AuditFlow logo

AuditFlow

UX Audit Platform

Back to home

AuditFlow

Privacy Policy

Last updated: July 13, 2026

1. Overview

AuditFlow is a workspace for UX audits, product reviews, findings, evidence, client feedback, recommendations, and report generation. This Privacy Policy explains what information we collect, how we use it, and the choices available to you when you use AuditFlow.

By using AuditFlow, you acknowledge that your workspace may include client names, website URLs, screenshots, audit findings, notes, annotations, reports, and comments that you choose to upload or create in the product.

2. Information we collect

Account information: name, email address, login details, authentication events, account settings, subscription status, and related account metadata.

Workspace content: clients, projects, websites, audit types, findings, journeys, steps, recommendations, framework items, evidence files, image annotations, report settings, exported report content, and client portal comments.

Billing information: subscription plan, billing status, payment method details, invoices, receipts, and tax-related billing details. Payments are processed by Stripe. AuditFlow does not store full credit card numbers on its own servers.

Technical information: device and browser details, IP address, pages visited, features used, product interaction events, session diagnostics, error logs, security events, and performance information used to operate, secure, troubleshoot, and improve AuditFlow.

3. How we use information

We use information to create and manage accounts, authenticate users, provide the AuditFlow workspace, save audit content, generate previews and PDF reports, support client portal access, process billing, troubleshoot bugs, improve the security and reliability of our services, prevent fraud and abuse, and communicate important service-related updates.

We also use product usage information, analytics, and aggregated or de-identified data to understand how AuditFlow is used, identify usability issues, improve features and performance, and enhance the overall user experience. We do not use your private client workspaces or personal information for advertising, and we do not sell personal information.

4. Service providers

AuditFlow relies on third-party service providers to operate the product. Supabase provides authentication, database services, and file storage. Vercel provides hosting and deployment infrastructure. Stripe provides payment processing, subscriptions, invoices, and billing-related services. Postmark provides transactional email delivery for account emails, password resets, billing-related messages, and client portal notifications. PostHog provides product analytics and session replay to help us understand how AuditFlow is used, diagnose issues, and improve the product.

These providers may process information only as needed to provide their services to AuditFlow and are subject to their own security, privacy, and compliance practices. Postmark may process email addresses, message content, delivery status, and limited email metadata so that AuditFlow can send transactional and notification emails. PostHog may collect information such as pages visited, feature usage, browser and device information, and session diagnostics. Where enabled, session replay recordings are used to improve usability and troubleshoot technical issues. We configure PostHog to avoid capturing sensitive information such as passwords and take reasonable steps to limit the collection of confidential customer data.

5. Customer content and client data

You are responsible for the client materials and screenshots you upload to AuditFlow. You should only upload content that you have permission to store, review, annotate, and include in reports.

If you invite a client or share a client portal link, you are responsible for making sure the link is shared only with appropriate reviewers. Client portal comments and feedback may become part of your project record.

6. Data sharing

We do not sell personal information. We may share information with service providers that help us operate AuditFlow, comply with legal obligations, enforce our terms, protect the product, investigate abuse, process payments, or complete a business transaction such as a merger, acquisition, or sale of assets.

7. Data retention and deletion

We keep account information and workspace content for as long as needed to provide AuditFlow, comply with legal or billing obligations, resolve disputes, maintain security, and support backups. If you delete content from your workspace, it may take a reasonable period of time for copies to be removed from backups or logs.

You may request access, correction, export, or deletion of your account information using the contact method provided in AuditFlow or on the AuditFlow website. Some information may be retained where required for tax, security, legal, fraud prevention, or legitimate business reasons.

8. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information in AuditFlow. However, no online service can guarantee complete security. You are responsible for using a strong password, protecting your account credentials, and controlling who can access your client portal links.

9. International use

AuditFlow and its providers may process information in the United States and other locations where our service providers operate. By using AuditFlow, you understand that information may be processed outside your state, province, or country.

10. Changes to this policy

We may update this Privacy Policy as AuditFlow changes. The updated date above shows when this page was last revised. Continued use of AuditFlow after an update means you acknowledge the revised policy.