DESIGNER FLOW CHART Terms Privacy Sign in

Privacy Policy

Effective 7 September 2026 · Version 1.0
1. Who we are2. What this policy covers3. What we collect4. What we do not collect5. Why we collect it6. Your flows and files7. Payments8. Cookies9. Who we share information with10. Overseas storage and disclosure11. How we protect it12. How long we keep it13. Machine learning and analytics14. Getting access to, or correcting, your information15. Complaints16. Data breaches17. Direct marketing18. Children19. If you put other people’s information into a flow20. Changes to this policy21. Contact

In one paragraph. We collect the least we can: an email address, a hashed password, the flows you save, and the records needed to take a payment and answer a question about it. Your card number never reaches us. Your flows are stored under your own account identifier and nobody else can address them. We do not sell your information and we do not use your flows to train machine learning models.

1. Who we are

  1. Designer Flow Chart is supplied by Keo Collective (ABN 78 904 659 362), trading as Designer Flow Charts.
  2. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we handle personal information in accordance with them.
  3. In this policy personal information has the meaning it has in the Privacy Act: information or an opinion about an identified individual, or an individual who is reasonably identifiable.

2. What this policy covers

  1. This policy covers designerflowchart.com, the application served from it, and the emails we send you about your account.
  2. It does not cover any other website you reach from a link on ours, or any other product we supply, each of which has its own policy.
  3. This policy forms part of our Terms of Service and Licence Agreement.

3. What we collect

When you create an account

While you use the Service

When you pay

When you email us

4. What we do not collect

5. Why we collect it

  1. To give you the Service. An email address and a password are how the Service knows which flows are yours and nobody else's.
  2. To take payment and issue a tax invoice. We are required to keep records of the sales we make.
  3. To answer you. If you ask why a payment failed, the event log is the answer.
  4. To keep the Service working and secure — finding faults, stopping abuse, and knowing when something has gone wrong.
  5. To meet our legal obligations, including tax and record-keeping law.

We do not use your information for any other purpose without telling you, unless the Privacy Act allows or requires it.

6. Your flows and files

  1. Your flows and uploaded files are stored in object storage under a prefix built from your own account identifier and nothing else. There is no address another account could ask for that reaches your folder.
  2. We do not read your flows in the ordinary course of running the Service. We would only open one if you asked us to, in order to help you with a problem, or if we were required to by law.
  3. Your flows are not shared with any other user unless you export a file and share it yourself. There is no public link and no shared workspace.
  4. You may export every flow and every generated document at any time, on any plan, in JSON, PNG, SVG, HTML, plain text, Markdown or CSV.
  5. You may delete a flow at any time from the application. Deletion removes it from storage and from the index; it can persist in backups for up to 30 days.

7. Payments

  1. Payments are processed by Stripe. When you pay, you leave our page and complete the payment on a page hosted by Stripe.
  2. Stripe collects and holds your card details under its own privacy policy, at stripe.com/au/privacy. We never receive them.
  3. Stripe tells us, by a signed message to our server, that a payment succeeded, failed, or that a subscription changed. That message carries the account identifier we gave it, so we know whose plan to change.
  4. We keep the payment records we need for tax and accounting purposes for seven years, as Australian law requires.

8. Cookies

  1. We set one cookie: a session token, so you stay signed in. It is HttpOnly, so no script running on the page can read it, and it expires after 30 days or when you sign out.
  2. We set no advertising, tracking or analytics cookies.
  3. The application also stores a few settings in your own browser's local storage — your last drawer width, your numbering prefixes, your chosen shape set. That never leaves your browser and we cannot read it.
  4. Blocking the session cookie will stop you from signing in. Blocking local storage only loses your settings.

9. Who we share information with

We disclose personal information only to the following, and only so far as each needs it:

We do not sell personal information. We do not disclose it for anyone else's marketing.

10. Overseas storage and disclosure

  1. Cloudflare and Stripe are global providers. Your information may be stored or processed outside Australia, including in the United States and the European Union.
  2. By using the Service you consent to that disclosure. Where APP 8.1 requires it, we take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles, including by relying on their published data protection commitments and contractual terms.
  3. We do not otherwise send your information overseas.

11. How we protect it

12. How long we keep it

  1. Your flows and files — while your account is open. Deleted within 30 days of you closing the account.
  2. Your account record — while the account is open, then deleted within 30 days, other than what is needed for the records below.
  3. Payment and tax records — seven years, as Australian tax law requires.
  4. The account event log — 24 months.
  5. Server request logs — as long as our hosting provider keeps them, currently a short rolling window measured in days.
  6. Emails you send us — two years after the matter is closed.
  7. Backups roll over within 30 days, so deleted content can persist in a backup for up to that long before it is gone.

13. Machine learning and analytics

  1. We do not use your flows, your files or your account information to train, fine-tune or evaluate any machine learning model, ours or anyone else's.
  2. The Service has a feature that formats your flow as text you can paste into an AI assistant yourself. That is a file you copy and send; nothing is sent anywhere by the Service.
  3. Any usage counting we do is aggregate — how many accounts, how many flows — and does not identify anyone.

14. Getting access to, or correcting, your information

  1. You may ask us for a copy of the personal information we hold about you, and we will provide it within 30 days.
  2. Most of it you already hold: your email address is on your account, and every flow can be exported from the application at any time.
  3. You may ask us to correct anything that is wrong, and we will correct it or explain why not.
  4. You may ask us to delete your account and its content. We will, within 30 days, except for records we are required to keep.
  5. There is no charge for any of this. We may ask you to confirm you control the email address on the account before we act.
  6. Write to hello@designerflowcharts.com.

15. Complaints

  1. If you think we have mishandled your personal information, write to hello@designerflowcharts.com with the word Privacy in the subject.
  2. We will acknowledge within 5 business days and give you a written answer within 30 days.
  3. If you are not satisfied with our answer you may complain to the Office of the Australian Information Commissioner at oaic.gov.au, or by phone on 1300 363 992.

16. Data breaches

  1. We have a process for assessing a suspected breach of personal information.
  2. Where a breach is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and we will tell you what happened, what information was involved, and what to do about it.
  3. Where a breach is not likely to cause serious harm, we will still tell you if it involved your information.

17. Direct marketing

  1. We send you emails about your own account: sign-up, payments, renewals, failures, and material changes to these documents. Those are not marketing and you cannot opt out of them while the account is open.
  2. If we ever send anything else — a note about a new feature, for example — every one of those emails carries an unsubscribe link and we act on it at once.
  3. We do not give your address to anyone else to market to you.

18. Children

  1. The Service is for business use and is not directed at children. You must be at least 16 to create an account.
  2. If we learn we hold personal information about a child under 16 collected through an account, we will delete it.

19. If you put other people’s information into a flow

  1. A flow can contain other people's names, roles and contact details. Where it does, you are the one who decided to collect them, and you remain responsible for them under the Privacy Act.
  2. We hold that information for you as a service provider. We do not use it for anything except running the Service for you.
  3. You should make sure your own privacy notice tells those people that their information is stored on a hosted service, and that you have a lawful basis for putting it there.
  4. If one of those people asks you to delete their information, delete it from the flow — you can do that yourself at any time.

20. Changes to this policy

  1. The current version is always at designerflowchart.com/privacy and carries the date it took effect.
  2. For a change that materially affects how we handle your information, we will email the address on your account at least 14 days before it takes effect.

21. Contact

Keo Collective (ABN 78 904 659 362), trading as Designer Flow Charts
hello@designerflowcharts.com
Put Privacy in the subject line and it is treated as a privacy request.