Privacy Policy
Last updated: April 13, 2026
This Privacy Policy describes how GlassFlow GmbH (“NavFlow”, “we”, “us”) collects, uses, and shares information when you use the NavFlow service at navflow.ai and related subdomains (the “Service”).
1. Information We Collect
Account information. When you sign up, directly or via a social provider such as Google, we collect your name, email address, and a unique identifier from the provider.
Usage data. We collect logs and telemetry about how you use the Service (pages visited, API calls, errors, approximate IP-based location) to operate, secure, and improve the product.
Customer data. Events and data you send through NavFlow are stored and processed on your behalf. We treat this as confidential and do not use it to train models or for any purpose other than providing the Service to you.
Cookies. We use strictly necessary cookies to keep you signed in and to maintain session state. We do not use third-party advertising cookies.
2. How We Use Information
- Provide, operate, and maintain the Service.
- Authenticate you and secure your account.
- Respond to support requests and communicate service-related notices.
- Monitor performance, diagnose problems, and prevent abuse.
- Comply with legal obligations.
3. Google User Data
If you sign in with Google, we receive your basic profile (name, email address, profile picture URL, and Google user ID) strictly to create and authenticate your NavFlow account. We do not access your Gmail, Drive, Calendar, or any other Google data. We do not share Google user data with third parties, and we do not use it for advertising or model training.
NavFlow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Sharing of Information
We do not sell personal information. We share information only with:
- Sub-processors who help us operate the Service (cloud hosting, authentication, email delivery, analytics, error monitoring). Each is bound by data-protection obligations.
- Legal authorities when required by applicable law, subpoena, or to protect rights and safety.
- Acquirers in connection with a merger, sale, or asset transfer, subject to the terms of this Policy.
5. Data Retention
We retain account information for as long as your account is active and as needed to provide the Service. You may request deletion at any time by emailing privacy@navflow.ai. Customer data retention follows your configured retention policy within the product.
6. Security
We use industry-standard safeguards (encryption in transit, encryption at rest for sensitive data, access controls, and audit logging) to protect your information. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction (including the EU/UK under GDPR and California under CCPA), you may have the right to access, correct, delete, or port your personal information, and to restrict or object to certain processing. Contact us at privacy@navflow.ai to exercise these rights.
8. International Transfers
NavFlow is operated from the European Union. If you access the Service from outside the EU, your information may be transferred to and processed within the EU. Where required, we use Standard Contractual Clauses or equivalent safeguards.
9. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced via the Service or email. The “Last updated” date at the top reflects the current version.
11. Contact
Questions or requests about this Policy:
GlassFlow GmbH
Prinzessinnenstraße 19/20, 10969 Berlin, Germany
privacy@navflow.ai