Privacy at a glance
Flowbord is EU-hosted, and your data never leaves the EU. Flowbord runs on EU-owned infrastructure operated within the European Union. There is no US parent company anywhere in our ownership chain, which matters: an "EU region" owned by a US company still sits under US legal reach (such as the CLOUD Act and FISA 702). The label is not the law. We chose ownership over labels so your project data is not exposed to foreign legal reach.
This policy explains, in plain English, what data we collect, why, where it lives, and the rights you have under the EU General Data Protection Regulation (GDPR). Flowbord is currently in beta, and this policy will evolve as the product does. We will tell you about material changes.
Who we are
Flowbord is a project-tracking tool for teams building software with AI coding agents. It is built and operated by its founder, an individual based in Denmark, within the European Union. For the personal data we describe below, Flowbord acts as the data controller for account and usage data, and as a data processor for the project content you and your agents create inside the product.
You can reach us about anything in this policy at [email protected].
What Flowbord actually does (so the data flow makes sense)
Understanding the data picture is easier once you know how Flowbord works. A human seeds an idea. Your own Claude Code connects to Flowbord over the Model Context Protocol (MCP) and expands that seed into specs, sprints, and tickets — but only as proposals that a human reviews and approves. Flowbord stores your structured project data (specs, tickets, plans, proposals, audit records) and serves the right slice of it back to your agent over MCP.
The large-language-model calls happen on your side, not ours. Your Claude Code runs in your own environment under your own model provider account. Flowbord does not run the model for you and does not send your project data to a third-party LLM. We serve context to, and receive proposals from, the agent you control.
What data we collect
Account data
- Your name and email address, used to create and secure your account and to contact you about the service.
- Your organization, your membership in it, and your role (Developer, Manager, Admin, or Owner), used for access control.
- Authentication data, including your password (stored only as a secure hash) and the API key issued to your organization for MCP access.
Project data you and your agents create
- The content you put into Flowbord: roadmaps, sprints, tickets, specs, plans, decisions, glossaries, and other context documents, along with their versions and links.
- Agent proposals and jobs — what your agent proposed, and the record of what was approved, rejected, or promoted.
- This is your data. We process it to provide the service to you and on your behalf.
Audit and usage data
- An audit record of every MCP tool call made against your organization, so you (and we, for support and security) can see what an agent did and why.
- Standard operational logs needed to run, secure, and debug the service.
Privacy and security mechanics built into the product
We try to design for privacy rather than bolt it on. Concretely:
- Secrets are redacted before they are stored. Values that look like API keys or other credentials are stripped from audit logs before they hit the database, so secrets passing through a tool call are not retained in plain text.
- Tenant isolation is enforced at the database layer, and it fails loud. Each organization's data is fenced off by a database-level filter; if that isolation cannot be applied, the request fails rather than risk leaking across organizations.
- One API key per organization, scoped to that organization, so MCP access is contained and revocable.
- Role-based access (Developer, Manager, Admin, Owner) governs who can do what.
- Destructive and high-stakes actions are fail-closed. Deleting data and promoting content to canon are never auto-approved by an agent; a human must promote them.
Where your data is hosted
Flowbord is self-hosted on EU-owned infrastructure located in the European Union, the same way our sibling project applogger.eu is run. Your data is stored and processed in the EU and does not leave the EU. Because there is no US entity in the ownership chain, your data is not subject to US extraterritorial access regimes through us.
Legal bases for processing
- Performance of a contract — to provide the Flowbord service to you and your organization.
- Legitimate interests — to secure the service, prevent abuse, keep audit trails, and improve the product, balanced against your rights.
- Consent — where we ever ask for it explicitly (for example, optional communications). You can withdraw consent at any time.
- Legal obligation — where we must process data to comply with the law.
Cookies
Flowbord uses only the minimal, essential cookies needed to keep you signed in and to keep the application secure (for example, your session and security tokens). We do not use these to track you across other sites.
Data retention and working-document TTL
We keep your account and project data for as long as your account is active, and for a reasonable period afterwards to meet legal, security, and operational needs. When you delete data, or close your account, we delete or anonymize the associated personal data within a reasonable timeframe, subject to backups that age out on their normal cycle.
Some context documents are deliberately ephemeral. "Working" documents (such as scratch notes, research, meetings, and plans) carry a time-to-live and are automatically soft-deleted by a scheduled purge once they expire, so the context brain stays lean and stale material does not linger.
Sub-processors
We keep our supplier chain short and EU-based. We currently rely on:
- an EU hosting provider for the infrastructure that runs Flowbord, located in the EU; and
- an email provider for transactional email (such as sign-in and account notifications).
We will keep this list current as the service grows, and we will not add a sub-processor that would move your data outside the EU.
International transfers
There are none outside the EU. Your data is hosted and processed within the European Union and is not transferred to third countries by us.
Your GDPR rights
You have the right to access your personal data; to have inaccurate data corrected; to have your data erased; to restrict or object to certain processing; to data portability; and, where processing is based on consent, to withdraw that consent. You also have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, email [email protected]. We will respond within the timeframes GDPR requires. Note that for the project content you create, your organization may be the controller, in which case we will help you fulfil requests rather than action them unilaterally.
Children
Flowbord is a tool for professional software teams and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
Because Flowbord is in beta, this policy may change. When we make material changes we will update the date above and, where appropriate, notify you. Continued use of Flowbord after a change means you accept the updated policy.
Contact
Questions, requests, or concerns about privacy: [email protected].