Data Sovereignty & Security Transparency

AetherFlow Privacy Policy

How we protect your workspace configurations, safeguard OAuth credentials, and strictly enforce a zero-model-training architecture across all AI workflow pipelines.

Last Updated: September 17, 2026Version: 2.4GDPR & CCPA Compliant

Executive Summary • Privacy at a Glance

Guaranteed by Contract & Architecture
Strict Guarantee

Zero AI Model Training

We strictly guarantee your workflow graph payloads, user prompts, and execution outputs are NEVER used to train foundational LLMs.

AES-256-GCM

Hardware Secret Encryption

All OAuth 2.0 tokens, API keys, and database credentials are encrypted at rest using AES-256-GCM backed by hardware KMS.

Full Sovereignty

GDPR & CCPA Compliant

Instant data export, complete portability, and permanent workspace deletion rights available through self-serve console controls.

Zero Cross-Leakage

Multi-Tenant Isolation

Workflow execution sandboxes, Redis message queues, and vector namespaces are isolated with strict tenant boundaries.

Section 01Policy Standard

Introduction & Scope

Our commitment to data sovereignty and transparent AI workflow orchestration.

Welcome to AetherFlow AI Studio ("AetherFlow", "we", "us", or "our"). We build modern visual AI orchestration platforms enabling engineering, operations, and product teams to automate stateful workflows, integrate multi-agent cognitive systems, and synchronize Model Context Protocol (MCP) servers.

This Privacy Policy transparently governs how we collect, process, encrypt, and safeguard information when you access our web application, desktop client, APIs, and workflow engine at aetherflow.ai and its subdomains.

By creating an account or using AetherFlow, you acknowledge the processing of information in accordance with this Privacy Policy.

Section 02Policy Standard

Information We Collect

The categories of technical and personal data required to run your workflows.

We minimize data collection strictly to what is necessary to operate our visual workflow engine reliably, secure tenant credentials, and deliver autonomous agent execution.

2.1 Account & Identity Information

When registering, we collect your name, email address, profile avatar, and encrypted authentication tokens provided through OAuth (such as Google Sign-In).

2.2 Workflow Canvas & Node Configurations

We store your visual canvas layouts, node configurations, parameters, connections, variable mappings, and triggers to execute your workflows upon request.

2.3 Connected App Credentials & API Keys

When you connect third-party platforms (e.g., Slack, GitHub, Google Sheets, PostgreSQL, Telegram), we store OAuth access tokens, refresh tokens, and API secrets. All secrets are immediately encrypted at rest using envelope encryption backed by AWS KMS.

2.4 Execution Logs & Runtime Telemetry

During workflow execution, ephemeral runtime logs (node status, latency, error traces) are collected to enable canvas debugging and variable inspection in your execution inspector.

Section 03Policy Standard

AI Processing & Zero-Model-Training Guarantee

Uncompromising commitment: your proprietary data is never used to train LLMs.

AetherFlow connects to commercial and open-source Large Language Models (including OpenAI, Anthropic Claude, Google Gemini, Ollama, and DeepSeek) via secure API endpoints.

We uphold a strict zero-data-retention and zero-model-training standard across all cognitive nodes.

Our Ironclad AI Training Commitment

AetherFlow does not use, sell, or license customer workflow inputs, prompts, document embeddings, or execution outputs to train, fine-tune, or calibrate public or proprietary foundational AI models.

3.1 Direct Enterprise API Ingress

Prompts dispatched through LLM nodes utilize zero-data-retention enterprise endpoints with our foundation model partners.

3.2 Self-Hosted & Local LLM Support

When using our Ollama or custom MCP tool nodes, execution data remains entirely on your infrastructure and never leaves your private perimeter.

Section 04Policy Standard

Third-Party Integrations & OAuth Access

How AetherFlow communicates with external SaaS services with least privilege.

AetherFlow enables automated actions across third-party platforms (Google Workspace, Slack, LinkedIn, YouTube, TikTok, Facebook Pages, WhatsApp).

We request only the minimum required OAuth scopes necessary to execute the specific triggers or actions configured on your canvas.

You can revoke AetherFlow’s access to any external service at any moment via your workspace Connection settings or directly through the third-party provider console.

Section 05Policy Standard

Security Architecture & Cryptography

Defense-in-depth infrastructure protecting your secrets and workflows.

Security is central to our system design. We employ industry-standard administrative, physical, and cryptographic controls to protect against unauthorized access, loss, or alteration.

5.1 Cryptography at Rest & in Transit

All network communication is strictly enforced over TLS 1.3. Credentials, database connection strings, and webhook signing secrets are encrypted at rest with AES-256-GCM.

5.2 Execution Sandboxing

Custom code execution (JavaScript / Python VM nodes) runs inside isolated ephemeral sandboxes with strict memory and CPU quotas, preventing cross-tenant memory leakage.

Section 06Policy Standard

Data Retention & Automated Purge

Configurable log retention and complete 1-click workspace erasure.

We retain your account and workflow data for as long as your workspace remains active. You can customize the retention window for detailed execution traces (e.g., 7 days, 30 days, or 90 days).

Upon workspace deletion, all associated workflows, node configurations, vector embeddings, and encrypted credentials are systematically and irrevocably purged from active databases within 14 days.

Section 07Policy Standard

Your Global Privacy Rights (GDPR & CCPA)

Full autonomy over your personal data under global data protection laws.

Regardless of your geographic location, AetherFlow grants comprehensive privacy rights to all registered users:

• Right to Access: Request a machine-readable export of all account and workflow data.

• Right to Rectification: Correct any inaccurate personal or billing information.

• Right to Erasure ("Right to Be Forgotten"): Permanently delete your user profile and all workspaces.

• Right to Restrict & Object: Object to automated telemetry processing or withdraw marketing consents.

• Non-Discrimination: We will never discriminate against you for exercising your privacy rights.

Section 08Policy Standard

Cookies & Local Storage Usage

Transparent disclosure of all client-side storage mechanisms.

We use cookies and HTML5 localStorage exclusively to maintain secure authentication sessions, preserve canvas preferences, and collect anonymous system telemetry.

Cookie NameCategoryDurationPurpose
af_sessionEssential30 daysMaintains authenticated session state and workspace tokens securely.
af_themeFunctional1 yearStores visual theme preferences (Light / Dark mode).
af_canvas_prefsFunctional6 monthsRemembers canvas zoom, grid snap, and minimap toggle settings.
ph_opt_inAnalytics1 yearTelemetry flag for anonymous UI performance and error diagnostic metrics.
Section 09Policy Standard

Authorized Infrastructure Sub-Processors

Audited cloud providers powering our reliable high-availability stack.

To provide our global platform, AetherFlow engages carefully vetted third-party sub-processors compliant with SOC 2 Type II and ISO 27001 standards.

Sub-ProcessorPurposeEntity LocationData Processed
Amazon Web Services (AWS)Cloud compute, workflow sandbox execution, and KMS encryptionUnited States & EUEncrypted workflow graphs, execution logs
Google Cloud Platform (GCP)Identity management, OAuth validation, and object storageUnited States & EUUser profile metadata, encrypted assets
MongoDB AtlasPrimary persistent database for workflows and workspace metadataUnited States & EUUser accounts, workflow canvas JSON, team configs
Redis CloudHigh-throughput event queues, rate limiting, and execution statesUnited States & EUTransient workflow run jobs, active execution tokens
Qdrant CloudVector similarity search for Knowledge RAG nodesUnited States & EUVector embeddings and indexed document chunks
PostHog Inc.Product analytics, performance telemetry, and error monitoringEU (Frankfurt)Anonymized page views, UI feature usage telemetry
Section 10Policy Standard

International Transfers, Minors & Policy Changes

Standard contractual clauses, child privacy protection, and update protocols.

Cross-Border Transfers: When data is transferred outside the European Economic Area (EEA), we rely on European Commission-approved Standard Contractual Clauses (SCCs) to ensure equivalent protection.

Children’s Privacy: AetherFlow is strictly designed for enterprise and professional use. We do not knowingly collect personal data from individuals under 16 years of age.

Policy Updates: When material revisions are made to this policy, we notify active workspace owners via in-app banner and email 14 days prior to effective changes.

Section 11Policy Standard

Contact Information & Data Protection Officer

Direct lines to our dedicated security and privacy compliance officers.

If you have questions, feedback, or wish to exercise your statutory privacy rights, our Data Protection Officer is readily available:

• Email: privacy@aetherflow.ai

• Security Escalations: security@aetherflow.ai

• Mailing Address: AetherFlow AI Studio Inc., Attn: Privacy & Data Protection Officer, 548 Market St, Suite 39201, San Francisco, CA 94104, USA.