MFlowDelivery Intelligence

Privacy Policy for MFlow

Effective Date: September 09, 2026

1. Introduction

Welcome to MFlow ("Service", "we", "us", "our"). We value your privacy and are committed to protecting your personal data. This Privacy Policy ("Policy") explains what information we collect, how we use, share, and protect it in connection with your use of our Service.

MFlow is an AI-powered delivery and coding-agent platform. The Service includes project boards, a knowledge base, AI automation, MCP (Model Context Protocol) integrations for external AI clients, and a coding agent that can work in your GitHub repositories.

By using our Service, you agree to the collection and use of information in accordance with this Policy. If you do not agree with this Policy, please do not use our Service.

2. Information We Collect

We collect various types of information to provide and improve our Service:

2.1. User-Provided Information:

  • Registration Data: Name, email address, company or workspace name (if applicable), and password. If you sign in with Google, we receive the basic Google profile information described in Section 3.
  • Board and Knowledge-Base Data: Information you input into the Service for project management, including project names, tasks, descriptions, deadlines, statuses, assigned users, comments, uploaded files, attachments, and knowledge-base content.
  • Communication Data: Information you provide when contacting customer support or otherwise communicating with us.
  • Payment Information: If you use paid features, our payment processors (not us directly) may collect payment information (e.g., credit card details) necessary to process payments.

2.2. Automatically Collected Information:

  • Usage Data: Information about how you interact with the Service, including pages visited, features used, time spent on the platform, clicks, IP address, browser type, operating system, device type, device identifiers, and general location data.
  • Cookies and Similar Technologies: We use cookies and other tracking technologies to collect information about your activity on the Service, enhance user experience, and analyze usage. See Section 12 for more details.

2.3. Information Processed by AI:

  • Our AI features process your Board and Knowledge-Base Data and, when you use the coding agent, the repository and source-code data described in Section 2.4, to provide features such as task automation, planning assistance, semantic search, code generation, and pull-request drafting.
  • Some AI processing involves sending data to third-party AI service providers — specifically Google (Gemini), OpenAI, Anthropic, and DeepSeek — depending on which model is configured for your workspace or which provider you connect with your own key. These providers process data under confidentiality and data-processing terms that align with our privacy commitments. See Section 6 for details.
  • Bring-your-own-key (BYOK): You may connect your own OpenAI, Anthropic, Google, or DeepSeek API key to the Service. We store such keys encrypted with AES-256-GCM, and they are never retrievable in full once saved.
  • Vector embeddings: To provide semantic search and retrieval, we embed Board and Knowledge-Base Data into a vector database (Chroma). Embeddings are scoped per workspace/user and are used to return relevant results from your own data.

2.4. Repository and Coding Agent Data:

  • GitHub repository access: When you connect GitHub, we request OAuth authorization to access the repositories you select. Depending on the permissions you grant, this includes reading repository metadata, cloning private repositories, and reading source code and repository contents.
  • Code execution: Authorized repositories are cloned into an isolated sandbox on a dedicated host so the coding agent can run code, tests, and build commands. Sandboxes are isolated with gVisor and are ephemeral — they are discarded when the task or session ends.
  • Writing on your behalf: With the permissions you grant, the coding agent may push branches to your repository and open pull requests. Agent output is not merged automatically; proposed changes are surfaced for human review before merging.

2.5. MCP Client Data:

  • Connected AI clients: You can connect external AI clients such as Claude Desktop, Claude Code, or claude.ai to MFlow over OAuth through the Model Context Protocol (MCP). Depending on the scopes you approve, an authorized client may read and write board and knowledge-base data in your workspace.
  • Conversation data: MFlow does not collect or retain conversation data from connected AI clients. Conversations remain between you and the AI client/model provider; MFlow receives only the board or knowledge-base read/write requests those clients make on your behalf.

3. Use of Google User Data

If you choose to sign in to MFlow with Google, we may access certain Google user data through Google Sign-In.

  • Data Accessed: We access your basic Google profile information (name, email address, profile picture) for authentication, account creation, and identification within the Service.
  • Scopes: The Service currently requests only the profile information necessary for Google Sign-In. We do not request Gmail scopes (such as gmail.readonly, gmail.modify, or gmail.compose) or Google Calendar scopes.
  • Purpose of Use: Google user data is used solely to provide and improve the user-facing authentication features of MFlow, such as facilitating login and associating your Google identity with your MFlow account.
  • Compliance with Google Policies: MFlow's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • No Advertising Use: We do not use Google user data for serving advertisements.
  • Limited Transfer: We do not transfer Google user data to others except when necessary to provide or improve the Service's features, comply with applicable laws, or as part of a merger, acquisition, or sale of assets (with user consent where required). See Section 6 for general data sharing details.
  • Limited Human Access: We do not allow humans to read your Google user data unless: (a) we have your affirmative agreement for specific data; (b) it is necessary for security purposes (e.g., investigating abuse); (c) it is necessary to comply with applicable law; or (d) the data has been aggregated and anonymized for internal operations (e.g., reporting).

4. How We Use Your Information

Beyond the specific uses of Google data outlined above, we use the collected information generally for the following purposes:

  • Providing and Maintaining the Service: Creating and managing your account, processing your Board and Knowledge-Base Data with AI, running the coding agent (including cloning repositories, executing code in isolated sandboxes, and opening pull requests), serving MCP client requests you authorize, processing payments, providing technical support, and authenticating users.
  • Improving and Developing the Service: Analyzing Service usage to identify trends, enhance functionality, develop new features, and train/improve our AI models (primarily using anonymized/aggregated data). We do not use conversation data from connected AI clients for this purpose.
  • Communication: Sending you essential service notifications, updates, security alerts, and support messages. We may also send marketing materials, but you will have the option to opt-out.
  • Security and Fraud Prevention: Protecting the Service, our systems, and our users from unauthorized access, fraud, abuse, and other illegal activities.
  • Legal Compliance: Fulfilling legal obligations, responding to valid legal requests (e.g., court orders, subpoenas), and enforcing our terms and policies.

5. Legal Basis for Processing (for EU/EEA Users)

If you are in the European Economic Area (EEA), our legal basis for collecting and using the personal data described above depends on the data and the specific context:

  • Consent: Where you have given us explicit consent (e.g., for marketing emails, connecting your Google account, or connecting an external MCP client).
  • Contract: Processing is necessary to perform our contract with you (i.e., providing the Service as described in our Terms of Service).
  • Legitimate Interests: Processing is necessary for our legitimate interests (e.g., improving the Service, security, fraud prevention), provided these interests are not overridden by your data protection rights.
  • Legal Obligations: Processing is necessary to comply with our legal obligations.

6. Data Sharing and Disclosure

We do not sell your personal data, including any Google user data. We share your information only in the following limited circumstances:

  • Service Providers: We engage third-party companies and individuals ("Service Providers") to perform services on our behalf. These Service Providers have access to your data only to perform these tasks and are obligated contractually not to disclose or use it for other purposes. Our current core Service Providers include:
    • Hosting and infrastructure: Hetzner (dedicated hosting) managed through Coolify, and Cloudflare R2 for attachment and file storage.
    • Authentication: Google Firebase for authentication services.
    • AI model providers: Google (Gemini), OpenAI, Anthropic, and DeepSeek receive the data necessary to process your AI requests when those models are configured for your workspace or when you connect your own key. If you use BYOK, you authorize us to send requests to that provider with your key; that provider's privacy policy also applies.
  • Legal Requirements: We may disclose your information if required by law, subpoena, or other legal process, or if we have a good faith belief that disclosure is necessary to protect safety, rights, or property, or to investigate fraud.
  • Business Transfers: If MFlow is involved in a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service of any change in ownership or uses of your personal data, as well as any choices you may have. Any acquiring entity will be required to adhere to the commitments made in this Policy (or provide notice of changes).
  • Aggregated or Anonymized Data: We may share aggregated or anonymized data (which cannot reasonably identify you) for research, analysis, or reporting purposes.
  • With Your Consent: We may share your information with third parties when we have your explicit consent to do so (e.g., if you authorize an external AI client to access your MFlow workspace through MCP).

7. Data Security

We implement reasonable technical and organizational security measures designed to protect your information from unauthorized access, alteration, disclosure, or destruction. These include, but are not limited to:

  • Encryption of data in transit (using TLS/SSL) and at rest.
  • AES-256-GCM encryption for stored BYOK API keys; once saved, such keys are never retrievable in full.
  • Dedicated hosts and gVisor-based isolation for coding-agent sandboxes, which are ephemeral and discarded after use.
  • Human review of coding-agent output before changes are merged.
  • Strict access controls and authentication mechanisms.
  • Regular security assessments and vulnerability scanning.
  • Pseudonymization or anonymization where appropriate.
  • Secure software development practices.

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you the Service. We will also retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Board and Knowledge-Base Data is retained until you delete the relevant project, workspace, or your account, subject to your subscription plan terms. Usage data may be retained for analytical purposes for a longer period, typically in an aggregated or anonymized form.

Coding-agent sandboxes are ephemeral. Repository clones and working copies in a sandbox are discarded when the task or session ends. GitHub connection credentials and permissions are retained only while your GitHub connection is active, and can be revoked from your account settings or GitHub.

Google user data associated with your account is deleted upon your request, when you disconnect your Google account from our Service, or when you delete your MFlow account entirely.

9. Your Rights & Data Deletion

Depending on your jurisdiction (e.g., GDPR, CCPA), you may have rights regarding your personal data:

  • Access: Request a copy of your data.
  • Rectification: Request correction of inaccurate data.
  • Erasure ('Deletion'): Request deletion of your data.
  • Restriction: Request restriction of processing.
  • Portability: Request your data in a machine-readable format.
  • Objection: Object to processing based on legitimate interests or for direct marketing.
  • Withdraw Consent: Withdraw consent where processing relies on it.

You can typically manage your account information, GitHub connection, MCP authorizations, and some project data directly within the Service settings. To exercise your rights, including requesting data deletion, please contact us at support@m-flow.io. We will respond to your request within a reasonable timeframe and in accordance with applicable laws. We may need to verify your identity before processing your request. Deleting your account will result in the deletion of your personal data and project data according to our retention policies (Section 8).

10. Children's Privacy

Our Service is not directed to individuals under the age of 13 (or a higher age threshold depending on the jurisdiction, such as 16 in the EEA). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child without parental consent, we will take steps to delete such information. If you believe a child has provided us with personal data, please contact us at support@m-flow.io.

11. International Data Transfers

Your information, including personal data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ. Our primary data processing and hosting occurs on Hetzner infrastructure managed through Coolify. Some Service Providers (for example Google Firebase for authentication, Cloudflare R2 for file storage, and the AI model providers listed in Section 6) may process data in their respective locations. Where such processing involves transfers of EEA/UK/Switzerland personal data, we take appropriate safeguards to ensure your data is treated securely and in accordance with this Policy, such as using Standard Contractual Clauses where applicable.

12. Cookies and Similar Technologies

We use cookies (small text files placed on your device) and similar technologies (e.g., web beacons, pixels) to:

  • Enable essential Service functions (e.g., session management, authentication).
  • Remember your preferences and settings.
  • Analyze Service usage, performance, and user interaction.
  • Ensure security and prevent fraud.

You can typically manage cookies through your browser settings. However, disabling essential cookies may impair the functionality of the Service.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. We will notify you of any material changes by posting the new Policy on this page and updating the "Effective Date" at the top. We may also notify you via email or through the Service. You are advised to review this Policy periodically. Changes are effective when posted on this page.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: support@m-flow.io