flowchart.chat

Privacy

What flowchart.chat collects, why, who else handles it, and how long it stays. It describes what the product does today.

Updated 8 October 2026

Who runs flowchart.chat

flowchart.chat is made by Tone Row, the company of Rob Gordon. For any question about your data, or to ask for something the account menu doesn't do, email rob@flowchart.chat.

The short version

What we collect, and why

Your documents

Without an account, the editor keeps your document in your browser's local storage. Our server gets it only when you save it to an account, publish it, or ask for an AI edit. When you're signed in, new documents go into your account and your edits save to our server as you type. Session replay also records it, as described under Analytics and session replay. A share link carries the whole document inside the link, so anyone you send it to can read it.

Your account

Payments

Stripe runs checkout and the billing page. When a payment is due, Stripe collects your card and billing details, and we never see your card number. When nothing is due, such as with a free invite, Stripe doesn't ask for a card, but it still asks for your name and address for tax. Stripe is the merchant of record, so it handles tax and sends the invoices. When you're signed in, we give Stripe your account email and our IDs for you and the workspace. With an invite, we also send the invite code and the hash of your email address described under How long we keep it. We store Stripe's IDs for your customer record and subscription, the plan, its status, and its renewal and cancel dates. After a checkout without an account, we also store the email you gave Stripe and use it to attach the plan to your account.

AI edits

When you ask for an AI edit, we send your instruction to Anthropic, which runs the Claude model that writes the edit. With it goes your document's text when you edit, or the text you paste when you convert. We don't store the text or the answer. To cap use, we count AI requests per day for each IP address (for IPv6, each network prefix).

Walking a published guide

When you walk through a guide, the page records the walk: a random ID, the steps you choose, and when you chose them. It doesn't record anything you type. On the Team plan, members of the guide's workspace can see how many walks reached and ended at each step of each version. They can't see single walks. Your browser keeps your place in local storage so you can pick up where you left off.

Early access to the call copilot

The early-access form emails your address to rob@flowchart.chat. We don't store it in our database, and we only email you about the copilot.

Bot checks and rate limits

The sign-in and early-access forms use Cloudflare Turnstile, which sends your IP address and signals from your browser to Cloudflare to tell people from bots. Cloudflare also counts requests per IP address (for IPv6, per network), or per account for export and delete, for a minute at a time, to slow down abuse. We don't keep those counts.

Analytics and session replay

We use PostHog to learn how people use the editor and guides. PostHog's script and data go through flowchart.chat/ingest, an address on our own site. Before our server passes a request on to PostHog, it removes your cookies and sign-in headers. With data, it passes on your IP address and your browser's other request headers, but it replaces the Origin and Referer headers with flowchart.chat's own address. When it fetches PostHog's script, it sends none of your browser's headers. PostHog uses the IP address to estimate your location and stores it with each event.

PostHog keeps replays for 90 days. It keeps events with no end date, for as long as our PostHog plan allows. Deleting your account doesn't delete PostHog data. To have it deleted, email rob@flowchart.chat.

Who else handles your data

Cookies and browser storage

We don't use advertising cookies.

How long we keep it

Account, workspaces, documents and guides
Until you delete them or the account. Deleting a document in the Library takes down the guide published from it. The guide's link and every version's link then say its author took it down. We keep that guide's versions and walks with the workspace until the workspace is deleted. The versions stay in your export, and the walks aren't in it.
Sign-in link records
At least a day. Each new sign-in request clears records more than a day old.
Sessions
As long as the session cookie lasts. Ended sessions are cleared out at a later sign-in.
An unpaid checkout
Once the workspace made for it is 7 days old, the next checkout without an account removes it.
Daily AI request counts
We don't delete these on a schedule yet.
Guide walks
Until the guide's workspace is deleted.
Payments
Stripe keeps your customer record, with your email, and your invoices and payment records after you delete your account, as the merchant of record.
Analytics and replays
Replays for 90 days. Events with no end date, for as long as our PostHog plan allows.
Invite redemptions
When a checkout with a free invite completes, we record the invite code, the time, and a SHA-256 hash of your account's email address. Before hashing, we lowercase the address and drop any + part, and for Gmail and Googlemail addresses we also drop the dots. We use the record to refuse the invite to the same inbox again, even from a new account. Deleting your account doesn't remove the record, and it has no end date yet. The hash doesn't hold the address itself. It isn't salted, so anyone holding it can check whether a known address used the invite. We also send the code and the hash to Stripe with the checkout, and Stripe keeps them with its record of that checkout.
Early-access emails
In our inbox until we delete them.

Export or delete your account

Sign in and open the account menu, the button with your email at the top right.

Published guides are public

When you publish a guide, anyone with its link can open it, and every earlier version stays at its own link, until you delete its document or your account. For now, a copy cached in another Cloudflare data center, or in the browser of someone who opened it, can keep showing the guide after that: the main link for up to a minute, and a version's own link for as long as a year. Guide pages ask search engines not to index them, unless we choose to feature a guide. Then we list it in our sitemap and tell search engines about it.

Children

flowchart.chat isn't meant for children under 13, and we don't knowingly collect their data.

Changes to this page

When this page changes, we change the date at the top.