Last updated: September 7, 2026
Files and text processed in your browser
The basic web tools process your working files and text in your browser. Formatting data, comparing text, processing PDFs, converting images, and generating local downloads do not upload that input to ToolFlowy. Copying or downloading a result is separate from an account save. If you choose a feature that sends data to an account or a third party, the transfer is described below and on the relevant tool page.
Cookies and browser storage
Language, theme, favorites, recent tools, and supported local histories use cookies or browser storage on your device. Sign-in uses session and security cookies. A support message draft can remain in the current browser session so that you can restore it after reloading. One-time transfers between tools expire after ten minutes and are removed when consumed. You can clear this data through the tool controls or your browser's site-data settings; clearing sign-in cookies signs you out.
Google sign-in and account records
When you sign in with Google, ToolFlowy receives your name, email address, profile image, and Google account identifier using the openid, email, and profile scopes. Account and session records are stored in ToolFlowy's database to provide sign-in, account access, and connected-device controls. Google passwords and Google authentication cookies are not copied to extensions. Connected extensions receive revocable ToolFlowy session tokens, with token hashes, device identifiers, and expiry records stored on the server. Information received from Google APIs is used only to provide or secure the requested function, in line with the Chrome Web Store User Data Policy and its Limited Use requirements. It is not sold or used for personalized advertising or credit decisions; human access is limited to your consent, security or abuse prevention, or legal requirements.
Optional account settings
Supported Pro account saves store the settings you explicitly choose: formatter mode and indentation, snippet appearance, PDF operation and page-range settings, or invoice currency, tax rate, and default due-day settings. These presets do not include working JSON, source code, PDF files, filenames, or invoice contents. Creating and applying Pro settings requires an active entitlement. Preset metadata and deletion remain available after that entitlement ends.
Invoice contacts and history
Invoice tools can separately save account data when you choose those features and have an active Pro entitlement. Saved contacts can include a name, email address, phone number, address lines, city, region, postal code, and country. Saved invoice history includes the invoice number, currency, total, issue and due dates, and status. Numbering stores the chosen prefix, year, and counter. This is separate from local PDF creation and from settings presets; the history endpoint does not store PDF bytes or line-item contents. You must have permission to enter another person's contact data. Saved contacts and records have no automatic expiry. You can delete them, clear all invoice data, or export your account's invoice data; deletion and export do not require an active Pro entitlement.
Other explicit saves and external previews
Where a tool offers an account save, it can send the selected icon prompt, visual settings and rendered PNG, mockup artwork, SEO metadata, color palette, link-page fields, or resume fields and photo to ToolFlowy's database. Source code and invoice fields are not accepted by this general asset save. Loading an external preview or opening a third-party link makes a request to that provider; an external image preview is loaded only after your confirmation. Account saves include version history. Deleting an asset hides it immediately and allows restoration for 30 days. After that window, it cannot be restored and is permanently removed on the next account asset access or save. Deleting the owning account removes its assets and versions. You can also choose Delete permanently in Recently deleted to immediately remove a save and all its versions.
Notion Clipper
Notion credentials and destination settings stay in the extension's local storage. When you confirm a capture, the selected page content, text, table or list cells, images, or supported YouTube/X content goes directly from the extension to Notion. ToolFlowy does not receive your Notion credential or capture content. Local summaries and tags are not sent to an AI provider. Content saved in Notion is subject to your Notion workspace's settings and retention.
Other supported Chrome extensions
Smart Tab Manager reads tab information for the actions you request. If you connect your ToolFlowy account and sync a workspace, its name, icon, open mode, saved HTTP(S) URLs, titles, and pinned states are stored on the server. Current open-tab backups, closed-tab history, and favicons stay on your device. Conflicting workspace revisions are preserved until you choose which copy to keep. JSON Lens formats current-tab JSON locally and can sync compatible formatter settings without uploading the JSON or page URL. Download Organizer reads filenames and extensions to organize downloads locally; it does not read file contents. An extension's catalog page shows whether it is currently available to install.
Usage and performance measurement
For signed-in users, product events contain an internal account identifier, product identifier, a bounded action or failure code, an optional destination or connected-device identifier, and a timestamp. These events do not accept working input, output, filenames, clipboard contents, or page URLs. When field performance measurement is enabled, a 5% page-load sample contributes only allowed route identifiers, metric names, navigation types, hourly histogram buckets, and counts. These aggregates contain no user or session identifier, full URL, query string, or IP-derived field. The retention policy for these aggregates is 35 days, enforced through the operator's pruning procedure.
Google AdSense and advertising choices
ToolFlowy is being prepared for Google AdSense review. Site-ownership metadata and ads.txt identify the publisher; they do not themselves load advertising scripts or set advertising cookies. Advertising is not currently enabled. If advertising is enabled, third-party vendors, including Google, may use cookies to serve ads based on prior visits to this or other websites. Google's advertising cookies allow Google and its partners to serve ads based on those visits. ToolFlowy does not provide working files, tool input or output, or account-profile data as advertising targeting data. You can manage or turn off personalized Google ads in My Ad Center, and manage participating third-party vendors' choices through WebChoices. See how Google uses information from partner sites. Where required, an advertising consent message will offer choices before relevant advertising storage or processing begins. Personalized ads to visitors in the EEA, UK, or Switzerland require a Google-certified consent platform.
Service providers and retention
ToolFlowy uses its hosting and database providers to operate the service, Google for sign-in, and Polar for payment and license records. The server and hosting provider can process technical request information needed to deliver and protect the service. ToolFlowy stores Polar customer, subscription, and license references; Polar handles its checkout and payment data. New Pro checkout is currently unavailable. Local data remains until you clear it or uninstall the extension. Account saves remain until you delete the saved data or request account deletion; invoice data has no time-based expiry. Connected-device sessions expire or can be revoked, and account-linked usage events remain until account deletion. Support correspondence is used to respond to and resolve your request. Data you send to an external provider is handled under that provider's policies. ToolFlowy does not sell your working content or account data.
Access, deletion, and your choices
You can clear local histories and browser site data, delete supported account saves and presets, reset a synced browser workspace, and revoke connected devices. To request account access, correction, export, or deletion, contact support@toolflowy.com. We may need to verify that you control the account before acting. Deleting data from ToolFlowy does not delete a copy you separately saved to Notion, downloaded, or sent to another provider.
Contact and policy updates
ToolFlowy's privacy contact is support@toolflowy.com. Include the affected account or feature, but do not send passwords, tokens, payment-card details, or sensitive working files. This page describes the current service and is updated when its data practices change; the date above identifies the latest revision.