Auto Everything Flow
Home

Privacy Policy

Effective date: August 30, 2026

1. Purpose and scope

Auto Everything Flow is a Chrome extension built solely to automate and organize creation workflows on Google Flow AI. It supports bulk prompt submission, character references, scanning, previewing, and downloading images and videos from a Flow gallery. When enabled, the Flow creator Community supports this same narrow purpose through workflow help and experience sharing.

We do not sell personal data, build advertising profiles, perform credit assessments, or collect general browsing history outside Flow.

2. Data processed locally

Chrome local storage may contain prompt lists, character configurations and saved character entries; language, theme, speed, scan, download, notification, and workflow settings; job/download history, media preview metadata, file names, session statistics, and limited diagnostics. Access and refresh tokens needed to continue a signed-in Supabase session are also stored locally. The access token is sent as a Bearer credential to Supabase Auth and authorized Supabase Edge Functions to verify identity; the refresh token is used only with Supabase Auth to renew the session. When browser synchronization is enabled, Chrome Sync may synchronize the best-effort device fingerprint and cached usage state across devices: the anonymous or signed-in subject/user identifier, prompt and download counters and limits, Pro state, rolling-window timestamps, and cache timestamp. During Google sign-in, the short-lived Google OAuth access token returned by Chrome Identity is sent transiently to the fixed Supabase google-auth Edge Function to verify Google identity and establish a Supabase session. The Google password is not shared with the extension.

3. Flow website content

The extension runs only on permitted Google Flow AI pages. To perform actions you choose, it may read the prompt editor, generation cards, prompt metadata, media thumbnails, and image/video URLs for scanning, previewing, sorting, and downloading. It does not read unrelated websites or collect general browsing history.

4. Account, quota, and Pro data

Supabase may process an anonymous or signed-in user UUID, installation ID, best-effort device fingerprint, rolling 24-hour usage counters, and quota-window timestamps. If you sign in, your email is used for account verification and matching Pro access.

Lemon Squeezy handles checkout and billing. For a signed-in user, the extension may add the email address to the Lemon Squeezy checkout URL to prefill checkout and support subscription matching. The extension does not receive card numbers or full payment details. Supabase may retain subscription ID, product/variant, status, and validity dates to verify Pro access.

5. Optional Flow Community

The Community is used only when it is enabled, you are signed in, and you choose to join. It may process your public display name and unique handle, public messages, message/presence IDs and timestamps, short-lived online presence leases, reports, block relationships, restrictions, and content-free moderation audit records. Your email is not public. The initial release has no direct messages, file/audio uploads, or message editing. An authorized moderator may inspect only specifically reported content for safety.

6. Optional translation

If you ask to translate a Community message, the client sends the message ID and target language to Supabase. After authorization, the server sends only that message body and target language to Google Cloud Translation. Results may be cached for up to 24 hours; the original remains available and Google attribution is shown.

7. Service providers

  • Supabase: authentication, profiles, quota, Pro status, and Community data when enabled.
  • Google: OAuth, optional Chrome Sync, and Cloud Translation only on user request.
  • Lemon Squeezy: checkout, subscription, and billing processing.

Only data necessary for the selected function is shared. It is not transferred for advertising, data brokerage, credit assessment, or an unrelated purpose.

8. Retention and deletion

  • Public Community messages are normally retained for no more than 90 days.
  • Reported content may remain as non-public evidence until review closes, then be deleted or tombstoned by the next cleanup job.
  • Translation cache entries last up to 24 hours; resolved or dismissed reports up to 180 days.
  • Content-free safety audit records and inactive restrictions last up to 365 days; active restrictions remain until expiry or revocation.
  • Presence, operational webhook receipts, and cost/quota periods are kept only for the short or bounded periods required by their functions.

“Delete my Community data” removes the Community profile, messages, translations, report/block relationships, and presence. It does not automatically delete the sign-in account, Pro/Lemon subscription, or safety and quota records. A content-free deletion receipt may remain for up to 24 hours. Complete server-account deletion can be requested by email.

9. Chrome permissions

  • activeTab, tabs, scripting: locate the Flow tab and run the automation selected by the user.
  • storage: retain preferences, job data, and session state.
  • downloads: save selected media.
  • notifications and alarms: report status and run bounded background timers.
  • sidePanel: show the extension interface.
  • identity: start Google sign-in.

Host access is limited to Google Flow and the fixed production Supabase domain. The extension does not request the debugger permission.

10. Security and Limited Use

Server traffic uses HTTPS/WSS; server secrets are not shipped in the extension; authorization and row-level controls restrict database access. We limit data access, volume, and retention to what each feature requires.

Auto Everything Flow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, and the Chrome Web Store User Data Policy Limited Use requirements.

11. Children, changes, and contact

The service is not directed to children, and we do not knowingly collect personal data from children. Material changes will update the effective date and, when required, trigger an in-extension notice or renewed consent.

Privacy, access, or deletion requests: autoeverythingflow@gmail.com

Gizlilik Politikası

Yürürlük tarihi: 30 Ağustos 2026

1. Amaç ve kapsam

Auto Everything Flow, yalnızca Google Flow AI üzerindeki üretim iş akışlarını otomatikleştirmek ve düzenlemek için geliştirilmiş bir Chrome eklentisidir. Toplu prompt gönderme, karakter referansı, Flow galerisindeki görsel ve videoları tarama, önizleme ve indirme işlevlerini destekler. Etkinleştirildiğinde Flow üreticilerine özel Topluluk da aynı dar amaç kapsamında iş akışı yardımı ve deneyim paylaşımı sunar.

Kişisel verileri satmayız, reklam profili oluşturmayız, kredi değerlendirmesi yapmayız ve Flow dışındaki genel tarama geçmişini toplamayız.

2. Yerel işlenen veriler

Chrome yerel depolamasında prompt listeleri, karakter yapılandırmaları ve kayıtları; dil, tema, hız, tarama, indirme, bildirim ve iş akışı ayarları; iş/indirme geçmişi, medya önizleme meta verileri, dosya adları, oturum istatistikleri ve sınırlı tanılama kayıtları bulunabilir. Oturum açmış Supabase oturumunu sürdürmek için erişim ve yenileme belirteçleri de yerelde saklanır. Erişim belirteci kimliği doğrulamak için Supabase Auth'a ve yetkili Supabase Edge Function'larına Bearer olarak gönderilir; yenileme belirteci yalnızca oturumu yenilemek için Supabase Auth ile kullanılır. Tarayıcı eşitlemesi açıksa Chrome Sync; best-effort cihaz parmak izini ve önbelleğe alınmış kullanım durumunu (anonim veya oturum açmış subject/kullanıcı kimliği, prompt ve indirme sayaçları ile limitleri, Pro durumu, rolling pencere ve önbellek zamanları) cihazlar arasında eşitleyebilir. Google ile giriş sırasında Chrome Identity tarafından döndürülen kısa ömürlü Google OAuth erişim belirteci, Google kimliğini doğrulamak ve Supabase oturumunu kurmak amacıyla sabit Supabase google-auth Edge Function'ına geçici olarak gönderilir. Google parolası eklentiyle paylaşılmaz.

3. Flow web sitesi içeriği

Eklenti yalnızca izin verilen Google Flow AI sayfalarında çalışır. Seçtiğiniz işlemler için prompt editörünü, üretim kartlarını, prompt meta verilerini, medya küçük resimlerini ve görsel/video URL'lerini tarama, önizleme, sıralama ve indirme amacıyla okuyabilir. İlgisiz siteleri veya genel tarama geçmişini okumaz.

4. Hesap, kota ve Pro verileri

Supabase anonim veya oturum açmış kullanıcı UUID'si, kurulum kimliği, best-effort cihaz parmak izi, rolling 24 saatlik kullanım sayaçları ve kota penceresi zamanlarını işleyebilir. Giriş yaparsanız e-posta adresiniz hesap doğrulama ve Pro erişimini eşleştirme için kullanılır.

Ödeme ve faturalandırmayı Lemon Squeezy yönetir. Oturum açmış kullanıcı için eklenti, ödeme sayfasını önceden doldurmak ve abonelik eşleştirmesini desteklemek amacıyla e-posta adresini Lemon Squeezy ödeme URL'sine ekleyebilir. Eklenti kart numaranızı veya tam ödeme bilgilerinizi almaz. Supabase, Pro erişimini doğrulamak için abonelik kimliği, ürün/varyant, durum ve geçerlilik tarihlerini saklayabilir.

5. İsteğe bağlı Flow Topluluğu

Topluluk yalnızca etkinleştirildiğinde, giriş yaptığınızda ve katılmayı seçtiğinizde kullanılır. Herkese açık görünen adınız ve benzersiz handle'ınız, mesajlarınız, mesaj/presence kimlikleri ve zamanları, kısa süreli çevrimiçi presence lease kayıtları, raporlar, engel ilişkileri, kısıtlamalar ve içeriksiz moderasyon kayıtları işlenebilir. E-posta adresiniz herkese gösterilmez. İlk sürümde doğrudan mesaj, dosya/ses yükleme veya mesaj düzenleme yoktur. Yetkili moderatör yalnızca özellikle raporlanan içeriği güvenlik amacıyla inceleyebilir.

6. İsteğe bağlı çeviri

Bir Topluluk mesajını çevirmeyi istediğinizde istemci mesaj kimliği ve hedef dili Supabase'e gönderir. Yetkilendirme sonrasında sunucu yalnızca o mesaj gövdesini ve hedef dili Google Cloud Translation'a iletir. Sonuç en fazla 24 saat önbelleğe alınabilir; orijinal metin erişilebilir kalır ve Google atfı gösterilir.

7. Hizmet sağlayıcılar

  • Supabase: kimlik doğrulama, profil, kota, Pro ve etkinse Topluluk verileri.
  • Google: OAuth, isteğe bağlı Chrome Sync ve yalnızca istek üzerine Cloud Translation.
  • Lemon Squeezy: ödeme, abonelik ve faturalandırma.

Yalnızca seçilen işlev için gerekli veri paylaşılır; reklam, veri komisyonculuğu, kredi değerlendirmesi veya ilgisiz amaçlar için aktarılmaz.

8. Saklama ve silme

  • Herkese açık Topluluk mesajları normalde en fazla 90 gün tutulur.
  • Raporlanan içerik, inceleme bitene kadar herkese kapalı kanıt olarak kalabilir; ardından sonraki temizleme işinde silinir veya tombstone'a çevrilir.
  • Çeviri önbelleği en fazla 24 saat; çözülen/reddedilen raporlar en fazla 180 gün tutulur.
  • İçeriksiz güvenlik kayıtları ve pasif kısıtlamalar en fazla 365 gün; aktif kısıtlamalar bitiş veya kaldırılma tarihine kadar tutulur.
  • Presence, operasyonel webhook ve maliyet/kota dönemleri işlev için gerekli kısa veya sınırlı sürelerde tutulur.

“Topluluk verilerimi sil” Topluluk profilini, mesajları, çevirileri, rapor/engel ilişkilerini ve presence kayıtlarını kaldırır. Giriş hesabını, Pro/Lemon aboneliğini veya güvenlik ve kota kayıtlarını otomatik silmez. İçeriksiz silme makbuzu en fazla 24 saat kalabilir. Tam sunucu hesabı silme talebi e-postayla iletilebilir.

9. Chrome izinleri

  • activeTab, tabs, scripting: Flow sekmesini bulmak ve seçilen otomasyonu çalıştırmak.
  • storage: tercihleri, iş verisini ve oturum durumunu saklamak.
  • downloads: seçilen medyayı indirmek.
  • notifications ve alarms: durum bildirmek ve sınırlı arka plan zamanlayıcılarını çalıştırmak.
  • sidePanel: eklenti arayüzünü göstermek.
  • identity: Google girişini başlatmak.

Host erişimi Google Flow ve sabit üretim Supabase alan adıyla sınırlıdır. Eklenti debugger izni istemez.

10. Güvenlik ve Limited Use

Sunucu trafiği HTTPS/WSS kullanır; sunucu sırları eklentiye konulmaz; yetkilendirme ve satır düzeyi kurallar veritabanı erişimini sınırlar. Veri erişimi, miktarı ve saklaması her özelliğin gerektirdiğiyle sınırlandırılır.

Auto Everything Flow'un Google API'lerinden aldığı bilgileri kullanması ve başka uygulamalara aktarması, sınırlı kullanım şartları dahil Google API Services User Data Policy ve Chrome Web Store User Data Policy Limited Use gerekliliklerine uygun olacaktır.

11. Çocuklar, değişiklikler ve iletişim

Hizmet çocuklara yönelik değildir ve bilerek çocuklardan kişisel veri toplamayız. Önemli değişikliklerde yürürlük tarihi güncellenir; gerektiğinde eklenti içi bildirim veya yeniden onay sunulur.

Gizlilik, erişim veya silme talepleri: autoeverythingflow@gmail.com