Privacy
What flowchart.chat collects, why, who else handles it, and how long it stays. It describes what the product does today.
Updated 8 October 2026
Who runs flowchart.chat
flowchart.chat is made by Tone Row, the company of Rob Gordon. For any question about your data, or to ask for something the account menu doesn't do, email rob@flowchart.chat.
The short version
- You can use the editor without an account. We measure use of the editor and of published guides with PostHog, and we record sessions there, including your document's text. Replay leaves out the account area and the Upgrade and Welcome screens, and doesn't record visitors in the EU, the rest of the EEA, the UK or Switzerland.
- If your browser sends Do Not Track or Global Privacy Control, our pages never load PostHog.
- An account needs only your email address. Payments go through Stripe, and we never see your card.
- Published guides are public to anyone with the link.
- Once you've signed in with the emailed link, you can export your data or delete your account from the account menu.
- We don't sell your data, and we don't show ads.
What we collect, and why
Your documents
Without an account, the editor keeps your document in your browser's local storage. Our server gets it only when you save it to an account, publish it, or ask for an AI edit. When you're signed in, new documents go into your account and your edits save to our server as you type. Session replay also records it, as described under Analytics and session replay. A share link carries the whole document inside the link, so anyone you send it to can read it.
Your account
- Email address. We use it to send sign-in links and to name your account.
- Sign-in requests. When you ask for a link, we store your email, a hash of the link, the page to return to, and your IP address. For an IPv6 address, we store only its network prefix. This lets us limit how many links one address or one network can ask for.
- Your session. Your browser holds a random secret in a cookie. We store only a hash of it.
- Workspaces, documents and guides. We store the documents you save and the guides you publish, in the workspace you save them to.
Payments
Stripe runs checkout and the billing page. When a payment is due, Stripe collects your card and billing details, and we never see your card number. When nothing is due, such as with a free invite, Stripe doesn't ask for a card, but it still asks for your name and address for tax. Stripe is the merchant of record, so it handles tax and sends the invoices. When you're signed in, we give Stripe your account email and our IDs for you and the workspace. With an invite, we also send the invite code and the hash of your email address described under How long we keep it. We store Stripe's IDs for your customer record and subscription, the plan, its status, and its renewal and cancel dates. After a checkout without an account, we also store the email you gave Stripe and use it to attach the plan to your account.
AI edits
When you ask for an AI edit, we send your instruction to Anthropic, which runs the Claude model that writes the edit. With it goes your document's text when you edit, or the text you paste when you convert. We don't store the text or the answer. To cap use, we count AI requests per day for each IP address (for IPv6, each network prefix).
Walking a published guide
When you walk through a guide, the page records the walk: a random ID, the steps you choose, and when you chose them. It doesn't record anything you type. On the Team plan, members of the guide's workspace can see how many walks reached and ended at each step of each version. They can't see single walks. Your browser keeps your place in local storage so you can pick up where you left off.
Early access to the call copilot
The early-access form emails your address to rob@flowchart.chat. We don't store it in our database, and we only email you about the copilot.
Bot checks and rate limits
The sign-in and early-access forms use Cloudflare Turnstile, which sends your IP address and signals from your browser to Cloudflare to tell people from bots. Cloudflare also counts requests per IP address (for IPv6, per network), or per account for export and delete, for a minute at a time, to slow down abuse. We don't keep those counts.
Analytics and session replay
We use PostHog to learn how people use the editor and guides. PostHog's script and data go through flowchart.chat/ingest, an address on our own site. Before our server passes a request on to PostHog, it removes your cookies and sign-in headers. With data, it passes on your IP address and your browser's other request headers, but it replaces the Origin and Referer headers with flowchart.chat's own address. When it fetches PostHog's script, it sends none of your browser's headers. PostHog uses the IP address to estimate your location and stores it with each event.
- Every event carries the page's address and title, the page you came from, your browser, operating system, device type, screen size, language and time zone, and random IDs for your browser and your visit. Before an event leaves your browser, we remove the part of an address after
#, so a share link's document never reaches PostHog in an event. We also remove two values from the address: the sign-in link'stokenand the Stripe checkout reference,session_id. Everything else in the address stays, such as an invite code or campaign tags. Replay removes the same parts from the addresses it records. If you open a share link, replay records the document like any other. - In the editor, PostHog records page views and leaves, and a few actions: creating a document, importing a flowchart.fun chart, publishing a guide, and copying or opening its link. Publish and link events name the guide by its link, which comes from your document's title, and publish events add the version. No event carries your email address or your document's text.
- When you sign in, PostHog ties your events to your account's user ID, never your email, including earlier events from the same browser. It also stores the IDs of your workspaces, and groups events under the open workspace with its type and plan. When the editor finds you signed out, PostHog in this browser drops your user ID and its browser ID and starts over with a new random ID, so later events from this browser aren't tied to your account. That includes signing out here, a session that expired, Sign out everywhere from any device, and deleting your account.
- On published guides, PostHog records page views, page leaves, and walk events: when a walk starts, each step by its name, and the step it ends on. Each event names the guide, its version and the workspace that published it.
- Nothing else is captured as events. Our code switches off PostHog's click events, error reports, performance measurements, heatmaps, console logs, surveys, product tours, chat and experiments. Replay, below, still records clicks. Each page load also asks PostHog for its settings, and that request sends your random IDs and, once you sign in, your user ID and workspace IDs.
- Session replay records the editor and published guides as you see them: the page, clicks, scrolling and mouse movement. That includes your document's text in the editor and the diagram. It hides what you type in form fields, such as the title box, the import box or the email field, but records the editor itself. It shows the account area (sign-in, the account menu and account deletion), the Upgrade screen and the Welcome screen as blank boxes. It doesn't record network requests, the browser console or drawing canvases. Checkout and the billing page run on Stripe's site, where replay never runs.
- Session replay doesn't record visitors in the European Union, including its outermost regions, Ă…land, the Canary Islands, and Ceuta and Melilla. Nor does it record visitors in Iceland, Liechtenstein, Norway, Svalbard and Jan Mayen, the United Kingdom, Gibraltar, Jersey, Guernsey, the Isle of Man or Switzerland. Cloudflare looks up the country of your IP address. The page asks our server before it starts recording, and our analytics address refuses replay data from those countries. If Cloudflare can't place your address in a country, or you use Tor, replay doesn't record you either. A VPN or travel can make the lookup wrong.
- Do Not Track. If your browser sends Do Not Track or Global Privacy Control, our pages never load PostHog. It sets no cookie, stores nothing in your browser, and gets no events and no replay. PostHog data stored before you turned the setting on stays until you clear it.
PostHog keeps replays for 90 days. It keeps events with no end date, for as long as our PostHog plan allows. Deleting your account doesn't delete PostHog data. To have it deleted, email rob@flowchart.chat.
Who else handles your data
- Cloudflare hosts the site, the database, and the storage for guide walks. It sends sign-in emails and runs the bot check and rate limits. Every request to flowchart.chat passes through Cloudflare.
- Stripe takes payments, as the merchant of record.
- PostHog runs analytics and session replay, in its US cloud.
- Anthropic writes AI edits.
Cookies and browser storage
__Host-sessionkeeps you signed in. The session ends 15 to 30 days after you last use it, and always 90 days after you sign in. After a checkout without an account, it holds a one-day session for the workspace you paid for.__Host-claimis set when you start a checkout without being signed in, so the plan you pay for finds its way back to this browser. It lasts 2 days.ph_phc_u6GcjLUyaLTd3oPyXxUxK3fUtNg64FR35hcn7nV4u3RQ_posthogis PostHog's cookie, set for a year, and a local storage entry of the same name. It holds random IDs for your browser and your visit, your user ID once you sign in, your workspace IDs with the open workspace's type and plan, and the address and referring page of your first visit, without the part after#. PostHog also keeps the current visit and tab in session storage, under names that start withph_. If your browser sends Do Not Track or Global Privacy Control, PostHog sets none of these, though any it set before stay until you clear them.- Local storage holds your drafts, copies of your account's documents, which document and workspace are open, a copy of your account details, including your email, for a fast start, and your place in each guide you walk. Session storage keeps which document and workspace each tab has open. Signing out removes the copy of your account details and leaves the copies of your account's documents in this browser. Deleting your account removes this browser's copies of the documents in the workspaces it deleted, and keeps a list of those workspace IDs so the documents don't come back. Copies in other browsers, and copies from team workspaces that other members keep, stay until you clear them.
We don't use advertising cookies.
How long we keep it
- Account, workspaces, documents and guides
- Until you delete them or the account. Deleting a document in the Library takes down the guide published from it. The guide's link and every version's link then say its author took it down. We keep that guide's versions and walks with the workspace until the workspace is deleted. The versions stay in your export, and the walks aren't in it.
- Sign-in link records
- At least a day. Each new sign-in request clears records more than a day old.
- Sessions
- As long as the session cookie lasts. Ended sessions are cleared out at a later sign-in.
- An unpaid checkout
- Once the workspace made for it is 7 days old, the next checkout without an account removes it.
- Daily AI request counts
- We don't delete these on a schedule yet.
- Guide walks
- Until the guide's workspace is deleted.
- Payments
- Stripe keeps your customer record, with your email, and your invoices and payment records after you delete your account, as the merchant of record.
- Analytics and replays
- Replays for 90 days. Events with no end date, for as long as our PostHog plan allows.
- Invite redemptions
- When a checkout with a free invite completes, we record the invite code, the time, and a SHA-256 hash of your account's email address. Before hashing, we lowercase the address and drop any
+part, and for Gmail and Googlemail addresses we also drop the dots. We use the record to refuse the invite to the same inbox again, even from a new account. Deleting your account doesn't remove the record, and it has no end date yet. The hash doesn't hold the address itself. It isn't salted, so anyone holding it can check whether a known address used the invite. We also send the code and the hash to Stripe with the checkout, and Stripe keeps them with its record of that checkout. - Early-access emails
- In our inbox until we delete them.
Export or delete your account
Sign in and open the account menu, the button with your email at the top right.
- Export my data downloads a JSON file with your account, your workspaces and their plans, and the documents and guides of the workspaces you own, with every guide version.
- Delete account asks you to type your email, then deletes your account and every workspace only you belong to, with their documents, guides and guide walks. Those guides' links then say the guide was deleted. To say that, we keep each deleted guide's link name, which comes from its document's title. If you redeemed an invite, we keep the invite code, the time and a hash of your email address, so the same inbox can't use the invite again. Deleting the account doesn't remove that record. A paid plan is canceled at once, with no refund for the rest of the period. If you own a team with a plan, cancel that plan in Manage billing first.
Published guides are public
When you publish a guide, anyone with its link can open it, and every earlier version stays at its own link, until you delete its document or your account. For now, a copy cached in another Cloudflare data center, or in the browser of someone who opened it, can keep showing the guide after that: the main link for up to a minute, and a version's own link for as long as a year. Guide pages ask search engines not to index them, unless we choose to feature a guide. Then we list it in our sitemap and tell search engines about it.
Children
flowchart.chat isn't meant for children under 13, and we don't knowingly collect their data.
Changes to this page
When this page changes, we change the date at the top.