Privacy Policy
Effective 7 September 2026 · Version 1.0
In one paragraph. We collect the least we can: an email address, a hashed password, the
flows you save, and the records needed to take a payment and answer a question about it. Your card
number never reaches us. Your flows are stored under your own account identifier and nobody else
can address them. We do not sell your information and we do not use your flows to train machine
learning models.
1. Who we are
- Designer Flow Chart is supplied by Keo Collective (ABN 78 904 659 362), trading as Designer Flow Charts.
- We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we
handle personal information in accordance with them.
- In this policy personal information has the meaning it has in the Privacy Act:
information or an opinion about an identified individual, or an individual who is reasonably
identifiable.
2. What this policy covers
- This policy covers designerflowchart.com, the application served from it, and the emails we
send you about your account.
- It does not cover any other website you reach from a link on ours, or any other product we
supply, each of which has its own policy.
- This policy forms part of our Terms of Service and Licence Agreement.
3. What we collect
When you create an account
- your email address;
- a one-way cryptographic hash of your password, together with the random salt used to make it;
- the date the account was created.
While you use the Service
- the flows you save, and any images or files you attach to them;
- the name, size and last-changed time of each saved flow;
- a session token in a cookie, so that you stay signed in;
- a short event log of things that matter to your account — signing in, a plan changing, a
payment succeeding or failing — with the time it happened;
- ordinary web server request records held by our hosting provider, which include IP address,
browser type and the page requested.
When you pay
- an identifier from our payment processor that links your account to your subscription;
- your plan, your billing cycle, whether it is active, and when it next renews;
- the name and billing address you give the payment processor, where it passes them to us for
the tax invoice.
When you email us
- your email address and whatever you write to us, kept so that we can answer and so that we have
a record of what was asked and what we said.
4. What we do not collect
- We do not collect or store your card number, expiry or security code. Those go directly to our
payment processor and never pass through our systems.
- We do not run advertising trackers, social media pixels or third-party analytics scripts on
designerflowchart.com.
- We do not ask for your date of birth, your government identifiers, or any sensitive information
as that term is defined in the Privacy Act.
- We do not buy personal information about you from anyone else, and we do not build a profile of
you from outside sources.
5. Why we collect it
- To give you the Service. An email address and a password are how the Service knows which
flows are yours and nobody else's.
- To take payment and issue a tax invoice. We are required to keep records of the sales we
make.
- To answer you. If you ask why a payment failed, the event log is the answer.
- To keep the Service working and secure — finding faults, stopping abuse, and knowing
when something has gone wrong.
- To meet our legal obligations, including tax and record-keeping law.
We do not use your information for any other purpose without telling you, unless the Privacy Act
allows or requires it.
6. Your flows and files
- Your flows and uploaded files are stored in object storage under a prefix built from your own
account identifier and nothing else. There is no address another account could ask for that reaches
your folder.
- We do not read your flows in the ordinary course of running the Service. We would only open one
if you asked us to, in order to help you with a problem, or if we were required to by law.
- Your flows are not shared with any other user unless you export a file and share it yourself.
There is no public link and no shared workspace.
- You may export every flow and every generated document at any time, on any plan, in JSON, PNG,
SVG, HTML, plain text, Markdown or CSV.
- You may delete a flow at any time from the application. Deletion removes it from storage and
from the index; it can persist in backups for up to 30 days.
7. Payments
- Payments are processed by Stripe. When you pay, you leave our page and complete the payment on
a page hosted by Stripe.
- Stripe collects and holds your card details under its own privacy policy, at
stripe.com/au/privacy. We never receive them.
- Stripe tells us, by a signed message to our server, that a payment succeeded, failed, or that a
subscription changed. That message carries the account identifier we gave it, so we know whose plan
to change.
- We keep the payment records we need for tax and accounting purposes for seven years, as
Australian law requires.
8. Cookies
- We set one cookie: a session token, so you stay signed in. It is HttpOnly, so no script running
on the page can read it, and it expires after 30 days or when you sign out.
- We set no advertising, tracking or analytics cookies.
- The application also stores a few settings in your own browser's local storage — your last
drawer width, your numbering prefixes, your chosen shape set. That never leaves your browser and we
cannot read it.
- Blocking the session cookie will stop you from signing in. Blocking local storage only loses
your settings.
9. Who we share information with
We disclose personal information only to the following, and only so far as each needs it:
- Cloudflare — hosting, storage, database and network. It holds the flows, the account
records and the server logs.
- Stripe — payment processing, subscription management, tax invoices and refunds.
- Our email provider — to send account and payment emails to you.
- Our professional advisers — accountants and lawyers, where they need it and under a duty
of confidence.
- A purchaser of our business, if we sell it, on the same terms as this policy.
- Anyone we are required to disclose to by law, or where the Privacy Act permits it.
We do not sell personal information. We do not disclose it for anyone else's marketing.
10. Overseas storage and disclosure
- Cloudflare and Stripe are global providers. Your information may be stored or processed
outside Australia, including in the United States and the European Union.
- By using the Service you consent to that disclosure. Where APP 8.1 requires it, we take
reasonable steps to ensure overseas recipients handle your information consistently with the
Australian Privacy Principles, including by relying on their published data protection commitments
and contractual terms.
- We do not otherwise send your information overseas.
11. How we protect it
- Passwords are never stored. We store a PBKDF2-SHA256 hash with 150,000 iterations and a random
per-account salt, which cannot be turned back into the password.
- The session cookie is HttpOnly and is sent only over HTTPS.
- Everything between your browser and us travels over HTTPS.
- Every storage key and every database query is built from the signed-in account's own identifier,
so one account cannot address another's data.
- Payment messages from Stripe are verified by signature before we act on them, and each message
is acted on only once.
- Access to the production systems is limited to us.
- No system is perfectly secure. We take reasonable steps for the size of what we hold, and we
tell you promptly if something goes wrong — see clause 16.
12. How long we keep it
- Your flows and files — while your account is open. Deleted within 30 days of you closing
the account.
- Your account record — while the account is open, then deleted within 30 days, other than
what is needed for the records below.
- Payment and tax records — seven years, as Australian tax law requires.
- The account event log — 24 months.
- Server request logs — as long as our hosting provider keeps them, currently a short
rolling window measured in days.
- Emails you send us — two years after the matter is closed.
- Backups roll over within 30 days, so deleted content can persist in a backup for up to that
long before it is gone.
13. Machine learning and analytics
- We do not use your flows, your files or your account information to train, fine-tune or
evaluate any machine learning model, ours or anyone else's.
- The Service has a feature that formats your flow as text you can paste into an AI assistant
yourself. That is a file you copy and send; nothing is sent anywhere by the Service.
- Any usage counting we do is aggregate — how many accounts, how many flows — and does not
identify anyone.
14. Getting access to, or correcting, your information
- You may ask us for a copy of the personal information we hold about you, and we will provide it
within 30 days.
- Most of it you already hold: your email address is on your account, and every flow can be
exported from the application at any time.
- You may ask us to correct anything that is wrong, and we will correct it or explain why not.
- You may ask us to delete your account and its content. We will, within 30 days, except for
records we are required to keep.
- There is no charge for any of this. We may ask you to confirm you control the email address on
the account before we act.
- Write to hello@designerflowcharts.com.
15. Complaints
- If you think we have mishandled your personal information, write to
hello@designerflowcharts.com with the word Privacy in the subject.
- We will acknowledge within 5 business days and give you a written answer within 30 days.
- If you are not satisfied with our answer you may complain to the Office of the Australian
Information Commissioner at oaic.gov.au, or by phone on
1300 363 992.
16. Data breaches
- We have a process for assessing a suspected breach of personal information.
- Where a breach is likely to result in serious harm, we will notify you and the Office of the
Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and we will
tell you what happened, what information was involved, and what to do about it.
- Where a breach is not likely to cause serious harm, we will still tell you if it involved your
information.
17. Direct marketing
- We send you emails about your own account: sign-up, payments, renewals, failures, and material
changes to these documents. Those are not marketing and you cannot opt out of them while the
account is open.
- If we ever send anything else — a note about a new feature, for example — every one of those
emails carries an unsubscribe link and we act on it at once.
- We do not give your address to anyone else to market to you.
18. Children
- The Service is for business use and is not directed at children. You must be at least 16 to
create an account.
- If we learn we hold personal information about a child under 16 collected through an account,
we will delete it.
19. If you put other people’s information into a flow
- A flow can contain other people's names, roles and contact details. Where it does, you are the
one who decided to collect them, and you remain responsible for them under the Privacy Act.
- We hold that information for you as a service provider. We do not use it for anything except
running the Service for you.
- You should make sure your own privacy notice tells those people that their information is
stored on a hosted service, and that you have a lawful basis for putting it there.
- If one of those people asks you to delete their information, delete it from the flow — you can
do that yourself at any time.
20. Changes to this policy
- The current version is always at designerflowchart.com/privacy and carries the date it took
effect.
- For a change that materially affects how we handle your information, we will email the address
on your account at least 14 days before it takes effect.
21. Contact
Keo Collective (ABN 78 904 659 362), trading as Designer Flow Charts
hello@designerflowcharts.com
Put Privacy in the subject line and it is treated as a privacy request.