Privacy Policy

Last updated: August 19, 2026

1. Data Ownership & Isolation

You own your data. Supa Flow AI uses a strict multi-tenant architecture. Every record (proposal, invoice, estimate) is tied to your unique user ID. Row-Level Security (RLS) is enforced at the database level to ensure User A can never see User B's data. Even our platform administrators have limited access, protected by secure roles and audit logs.

2. API Keys (BYOK) & Security

Supa Flow AI follows a "Bring Your Own Key" (BYOK) model. Your AI API keys (OpenAI, Anthropic, etc.) are stored using industry-standard encryption at rest. When you execute an AI action, the key is retrieved in a secure server-side environment, used to process your request, and never logged or exposed to the client-side browser.

3. Document Storage & Sharing

Proposals, invoices, and audits are stored in our secure database. While you have private access, you can generate "Public Share Links". These links use a secure, non-guessable token to allow your clients to view documents without an account. You can revoke these tokens at any time.

4. Usage Tracking

We collect minimal usage data to improve the platform and maintain security. We do not sell your personal information. Our business model is based on Lifetime Access sales, not data monetization.