StandardFlow AI

Privacy Policy

Effective date: June 23, 2026

StandardFlow, Inc., a Delaware corporation (“StandardFlow AI,” “we,” “us”) operates the standardflow.io website and the StandardFlow AI compliance-analysis application (together, the “Service”). This policy explains what information we collect, how we use it, the providers we rely on, and the choices you have. StandardFlow, Inc. is the controller responsible for personal information processed through the Service.

1. Information we collect

2. How we use information

Where the GDPR applies (EEA/UK), we rely on these legal bases: performance of a contract (to provide the Service to you), legitimate interests (to secure, maintain, and improve the Service), consent (for analytics cookies where required), and legal obligation (to comply with applicable law).

3. Cookies and analytics

We use Google Analytics 4 to understand how the website is used. It relies on cookies and similar identifiers. For visitors in the European Economic Area, the United Kingdom, and Switzerland, analytics storage is disabled by default using Google Consent Mode — no analytics cookies are set, and only privacy-preserving, cookieless measurement is used. You can also block cookies in your browser or install the Google Analytics opt-out add-on.

4. Service providers

We share information with vendors who process it on our behalf:

Documents you upload are processed by third-party large language model providers (including Google) solely to generate your analysis. We do not sell your personal information.

5. Where data is processed

Our application backend is hosted in Japan (Tokyo). Some of the providers above operate in the United States and other countries. Where personal data is transferred out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and equivalents) with the providers involved. By using the Service, your information may be transferred to and processed in these locations.

6. Data retention

We keep account and project data for as long as your account is active or as needed to provide the Service, after which we delete or anonymize it unless a longer retention period is required by law. You may request deletion of your data at any time (see Contact).

7. Security

We use access controls, encryption in transit, and tenant isolation to protect your data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

8. Your rights

Depending on where you live — for example under the GDPR (EEA/UK) or the CCPA/CPRA (California) — you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to opt out of the “sale” or “sharing” of personal information. We do not sell or “share” personal information (as those terms are defined under the CCPA/CPRA), and we will not discriminate against you for exercising your rights. To exercise any right, contact us below; we will respond within the timeframe required by law.

If you are in the EEA, the UK, or Switzerland and believe we have not resolved your concern, you also have the right to lodge a complaint with your local data protection supervisory authority.

9. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information.

10. Changes to this policy

We may update this policy from time to time. We will revise the effective date above and, for material changes, provide additional notice through the Service.

11. Contact

Questions or requests about this policy or your data:
StandardFlow, Inc. — legal@standardflow.io