Privacy Policy
BalanceFlow Privacy Policy
Effective date: 1 September 2026
This Privacy Policy explains how personal data is handled when you visit the public website at balanceflow.cloud, register or sign in through app.balanceflow.cloud, use BalanceFlow, subscribe, or contact us. It also explains the different role we may have when a business uploads information about its own customers. Read it alongside our Terms of Service and Cookie Policy.
1. Who is responsible
BalanceFlow is operated by Raman Miura, Mieczysława Karłowicza 14 30-047 Kraków, NIP: 6772465624 (“BalanceFlow”, “we”, “us”). For personal data used to operate accounts, billing, the website, security, and support, we are the data controller. Contact us about privacy at [email protected].
Where a business customer supplies personal data about other people in files for conversion or transformation on its instructions, that customer generally decides why and how that data is used and acts as its controller; BalanceFlow acts as its processor for that processing. This policy describes our practices but does not replace the customer's own privacy notice or a required data processing agreement (DPA). If your business needs a DPA, email [email protected] and have the DPA accepted or signed by both parties before uploading personal data requiring processing under it. Sending a request alone does not put a DPA in place.
2. What information we handle
-
Account and workspace information: name if provided, email address, login identifiers, authentication method, workspace memberships and roles, preferences, and account activity.
-
Conversion information: input files and their contents, template and mapping selections, rules, conversion status and history, resulting output files, and records of successful usage. Files may contain transaction information and personal data about your customers, payers, or other people. You decide which files to supply.
-
Billing information: BalanceFlow uses plan, subscription and payment status and Stripe transaction identifiers to manage paid access. Stripe processes payments and holds customer invoices and full payment-card details; the BalanceFlow app does not collect or store full card details or invoice copies. Billing and accounting records may be retained separately where required by law.
-
Technical and security information: IP address, timestamps, browser and device details, request and error logs, security events, and cookie or similar technology identifiers. We use Sentry for limited reports of unhandled backend exceptions and two backend processing metrics: conversion job duration on success or failure, and lifecycle counts for jobs starting, succeeding or failing. Those metrics carry environment, job type and outcome attributes, without account or file identifiers. We do not use its browser SDK. The backend integration has default personal data reporting, request-body capture, logs, performance traces and profiling disabled. We remove Cloudflare-prefixed request headers from Sentry error events; IP-bearing headers such as X-Forwarded-For are filtered. Error reports can include request and referring URLs containing workspace, conversion or template identifiers, browser details, and exception messages or stack traces that may contain database query values, including identifiers linking a workspace to a user. These reports may therefore contain personal data even though Sentry’s default personal-data option is off. We do not intentionally send uploaded files, generated files or their contents as attachments or request bodies.
-
Communications: messages to support, related attachments, and our responses.
-
Legal-document acceptance records: user ID, a reference to the document record and its legal version, acceptance time, IP address, user agent, and record timestamps.
-
Analytics information: Google Analytics is used on the public website at balanceflow.cloud with its standard measurement setup to understand website visits and page views. Google Analytics is not installed on app.balanceflow.cloud, including its registration and sign-in forms and signed-in pages.
If you choose Sign in with Google, we request only the openid, email and profile scopes. Google provides a Google account identifier, email address and basic profile details made available through those scopes. We use that information to create or identify your BalanceFlow account and let you sign in. Our user account record stores your name, email address and Google account identifier for this purpose while your account exists, subject to the account deletion and backup rules below. Our hosting provider processes those details to operate the service; we do not use Google sign-in information to send marketing unless you separately opt in. We do not import or store your Google profile photo.
Some information comes directly from you; sign-in and payment providers may provide account identifiers or payment status. Workspace owners or members may invite you and provide your email address. We may receive support information from someone contacting us on your behalf.
3. Why we use information and our legal grounds
| Purpose | Typical information | Legal basis when we act as controller |
|---|---|---|
| Create accounts, authenticate users, provide conversions and manage subscriptions | Account, workspace, conversion metadata, subscription status | Performance of a contract or steps requested before one |
| Process payments, keep invoices and required financial records | Billing and transaction information | Performance of a contract and compliance with legal obligations, depending on the activity |
| Answer questions and provide support | Contact information, messages, account details needed to investigate | Performance of a contract or legitimate interests in responding and improving support; legal obligation where applicable |
| Protect accounts and service, investigate misuse and maintain essential logs | Login events, IP addresses, logs and security data | Legitimate interests in service security and preventing abuse; legal obligation where applicable |
| Diagnose unhandled backend errors and monitor processing | Exception reports, which may include request URLs, record or workspace identifiers, browser details and error details, and limited backend metrics sent to Sentry | Legitimate interests in maintaining a reliable and secure service |
| Understand use of the public website through Google Analytics | Public-site visits, page views and data collected by the enabled standard measurement settings; | Consent |
| Send product updates and marketing emails to people who opt in | Email address and marketing preference | Consent given through an optional checkbox during registration; it can be changed in profile settings |
Our legitimate interests are the security, reliability and improvement of BalanceFlow and responding to requests; where we rely on them, we consider your interests and rights. For content processed on a business customer's instructions as its processor, the customer is responsible for identifying its own lawful basis and giving any required notice to the people whose data it provides.
An email address and authentication details are needed to create an account; some billing details are needed to buy a paid plan. Without them we cannot provide the relevant feature. Supplying files is optional, but a conversion cannot run without the data needed for that conversion.
4. Uploaded files, generated files, and deletion
Input files are stored separately while processing and deleted after processing finishes; they cannot be downloaded through BalanceFlow. Keep your own copies. Generated output files are stored and available for download for 14 days after a conversion finishes successfully, including to authorized users of the workspace where the conversion record was created. After 14 days, those output files are no longer available, while the conversion record remains viewable. You can delete your own conversion records using the delete control next to each record. When you delete a record, any files still stored for that conversion are deleted from active server storage. These statements reflect the Terms and must match the released implementation.
Cancelling a paid subscription moves the account to the Free plan when paid access ends; it does not delete the account or conversion records. If you request account closure by emailing [email protected], we delete all records you created, including those in workspaces owned by other users. We also delete all records in workspaces you own, including records created there by other members. This includes conversion records, templates, rules and any associated stored files. Deleted records cease to be available to other workspace members.
We host the app and database in DigitalOcean's NYC1 region in the United States and store database backups in the same region. We create database backups weekly and retain the four most recent versions, replacing the oldest backup when a new one is made. Backups may contain account, workspace and conversion records, but do not contain uploaded input files or generated output files. A record deleted from the active database may remain in a backup for up to approximately four weeks before that backup is replaced. If an older database backup is restored, previously deleted records contained in that backup may also be restored. Information we must retain for legal reasons, such as billing records, may remain after account closure; access to it will be limited to those purposes. We normally complete requested account closure and deletion from the active database within five working days after verifying the requester's identity. If we need more time or cannot delete particular records, we will explain why and respond within the period required by applicable law.
Uploaded files are processed on our server using predefined conversion rules and algorithms. We do not send uploaded files or generated output files to an AI provider or use their contents to train AI models.
5. How long we keep other information
We retain account and workspace data while the account exists, then delete or deidentify it according to the account-closure process, subject to legal obligations and the database backup cycle described above. Conversion records persist until the user deletes them or account closure removes them, subject to the rules above. Routine application, access and security logs are normally kept for up to 30 days. Only the database is backed up; server log files are not included in those backups. Logs relevant to a security incident or legal claim may be retained longer as needed for that purpose. Sentry retains backend error events and processing metrics for 30 days under its Developer plan, including after a related BalanceFlow account is deleted, unless an applicable deletion request is fulfilled sooner. Support emails, their attachments and our responses are normally deleted within 30 days after the last message in the support thread, unless needed longer for an unresolved issue, legal obligation or claim. We set Google Analytics' user-level and event-level data retention to 14 months to compare public-site trends during our product discovery period; aggregated reports may remain available longer. Stripe stores the payment and invoice records described above. Stripe explains its own retention practices in its Privacy Policy. We retain our billing and tax records for the periods required by Polish tax and accounting law. For most tax-related documents, this is five years from the end of the calendar year in which the relevant tax payment was due; a longer period may apply in particular circumstances. We may also retain limited information where necessary for an existing legal claim.
6. Who receives information
We make data available to authorized workspace members according to workspace permissions. At launch, the providers used to operate BalanceFlow include DigitalOcean for hosting, Cloudflare for traffic protection and security, Stripe for payments, Google for sign-in and public-site Analytics, Google Workspace for support email, Resend for automated email delivery, and Sentry for backend exception reporting and limited backend metrics. Cloudflare Web Analytics is disabled. Providers receive information needed for their roles and may act as processors or independent controllers depending on the service. We may disclose information when required by law or necessary to establish or defend legal claims, and in a business transfer subject to applicable safeguards. We do not sell personal data.
7. Processing outside the EEA
BalanceFlow's app, database and database backups are hosted in DigitalOcean's NYC1 region in the United States. DigitalOcean's Data Processing Agreement is incorporated into its customer terms. For transfers covered by that agreement, DigitalOcean relies on its EU–US Data Privacy Framework certification, with EU Standard Contractual Clauses as a fallback if that framework is invalidated or its certification lapses. Our Sentry organization stores backend error events and processing metrics in the United States. Sentry's published Data Processing Addendum identifies the EU–US Data Privacy Framework for transfers it covers and EU Standard Contractual Clauses when that framework is invalidated or does not apply. Other providers or their personnel may also access information outside the European Economic Area. Contact [email protected] for information about the safeguards relevant to your data.
8. Cookies and similar technologies
Essential technologies support login, security and service operation. Google Analytics runs on the public website only after you choose Accept analytics; it remains off if you choose Reject optional cookies. You can change or withdraw that choice at any time using the Cookie settings link in the public site's footer. Our Cookie Policy will describe the cookies and similar technologies we use, their providers, purposes and lifetimes.
9. Security
We use HTTPS to protect data sent between your browser and BalanceFlow, and internal access controls restrict access to files and records by workspace. Uploaded and generated files are not separately encrypted at rest. We also use the database backups described in section 4. If you think an account or file has been exposed, contact [email protected].
10. Your rights
Depending on the circumstances, you may request access to, correction or deletion of your personal data; restriction of processing; portability of data you provided; or object to processing based on legitimate interests. You can withdraw consent at any time where consent is the basis, without affecting processing that occurred before withdrawal. You can change your preference for product updates and marketing emails in your profile settings. You may complain to the Polish supervisory authority, Prezes Urzędu Ochrony Danych Osobowych (UODO), or another competent EEA authority.
Send requests, including requests for a copy or portable export of your account data, to [email protected]. We handle export requests manually and normally respond within five business days after verifying your identity. If we need more time, we will explain why and respond within the period required by applicable law. If the request concerns data a business customer uploaded and controls, we may direct you to that customer and assist it as required by our agreement and the law. Statutory rights are subject to applicable conditions and exceptions; for example, deleting an account does not necessarily erase records that we must keep by law.
11. Automated processing and children
BalanceFlow automatically transforms files using predefined algorithms and the templates and settings chosen by users. It provides the results as files for users to review and use; BalanceFlow does not itself take action based on those results or make solely automated decisions about people that have legal or similarly significant effects. Account registration is limited to people aged 18 or older. BalanceFlow is not directed at children.
12. Changes and contact
We will update the effective date when this policy changes, retain prior published document versions, and provide notice of material changes where appropriate. For each legal-document acceptance, we record the user ID, the referenced document record (which identifies its legal version), the acceptance time, IP address, user agent, and record timestamps. When an account is deleted, its associated acceptance records are deleted from the active database. Copies in database backups follow the replacement schedule described in section 4. The document versions themselves remain, but no longer identify the deleted user's acceptance. Recording acknowledgement of this Privacy Policy is separate from consent to optional processing, such as analytics or marketing emails. Contact [email protected] with privacy questions.