Effective date: July 22, 2026
FlowManual(“FlowManual,” “we,” “us,” or “our”) provides a document analysis platform for construction contractors. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
By creating an account or using FlowManual, you agree to this Privacy Policy. If you are using FlowManual on behalf of an employer or other organization, you represent that you have authority to bind that organization to this policy.
When you register, we collect your name, email address, and a hashed (one-way encrypted) password. We never store your password in plaintext.
FlowManual processes PDF documents you upload. Files are stored on Microsoft Azure (United States region), on an encrypted volume, and are encrypted in transit (HTTPS). File bytes are also encrypted at the application layer with AES-256-GCM before they are written to disk. FlowManual staff do not access your document contents.
FlowManual extracts plain text from your uploaded documents. This text is stored encrypted in our database and is used to power document analysis features. Raw document files are never transmitted to the analysis provider. Only the extracted plain text is sent. Document parsing (reading the layout, tables, and text out of a PDF) may be performed by Microsoft Azure Document Intelligence, which receives the document file for that purpose only, as described in Section 3.
Annotations, comparison discrepancies, scope gaps, cost estimates, RFI entries, equipment schedules, vendor price history, and GC pattern observations you generate are stored in our database, encrypted at the field level.
We maintain an audit log of document analysis calls that includes: timestamp, user ID, document ID, operation type, bytes transmitted, and a keyed HMAC-SHA-256 hash of the prompt (when an audit key is configured). Full prompt text is never stored. This log is visible only to you at /admin/security and is used to maintain an audit trail of analysis usage.
We do not sell your data. We do not use your document content for advertising. We do not share your data with third parties except as described in Section 3.
You can choose to let FlowManual use the documents you upload and the corrections you make to improve extraction quality for all customers. This is off by default and applies only if permission has been given: by you from your account settings, or by an organization administrator on your workspace's behalf as described below. Your personal opt-out always overrides an organization grant. You can turn it off at any time from your account settings, which immediately stops any future use of your data for this purpose; it does not undo improvements already made. Data used this way is never sold and never shared with third parties.
If your account belongs to an organization workspace on FlowManual, an organization administrator can grant this permission on behalf of the workspace, for example as part of a written pilot agreement between your company and FlowManual. An organization-level grant covers the accounts in that workspace, with one exception that always wins: you can opt your own account out at any time from the same account setting, and your opt-out overrides the organization's grant. Turning your setting off immediately stops any future use of your data for this purpose, whether permission came from you or from your organization.
We share data with the following processors only as necessary to provide the service:
For accounts on flowmanual.com, the application, the database, and uploaded files are hosted on Microsoft Azure in the United States. Files are kept on an encrypted volume. Microsoft processes this data on our behalf under a data processing agreement.
When you run document analysis, extracted plain text from your documents is sent to Anthropic’s API. Anthropic operates under a zero-data-retention policy: prompts and responses are not stored and are not used to train models. Raw document files are never transmitted. See Anthropic’s Privacy Policy.
When you upload a document, the PDF may be sent to Microsoft Azure Document Intelligence (United States region) to read its layout, tables, and text. Azure processes the file for that purpose only: it does not use your documents to train models, and analysis data is deleted within 24 hours. You can ask us to turn this off for your account, in which case parsing runs only on our own servers. See Microsoft’s data and privacy documentation.
Web search inside project chat is off by default and only available when we enable it on the hosted service. When you use it, the search query (which can include text from your conversation) is sent to Tavily to retrieve results. Queries are not used to train models. Web search stays off unless we enable it for the hosted service, and it is always off when redaction is active. See Tavily’s Privacy Policy.
Price check is off by default and only available when we enable it on the hosted service. When you use it, the product search text (which can include material names or details from your conversation) and an optional zip code are sent to SerpApi to retrieve current retail list prices; documents themselves are never sent. Price check is always off when redaction is active. See SerpApi’s Privacy Policy.
We use Resend to send service-related emails such as account confirmation, sign-in verification codes, and material changes to this policy. Resend processes the recipient email address and message contents on our behalf under a data processing agreement.
When an unexpected error occurs on our servers, we may send a scrubbed error report to Sentry (United States) so we can find and fix the failure. Reports are generated on our servers only; no Sentry code runs in your browser. Before a report is sent, every text value in it is truncated to 300 characters, request bodies, cookies, headers, and URL query strings are removed, and file paths outside our application directory are redacted, so reports carry error metadata rather than your document content. A report can include an opaque account identifier, never your email address. Sentry retains error events for 90 days. See Sentry’s Privacy Policy.
If you sign in with Google, Google authenticates you and shares your name and email address with us. This is governed by Google’s Privacy Policy.
You can connect accounts you already hold with third-party services (Microsoft OneDrive and SharePoint, Google Drive, Procore, Dropbox, Egnyte, Docusign, and Autodesk Construction Cloud) to import PDF documents into your projects. Connectors are off by default, and connections go through each provider’s own sign-in and consent screen, so we never see or store your password for that service. The provider issues access tokens, which we store encrypted with AES-256-GCM and use only to list the folders, files, or completed agreements you browse and to download the specific files you choose to import. Imported files are then stored and protected exactly like files you upload directly. We request read-only access wherever the provider supports it, we never change or delete anything in your connected account, and nothing is scanned in the background: browsing, importing, and manual re-scans run only when you start them. You can disconnect a provider at any time, which deletes the stored tokens, and you can also revoke FlowManual’s access from the provider’s own security settings. Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We have no marketing or advertising vendors. The hosted service at flowmanual.com uses one privacy-preserving analytics provider (PostHog) to understand product usage: which features are used, how far new accounts get in setup, and where errors happen. These are server-side event counts tied to an account identifier. They never include document content, filenames, or client and vendor names, and we do not use analytics cookies or session recording (see Cookies below).
FlowManual uses strictly necessary session cookies to keep you authenticated. We do not use tracking, advertising, or analytics cookies. No cookie consent banner is required because we do not place any non-essential cookies.
Your data is retained until you delete it or request account deletion. Deleted data is removed within 30 days.
We implement industry-standard safeguards including AES-256-GCM encryption for sensitive data, HTTPS-only transport, hashed passwords (scrypt, memory-hard), and no plaintext storage of credentials. No security measure is perfect; please notify us immediately if you suspect unauthorized access to your account.
For a technical overview of how we protect your data, see our Security page.
You have the right to:
To exercise any of these rights, email us at legal@flowmanual.com.
FlowManual is intended for professional use by adults. We do not knowingly collect personal data from anyone under 18. If we learn we have collected data from a minor, we will delete it promptly.
We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 30 days before the new policy takes effect. Continued use of FlowManual after the effective date constitutes acceptance of the updated policy.
Questions, requests, or concerns about this Privacy Policy should be directed to:
FlowManual
legal@flowmanual.com