wellflow.devAI models, for less
wellflow
Legal

Privacy Policy

General Provisions

This Policy describes what data the Wellflow AI platform ("Service"), accessible at wellflow.dev, collects, and how we use and store it. This Policy forms part of the Public Offer: https://wellflow.dev/en/terms. By using the Service, you agree to this Policy.

We collect only the data the Service needs to work, to handle payments, to prevent abuse and to debug issues. We do not sell data and do not use it for advertising.

Data We Collect

We process the following categories of data:

  • Account data: name, email address, account settings. Your password is stored only as a hash.
  • Payment data: amount, currency, date, status and payment ID. Card and crypto wallet details are processed by the payment provider; the Service does not receive or store them.
  • Technical data: IP address, browser and device type, time of sign-ins and API calls. Used for security, fraud prevention and service analytics.
  • Usage data: model, token counts, cost and time of each request, balance history.
  • Your correspondence with support, if you contact us.

Request Content

The Service does not store the content of successful API requests and responses: only metadata (model, tokens, cost) is kept. The exceptions, needed to run and debug the Service:

  • Error log. If a request fails at the provider, a fragment of the request and response is kept for diagnostics and deleted automatically within 7 days.
  • Abuse prevention. When an acceptable use rule is triggered, a short fragment of the text that triggered it is kept. It is deleted automatically after 30 days.
  • Dashboard chat. Saved chats are stored on the server so your history is available on any device. You can delete any chat at any time. Temporary chats are deleted automatically after 1 hour.
  • Image and video generation, web search. Requests and results are kept in your account history until the account is deleted or at your request.

Use of Request Content

We do not use the content of your requests to train models. Staff do not review it, except to investigate failures or violations of the Offer.

How We Use Data

We use data to:

  • provide access to the Service and your dashboard;
  • keep track of your balance, process payments and refunds;
  • protect the Service and users from fraud and abuse;
  • find and fix failures and improve the Service;
  • produce aggregated usage analytics;
  • send service messages: email confirmation, password recovery, payment notifications.

Sharing with Third Parties

We share data only to the extent the Service needs to work:

  • AI model providers. Request content is sent to upstream providers and intermediaries to get a response: the Service does not run models itself. Providers may be located in other countries and process data under their own terms.
  • Payment providers: the data needed to process a payment or refund.
  • hCaptcha: technical browser data at sign-in and sign-up, to protect against automated registrations.
  • Telegram: if you contact support via Telegram.
  • Public authorities: only upon a lawful request.

Cookies

The Service uses only necessary cookies and browser local storage: to keep you signed in, protect forms, remember your language and interface settings, and to credit a referral link for 24 hours. We do not use advertising or third-party analytics cookies. hCaptcha may set its own cookies on the sign-in and sign-up pages.

Retention

We keep data no longer than needed:

  • account data: while the account exists;
  • payment data: as long as required for settlements and by law;
  • error log: up to 7 days;
  • abuse prevention log: up to 30 days;
  • chats and generation history: until you delete them or the account is deleted; temporary chats: 1 hour.

Data Deletion

When an account is deleted, its data is deleted or anonymized, except data we are required to keep by law or for settlements.

Security

Data is transmitted over a secure HTTPS connection. Passwords and API keys are stored only as hashes. Only staff who need it for their work have access to data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we take reasonable measures to protect your data.

Your Rights

You can request a copy of your data, its correction or deletion, and delete your account. You can delete chats yourself in the dashboard. For other requests, write to support@wellflow.dev from the email address of your account. We respond within 30 days.

Children

The Service is not intended for persons under 18. If you learn that a child has given us their data, contact us and we will delete it.

Changes to This Policy

We may update this Policy. The current version is always available on this page, with the update date shown at the top. Continued use of the Service after changes means you accept the updated Policy.

Contact

For questions about data processing: support@wellflow.dev or Telegram: https://t.me/wellflow_dev.

↑ Back to top