1. Who we are
PersonaFlow (“we,” “us,” or “our”) operates the PersonaFlow platform available at personaflow.appand any associated subdomains or mobile applications (collectively, the “Service”).
PersonaFlow is the data controller for the personal data described in this policy. We are based in Slovenia, European Union, and this policy reflects our obligations under the EU General Data Protection Regulation (GDPR) and applicable Slovenian data protection law.
Contact us at: privacy@personaflow.app
2. Data we collect and why
2.1 Account & identity data
When you register, we collect your name, email address, and a hashed password (if you register with email/password). If you sign in via a social provider (Google, GitHub, Microsoft, LinkedIn, or Discord), we receive your name, email, and profile image from that provider via OAuth. We store the OAuth access and refresh tokens necessary to maintain the connection.
Legal basis: Performance of a contract (GDPR Art. 6(1)(b)) — you cannot use the Service without an account.
2.2 Profile & professional content
You may optionally provide: display name, headline, bio, profession, location, skills, goals, projects, links, profile photo, availability status, calendar booking URL, testimonials, job board listings, social media URLs, GitHub username, and custom domain. This content forms your public PersonaFlow profile page.
We also store profile version snapshots so you can review or restore previous versions of your profile.
Legal basis: Performance of a contract (Art. 6(1)(b)) and your explicit action in providing this content.
2.3 AI-generated content & knowledge documents
When you use AI writing features, your profile data and any text or files you upload as knowledge documents are sent to our AI provider (Groq, operating Llama models) to generate responses. AI generation requests and outputs are logged to track your monthly usage quota. Knowledge documents you upload (name, file type, and content) are stored in our database and used only to answer AI queries on your behalf.
Legal basis: Performance of a contract (Art. 6(1)(b)) — AI features are a core part of the Service you have requested.
2.4 Analytics & profile visitor data
We record events on published profiles (page views, link clicks, project clicks, contact form submissions) to provide profile owners with analytics. Events are associated with the profile owner's account. Visitor IP addresses are not stored; we record only anonymised interaction metadata (event type, path, timestamp, approximate geographic region derived from IP at collection time, referrer URL, and device type).
Legal basis:Legitimate interests (Art. 6(1)(f)) — enabling profile owners to understand their audience is a core feature. Visitors' interests are protected by the anonymisation of IP addresses.
2.5 Lead & contact form data
When a visitor submits the contact form on your public profile, we collect the visitor's name, email address, and message, and store this as a lead associated with the profile owner's account. Profile owners are responsible for handling this data in compliance with applicable law.
Legal basis: Legitimate interests (Art. 6(1)(f)) of the profile owner in receiving professional inquiries.
2.6 Session & technical data
We log your IP address and browser user-agent when you create a session (sign in). Sessions expire automatically. We use essential cookies and secure HTTP-only session tokens to maintain your logged-in state.
Legal basis: Legitimate interests (Art. 6(1)(f)) — securing accounts and preventing unauthorised access.
2.7 Billing & subscription data
Paid subscriptions are processed by Stripe, Inc.We store your Stripe customer ID and subscription ID to manage your plan. We do not store full payment card numbers, CVVs, or bank account details on our servers. Stripe's privacy policy applies to all payment data: stripe.com/privacy.
Legal basis: Performance of a contract (Art. 6(1)(b)) and compliance with legal obligations including VAT/invoicing requirements (Art. 6(1)(c)).
2.8 Integration & webhook data
If you connect Slack, Zapier, or Make.com, we store the webhook URL you provide and log deliveries (event type, destination URL, timestamp, response status). We connect to GitHub on your behalf using OAuth tokens you authorise. Social media profile URLs you add are stored as part of your profile.
Legal basis: Performance of a contract (Art. 6(1)(b)) — you explicitly configure these integrations.
2.9 Referral data
If you were referred by another user, we record the referring user's ID alongside your account to attribute referrals and apply any applicable rewards.
Legal basis: Legitimate interests (Art. 6(1)(f)) in operating a referral programme.
3. Third-party processors
We share personal data with the following processors under data processing agreements:
- Hosting & infrastructure — Vercel Inc. (USA) for application hosting; Neon or Supabase for managed PostgreSQL (EU or USA regions). Data transfers to the USA are covered by Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c).
- AI inference — Groq Cloud (USA) processes prompt data to generate profile copy and assistant responses. Covered by SCCs.
- Payments — Stripe Inc. (USA/EU) for subscription billing.
- Transactional email — Resend Inc. for sending digest emails and notifications.
- File storage — AWS S3 or compatible storage for avatar uploads and knowledge documents.
We do not sell, rent, or trade your personal data to any third party.
4. Public profiles
When you publish your profile, your profile content is publicly accessible at/u/your-username and may be indexed by search engines, embedded on third-party websites, and shared via QR codes or social cards. You control what content is published and can unpublish your profile at any time from your dashboard.
Lead data submitted through your public contact form is stored securely and accessible only to you. We deliver lead notifications to your email or configured webhooks.
5. Data retention
- Account & profile data — retained while your account is active. Upon account deletion, your data is permanently deleted within 30 days, except where we are legally required to retain certain records.
- Analytics events — 7 days on the Free plan; 90 days on Creator; up to 1 year on Pro. Events older than the retention window are automatically deleted.
- AI generation logs — retained for billing and abuse prevention for 90 days, then deleted.
- Session logs — automatically expire and are purged after expiry.
- Billing records — retained for 10 years as required by Slovenian accounting law (ZGD-1).
6. Your rights under GDPR
As a data subject in the EU/EEA, you have the following rights regarding your personal data:
- Right of access (Art. 15) — request a copy of all personal data we hold about you.
- Right to rectification (Art. 16) — correct inaccurate or incomplete data.
- Right to erasure (Art. 17) — request deletion of your data where no legal obligation to retain applies.
- Right to restriction (Art. 18) — ask us to pause processing your data in certain circumstances.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any right, email privacy@personaflow.app. We will respond within 30 days. You also have the right to lodge a complaint with the Slovenian Information Commissioner (Informacijski pooblaščenec): ip-rs.si.
7. Cookies
We use the following cookies:
- Session cookie (strictly necessary) — an HTTP-only, secure cookie that authenticates your session. Without it the Service cannot function.
- Theme preference (functionality) — a localStorage value storing your light/dark mode preference.
We do not use advertising, tracking, or third-party analytics cookies. No cookie consent banner is displayed because our cookies are either strictly necessary or stored in localStorage (not cookies).
8. Security
We apply industry-standard security measures: all data is transmitted over TLS/HTTPS; passwords are hashed with bcrypt; database access is restricted to application services; and OAuth tokens are stored encrypted. We conduct periodic security reviews. Despite these measures, no system is perfectly secure. If you discover a vulnerability, please disclose it responsibly to privacy@personaflow.app.
9. Children
PersonaFlow is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us immediately for deletion.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will notify registered users by email at least 14 days before material changes take effect. The “Last updated” date at the top of this page reflects the most recent revision.
11. Contact
For any privacy-related questions or to exercise your rights:
privacy@personaflow.app
For general support: support@personaflow.app