Privacy Policy
Last updated: July 11, 2026
StockFlow ("we", "us", or "our") operates the website stock-flow.io and the StockFlow metadata generation service. This Privacy Policy explains how we collect, use, and protect your personal data, and describes your rights under the General Data Protection Regulation (GDPR), the UK GDPR, and other applicable privacy laws.
1. Information We Collect
We collect the following types of information:
- Account information: Email address and hashed password when you register.
- Payment information: Processed securely by Dodo Payments (our Merchant of Record). We do not store credit card details on our servers.
- Images you upload: Photos and videos are transmitted to our AI service for metadata generation. We do not permanently store your images — they are processed in real time and discarded immediately after metadata is returned.
- Usage data: Number of images processed, plan type, and monthly reset dates — used to enforce plan limits.
- Analytics data: Pages visited, time on site, browser type, approximate location (country/city), and referral source — collected via analytics tools when you consent.
- Advertising data: Ad interactions and conversions (e.g., sign-up or upgrade after clicking an ad) — collected via advertising pixels when you consent.
2. How We Use Your Information
- To create and manage your account
- To process your images and return metadata
- To manage your subscription and billing
- To enforce usage limits based on your plan
- To send transactional emails (account confirmation, billing receipts, password resets)
- To respond to support requests
- To detect fraud and abuse
- To measure and improve our marketing campaigns (with your consent)
- To show relevant ads to people who have visited our website — remarketing (with your consent)
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases to process your personal data:
| Processing Activity |
Legal Basis |
| Account creation and authentication |
Contract performance (Art. 6(1)(b) GDPR) |
| Processing images to generate metadata |
Contract performance (Art. 6(1)(b) GDPR) |
| Subscription billing and payment management |
Contract performance (Art. 6(1)(b) GDPR) |
| Transactional emails (receipts, password resets) |
Contract performance (Art. 6(1)(b) GDPR) |
| Fraud detection and abuse prevention |
Legitimate interest (Art. 6(1)(f) GDPR) |
| Website analytics (Google Analytics) |
Consent (Art. 6(1)(a) GDPR) |
| Advertising pixels and remarketing (Google Ads, Meta Pixel) |
Consent (Art. 6(1)(a) GDPR) |
| Marketing emails |
Consent (Art. 6(1)(a) GDPR) |
| Compliance with legal obligations |
Legal obligation (Art. 6(1)(c) GDPR) |
Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
4. AI Processing of Images
Images you upload are processed by Anthropic's Claude AI to generate metadata (titles, keywords, categories). Images are transmitted securely and are not stored, used for AI training, or shared with third parties beyond what is necessary for the metadata generation request.
5. Third-Party Services
We use the following third-party services, each operating under its own privacy policy:
| Service |
Purpose |
Location |
| Dodo Payments |
Payment processing and subscription management |
United States |
| Anthropic (Claude API) |
AI image analysis and metadata generation |
United States |
| Supabase |
Database and user authentication |
United States |
| Railway |
Cloud hosting and server infrastructure |
United States |
| Zoho Mail |
Customer support email |
United States / EU |
| Google Analytics / Google Ads |
Website analytics and advertising measurement (with consent) |
United States |
| Meta (Facebook) Pixel |
Advertising measurement and audience targeting (with consent) |
United States |
We only share the minimum data necessary for each service to function.
6. International Data Transfers
Our service providers are primarily based in the United States. If you are located in the EEA or the United Kingdom, your personal data may be transferred to and processed in the United States, which may not offer the same level of data protection as your home country.
We rely on the following safeguards for international transfers:
- Standard Contractual Clauses (SCCs): Where applicable, we use the European Commission's approved Standard Contractual Clauses with our US-based processors (Anthropic, Supabase, Railway).
- Adequacy decisions: Where the European Commission has issued an adequacy decision for the destination country or transfer mechanism.
- Processor agreements: Each processor is contractually required to protect your data to standards equivalent to GDPR.
7. Data Retention
We retain your data for the following periods:
- Account data (email, plan, usage count): Retained while your account is active. If you delete your account or request erasure, data is removed within 30 days.
- Uploaded images: Not stored. Discarded immediately after metadata is returned (within seconds of upload).
- Billing records: Retained for 7 years to comply with tax and accounting obligations.
- Support correspondence: Retained for 2 years after the ticket is closed.
- Analytics data: Retained according to the respective service's policy (Google Analytics default: 14 months). Deleted upon account deletion request.
8. Your Rights
Under the GDPR and applicable privacy laws, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request deletion of your personal data, subject to legal retention obligations.
- Right to data portability: Request your data in a machine-readable format.
- Right to restrict processing: Request that we limit how we use your data while a dispute is resolved.
- Right to object: Object to processing based on legitimate interest or for direct marketing purposes. We will stop unless we have compelling legitimate grounds.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect past processing.
- Right to lodge a complaint: You have the right to complain to your local data protection supervisory authority. In the EU, a list of authorities is available at edpb.europa.eu.
To exercise any of these rights, contact us at support@stock-flow.io. We will respond within 30 days.
9. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by law.
- Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
- Notifications will describe the nature of the breach, the data affected, and the steps we are taking to address it.
10. Cookies and Tracking Technologies
We use the following categories of cookies and similar tracking technologies on our website:
- Essential cookies: Required for authentication and to keep you logged in. These cannot be disabled without breaking core functionality. No consent is required for these.
- Analytics cookies: Used to understand how visitors use our website (pages visited, time on site, traffic source). Placed by Google Analytics. Only active after you give consent.
- Advertising cookies: Used to measure the effectiveness of our ads and to serve retargeted ads on Google and Facebook/Instagram. Only active after you give consent.
You can manage your cookie preferences at any time by clearing your browser's local storage for stock-flow.io and reloading the page, which will display the consent banner again. You can also control cookies through your browser settings.
11. Analytics and Advertising Pixels
We may use the following tracking pixels on our public landing page (stock-flow.io). These are only activated after you provide cookie consent:
-
Google Analytics / Google Ads Tag: Collects anonymous data about website visits, page views, and conversions (e.g., when a visitor signs up or upgrades). You can opt out at tools.google.com/dlpage/gaoptout or via Google's Ad Settings.
-
Meta Pixel (Facebook/Instagram): Tracks actions taken on our website (page views, sign-ups, purchases) and sends this data to Meta to measure ad performance and build custom audiences for retargeting. You can opt out at facebook.com/adpreferences.
These pixels are not present in the logged-in application and do not have access to your uploaded images or generated metadata.
12. Remarketing
We may use remarketing features through Google Ads and Meta Ads to display advertisements to users who have previously visited our website. This means that after you visit stock-flow.io, you may see StockFlow ads while browsing other websites, YouTube, Facebook, or Instagram.
Remarketing only runs when you have consented to advertising cookies. You can opt out:
13. Security
All data is transmitted over HTTPS. Passwords are hashed using industry-standard algorithms and never stored in plaintext. Payment data is handled entirely by Dodo Payments and never touches our servers. Access to production data is restricted to essential personnel only.
14. Children's Privacy
StockFlow is not directed to children under 13 (or 16 in certain EU member states). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us at support@stock-flow.io and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice on our website at least 14 days before the changes take effect. The date at the top of this page reflects the most recent update.
16. Contact
For privacy-related questions, requests, or complaints, contact us at:
StockFlow
Email: support@stock-flow.io
We aim to respond to all privacy requests within 30 days.