Privacy Policy
Effective Date: August 2, 2026 · Last Updated: August 2, 2026
Pre-release legal draft
This policy reflects WidgetFlow’s current local-first architecture and remains subject to final owner and legal-counsel review before public release.
1. Scope
This Privacy Policy explains how Andrew Joseph Barron DBA WidgetFlow (“WidgetFlow,” “we,” “us,” or “our”) handles information associated with the WidgetFlow marketing website and pre-release desktop application.
2. The Local-First Boundary
WidgetFlow is designed so workspace artifacts are stored locally on your computer. Tasks, Documents, conversations, Projects, canvases, settings, Trash, and local backups are not automatically uploaded to a WidgetFlow account or centralized WidgetFlow database. The current website does not offer hosted sign-in, workspace synchronization, subscriptions, or payment processing.
Local does not mean isolated from every service. Information leaves your computer when you deliberately use a remote model or Agent, expose a local MCP endpoint, send a support message, publish or export content, or place backups in a destination you control.
3. Information the Website May Process
The marketing website is hosted by Vercel. Like most hosting providers, Vercel may process technical request information needed to deliver and protect the site, such as IP address, user agent, requested URL, timestamp, and diagnostic or security logs. WidgetFlow has not intentionally enabled advertising trackers, behavioral profiling, hosted authentication, payment cookies, or product analytics on the current website.
4. Communications
If you email us or request support, we receive the information you choose to provide, such as your email address, message, and attachments. We use it to respond, investigate issues, protect the Services, and maintain appropriate business records. Do not send workspace content or credentials unless necessary for your request.
5. Desktop Application Data
The desktop application stores workspace data and configuration in files and local databases on your computer. Provider credentials are stored locally for the connections you configure. Anyone with sufficient access to your computer, backups, or operating-system account may be able to access those files. Protect your device and backup media accordingly.
WidgetFlow does not automatically receive local workspace content, local application logs, local credentials, or backup contents. If a diagnostic workflow asks you to share any of this information, you decide what to provide.
6. AI, Agent, and MCP Data Flows
WidgetFlow can connect to Ollama on your machine and to remote services you select, including xAI, OpenAI, DeepSeek, and independently operated Agent endpoints. A request may include your prompt, selected conversation history, attachments, and any workspace context or tool result you authorize. Remote providers process that information under their own terms and privacy policies.
Agent endpoints may be operated by you or another party. Review the endpoint owner’s practices before connecting. Enabling local MCP access can permit authorized clients to read or change workspace data. Keep access keys private and do not expose the endpoint to untrusted networks.
7. How We Use Information We Receive
We use information actually received by WidgetFlow to:
- Deliver, secure, maintain, and troubleshoot the website and pre-release software
- Respond to support, legal, and business communications
- Investigate abuse, security events, and defects
- Comply with law and enforce our Terms
We do not sell personal information, share it for cross-context behavioral advertising, or use local workspace content to train AI models.
8. Disclosures
We may disclose information to service providers that help host, secure, or support the website; when required by law or valid legal process; to protect rights, safety, and security; or as part of a business transaction. Providers may use information only for the applicable service and under their own contractual and legal obligations.
9. Retention
Local workspace retention is controlled by you through the application, Trash, backups, and your filesystem. Removing the application may not remove its data directory or copies on backup media. Remote model and Agent providers apply their own retention rules.
We retain support communications and website operational records only as reasonably needed for the purpose collected, security, dispute resolution, and legal obligations. Specific periods may vary by provider and context; we do not claim fixed periods that we cannot verify.
10. Security and Backups
We use reasonable safeguards appropriate to a local-first pre-release product, but no system is completely secure. You are responsible for operating-system security, physical access, local network exposure, provider keys, external drives, and testing backups. Avoid storing secrets or irreplaceable information without an independent recovery copy.
11. Cookies and Similar Technologies
The current website does not intentionally set first-party analytics, advertising, authentication, or payment cookies. Hosting infrastructure may use technical mechanisms for delivery and security. See the Cookie Policy for details. Desktop local storage is application persistence, not cross-site tracking.
12. International Processing
WidgetFlow is operated from the United States. Website hosting, support communications, and remote providers you select may process information in the United States or other countries. Their laws may differ from those where you live. We will describe any required transfer mechanism before introducing a WidgetFlow-hosted service that relies on one.
13. Your Privacy Rights
Depending on where you live and subject to legal exceptions, you may have rights to know, access, correct, delete, restrict, object to, or obtain a portable copy of personal information we control, and to appeal or complain to a regulator. California residents may also have rights concerning sale, sharing, sensitive information, and non-discrimination; WidgetFlow does not currently sell or share personal information for behavioral advertising.
Most workspace data is under your direct local control. For information WidgetFlow actually holds, send a request to contact@widgetflow.ai. We may need to verify your identity and will respond as required by applicable law. Requests concerning a remote model or Agent provider may need to be directed to that provider.
14. Children
WidgetFlow is intended for adults and is not directed to children under 13. We do not knowingly collect personal information from children through the current website. If you believe a child provided information to us, contact us so we can investigate and take appropriate action.
15. Changes
We will update this policy before materially changing how WidgetFlow collects or uses data, including before introducing hosted accounts, synchronization, analytics, billing, or similar services. The date above identifies the current version.
16. Contact
Andrew Joseph Barron DBA WidgetFlow
Email: contact@widgetflow.ai
Website: https://www.widgetflow.ai
United States