Privacy
Privacy Policy
Last updated September 5, 2026
This Privacy Policy explains how the AtomsFlow website handles personal data. Files and settings in the desktop workbench stay on your device by default. Data on third-party sites or in a system calendar is handled by those services.
1. Data controller
The data controller for the Service is:
- Legal name: AtomsFlow
- Data Protection Officer (DPO): not appointed
- Privacy contact email: [email protected]
2. Data the website handles
Sign-in
When you sign in with Google, GitHub, or email, we keep display name, email, avatar if any, the sign-in method, and a user id. A new email receives a code and we store a hash of the password you set. The code is kept only for a short time and is deleted after it is checked. We do not store the password itself.
Purchases
When you pay, we keep the order, amount, currency, payment channel, session or order id, and entitlement state. We may also keep payment callbacks for posting and reconciliation. Full card numbers and wallet credentials are collected by the processor, not by us.
Logs and cookies
When you visit the website, the server may log IP address, time, request path, and error logs so we can run and debug the site. We use cookies to keep you signed in and to remember language. After you sign in and open the account page, we also keep an anonymous browser id and IP for admin contrast. That record is not counted as an install and is not used for advertising.
Desktop app
Even if you have not signed in, a desktop install may upload hashed device identifiers, a hashed network-interface identifier, system info, the app version, and an IP address. We use this to count installs, debug, and secure the service. It is not used for advertising. After you sign in, that install is linked to your account so we can later tell which desktops belong to the same user.
3. Data on your device
Cabinet files, folder notes, marks, calendar events, webpage entries, and local backups stay on your device. The website does not receive or store that content. If you sync events to a system calendar, that calendar service handles the data.
4. Why we use it
Website data is used to:
- Provide sign-in and the account.
- Check paid status and entry limits on the desktop.
- Post orders.
- Send sign-in codes.
- Run, debug, and secure the website.
- Meet legal duties.
5. Sharing
Only as needed for the feature you use, data is handled by the third party you choose: Google or GitHub for sign-in, the email service that sends codes, and the payment processor shown at checkout.
We do not sell personal data and we do not use it for advertising. We may provide information when the law requires it.
6. How long we keep it
Sign-in codes are deleted when they expire or after they are checked. Account, order, and entitlement records are kept while you use the Service and for any period the law requires. You delete data on the device yourself.
7. Your rights
You may have rights under applicable law to access, correct, or delete personal data. The website does not currently offer self-serve account deletion or a support inbox. Delete desktop data on the device. You may stop using the Service and sign out.
8. Processing outside China
If you sign in with Google or GitHub, or use a payment channel that may operate outside China, those services handle the related data under their own rules and may store it outside China. Whether that happens depends on the sign-in or payment method you choose.
9. Minors
The Service is not directed at people under 18.
10. Changes
We may update this Policy. The version posted on this page is the current one.