Data Governance & Privacy Spec v1.0

PRIVACY POLICY.

FlowGazer is built on structural discipline and cryptographic identity integrity. We protect your organization's operational state with zero-compromise data governance.

Effective Date: July 31, 2026 Security Standard: ISO/IEC 27001 Aligned
01 //

Executive Commitment

FlowGazer ("FlowGazer", "we", "us", or "our") provides a process-enforcement pipeline designed to enforce workflow discipline for high-performance engineering teams. We treat privacy not as a negotiable policy, but as a hardcoded technical contract.

This Privacy Policy outlines how information is collected, stored, processed, and safeguarded when you access or interact with FlowGazer applications, services, APIs, and associated tools.

02 //

Information We Collect

badge

Account & Identity Data

  • User credentials, full name, and email address.
  • Role assignments (e.g., ORG Admin, PM, DEV, QA, OPS).
  • Cryptographically hashed session tokens generated via @oslojs/crypto.
  • Organization membership and multi-tenant authorization bindings.
schema

Process & Telemetry Data

  • Story progressions across Board A (Development) and Board B (Infrastructure).
  • Gate status flips (Traffic Light transitions and approval signatures).
  • Bounce logic events, rejection audits, and quality assurance logs.
  • System interaction timestamps and client access metadata.
03 //

Data Processing & Purpose

We process collected data exclusively to operate, maintain, and enforce our process-enforcement engine under strict operational boundaries:

Enforcement

Gate Validation

Validating role authorizations for light flips and preventing self-review violations.

Auditability

Immutable Logs

Recording non-repudiable audit trails of bounce events and status state transitions.

Intelligence

AI Assistance

Generating DoD metrics and Release Notes without storing model training datasets.

04 //

Security & Identity Safeguards

FlowGazer enforces strict identity anchoring. All sessions use secure cryptographic hashing and HTTP-only cookie structures to prevent unauthorized session manipulation or token leakage.

Multi-tenant boundaries are strictly isolated at the database schema level. Your organization's stories, board topologies, and internal discussion comments remain inaccessible to other tenants.

05 //

Third-Party Services & AI Policy

FlowGazer integrates with AI models (such as Google Gemini APIs) to assist in generating Definition of Done (DoD) criteria, automated release notes, and operational recommendations.

MANDATE: ZERO PUBLIC MODEL TRAINING
Organization telemetry and prompt inputs sent to AI services are strictly ephemeral and are never used to train base foundation models.
06 //

User Rights & Retention

Organizations and users retain full right of access, correction, and deletion of personal account records, subject to system audit retention requirements mandated by organization administrators.

To request a full export or complete erasure of your organization's non-audit data, contact your Organization Admin or submit a request to privacy@flowgazer.com.

HAVE PRIVACY QUESTIONS?

Contact our Data Governance Officer at privacy@flowgazer.com