PRIVACY POLICY.
FlowGazer is built on structural discipline and cryptographic identity integrity. We protect your organization's operational state with zero-compromise data governance.
Executive Commitment
FlowGazer ("FlowGazer", "we", "us", or "our") provides a process-enforcement pipeline designed to enforce workflow discipline for high-performance engineering teams. We treat privacy not as a negotiable policy, but as a hardcoded technical contract.
This Privacy Policy outlines how information is collected, stored, processed, and safeguarded when you access or interact with FlowGazer applications, services, APIs, and associated tools.
Information We Collect
Account & Identity Data
- User credentials, full name, and email address.
- Role assignments (e.g., ORG Admin, PM, DEV, QA, OPS).
- Cryptographically hashed session tokens generated via
@oslojs/crypto. - Organization membership and multi-tenant authorization bindings.
Process & Telemetry Data
- Story progressions across Board A (Development) and Board B (Infrastructure).
- Gate status flips (Traffic Light transitions and approval signatures).
- Bounce logic events, rejection audits, and quality assurance logs.
- System interaction timestamps and client access metadata.
Data Processing & Purpose
We process collected data exclusively to operate, maintain, and enforce our process-enforcement engine under strict operational boundaries:
Gate Validation
Validating role authorizations for light flips and preventing self-review violations.
Immutable Logs
Recording non-repudiable audit trails of bounce events and status state transitions.
AI Assistance
Generating DoD metrics and Release Notes without storing model training datasets.
Security & Identity Safeguards
FlowGazer enforces strict identity anchoring. All sessions use secure cryptographic hashing and HTTP-only cookie structures to prevent unauthorized session manipulation or token leakage.
Multi-tenant boundaries are strictly isolated at the database schema level. Your organization's stories, board topologies, and internal discussion comments remain inaccessible to other tenants.
Third-Party Services & AI Policy
FlowGazer integrates with AI models (such as Google Gemini APIs) to assist in generating Definition of Done (DoD) criteria, automated release notes, and operational recommendations.
User Rights & Retention
Organizations and users retain full right of access, correction, and deletion of personal account records, subject to system audit retention requirements mandated by organization administrators.
To request a full export or complete erasure of your organization's non-audit data, contact your Organization Admin or submit a request to privacy@flowgazer.com.
HAVE PRIVACY QUESTIONS?
Contact our Data Governance Officer at privacy@flowgazer.com