Privacy Policy
Last updated: January 18, 2026
1. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Name (optional)
- Profile picture (if using OAuth)
- Payment information (processed securely by Stripe)
Usage Data
We automatically collect:
- Pages visited and features used
- AI generation requests and credit usage
- Browser type and device information
- IP address and approximate location
Content You Create
We store the websites, sections, and components you create using HTFlow to provide the Service and enable features like version history.
2. How We Use Your Information
We use your information to:
- Provide and improve the Service
- Process payments and manage subscriptions
- Send important service updates
- Respond to support requests
- Analyze usage patterns to improve features
- Prevent fraud and abuse
3. AI and Your Data
When you use AI features, your prompts and generated content are processed by our AI providers (OpenAI, Google). We do not use your content to train AI models. Your generated code and designs remain yours.
4. Data Sharing
We share data only with:
- Service providers: Stripe (payments), Supabase (database), Vercel (hosting)
- AI providers: OpenAI, Google (for AI generation)
- Legal requirements: When required by law or to protect rights
We never sell your personal information to third parties.
5. Data Security
We protect your data through:
- Encryption in transit (HTTPS) and at rest
- Secure authentication with OAuth and session tokens
- Regular security audits and updates
- Access controls and monitoring
6. Your Rights
You have the right to:
- Access: Request a copy of your data
- Correction: Update inaccurate information
- Deletion: Request deletion of your account and data
- Export: Download your created content
- Opt-out: Unsubscribe from marketing emails
7. Cookies
We use cookies for:
- Authentication and session management
- Remembering your preferences
- Analytics (anonymized usage data)
You can control cookies through your browser settings.
8. Data Retention
We retain your data while your account is active. After account deletion, we remove personal data within 30 days, except where required for legal or business purposes.
9. Children's Privacy
HTFlow is not intended for users under 13. We do not knowingly collect data from children.
10. International Transfers
Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place.
11. Changes to This Policy
We may update this policy periodically. We'll notify you of significant changes via email or in-app notification.
12. Contact Us
For privacy questions or to exercise your rights, contact us at info@htflow.com