Flowstem privacy policy
Last updated September 11, 2026
Flowstem is a local-first Chrome automation builder. Workflows run in your Chrome browser, while Flowstem accounts provide sign-in, plan, and local-run authorization features. Flowstem does not currently offer hosted workflow storage or cloud workflow execution.
Workflow data stored locally
Flowstem stores workflows, folders, backups, automatic recovery versions, settings, and AI provider keys in the current Chrome profile on the device where you use Flowstem. When you sign in, your local workflow library is associated with that Flowstem account in local extension storage. Flowstem does not upload workflow definitions, selectors, variables, captured data, or screenshots to the Flowstem account service as part of normal account use.
Provider keys are excluded from workflow exports, complete backups, and diagnostic reports. Flowstem diagnostic reports are generated locally and exclude workflow names and steps, selectors, variables, extracted data, URLs, screenshots, and API keys.
Flowstem accounts and plans
Flowstem uses account.flowstem.app to connect your
Flowstem account, confirm your Free or Desktop plan, and authorize local
workflow runs. For these features, the account service processes your
account ID, email address, plan information, device name, session and
device authorization details, and local-run authorization information
such as a run ID and timing data. A temporary account session token and
account connection details are stored locally in your Chrome profile.
Disconnecting your account removes the local Flowstem session record. Account and subscription information are handled through the Flowstem account service; normal account checks and run authorization do not upload your workflow content or AI provider keys.
AI providers
You can configure OpenAI, Anthropic, or Gemini with your own provider key. Flowstem keeps provider keys in your current Chrome profile and sends a key directly to the provider you select only when an AI command runs. The prompt and any workflow data included in that command are sent directly to that provider and are subject to its terms and privacy practices.
Google integrations
When you choose to connect Google, Chrome manages the related OAuth access tokens. Flowstem does not store those tokens in workflows, exports, logs, diagnostics, or its local extension storage.
Flowstem requests Google permissions to upload files that it creates to Drive, list spreadsheet names, and read or update the Google Sheets workbook selected in a command. It may also read the connected Google account's display name and email address to show connection status. Flowstem uses Google user data only to provide these user-requested features and does not use it for advertising. Flowstem's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Third-party destinations and websites
Your workflows may interact with websites and send data to APIs, webhooks, AI providers, Google Drive, or Google Sheets that you choose. Those third parties receive and handle data under their own terms and privacy practices. You are responsible for reviewing the destinations and data used in each workflow.
Local security considerations
Because provider keys are local secrets, anyone with access to the unlocked operating-system account or the active Chrome profile may be able to retrieve them. You are responsible for protecting device access and sharing workflows carefully.
Support and diagnostics
If you contact Flowstem support, we may use the information you send to respond to your request and troubleshoot an issue. Do not include provider keys, sensitive workflow data, or private files in support messages or screenshots. If you choose to share a diagnostic report, review the file before sending it and include only what is necessary for your request.
Website hosting
The Flowstem website is hosted by Vercel. Vercel may process technical information generated when you visit the site, such as IP address and request logs, under its own privacy notice.
Changes to this policy
Flowstem's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Flowstem uses this information only to provide or improve the browser automation features requested by the user, does not use it for personalized advertising, and does not sell it.
Flowstem may update this policy as the product evolves. Material changes will be reflected on this page by updating the last updated date.
Contact
Questions about this privacy policy can be sent to support@flowstem.app.