We built AgentFlow assuming our customers read their privacy policies — and act on what they find. Here's the full picture of how we handle your data, what regulations we cover, and the integrations you can plug in safely.
Documents are encrypted in transit (TLS 1.2+) and at rest. OAuth refresh tokens for Google Drive and Slack are Fernet-encrypted with per-user keys — even a database breach can't replay them.
Your data is sandboxed to your workspace. No third-party model provider sees a single byte without your explicit instruction. Sub-processors handle inference only, not retention.
Public APIs are IP- and email-rate-limited (5/hr, 20/day, 10/email/day). Workspace-level cost alerts flag anomalous usage. Per-user Fernet keys ensure token compromise stays contained.
Custom frameworks (industry-specific or regional) available on Business plan by request.
We auto-detect a contract's language and cite the right legal framework for that jurisdiction. One-click translation between the native and English report views on every scan.
| Integration | Scope | Token security | Status |
|---|---|---|---|
| Google Drive | Read-only via official Picker — we only see files you explicitly select | Fernet-encrypted per-user refresh token; revokable from Settings | Live |
| Slack | Write-only to channel of your choice (critical/high-risk alerts) | Fernet-encrypted per-user access token; one-click disconnect | Live |
| Resend (email) | Outbound transactional + weekly digests | Server-side API key; granular per-channel opt-out | Live |
| Claude 4.5 Sonnet (Emergent LLM) | Inference on uploaded documents | Provider-managed; no document retention, no training use | Live |
We notify customers in writing 30 days before adding a new sub-processor that materially changes data flow.
We've answered most of them. Drop us a note and we'll send a completed SIG/CAIQ within 1 business day.
Last updated: February 2026. Full Privacy Policy at /privacy.