Last updated: August 8, 2026
Privacy Policy
This Policy explains how SphereFlow handles information when you visit the site, create an account, use a workspace, import contacts, use AI-assisted features, or contact support.
Information We Process
- Account data: name, email, profession, authentication records, legal acceptance, workspace membership, and preferences.
- CRM data: names, contact details, dates, notes, relationships, interactions, reminders, custom fields, avatars, and imported files or mappings.
- Billing data: plan, subscription status, Stripe customer and subscription identifiers, invoices, and payment events. SphereFlow does not store full card numbers.
- Usage and security data: product events, feature usage, AI usage counts, request metadata, rate-limit hashes, device/browser information, and operational logs.
- Support data: messages and diagnostics you provide when requesting help.
How We Use Information
We use information to provide and personalize workspaces, build relationship queues, process imports and exports, generate reminders, deliver requested AI assistance, manage subscriptions, send account and digest emails, prevent abuse, troubleshoot problems, understand activation and conversion, and comply with legal obligations.
Contact Data and Workspace Roles
Workspace customers decide which contact data to submit and how to use it. In that context, the customer is responsible for notices, permissions, access requests, and industry rules that apply to those contacts. Active members of a shared workspace can access shared CRM data according to their role.
AI Processing
When you request AI extraction, the relevant contact context and interaction notes are sent to the configured API provider, such as Google Gemini or OpenAI. SphereFlow meters these requests and stores resulting suggestions for your review. Avoid submitting sensitive data that is unnecessary for the requested task.
Service Providers
We use service providers to operate SphereFlow, including Supabase for database, authentication, storage, and scheduled requests; Vercel for application hosting; Stripe for billing; Resend for email; Cloudflare Turnstile for authentication abuse protection; Sentry for sanitized error monitoring; and configured AI API providers. Sentry is configured not to receive CRM notes, request bodies, cookies, authorization headers, AI inputs, contact information, or user identity. These providers process information under their own terms and our service arrangements.
Analytics and Cookies
SphereFlow records first-party product events such as signup, onboarding, import, queue completion, AI usage, activation, and subscription changes. The current product does not require third-party advertising trackers. Authentication and security technologies may use cookies or local storage needed to keep you signed in and protect the service.
Retention and Security
Ending a paid subscription does not delete account or workspace data. While an account remains open, saved CRM data remains available read-only after paid access ends so the customer can view, export, or delete it. We otherwise retain data while needed to provide the service, meet legal obligations, resolve disputes, and protect the platform. You can delete a personal account from Settings; shared data may remain for other workspace members. We use access controls, row-level tenant policies, private storage, signed URLs, webhook verification, rate limits, and encryption provided by our infrastructure, but no system can guarantee absolute security.
Your Choices
- Update profession, workflow, notification, and billing preferences in the app.
- Download contact CSV and full account JSON exports from Settings.
- Disable weekly digests or lifecycle emails in Settings or through an email preference link.
- Delete your account from Settings. Workspace administrators may also manage shared access.
- Contact us about access, correction, deletion, or privacy rights that apply in your location.
Children and International Use
SphereFlow is not directed to children under 13. Information may be processed in the United States and other locations where service providers operate, subject to applicable safeguards.
Changes and Contact
We may update this Policy and will post the revised date. Privacy questions and requests can be sent to [email protected].