This privacy policy explains how ValidFlow collects, uses, stores, and protects your personal and project data. It covers what we access on connected platforms, where data is hosted geographically, and how long it is retained after you stop using the service.
ValidFlow reads metadata from connected platforms: issue fields, board structures, and workflow states from Jira and Monday.com; commit messages, file paths, and authorship records from GitHub and GitLab. We never store source code, diffs, pull request contents, or file contents. All data is primarily processed and stored in the EU at AWS London eu-west-2. Data may be transferred to other countries subject to appropriate safeguards as described in our full privacy policy, encrypted at rest with AES-256 and in transit with TLS 1.2 or higher.
We retain validation results and confidence score history for the duration of your account. When you delete your account, data is removed within thirty days unless longer retention is required for legal or legitimate business purposes. You can request a full data export or permanent deletion at any time by contacting privacy@validflow.co.uk. Deletion requests are processed within thirty calendar days.
ValidFlow does not sell your data or use it for advertising. Data may be shared with essential service providers including AWS for infrastructure, Amazon SES for email, and Stripe for payment processing. Transfers may also occur where required by law, during business transitions, or with your explicit consent. See the full policy for details.