Browserflow policy · Version 2026-10-01.4
Privacy Policy
Your account details, onboarding choices, saved flows, login profiles, settings and run results are stored on the server hosting Browserflow. Execution history may include page content, screenshots and technical logs. Passwords are stored as salted hashes. Login profiles, API keys and queued inputs are encrypted. Flow definitions, history and completed results may contain readable data in the workspace database. Do not include data you are not entitled to process. Construction drafts, including unfinished setup and editor fields and intermediate recorder steps, are saved automatically. Construction history snapshots are encrypted in the workspace.
How your data is used
Browserflow uses this data to authenticate you, operate your workspace, execute your requested workflows, provide support and protect the service. Workspace data is separated by account; the server operator has access to the host and stored data. Shared listing names, descriptions, creator profiles and other public listing information can be viewed by visitors. Shared template definitions may also be displayed publicly on the Browserflow website, including to visitors who are not signed in. Signed-in users can obtain and copy shared templates. Review all content before publication.
Browserflow’s responsibilities for its own account and service data and its responsibilities when processing workflow data on your behalf depend on the actual processing and applicable law. Where required, processing on your behalf must be governed by an appropriate data processing agreement. Your acceptance of these Terms is not blanket consent for unrelated processing of personal data.
Authorised Browserflow administrators can review construction activity per account, including entered non-secret values, drafts, saved flows, published versions and timestamps, to understand how the builder is used and improve the platform. Password fields, declared secret defaults, API credentials and saved login cookies are excluded from this review interface. Do not place credentials in ordinary text fields. This internal review does not send workflow content to advertising or analytics providers.
Retention & data requests
Stored data is retained until removed through the applicable feature, a supported cleanup process or an account-level request; not all data has automatic expiry. You can remove flows, login profiles and your marketplace listings. Removing a flow or profile does not automatically erase prior results, independent marketplace copies or backups. Any continued retention remains subject to applicable data protection requirements.
Contact [email protected] for access, correction or deletion requests, or to exercise applicable rights to restriction, objection or portability. You may also complain to the competent data protection authority. Information may need to be retained for legal obligations, security or resolving disputes, within applicable limits.
Additional construction history is retained for up to 30 days, with a rolling ceiling of 2,000 changes or 64 MB per workspace; older entries may therefore expire earlier. Workspace storage limits can shorten this history further, and an individual snapshot that cannot fit within the record or workspace limit is omitted so ordinary workspace use can continue. Unfinished setup and editor drafts expire after 30 days without updates. Cleanup runs periodically. Deleting a flow does not immediately erase its recent construction history. Current saved flows and published versions are not subject to this additional history window. Backups follow their separate retention schedule.
Third-party service providers
Browserflow uses third-party providers to operate and support the service, including when you use Browserflow default for browser connectivity or AI. These default connections are selected and managed by Browserflow and use external network, VPN or proxy services and an external large language model (LLM) provider, respectively. Depending on the features and services used, these may include hosting and cloud infrastructure, storage and backups, network connectivity, VPN, proxy and routing services, payment processing, authentication, service communications and customer support, security and operational monitoring, and AI services. Providers receive or process only the account, billing, technical or workflow data needed for their relevant function; use of a provider does not mean that every provider receives all your data.
Network, VPN, proxy and routing providers carry browser traffic and may process connection information, such as network addresses, destinations, timestamps and traffic volumes. Their access to traffic content depends on the connection, protocol and encryption in use. Third-party websites receive the requests and data sent by your workflows and apply their own privacy practices. This also applies when you configure your own supported proxy or VPN gateway. Using your own connection does not stop Browserflow from processing the workflow data needed to operate the browser session. Connections, integrations or AI providers you configure are also subject to the relevant provider’s terms and data practices.
When you authorise an external application or AI assistant through an API, MCP or another supported integration, it can receive workflow information, run status and results within its granted access. For MCP, this includes enabled workflows and the output fields selected for sharing. The external application processes the information you submit to it and the data it receives under its own privacy practices; disconnecting it does not delete copies it already holds. Review the access and data you make available before connecting.
Browserflow default uses a third-party large language model (LLM) provider selected and configured by Browserflow. When AI-assisted features are used, relevant workflow instructions, page context, technical errors and screenshots may be sent to that provider, or to your own AI provider if you have selected one. Masking and filtering do not guarantee that all sensitive information is removed. Only use these features with data you are entitled to send to that provider and review the provider settings for your intended use.
Browserflow remains responsible for its applicable obligations when selecting and using its own providers, including appropriate processing agreements, security safeguards and requirements for international data transfers. These provider categories are not permission to disclose data for unrelated purposes. Material changes to the described processing will be reflected in this privacy notice, with any additional information, notice or consent required by law.