Legal
Privacy Policy
Last updated: March 10, 2026
1. Data Controller
Flowstep OÜ ("the Company," "we," "us," or "our") (Tartu maantee 25, Floor 4, 10151 Tallinn, Estonia) is the data controller for personal data processed through flowstepai.org. Flowstep turns written design briefs into token-aligned, editable interface mockups for product designers and design system teams. You can contact us at [email protected] for any data-protection matter, including to exercise the rights described below.
2. Personal Data We Process
When you use Flowstep we process the following categories of personal data:
- Identity and contact data you submit (name, email address, employer, role);
- Account credentials (hashed password, authentication tokens);
- Design briefs and prompt text you submit to generate interface mockups;
- Design system token files you upload (JSON token files, Figma Tokens plugin exports, Tokens Studio JSON): these are processed solely to resolve your brief against your own design system and produce the requested output;
- Communications content (support messages, early-access program correspondence);
- Technical data collected automatically (IP address, browser type, operating system, pages visited, session duration);
- Usage and analytics data, where you have given your prior consent through our cookie banner.
We do not use the content of your design briefs or design token files to train our AI models without your explicit written consent.
3. Purposes and Legal Bases (Article 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the Service: receiving your design brief, resolving it against your token files, generating mockup outputs | Performance of contract / pre-contract steps (Art. 6(1)(b)) |
| Account management, authentication, and communications about your use of Flowstep | Performance of contract (Art. 6(1)(b)) |
| Responding to your inquiries and support requests | Pre-contract steps / legitimate interest (Art. 6(1)(b)/(f)) |
| Operating and securing the Service (fraud prevention, abuse detection, server logs) | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance and responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
| Analytics cookies to measure how designers use the brief-to-screen workflow | Consent (ePrivacy Directive + Art. 6(1)(a)) |
4. Recipients and Transfers
Personal data is shared only with processors acting on our behalf under Article 28 GDPR data-processing agreements (for example, cloud infrastructure providers (hosting, object storage), email delivery services, and analytics vendors). We do not share your design briefs or token files with third parties for their own commercial purposes.
Where data is transferred outside the EU/EEA (for example to sub-processors located in the United States), we rely on Standard Contractual Clauses approved under Article 46 GDPR and assess additional safeguards as required by the Schrems II ruling (Case C-311/18).
5. Retention
We retain personal data only for as long as necessary for the purposes described. Inquiry-form and support data is retained 24 months after last contact. Design brief content and token file uploads are retained for the duration of your active account and for a reasonable period following account closure to allow dispute resolution. Server access logs are retained 90 days.
6. Your GDPR Rights
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
- Right of access (Art. 15): you may confirm whether we process your data and obtain a copy;
- Right to rectification (Art. 16): you may have inaccurate data corrected;
- Right to erasure / "right to be forgotten" (Art. 17): you may request deletion, subject to limited exceptions (for example, where retention is required by law);
- Right to restriction of processing (Art. 18): you may request that we limit processing while a dispute is resolved;
- Right to data portability (Art. 20): you may receive your data in a structured, machine-readable format;
- Right to object (Art. 21): you may object to processing based on legitimate interests, including direct marketing without further conditions;
- Right not to be subject to automated decision-making (Art. 22): we do not engage in automated decision-making with legal or similarly significant effects.
To exercise any of these rights, email [email protected]. We respond within one month, extendable by two further months for complex or numerous requests (we will inform you if an extension is needed).
7. Right to Lodge a Complaint
You have the right to lodge a complaint with your national supervisory authority under Article 77 GDPR. Because Flowstep OÜ is established in Estonia, the lead supervisory authority for Flowstep is the Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate), reachable at www.aki.ee. If you are resident in another EU/EEA member state, you may also contact your local data protection authority. A full list of EU/EEA supervisory authorities is available at edpb.europa.eu.
8. Cookies
See our Cookie Policy. Non-essential cookies (analytics, preferences) are not set without your prior consent under the ePrivacy Directive.
9. Security
We implement technical and organisational measures appropriate to the risk, including TLS encryption in transit, encrypted storage, restricted internal access, and regular security review. No transmission over the internet is completely secure; if you have reason to believe your interaction with us has been compromised, please contact [email protected] immediately.
10. Changes
Material changes will be reflected by an updated "Last updated" date at the top of this page. Where required under GDPR, we will request renewed consent.
11. Contact
Flowstep OÜTartu maantee 25, Floor 4, 10151 Tallinn, Estonia
Email: [email protected]
Phone: +372 622 7140