LEGAL · PRIVACY
Privacy at production scale.
This notice explains what Flow processes when you use the website, Workspace, account billing, and the Flow Serial Studio MCP plugin.
Effective August 1, 2026
Data we process
Account identity and authentication records; Workspace scripts, assets, prompts, Takes and delivery metadata; API key digests and session identifiers; point, payment, receipt, invoice and refund records; security, reliability and support logs. Flow never stores an API key in plaintext after it is issued.
Why we process it
To authenticate users, provide and recover generation jobs, keep Series and Take truth consistent, account for prepaid points, fulfill billing requests, prevent abuse, support users and meet legal obligations.
AI and payment providers
Flow sends the minimum production input needed to configured image or video providers. Payment orders are handled by the selected payment channel. Flow does not use browser payment success screens as payment truth and does not sell personal information.
Retention and deletion
Workspace and billing records are retained while needed to provide the service, resolve disputes, meet accounting duties and protect system integrity. You may request account or content deletion; records that must be retained for legal, fraud-prevention or transaction integrity reasons may be restricted instead of erased.
Security
Credentials are hashed or encrypted, account access is ownership-scoped, billing PII uses a separate encryption key, and production logs are redacted. No internet service can promise absolute security.
Your choices
You can revoke Flow API keys at any time, stop using the plugin without deleting Workspace results, request access or correction, and contact Flow about deletion or privacy questions.
International availability
Flow web service availability and OpenAI plugin availability are separate. The Codex plugin is offered only where both Flow and OpenAI support the service; it is not offered as a way to bypass regional restrictions.
Contact
Privacy requests: support@kthuan.cn. Include “Privacy request” in the subject and do not send API keys, payment secrets or provider credentials.