Privacy Policy

Last updated: 2026-08-10. This policy applies to cakeflow.app and every workspace and portal we host on your behalf.

This policy explains, in plain language, what personal data CakeFlow handles, why, and what you can do about it. If you're a data protection officer or a university procurement reviewer, the short version is at the bottom under "For institutional reviewers."

Who we are

CakeFlow is operated by CakeFlow Pte. Ltd.. In this policy, "CakeFlow," "we," and "us" mean that entity. "You" means the person using CakeFlow — either directly, or through a workspace your employer or an agency set up for you.

For customers in the EU, UK, and other regions with data protection laws, we act as a data processor for the content you record inside your workspace, and as a data controller for the account information you give us to create and bill the account.

What data we handle, and why

We split personal data into two categories because they're handled very differently.

1. Account data (we're the controller)

Data you give us so we can run your account.

  • Name and email address of workspace admins and members.
  • Billing contact and tokenised payment method (we never see or store card numbers — the payment processor handles that).
  • Workspace name, workspace domain, logo, and other branding you upload.
  • Support conversations and anything you send us by email or through the contact form.

We use this to create your account, authenticate you, send you transactional email (receipts, security alerts, expiry warnings), bill you, and provide support. We don't sell it, we don't share it with advertisers, and we don't use it to train AI models.

Legal basis (GDPR): contract performance, and our legitimate interest in running and securing the service.

2. Workspace content (we're the processor)

Data captured through the browser extension when someone in your workspace records a workflow.

  • Screenshots of the screen during the recording.
  • A text-based action log — clicks, field names, page transitions, timestamps.
  • Typed values in non-sensitive fields, so steps can be described accurately in the generated guide.
  • Recording metadata — who recorded, when, in which workspace.

This may contain personal data belonging to your users, students, or customers — for example, a student's name visible on a registrar screen. We process it only to generate the outputs you asked us to generate (video, docs, FAQ, AI answers) and to keep the portal running.

Legal basis (GDPR): we process it on your written instructions under the Data Processing Addendum you sign when you create a paid workspace. You are the controller.

What we don't collect

We want to be blunt about this because it matters for approvals.

  • We don't record keystrokes outside an active recording window.
  • We don't capture browsing activity outside the extension.
  • We don't store the contents of password fields, even temporarily. They're blocked before capture.
  • We don't store payment card numbers.
  • We don't sell any personal data to anyone, ever.

What the AI sees

The AI assistant that powers "chat with your portal" is trained per-workspace on your recorded workflows. It reads the text-based action log, not screenshots.

Screenshots stay in our storage and are used only to render the video and step images. They are never sent to the AI provider.

The inference is always run through a Western AI provider (US or EU-based). We may use open-weight models originating in China (Qwen, DeepSeek, Kimi, GLM) because they cost 5–30× less to run than comparable alternatives, but the server that receives your data is always a US or EU company we can sign a DPA with. We do not call Chinese AI vendors' APIs directly.

The model provider does not train its base models on your data. We contractually require zero-retention or short-retention endpoints where available.

Sub-processors

We use a small number of sub-processors. The current list is on our Security page. We notify workspace admins by email at least 30 days before any material change, and you can object.

Where your data is stored

You choose your storage region — EU, US, or AU — at the workspace level, and screenshots and recordings for that workspace stay in that region.

Some sub-processors (transactional email, payment processing) are US-based. When personal data leaves the EEA/UK, we use the European Commission's Standard Contractual Clauses and, where applicable, the UK IDTA, together with technical measures like encryption in transit and at rest.

How long we keep it

Workspace content

Default retention is 90 days. You can configure this per workspace, including auto-delete after N days.

Account data

Kept while your account is active, and for up to 12 months after cancellation for tax, audit, and dispute-handling reasons. After that, we delete or fully anonymise it.

Backups

Encrypted backups are held for up to 35 days and then rotated out.

Support emails

Kept for up to 24 months.

If you cancel, you can still export all your content — see the Data export page. Once the retention window ends, deletion is permanent.

Your rights

If you have an account with us directly, you can:

  • Access the personal data we hold about you.
  • Correct it if it's wrong.
  • Export your account data in a machine-readable format.
  • Delete your account and your workspace's content.
  • Object to a specific use, or restrict processing while we sort a dispute.
  • Withdraw consent where processing is based on consent.

Do any of these from your workspace settings, or email privacy@cakeflow.app. We answer inside 30 days, usually inside 5 working days.

If your personal data sits inside someone else's workspace — for example, you're a student and your university records a registrar workflow — please contact that institution first. They are the controller. We'll support them in responding to you.

You have the right to complain to your local data protection authority. For the EU, that's the authority in your country of residence; for the UK, the ICO.

Security

We use TLS in transit and AES-256 at rest. Access is role-based, with SSO available on the Agency plan, and internal engineering access is logged and limited to on-call. Full detail on the Security page.

If something goes wrong, we notify affected workspace admins without undue delay — and in any case within 72 hours of becoming aware of a personal data breach that meets the GDPR notification threshold.

Cookies and analytics

On the marketing site (cakeflow.app), we use a small set of cookies:

Strictly necessary

Cookies to keep you logged in and remember your workspace.

Analytics

Cookies to understand which pages get read (we currently use a privacy-friendly, cookieless analytics provider, so no personal identifier is shared).

Inside a customer portal, we use only what's needed to serve the portal itself and record aggregate analytics for the workspace owner. We do not run advertising cookies, we do not sell traffic data, and there are no third-party ad pixels on our pages.

Children

CakeFlow is a workplace tool. We do not knowingly collect personal data from children under 13 (or the equivalent minimum age in your country). If a university uses CakeFlow to train staff on a system that serves students, those students' personal data can appear inside recordings — that's the university's decision as controller, and it's governed by our DPA and, where relevant, our FERPA-aligned controls.

Changes to this policy

If we change this policy in a way that reduces your rights or changes how we handle content, we email workspace admins at least 30 days before the change takes effect. Small clarifications, we just update.

Contact

Privacy questions and rights requestsprivacy@cakeflow.app

For institutional reviewers

  • We are a processor under GDPR for workspace content, and a controller for account data.
  • DPA is available and signable from day one — download it from the Security page.
  • Storage region is a workspace-level choice: EU, US, or AU.
  • Sub-processor list, encryption, retention, and access controls are on the Security page.
  • AI provider receives only text-based action logs, never screenshots.
  • FERPA: we act as a school official / service provider under the controls described on the Security page. No SOC 2 report yet — target completion published there.