Privacy Policy

How TimelineFlow handles accounts, local and cloud projects, AI prompts and references, payment records and privacy requests.

Effective date: September 20, 2026

Draft — operator details are not approved. Live checkout is unavailable.

Choose what you send to AI services. Hosted generation sends prompts, selected references and settings through our server to fal and selected upstream models. Provider media links may be accessible to anyone with the URL. Opening the editor does not automatically upload your local workspace.

1. Operator and privacy contact

The operator identified above is responsible for the personal data handled by TimelineFlow. Contact [email protected] for privacy requests and [email protected] for account or billing support.

TimelineFlow determines how account, security and billing records are used. An organisation supplying content may control its processing purposes and remain responsible for lawful collection and instructions. Provider roles and transfer safeguards depend on the applicable agreements; a policy link does not claim an unexecuted processor agreement exists.

2. Scope and roles

This Policy covers TimelineFlow websites, accounts, the editor, cloud files, public and community features, messages, support, Connector, and related services. It does not govern third parties you choose, including Google, AI providers, stock-media sources, Ollama, ComfyUI, custom nodes, models, or websites linked from the Service. Their policies apply independently.

When a business uses TimelineFlow to process personal data on its behalf, separate controller/processor terms or a data processing agreement may be required. Do not use the consumer Service for regulated processing that requires such terms until they are agreed.

3. Data we process

Account data includes email, profile, authentication, session records, consent versions and timestamps. Collaboration data includes shared projects, files, messages, permissions and moderation reports. Technical records can include IP address, browser/device information, request IDs, errors and security events.

Hosted AI processes prompts, selected image/video/audio references, model settings, outputs and links, statuses, usage and costs. References may contain faces, voices and other personal data. Billing records include account and plan identifiers, credit grants, reservations, settlements, reversals, price versions, administrative reasons and payment transaction IDs.

Local media stays on your device unless you select a feature that uploads or shares it. Cloud sync, collaboration, messages, hosted AI and remote BYOK providers can transmit selected content. Recipient copies may remain after you delete your copy.

4. Hosted AI, BYOK and local tools

With the TimelineFlow provider, our server receives the request and references, prepares a priced job, sends it to fal and retrieves output. fal may route work to the selected language, image, video, speech or music supplier, including OpenRouter for supported assistant models. Read fal Privacy, fal Dpa and fal Retention; upstream and model-specific policies also apply.

We request no fal JSON input/output history storage, reference-upload expiry after 24 hours and provider-generated media expiry after 7 days. Provider controls are separate from our server records, imported project files, backups and upstream policies. Provider URLs can act as bearer links: do not publish private media links. Download or import results before expiry.

BYOK uses your provider account and its own retention, data-use and billing policies. Keys can remain in browser memory or be saved in browser storage only when you select that option. Connector forwards chosen work to configured ComfyUI or Ollama; workflows and plugins may contact remote services. Submit references only with appropriate rights and consent, and avoid unnecessary sensitive data.

5. Why we process data and legal bases

Where GDPR, UK GDPR, or similar law applies, we rely on the following bases:

  • Contract: create and secure accounts; authenticate users; operate editor, cloud, messaging, community, generation, and Connector features; provide support; administer Free Beta access, fair-use and storage limits; and administer future subscriptions only after purchase.
  • Legitimate interests: prevent fraud and abuse, protect users and systems, diagnose faults, measure service performance, understand aggregate feature use, defend legal claims, and improve reliability. We balance these interests against your rights.
  • Legal obligation: respond to lawful requests, keep tax/transaction records, enforce sanctions, preserve evidence, and meet consumer, safety, and platform duties.
  • Consent: only where law requires it, such as optional non-essential cookies or marketing. You may withdraw consent prospectively without affecting prior processing.
  • Vital interests: exceptionally, to address a credible threat to someone's life or physical safety.

We do not currently use personal data for behavioural advertising, sell personal data for money, or use private content to train generative models. If this changes, we will update this Policy and provide choices required by law before the new use.

6. Recipients and payments

Recipients include hosting, database, object storage/CDN, email and security providers needed for TimelineFlow; fal and relevant upstream models for selected AI work; and people you share with. Authorised staff access records as needed for support, moderation, billing and security. Disclosure may also be required by law or to address fraud and protect rights.

Paddle processes checkout, payment details, tax, subscriptions, receipts, refunds and fraud checks as merchant of record under paddle Privacy and paddle Terms. Our server receives transaction/subscription IDs, statuses and accounting details, not full card numbers. Paddle may process data internationally under its stated safeguards.

AI and infrastructure processing may occur outside your country. Legal bases, processor terms and transfer safeguards must be documented for the configured operator and providers. A provider policy link does not establish that every deployment satisfies every jurisdiction. Ask [email protected] for current recipients and applicable safeguards.

Current infrastructure integrations include Render for application hosting and databases, Cloudflare for CDN/security, R2 file storage and configured call transport, and Resend for transactional email. Google processes sign-in when you choose Google login. Calls transmit the participants' chosen audio, video and connection metadata through the configured real-time providers; recordings and shared files are processed when those features are used. Which providers receive data depends on the feature and deployment.

7. Cookies and browser storage

TimelineFlow currently uses essential session mechanisms and browser storage for authentication, OAuth state, security, workspace-handle access, editor preferences, access state, and notice choices. Generation preferences may be stored locally. Provider API keys are stored in browser local storage only when you explicitly select Save on this device. Essential storage is necessary for requested functionality. We do not currently use optional advertising or marketing cookies. We will not set optional analytics, advertising, or marketing cookies without the notice and choice required by law.

Clearing cookies or site data may sign you out, remove preferences and locally saved API keys, revoke remembered workspace access, or require reconfiguration. It does not necessarily delete server data.

8. Retention and deletion

To prevent repeat welcome-credit claims, we retain keyed hashes of the verified email, Google identity when used, and network address (an IPv6 /64 where applicable), together with the campaign claim and credit ledger. These promotion records do not store the raw email or IP address. They remain after account deletion for campaign abuse prevention and financial reconciliation, with no automatic deletion currently configured. You may contact [email protected] to request review or exercise your privacy rights.

Server input and output payloads for completed successful hosted AI work become eligible for cleanup 30 days after delivery has been acknowledged, and no earlier than 30 days after completion. Successful results that have not been acknowledged are retained for recovery; pending or financially unresolved work may be retained longer. Failed-job payloads become eligible after 30 days. Unused expired quotes are cleaned after one day. Saved project media and cloud files have separate lifecycles. Contact [email protected] to request deletion or review of retained content.

Financial ledger entries, payment IDs, credit amounts, price versions and administrative audit evidence are retained for accounting, tax, fraud prevention, disputes and legal duties. Retention is determined by the applicable legal requirements, open disputes and the need to reconcile transactions. These records currently have no automatic deletion period; after account closure, their use is restricted to those purposes. Contact [email protected] to request a retention review. Account closure does not guarantee deletion of legally required financial records.

Account, consent, security and support data stays while needed for the account and applicable security, disputes and legal duties. Messages, moderation, backups, caches, legal holds and recipient copies may have separate lifecycles. Where a fixed period is not configured, purpose, sensitivity, security risk and legal duties determine retention. Local files remain under your control.

Request access, correction or deletion through [email protected]. We verify identity and explain applicable exceptions and appeal routes. Delete local files and saved keys separately. Account deletion cannot retract collaborator copies or immediately purge every provider record, backup or legal hold. Independent provider accounts follow their own deletion process.

9. Security and international transfers

We use access controls, hashed passwords and session/Connector tokens, transport security, rate limiting, and restricted service credentials designed to protect data. No system, device, browser storage, local network, provider, or transmission is completely secure. You are responsible for device security, backups, endpoint configuration, and secret rotation.

TimelineFlow and its providers may process data outside your country. Where required, we rely on adequacy decisions, approved contractual safeguards, or another lawful transfer mechanism and assess supplementary measures. Your direct selection of a provider may also create a transfer governed by your relationship with that provider.

10. Your privacy rights

Depending on location, you may have rights to access, correct, delete, restrict, object, withdraw consent, obtain a portable copy, appeal a refusal, and complain to a supervisory authority. You may also have rights to know categories/sources/recipients, correct inaccuracies, delete data, and opt out of sale, sharing, targeted advertising, or certain profiling. TimelineFlow does not currently sell data or use it for cross-context behavioural advertising.

Email [email protected] to exercise a right. Describe the account and request. We may verify identity, ask an authorised agent for proof, refuse or charge for manifestly unfounded/excessive requests where permitted, and retain data where an exemption applies. We will respond within the legally required period and explain any denial or appeal route.

11. Age limits and sensitive data

TimelineFlow is for people aged 18 or older and is not directed to children. If you believe a minor provided data, contact us for investigation and deletion. Do not submit sensitive or regulated data unless necessary, lawful, and supported by appropriate notices, consents, security, and contractual terms.

12. Automated decisions

We may use automated rate limits, spam signals, and security checks to protect the Service, but do not currently make solely automated decisions that produce legal or similarly significant effects about users. Provider moderation or generation decisions are governed by that provider. Contact support if you believe an automated restriction was incorrect.

13. Changes to this Policy

We may update this Policy as the Service, providers, or law changes. We will change the date above and give additional notice for material changes when required. A new purpose that requires consent will not apply until valid consent is obtained. Previous versions and acceptance evidence should be retained for audit purposes.

The rules governing use of the Service are in the Terms of Service. Subscription cancellation and refunds are covered by the Refund & Cancellation Policy.