Legal
Privacy policy
Last updated 26 August 2026
This text describes how lotflows actually works today, and it is published so you can read it before you sign up. It has not been through legal review yet, so read it as a description of our practice rather than as a final agreement.
1. What we collect
Three things. Account data: your email address, the organisation you belong to and your role in it. Usage data: sign-in codes, sessions, IP address and an audit record of actions that change something. Content: the files, catalog data and images you upload, and the messages you send to other users through the product.
2. Why we hold it
To run the service you asked for, to keep accounts secure and abuse detectable, to bill subscriptions, and to send the emails the product needs to send. Where the law requires a legal basis, ours is the contract with you for the service itself, our legitimate interest in security and fraud prevention, and your consent for anything promotional.
3. Sign-in codes and sessions
There are no passwords. Sign-in codes are stored hashed and kept for seven days, because that record is the only way to investigate a disputed sign-in. Sessions that have ended are kept for thirty days so that a question like which device was signed out and when can still be answered, then deleted.
4. Email
Some emails are not optional: sign-in codes, invitations, a notice when your login address is changed, and decisions on an application. They are the only out-of-band signal that something is happening on your account. Everything else — product and marketing email — follows the preferences in your settings, and switching one off means it is not sent.
5. Images and watermarking
Images you upload are stored and resized, and every derivative at 480 pixels or larger carries an invisible watermark so a picture that turns up elsewhere can be traced back. The watermark identifies the source of the image, not the person viewing it.
6. Who else sees it
Other users see exactly what you published to them, and nothing else — which organisation a record belongs to is part of every database query, not a setting. We use a small number of processors to operate the service: email delivery, object storage for images, payment processing for subscriptions, and hosting. We do not sell personal data and we do not share it for advertising.
7. Where it is processed
The service runs in the United States, so data you send us is processed there. If you are in a jurisdiction that restricts transfers, that is the transfer you are agreeing to when you use the service.
8. How long we keep it
Catalog data stays until you delete it or close the account. Audit records of actions are kept because the whole point of an audit trail is that it can be checked afterwards; operational records such as scheduled-job runs are kept for ninety days, and failures are kept longer. Closing an account moves it to a closed state rather than erasing history that other users still legitimately rely on.
9. Your rights
You can ask for a copy of your personal data, ask us to correct it, ask us to delete it, or object to a particular use. Write to the address in the footer from the email address on the account and we will respond within thirty days. If you are in the EU, the UK or Brazil, you also have the right to complain to your local data protection authority.
10. Cookies
The product sets one cookie, and it is the session cookie that keeps you signed in. This website sets none at all. There are no advertising or cross-site tracking cookies anywhere on either.
11. Changes and contact
If we change this policy in a way that matters, we announce it by email rather than only updating the date at the top. The controller responsible for your data, and the contact for privacy requests: «TBD».