Privacy Policy

Effective date: May 2, 2026  ·  Botflow LLC, North Carolina

1. Who We Are

Botflow LLC ("Botflow," "we," "us," or "our") is a limited liability company incorporated in North Carolina. We operate the Botflow platform, accessible at botflow.io, which is powered by OpenVibeCode — our source-available development environment that lets you build full-stack applications directly in the browser.

Questions about this Privacy Policy can be directed to awkohler@botflow.io.

2. Information We Collect

2.1 Account Information

Authentication and account management are handled by Clerk. When you sign up, Clerk collects your email address and, optionally, your name and profile photo. If you use a social login (e.g., GitHub, Google), Clerk receives basic profile information from that provider. We receive a user ID and basic profile metadata from Clerk to associate your account with your projects.

2.2 Project Data

We store the files, code, project configuration, and metadata that you create inside Botflow. This data is stored in our PostgreSQL database (hosted on Neon) and includes project names, descriptions, file trees, file contents, and related settings.

2.3 Uploaded Files

If you upload assets to your projects, those files are processed and stored through UploadThing, a third-party file-handling service. Files you upload are stored on UploadThing's infrastructure.

2.4 GitHub Integration

If you connect your GitHub account to Botflow, we store a GitHub OAuth access token in our database to perform Git operations (reading and writing repositories) on your behalf. We only request the minimum GitHub scopes necessary to enable the features you use. You can revoke this access at any time from your GitHub account settings or from within Botflow.

2.5 AI Features

Botflow offers AI-assisted coding features powered by models from OpenAI, Anthropic, and Fireworks AI. When you use these features, the relevant portions of your code or conversation are sent to the applicable AI provider for processing. Please review the privacy policies of OpenAI, Anthropic, and Fireworks AI to understand how they handle this data.

2.6 Subscription & Billing

Subscription and billing are managed by Clerk. Payment card data is handled entirely by Clerk's payment infrastructure and is never stored on Botflow's servers. We receive information about your subscription plan (Free, Pro, or Max) and subscription status.

2.7 Usage & Technical Data

We may automatically collect information such as your IP address, browser type, operating system, referring URLs, pages visited, and timestamps when you use the platform. This data helps us understand how the service is used and improve reliability.

3. How We Use Your Information

  • Providing, operating, and improving the Botflow platform.
  • Authenticating your identity and securing your account.
  • Storing and serving your project files and settings.
  • Processing GitHub operations on your behalf when you use the GitHub integration.
  • Sending transactional emails (e.g., account notifications) through Clerk.
  • Responding to your support requests.
  • Detecting and preventing abuse, fraud, or security incidents.
  • Complying with applicable laws and enforcing our Terms of Service.

We do not sell your personal information to third parties. We do not use your project code to train AI models without your explicit consent.

4. Sharing of Information

We share data only in the following limited circumstances:

  • Service providers: Clerk (authentication & billing), Neon (database), UploadThing (file storage), Vercel (hosting), and AI providers (OpenAI, Anthropic, Fireworks AI) — solely to provide the services you use.
  • Legal requirements: When required by law, regulation, or valid legal process.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with appropriate protections applied.
  • With your consent: In any other case where you have given explicit permission.

5. Data Retention

We retain your account and project data for as long as your account remains active. If you delete your account, we will delete or anonymize your personal data within 90 days, except where we are required to retain it for legal or compliance purposes. Uploaded files hosted by UploadThing are subject to UploadThing's own retention policies.

6. Cookies & Tracking

Botflow uses cookies and similar technologies set by Clerk to maintain authentication sessions. We do not use advertising or behavioral-tracking cookies. You can control cookies through your browser settings, but disabling session cookies will prevent you from staying logged in.

7. Security

We implement industry-standard security measures, including TLS encryption for data in transit and access controls for data at rest. However, no system is completely secure. We encourage you to use a strong, unique password and to protect your account credentials.

8. Children's Privacy

Botflow is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently done so, please contact us at awkohler@botflow.io and we will delete the information promptly.

9. Your Rights

Depending on your location, you may have rights regarding your personal data, including the right to access, correct, or delete it. To exercise any of these rights, contact us at awkohler@botflow.io. We will respond within the timeframe required by applicable law.

North Carolina residents may also have rights under the North Carolina Identity Theft Protection Act and any applicable state data-privacy legislation.

10. Third-Party Links

The platform may contain links to third-party websites or services. This Privacy Policy does not apply to those services, and we encourage you to review their privacy policies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. If changes are material, we will notify you via email or a prominent notice within the platform. Continued use of Botflow after changes take effect constitutes acceptance of the updated policy.

12. Contact

If you have questions or concerns about this Privacy Policy, please contact us:

Botflow LLC
North Carolina, USA