PRIVACY POLICY
Your Privacy, Protected
We believe privacy is a fundamental right, not a premium feature. Here's exactly how we protect your data.
Last updated: January 2026
TL;DR - The Important Stuff
We never sell your data. Period.
You can export everything anytime.
Your data is encrypted at rest and in transit.
You control what gets deleted.
No third-party tracking or analytics that compromise privacy.
Our Privacy Commitments
No Data Selling
Your information is never sold, rented, or shared with third parties for their marketing purposes.
Full Export Anytime
Download all your data in standard formats whenever you want. No restrictions, no waiting periods.
Encryption at Rest
Your data is encrypted using AES-256 encryption when stored on our servers.
You Control Deletion
Delete your account and all associated data permanently at any time. We don't keep shadows.
Full Privacy Policy
We collect information you provide directly to us:
• Account information (email, name) when you register
• Client data you enter (contacts, notes, follow-ups)
• Usage data to improve our service
• Support communications
We do NOT collect:
• Data from your device beyond what's necessary for the app
• Information from third-party sources without your consent
• Biometric or sensitive personal information
We use your information to:
• Provide, maintain, and improve WinFlow
• Send you technical notices and support messages
• Respond to your comments and questions
• Analyze usage patterns to improve user experience
We do NOT use your information to:
• Target you with third-party advertisements
• Build profiles for external marketing
• Share with partners for their commercial purposes
Your data is protected by:
• AES-256 encryption at rest
• TLS 1.3 encryption in transit
• Regular security audits
• Access controls and authentication
• Cloudflare's enterprise-grade infrastructure
Data is stored in secure data centers with physical and digital access controls. We maintain backups for disaster recovery, which are also encrypted.
You have the right to:
• Access: Request a copy of all your data
• Export: Download your data in CSV, Excel, or JSON
• Correct: Update any inaccurate information
• Delete: Permanently remove your account and data
• Object: Opt out of certain data processing
• Portability: Take your data to another service
To exercise these rights, contact us at [email protected] or use the in-app export and deletion features.
We use minimal cookies:
• Essential cookies for authentication and security
• Preference cookies to remember your settings
We do NOT use:
• Third-party advertising cookies
• Cross-site tracking
• Social media tracking pixels
• Invasive analytics that identify individuals
You can disable cookies in your browser settings, though some features may not work properly.
We retain your data only as long as needed:
• Active account data: Kept while your account is active
• Deleted account data: Permanently removed within 30 days
• Backup data: Purged from backups within 90 days
• Support communications: Kept for 2 years for service improvement
You can request immediate deletion at any time.
We may update this policy occasionally. When we do:
• We'll notify you via email for significant changes
• We'll post the updated policy with a new date
• We'll never reduce your rights without explicit consent
• Continued use after changes indicates acceptance
Last updated: January 2026
For privacy-related questions or to exercise your rights:
Email: [email protected]
We aim to respond to all privacy inquiries within 48 hours.
Questions About Privacy?
We're happy to answer any questions about how we handle your data.
Contact Our Privacy Team