Legal

Privacy Policy

IconFlow Labs ("we", "us" or "our") takes privacy seriously. This policy explains how personal data is handled when you visit, create an account for, or use the IconFlow Labs software service (the "Service").

This policy distinguishes storage and processing needed to provide the Service from optional product analytics. Optional analytics remains off until you consent. These controls support privacy choices but are not, by themselves, a claim of legal compliance.

Controller

IconFlow Labs determines the purposes and means of the processing described here. No postal address or registration details are stated because no verified details are present in the Service configuration. Privacy questions can be sent to the contact address below.

On this page

1. Scope

This policy applies to visitors, registered users and customers of the Service. It covers the public website, authenticated product, support functions and payments. Third-party services linked from IconFlow have their own privacy notices.

2. Data we process

The data processed depends on how you use IconFlow. We seek to limit it to what is needed for the purposes described below.

  • Account and profile data, such as email address, authentication identifier, name where supplied, language and interface preferences.
  • Authentication and security data, including session tokens, login events and information needed to prevent abuse.
  • Product data, including generation settings, prompts, generated icons or logos, exports and usage history needed to provide the Service.
  • Support data, including ticket subjects, messages, attachments and technical context that you submit.
  • Billing and transaction data, such as the selected credit pack, currency, amount, billing address, tax information, Stripe customer and invoice references. IconFlow does not receive full card credentials.
  • Technical data supplied in ordinary network requests, such as IP address, browser, device, operating system, language, timestamps and requested routes.
  • Optional analytics data described in section 6, but only after analytics consent.

3. Why we process data

  • Create and secure accounts, authenticate users and maintain sessions.
  • Generate, save, display and export requested icon and logo assets.
  • Provide purchased credits, invoices, customer support and service communications.
  • Calculate tax, prevent fraud, enforce usage limits and meet accounting or other legal duties.
  • Maintain reliability, investigate errors and protect the Service and its users.
  • With consent, understand acquisition, signup, onboarding, activation and purchase paths and improve product usability.

5. Service providers and recipients

We use providers only for defined operational purposes and disclose data as needed for those purposes. Current integrations found in the Service include:

  • Supabase for database, storage and account authentication, including necessary authentication cookies.
  • Google as an optional OAuth login provider when you choose Sign in with Google. The Service requests the data needed to authenticate the account.
  • Stripe for payment checkout, billing, tax and transaction processing. Card and payment credentials are handled by Stripe, not PostHog.
  • Resend for transactional and service email delivery.
  • GitHub for the configured support-ticket workflow; support content may be copied to the private or restricted repository configured by IconFlow administrators.
  • Trustpilot review invitations may be facilitated through the configured after-sales email address when a payment confirmation is sent.
  • AI and infrastructure providers where needed to generate and store requested assets.
  • PostHog for optional product analytics as described below.

6. Optional PostHog product analytics

IconFlow uses PostHog Cloud EU only after you accept analytics. Before that choice, the browser SDK is not initialized, analytics events and identification are not sent, PostHog storage is not created and session replay does not start. Rejecting analytics does not prevent account creation or ordinary use of the Service.

The implementation sends selected events rather than automatically capturing every click or form. It can measure sanitized page views, navigation choices identified by a stable application-route name, email or Google signup start and authoritative authenticated completion, onboarding completion, first successful logo generation, pricing views, checkout start and confirmed one-time credit-pack purchases. Event properties are limited to bounded operational values such as signup method, product surface, content mode, quality, plan, one-time billing period and currency, plus browser or device information added by the service.

Analytics may also measure batch creation, successful sample and full-batch generation, and successful exports. Properties are limited to operational values such as input method, sample size, item count, quality, content mode, workflow and export format.

Page and landing URLs are reduced to paths without query strings or fragments, and referrers are reduced to their origin. Only sanitized UTM source, medium, campaign, term and content values are retained as acquisition properties. SDK-generated current, initial and session-entry URL properties, including replay network request names, are stripped of query strings and fragments before sending. Authenticated analytics is associated with the stable internal Supabase authentication UUID so the journey from signup through activation and purchase can be understood. Names, email addresses, phone numbers, addresses, passwords, authentication tokens, support messages, prompts, descriptions, filenames, generated content, Stripe session or invoice identifiers, full billing details and card data are not intentionally sent to PostHog.

After Stripe confirms a one-time credit-pack payment through the signed invoice.paid webhook, the backend may send purchase_completed only when the user's current server-side analytics consent is granted for the current policy version. Delivery is deduplicated with a secret-derived identifier and includes only plan, one-time billing period and currency. Stripe and the IconFlow database remain authoritative for payment and credits.

Analytics is used to improve signup and onboarding, identify usability problems, measure activation, improve product features, understand conversion paths and acquisition channels, and assess reliability where the selected events support it. PostHog failures do not block product functions.

6.1 Session replay and automatic capture

Session replay and limited automatic capture are optional and start only after analytics consent. Replay records product interactions. Form inputs, DOM attributes, customer-created text and all text not explicitly marked as safe are masked. Images, canvas or video content and marked customer-content elements are blocked. Safe interface labels and limited application-generated operational values, such as selections, status, progress, costs, credit balance and timestamps, can remain readable so workflows are understandable. Prompts, descriptions, filenames, names, emails, support messages and generated content are not revealed. PostHog automatically captures only clicks or changes on buttons and choice controls; automatic page views and page-leave events, dead-click capture, heatmaps, exception capture, performance capture, surveys and feature-flag requests remain disabled. You can withdraw consent at any time in Analytics settings, which stops replay and later browser events.

6.2 Consent and withdrawal

Analytics is optional and off by default. You can accept or reject it in the first-view banner and later reopen Analytics settings from the public footer or authenticated application navigation. Changing from accepted to rejected opts PostHog out, resets the analytics identity, removes accessible PostHog identity and session storage and legacy PostHog cookies, and prevents later browser events. PostHog may retain its local opt-out marker with value 0 so the SDK continues to honor the withdrawal. Necessary authentication cookies are not removed. A reload is not normally required.

6.3 Hosting and transfers

The configured ingestion host is PostHog Cloud EU (eu.i.posthog.com). PostHog states that Cloud EU data is hosted in Frankfurt. PostHog, Inc. is the processor and its current data-processing terms state that processing may also occur outside the protected area, including in the United States and locations used by listed subprocessors, with transfer mechanisms described in its DPA. We do not claim that analytics data can never leave the EEA or Switzerland. Production administrators must keep the EU host configured, review the DPA and subprocessor list, and verify that PostHog project-level IP capture remains disabled.

7. Cookies and browser storage

Necessary storage remains active because it supports authentication, security, application operation, preferences and remembering your analytics choice. Analytics storage is separate and optional.

  • iconflow_analytics_consent: first-party necessary cookie storing only policy version 1 and granted or denied. It lasts approximately 180 days and is readable by the application so the choice can be enforced.
  • Supabase authentication cookies, normally named with the sb-[project-reference]-auth-token pattern and sometimes split into numbered chunks: necessary session and token storage, lasting according to the configured authentication session and refresh-token rules.
  • theme: necessary preference in localStorage used by the interface theme provider, retained until changed or cleared. Language is primarily represented in the page URL and account preference.
  • ph_[PostHog-project-token]_posthog: optional PostHog localStorage created only after consent. It stores the analytics distinct identifier, session and related analytics state. The configured implementation uses localStorage only, not PostHog cookies. localStorage has no fixed browser expiry and remains until it is cleared, consent is withdrawn or the browser removes it.
  • __ph_opt_in_out_[PostHog-project-token]: PostHog's optional localStorage consent marker, written as 1 after acceptance and 0 after withdrawal following a prior acceptance. It has no fixed browser expiry. The value 0 may remain after withdrawal to enforce the opt-out; it contains no analytics identifier.

8. Payments and Stripe

Stripe processes checkout, payment credentials, billing details, tax and transaction records under its own privacy terms. IconFlow receives references and status information needed to issue credits, invoices and support purchases. With current analytics consent, PostHog may receive the bounded checkout-start and purchase-completion fields listed in section 6, but not Stripe session, customer or invoice identifiers, card credentials or full billing information. Stripe and the IconFlow database remain authoritative for transaction processing and credits.

9. Advertising and webmaster tools

No Google Analytics, Microsoft Clarity, Meta Pixel, advertising or remarketing tag, chat widget, or visitor-tracking embed was found in the application code during this update. A NEXT_PUBLIC_GA_MEASUREMENT_ID environment entry exists but is not referenced by application code; it does not activate Google Analytics by itself and should be removed if obsolete. Verification or indexing tools without a visitor script are not treated as analytics cookies. If tracking or advertising technology is added later, this policy and the consent categories must be reviewed before activation.

10. Retention and security

We retain personal data only for as long as reasonably needed for the Service, the purposes above, dispute handling and applicable accounting or legal duties. Account deletion does not necessarily erase transaction records that must be retained by law. Provider retention settings also apply. Analytics retention must be configured and periodically reviewed in PostHog.

We use reasonable technical and organisational measures intended to protect data, including access controls and authenticated service boundaries. No online service can guarantee absolute security.

11. Your choices and rights

Depending on your location and applicable law, including Swiss law and, where applicable, EEA or UK data-protection law, you may have rights to request access, correction, deletion, restriction, objection, portability or withdrawal of consent, and to complain to a competent supervisory authority. These rights can be subject to legal conditions and exceptions. We may need to verify your identity before acting on a request.

You can withdraw analytics consent at any time through Analytics settings. Withdrawal does not affect processing that occurred before withdrawal. You may also contact us about deletion of analytics data associated with your internal account identifier.

12. Children and policy changes

The Service is not directed to children under 16 and we do not knowingly collect their personal data without authorization required by applicable law. Contact us if you believe a child has supplied personal data.

We may update this policy as the Service and its providers change. Material changes to optional analytics purposes can trigger a new consent request by increasing the stored consent-policy version; cosmetic wording changes alone should not. The date above shows the latest revision.

13. Contact

For privacy questions or requests, contact support@iconflowlabs.com. No unverified company address, representative, registration number or separate privacy email has been added to this policy.

Privacy contact: support@iconflowlabs.com

Back to top