1. Scope
This policy applies to visitors, registered users and customers of the Service. It covers the public website, authenticated product, support functions and payments. Third-party services linked from IconFlow have their own privacy notices.
2. Data we process
The data processed depends on how you use IconFlow. We seek to limit it to what is needed for the purposes described below.
- Account and profile data, such as email address, authentication identifier, name where supplied, language and interface preferences.
- Authentication and security data, including session tokens, login events and information needed to prevent abuse.
- Product data, including generation settings, prompts, generated icons or logos, exports and usage history needed to provide the Service.
- Support data, including ticket subjects, messages, attachments and technical context that you submit.
- Billing and transaction data, such as the selected credit pack, currency, amount, billing address, tax information, Stripe customer and invoice references. IconFlow does not receive full card credentials.
- Technical data supplied in ordinary network requests, such as IP address, browser, device, operating system, language, timestamps and requested routes.
- Optional analytics data described in section 6, but only after analytics consent.
3. Why we process data
- Create and secure accounts, authenticate users and maintain sessions.
- Generate, save, display and export requested icon and logo assets.
- Provide purchased credits, invoices, customer support and service communications.
- Calculate tax, prevent fraud, enforce usage limits and meet accounting or other legal duties.
- Maintain reliability, investigate errors and protect the Service and its users.
- With consent, understand acquisition, signup, onboarding, activation and purchase paths and improve product usability.
4. Legal grounds
Depending on the processing and applicable law, we rely on steps requested before entering a contract, performance of the Service contract, legal obligations, legitimate interests such as security and service improvement, or your consent. Optional PostHog analytics is based on consent where consent is the applicable basis. Withdrawing analytics consent does not affect processing that is genuinely needed to provide the Service or meet legal duties.
5. Service providers and recipients
We use providers only for defined operational purposes and disclose data as needed for those purposes. Current integrations found in the Service include:
- Supabase for database, storage and account authentication, including necessary authentication cookies.
- Google as an optional OAuth login provider when you choose Sign in with Google. The Service requests the data needed to authenticate the account.
- Stripe for payment checkout, billing, tax and transaction processing. Card and payment credentials are handled by Stripe, not PostHog.
- Resend for transactional and service email delivery.
- GitHub for the configured support-ticket workflow; support content may be copied to the private or restricted repository configured by IconFlow administrators.
- Trustpilot review invitations may be facilitated through the configured after-sales email address when a payment confirmation is sent.
- AI and infrastructure providers where needed to generate and store requested assets.
- PostHog for optional product analytics as described below.
6. Optional PostHog product analytics
IconFlow uses PostHog Cloud EU only after you accept analytics. Before that choice, the browser SDK is not initialized, analytics events and identification are not sent, PostHog storage is not created and session replay does not start. Rejecting analytics does not prevent account creation or ordinary use of the Service.
The implementation sends selected events rather than automatically capturing every click or form. It can measure sanitized page views, navigation choices identified by a stable application-route name, email or Google signup start and authoritative authenticated completion, onboarding completion, first successful logo generation, pricing views, checkout start and confirmed one-time credit-pack purchases. Event properties are limited to bounded operational values such as signup method, product surface, content mode, quality, plan, one-time billing period and currency, plus browser or device information added by the service.
Analytics may also measure batch creation, successful sample and full-batch generation, and successful exports. Properties are limited to operational values such as input method, sample size, item count, quality, content mode, workflow and export format.
Page and landing URLs are reduced to paths without query strings or fragments, and referrers are reduced to their origin. Only sanitized UTM source, medium, campaign, term and content values are retained as acquisition properties. SDK-generated current, initial and session-entry URL properties, including replay network request names, are stripped of query strings and fragments before sending. Authenticated analytics is associated with the stable internal Supabase authentication UUID so the journey from signup through activation and purchase can be understood. Names, email addresses, phone numbers, addresses, passwords, authentication tokens, support messages, prompts, descriptions, filenames, generated content, Stripe session or invoice identifiers, full billing details and card data are not intentionally sent to PostHog.
After Stripe confirms a one-time credit-pack payment through the signed invoice.paid webhook, the backend may send purchase_completed only when the user's current server-side analytics consent is granted for the current policy version. Delivery is deduplicated with a secret-derived identifier and includes only plan, one-time billing period and currency. Stripe and the IconFlow database remain authoritative for payment and credits.
Analytics is used to improve signup and onboarding, identify usability problems, measure activation, improve product features, understand conversion paths and acquisition channels, and assess reliability where the selected events support it. PostHog failures do not block product functions.
6.1 Session replay and automatic capture
Session replay and limited automatic capture are optional and start only after analytics consent. Replay records product interactions. Form inputs, DOM attributes, customer-created text and all text not explicitly marked as safe are masked. Images, canvas or video content and marked customer-content elements are blocked. Safe interface labels and limited application-generated operational values, such as selections, status, progress, costs, credit balance and timestamps, can remain readable so workflows are understandable. Prompts, descriptions, filenames, names, emails, support messages and generated content are not revealed. PostHog automatically captures only clicks or changes on buttons and choice controls; automatic page views and page-leave events, dead-click capture, heatmaps, exception capture, performance capture, surveys and feature-flag requests remain disabled. You can withdraw consent at any time in Analytics settings, which stops replay and later browser events.
6.2 Consent and withdrawal
Analytics is optional and off by default. You can accept or reject it in the first-view banner and later reopen Analytics settings from the public footer or authenticated application navigation. Changing from accepted to rejected opts PostHog out, resets the analytics identity, removes accessible PostHog identity and session storage and legacy PostHog cookies, and prevents later browser events. PostHog may retain its local opt-out marker with value 0 so the SDK continues to honor the withdrawal. Necessary authentication cookies are not removed. A reload is not normally required.
6.3 Hosting and transfers
The configured ingestion host is PostHog Cloud EU (eu.i.posthog.com). PostHog states that Cloud EU data is hosted in Frankfurt. PostHog, Inc. is the processor and its current data-processing terms state that processing may also occur outside the protected area, including in the United States and locations used by listed subprocessors, with transfer mechanisms described in its DPA. We do not claim that analytics data can never leave the EEA or Switzerland. Production administrators must keep the EU host configured, review the DPA and subprocessor list, and verify that PostHog project-level IP capture remains disabled.
8. Payments and Stripe
Stripe processes checkout, payment credentials, billing details, tax and transaction records under its own privacy terms. IconFlow receives references and status information needed to issue credits, invoices and support purchases. With current analytics consent, PostHog may receive the bounded checkout-start and purchase-completion fields listed in section 6, but not Stripe session, customer or invoice identifiers, card credentials or full billing information. Stripe and the IconFlow database remain authoritative for transaction processing and credits.
9. Advertising and webmaster tools
No Google Analytics, Microsoft Clarity, Meta Pixel, advertising or remarketing tag, chat widget, or visitor-tracking embed was found in the application code during this update. A NEXT_PUBLIC_GA_MEASUREMENT_ID environment entry exists but is not referenced by application code; it does not activate Google Analytics by itself and should be removed if obsolete. Verification or indexing tools without a visitor script are not treated as analytics cookies. If tracking or advertising technology is added later, this policy and the consent categories must be reviewed before activation.
10. Retention and security
We retain personal data only for as long as reasonably needed for the Service, the purposes above, dispute handling and applicable accounting or legal duties. Account deletion does not necessarily erase transaction records that must be retained by law. Provider retention settings also apply. Analytics retention must be configured and periodically reviewed in PostHog.
We use reasonable technical and organisational measures intended to protect data, including access controls and authenticated service boundaries. No online service can guarantee absolute security.
11. Your choices and rights
Depending on your location and applicable law, including Swiss law and, where applicable, EEA or UK data-protection law, you may have rights to request access, correction, deletion, restriction, objection, portability or withdrawal of consent, and to complain to a competent supervisory authority. These rights can be subject to legal conditions and exceptions. We may need to verify your identity before acting on a request.
You can withdraw analytics consent at any time through Analytics settings. Withdrawal does not affect processing that occurred before withdrawal. You may also contact us about deletion of analytics data associated with your internal account identifier.
12. Children and policy changes
The Service is not directed to children under 16 and we do not knowingly collect their personal data without authorization required by applicable law. Contact us if you believe a child has supplied personal data.
We may update this policy as the Service and its providers change. Material changes to optional analytics purposes can trigger a new consent request by increasing the stored consent-policy version; cosmetic wording changes alone should not. The date above shows the latest revision.
13. Contact
For privacy questions or requests, contact support@iconflowlabs.com. No unverified company address, representative, registration number or separate privacy email has been added to this policy.
Privacy contact: support@iconflowlabs.com
Back to top