such as invitations and plan notices.
The apps you connectWhen you connect Gmail, Notion, Podio or any other app, OpFlow sends and receives data there at your direction. If you give an AI step your own provider key, that provider receives its prompts.

We may also disclose information when the law requires it, to protect people or the Service, or in a sale of the business, in which case we tell you first.

05Data from connected apps

OpFlow reads and writes data in the apps you connect only to run the workflows you build and the tests you start. We do not use it for advertising and we do not sell it.

OpFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

06AI features

When you use the assistant, the agent builder, an agent or an AI step, the prompt and the data you pass in go to an AI provider so it can reply. Providers are listed above. We do not use your workspace content to train AI models, and our providers act on our instructions under their business terms. Do not put anything into an AI step you are not allowed to share with a provider.

07Cookies and local storage

OpFlow keeps your sign-in session, your theme choice and, while you sign up, the plan you picked in your browser's storage. It does not use advertising cookies or third-party trackers. Our pages load the Inter typeface from Google Fonts, which means Google receives your IP address when a page loads. We do not respond to Do Not Track signals because we do not track you across sites.

08How long we keep it

  • Account and workspace data: while your account is open, and for up to 30 days after you close it, then we delete it. Backups age out on the provider's schedule.
  • Run history: your plan sets how much history the app shows you.
  • Billing records: as long as tax and accounting law require.
  • Logs: for a limited period, for security and debugging.
  • Problem reports: until we have dealt with them, then as long as they are useful for improving OpFlow.

On request, we delete your account data sooner. Write to [email protected].

09Security

Your connection to OpFlow is encrypted in transit. Credentials for connected apps are encrypted at rest with AES-256-GCM, with the key held outside the database. Workspaces are separated by database row-level security, so one organization cannot read another's data. Access inside Opscend is limited to the people who need it. No system is perfectly secure. If a breach affects you, we tell you as the law requires.

10Your choices and rights

You can ask us to give you a copy of your personal information, correct it, delete it, limit or stop certain uses, or move it to another service. For the personal data inside a workspace, we pass your request to the workspace owner when they are the one who controls it. Write to [email protected]. We answer within 45 days.

We do not discriminate against you for using these rights. You can also complain to your data protection authority.

11California and other US states

In the last 12 months we collected the categories listed above, which include identifiers, account and billing information, internet activity such as logs, and content you provide. We use and share them as described in this policy. We do not sell personal information and we do not share it for cross-context behavioral advertising. Residents of California and other states with privacy laws have the rights above, and may use an authorized agent to make a request.

12Outside the United States

OpFlow is run from the United States and your data is processed there. If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on the contract with you, our legitimate interests in running and securing the Service, and legal obligations. Where data is transferred, we use the transfer tools the law accepts, such as standard contractual clauses. A data processing addendum is available on request.

13Children

OpFlow is a business tool for people 18 and older. We do not knowingly collect information from children. If you think we have, write to [email protected] and we will delete it.

14Changes to this policy

When we change this policy we update the date at the top. For a material change we tell you by email or in the app before it takes effect.

15Contact

Opscend LLC, Chicago, Illinois. Privacy requests: [email protected]. Everything else: [email protected].

Ask Oppa