Privacy

What we collect, and what we don't.

FlowRail reads code before it reaches disk. This is the honest account of what that means for your data. No boilerplate, no claims the product can't back.

Last updated September 29, 2026
01

The short version

FlowRail is a security gate for AI coding agents. To do its job it has to read the code your agent is about to write, so yes, your code leaves your machine. This page is the plain-English version of what that means, scoped to what the product actually does today.

  • Submitted code and specifications are sent over HTTPS to api.flowrail.ai and its configured model providers for analysis. The models and providers can differ between review and verification phases.
  • FlowRail does not store the original source files or specification bodies in its database. It stores review requirements, findings, verdicts, file paths and content fingerprints. These derived records describe your code and design; they are not a promise that no information from your submission is retained.
  • Request and response bodies are not intentionally captured in application logs. Credential-pattern redaction and error scrubbing reduce exposure, but they do not remove every possible code or specification snippet. An unusual exception can include a snippet in hosting logs or, when enabled, error-monitoring traces.
  • No product analytics, no marketing pixels, no ad tech, no data brokers. FlowRail does not train models on your code.
  • Workspace API keys and dashboard tokens are stored as SHA-256 hashes, not as raw secrets.
  • Stripe handles payment details directly on its hosted checkout and billing pages. FlowRail stores account-linked subscription, usage and invoice records separately from workspace review data.
  • You can request deletion of workspace records. Billing records are retained after account or workspace deletion; logs, model-provider data and Stripe data follow the separate handling described below.
FlowRail is a beta product provided by The Everyday Lab LLC. If this page and the product ever disagree, that's a bug. Tell us and we'll fix one of them.
02

What leaves your machine, and when

The installed hooks and tools submit content when your agent performs supported operations. Server-side review and verification jobs can keep processing that submission while the agent waits or retries for the result; this is not a continuous upload of your project.

TriggerWhat is sentWhere it goes
Your agent writes or edits a code fileThe post-edit file content, its path, and the active design-review idapi.flowrail.ai, then the configured model provider or providers
Your agent runs a design review on a specThe spec text plus coarse repo signals: language and framework hints drawn from filenames and package names, never from file contentsapi.flowrail.ai, then the configured model provider or providers
Your agent runs an npm or pip installThe resolved package list as name/version pairs, plus the active design-review idapi.flowrail.ai; a local dry-run also resolves names against whichever package registry your machine is configured to use
A pinned secret pattern matches on a writeA detection id, the file path, the pattern id, and the line numberapi.flowrail.ai. The matched secret itself is never transmitted
A destructive infrastructure call is blockedThe tool, HTTP method, host, path, and which signals matchedapi.flowrail.ai. The raw command, request body, headers, and query string are never sent
Your agent asks for the audit lineageThe design-review id onlyapi.flowrail.ai (no LLM call)

Every request carries your workspace bearer token, so activity is attributed to your workspace and only your workspace.

03

What we store

The event store retains review and verification evidence. Account and billing records are separate. The table below describes event data; it is not a complete list of database tables.

EventPersistedNot persisted
Design review completedReview id, spec path, SHA-256 of the spec, the predicted threat list, approved dependencies, channel allowlistThe original specification body
Verification completedVerification id, file path, SHA-256 of the content, pass/fail status, per-guardrail verdicts with a short reason summaryThe original submitted file body
Dependency install checkedCheck id, the resolved package list (name, version, registry URL), the allow/block verdict, which signals firedNothing
Secret detectedDetection id, file path, pattern id, line numberThe matched secret string
Destructive API blockedBlock id, tool, method, host, path, matched signal kindsThe raw command, request body, headers, query string

Content fingerprints are SHA-256 hashes, not copies of your files. Separately, stored requirements, findings and reason summaries contain derived information about your submission. The original-body storage policy does not make those records anonymous or rule out snippets in exceptional logs.

Account data is separate and minimal: the email address and identity your sign-in provider hands us, your workspace membership, and your API key records. Key material is stored as a hash, so a database snapshot is not a credential dump.

For paid accounts, FlowRail stores the account identifier, Stripe customer and subscription identifiers, subscription and payment status, your managed-usage choice and spending cap, billing periods, usage reservations and charges, and invoice references. These records let us account for completed checks, reconcile payments and avoid duplicate charges. Full card numbers and card security codes are entered on Stripe’s pages, not stored in FlowRail’s billing ledger.

04

How we use it

  • To return a verdict to your agent, which is the entire point of the request.
  • To build the audit lineage you see in the dashboard: which review, which threat, which guardrail, which decision.
  • To enforce per-workspace quotas and catch abuse.
  • To manage subscriptions, enforce your chosen usage limit, account for charges and reconcile invoices and payments through Stripe.
  • To debug failures, using logs governed by the scrub rules described on the security page.

That's the complete list. We don't sell data, share it with advertisers or data brokers, build cross-site profiles, or run product analytics and marketing telemetry. FlowRail does not use your code to train models.

The LLM provider that processes a verification request has its own data-use policy, and FlowRail is a thin client in front of it, so we can't override the terms you or your operator agreed to with that provider. Ask us which backend and model your workspace resolves to and we'll tell you.
05

How long we keep it

DataRetention
Original source and specification bodies in FlowRailProcessed in server memory while analysis runs, including background review or verification jobs. Not stored as original bodies in the database. Derived results and exceptional logs are separate categories below.
Cached analysis resultsDerived verdicts can be reused for an identical check. Cache lifetime depends on the check and configuration; this is separate from retained review evidence.
Event rows (metadata, fingerprints, verdicts)Kept for the life of the workspace, or until you ask for a wipe.
Account and API key recordsKept while the account is active. A revoked key stays as a hashed tombstone so the audit trail stays intact. Financial records are handled separately below.
Billing records (account linkage, subscriptions, usage charges and invoice references)Retained after account or workspace deletion to preserve payment history and settle outstanding charges. A workspace wipe does not delete this financial ledger or records held by Stripe. Contact us about the billing records associated with your account.
Hosting logs and optional error-monitoring tracesAn unusual exception may include a code or specification snippet despite scrubbing. Retention follows the hosting and error-monitoring configuration. Contact us for current deployment settings; this is not a zero-retention guarantee.
06

Who else touches the data

FlowRail runs on a short list of providers. Each is here because the product needs it, not because of a marketing integration.

ProviderWhyWhat it sees
LLM providerRuns the verification and design-review passesSubmitted file or specification content. A router such as OpenRouter and its selected provider may both process a request. Provider retention and data use are governed by the applicable provider terms, not by FlowRail's database policy.
NeonHosts the Postgres database (US East)Stored metadata, content fingerprints, derived review evidence and account-linked billing records. The original source files and specification bodies are not stored here.
Fly.ioRuns the API server and this website (region iad)Request traffic and application logs.
ClerkAuthenticates sign-in to the dashboardYour email address and session.
StripeProcesses paid-pilot subscriptions, payments and invoices, and hosts the billing portalYour account identifier and subscription and usage-charge information from FlowRail, plus the payment and billing details you enter directly on Stripe’s pages. Stripe retains and processes its records under its own privacy policy; a FlowRail workspace wipe does not erase them.
SentryError monitoring, only when a deployment has it configuredScrubbed exception traces when configured. Request bodies and stack-frame local variables are removed, but exception text can still include an unrecognized snippet.

If you need this list inside a vendor questionnaire, write to us and we'll fill it in directly.

07

Cookies

  • The dashboard session cookie is HttpOnly, Secure, SameSite=Strict, and scoped to the dashboard path, so it can't be read by JavaScript and isn't sent on cross-site navigations.
  • The web app sets a sign-in session cookie and a CSRF double-submit cookie. Both are functional; neither tracks you.
  • No analytics cookies, no advertising pixels, no third-party trackers. That's why there's no consent banner on this site.
08

Your choices

  • Wipe: email us to request deletion of workspace review records, dashboard tokens and ordinary contact details. The API key is deactivated and kept as a hashed tombstone. The separate billing ledger and Stripe’s financial records are retained; deletion does not erase invoices or usage charges already incurred.
  • Billing: use Manage billing in Settings → Billing to view invoices, update your payment method or cancel at the end of the paid period. Removing hooks or turning managed usage off does not cancel a subscription. Contact us if you need help canceling before an account deletion.
  • Access: your event history is visible in the dashboard, and the lineage skill returns it from inside the agent.
  • Self-host: run the same container image on your own infrastructure, with your own database and your own model key, and our shared server never sees your code.
  • Turn it off: FlowRail only runs through the hooks the installer writes into your repo. Remove them and nothing is sent.
09

Changes and contact

We update this page when the product changes and move the date at the top. Material changes get an email to workspace owners.

Questions, wipe requests, and vendor-review paperwork go to hello@flowrail.ai. Security reports have their own process. See the security page.