Privacy Policy

This policy explains how Fundflow handles information when authorized users access and use the application.

Effective date: September 18, 2026

Scope

Fundflow is primarily an internal application for managing funded projects, including budgets, suppliers, purchases, personnel, compliance, reports, and related documents.

Information we collect

  • Account information, such as your name, email address, profile image, sign-in provider, role, and access status.
  • Information entered or uploaded to Fundflow, such as project, financial, supplier, personnel, compliance, reporting, and file data.
  • Authentication, session, security, and operational information, such as timestamps, IP address, browser or device details, and application logs.

How we use information

We use information to authenticate users, control access, provide project-management features, create requested exports, maintain auditability, secure and troubleshoot the service, and meet operational or legal obligations.

Google user data

When you sign in with Google, Fundflow receives basic identity information, such as your name, email address, profile image, and Google account identifier, to authenticate and link your account.

If you separately authorize the Google Drive file permission, Fundflow uses it only when you request a Google Sheets export. Fundflow creates the requested spreadsheet in your Google Drive and does not read unrelated Drive files.

Fundflow's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not sold, used for advertising, or used to train generalized AI or machine-learning models.

How information is shared

Information may be available to authorized Fundflow users according to their roles. It is processed by service providers needed to operate the application, including Cloudflare for hosting, database, file storage, security, and logs, and Google for sign-in and user-requested Sheets exports. We do not sell personal information.

Storage and security

Application records are stored in Cloudflare D1, uploaded files in Cloudflare R2, and operational logs in Cloudflare services. Fundflow uses access controls, secure connections, and encrypted OAuth tokens, but no system can guarantee absolute security.

Retention

Information is kept for as long as needed to operate Fundflow, maintain project and audit records, secure the service, and meet applicable obligations. Retention may continue after access is removed when records must be preserved.

Your choices

You can revoke Fundflow's Google access from your Google Account. Contact your Fundflow administrator to ask about access to, correction of, or deletion of your account information, subject to project, audit, and legal retention needs.

Changes to this policy

We may update this policy when Fundflow or its data practices change. The effective date above identifies the current version.

Contact

For privacy, account, or service questions, contact the Fundflow administrator who gave you access.