Product policy
Privacy
Effective July 30, 2026
Plain-language summary
SignalFlow Studio is designed around reviewable, browser-local campaign work. Saved campaigns use a versioned local record in the browser you are using. The hosted application processes the information needed to generate a campaign, but it does not silently publish content or sell personal data.
Information you choose to provide
A campaign may include product notes, audience information, public URLs, a public GitHub repository reference, uploaded text or code files, media-file metadata, model settings, and the channel drafts you edit. Do not submit secrets, private credentials, or information you are not authorized to use.
Browser-local campaign storage
When you save a campaign, SignalFlow stores a canonical Campaign record in browser local storage. The record contains the authoritative current drafts, portable source and generation metadata, and optional revision history. Temporary model keys and browser File objects are excluded. Clearing browser data, using another browser, or using another device can make the local library unavailable. Export important campaigns before clearing local data.
Uploaded files and public source extraction
Supported text, Markdown, CSV, JSON, and code files are read in the browser and relevant text is sent with the generation request. Image and video uploads are treated as asset references in the active campaign route; they are not represented as automatically understood visual content. Public links and public GitHub repositories may be requested by the server to extract relevant context.
Model providers and temporary keys
Campaign generation requires a real model provider route. When you select an external provider, the campaign context is sent to that provider to perform the requested generation. A temporary provider key entered in the Studio is used for that request and is excluded from the local campaign library and canonical exports. The chosen provider has its own terms and privacy policy. Custom or local endpoints are available only when the current deployment and session capability allows them.
Owner access and social connectors
A protected deployment uses an HTTP-only owner session cookie. LinkedIn, X, and Reddit OAuth sessions are encrypted in HTTP-only cookies, and raw social access tokens are not returned to page JavaScript. Direct publishing is attempted only after explicit approval, and success is shown only after the destination API confirms it.
Current cloud and extension boundaries
SignalFlow does not currently provide a cloud campaign database, cross-device synchronization, collaboration, durable background jobs, or hosted asset storage. The browser extension can verify a compatible Studio capability document, but acknowledged capture ingestion, screenshots, and recordings are not implemented. A browser message is not treated as durable delivery.
Operational data
The hosting platform may process standard technical information needed to deliver and secure the service, such as request metadata, timestamps, IP-derived network information, device or browser details, and error logs. SignalFlow does not add advertising trackers in the current product.
Deletion and control
- Delete individual campaigns from the local library.
- Clear the complete browser-local library from Settings.
- Disconnect an official social connector from the Connections page.
- Close the owner session from Settings.
- Clear site data in your browser to remove browser-held SignalFlow data.
Open-source project and questions
SignalFlow Studio is maintained through its public GitHub repository. Privacy questions, security concerns, and correction requests can be raised through the repository issue tracker without posting credentials or sensitive personal data in a public issue.