Privacy Policy
This policy covers the Worfilo service at worfilo.com. We keep what we collect to what the product needs to work.
01What we collect
- Account details: your email address and name. If you sign in with Google, we receive the name and email on your Google account.
- Workflows: the graphs you build, their names, published versions, and node configuration.
- Run history: each run's trigger payload, the inputs and outputs of every node, errors, timings, and token counts, so you can replay and debug runs.
- Credentials: API keys and headers you save. They are encrypted at rest, never returned to the browser after saving, and redacted from stored run inputs.
- Connections and APIs: the apps you connect and the APIs you add, with their tokens, keys and OAuth secrets. These are encrypted at rest, never returned to the browser, and scrubbed from API responses and run records.
- Workflow generation prompts: the descriptions you type into the AI assistant.
We do not use analytics, advertising trackers, or tracking pixels.
02How we use it
- To sign you in and keep your session active.
- To store, run, and show the history of your workflows.
- To draft workflows from your descriptions when you use the AI assistant.
- To prevent abuse, such as rate limiting AI generation and blocking requests to private networks.
- To answer you when you contact support.
03Who processes your data
We do not sell your data. We share it only with the providers that run the service:
- Supabase handles authentication and stores your account email, name, and password hash.
- Google verifies your identity if you choose to sign in with Google.
- Vercel hosts the application.
- Our database provider stores workflows, runs, and encrypted credentials.
- Anthropic receives your prompt when you generate a workflow with AI, and receives the node inputs of agent nodes that use an Anthropic credential.
Workflows can also send data anywhere you configure them to: a connected app such as GitHub or Slack, an API you added, or an HTTP Request node. Those services receive what your workflow sends under their own terms.
05Retention and deletion
We keep your data while your account exists. Deleting a workflow deletes its versions and run history, and disconnecting an app or deleting an API deletes its stored secrets. To delete your account and everything in it, email support@worfilo.com from the address on the account and we will remove it within 30 days.
06Security
Traffic is encrypted in transit, and credentials, connections and API secrets are encrypted at rest. Worfilo is still under development, so no system is guaranteed to be free of flaws: avoid storing data you cannot afford to lose, and report any vulnerability to support@worfilo.com.
07Your rights
You can ask us for a copy of your data, to correct it, or to delete it by emailing support@worfilo.com. Depending on where you live, you may also have the right to object to processing or to complain to your data protection authority.
08Children
Worfilo is not intended for anyone under 16, and we do not knowingly collect their data.
09Changes to this policy
We will update the date above when this policy changes, and email account holders about material changes before they take effect.
10Contact
Questions about privacy: support@worfilo.com.