Legal
Privacy policy
This policy explains what Second Flow handles when it provides comprehension coverage for AI-generated code, why that information is needed, and the choices available to you.
Effective August 27, 2026
At a glance
What Second Flow does
Second Flow creates understanding checks from code changes and approved project context, receives authors' explanations, and gives their organization an ownership signal.
What we handle
Account and organization details, repository and pull request context, submitted explanations, results, integration data, support messages, and technical logs.
What we do not do
We do not sell personal information or share it for cross-context behavioral advertising. We do not use customer content to train general-purpose AI models.
Your controls
Depending on where you live, you may ask to access, correct, delete, restrict, object to, or export personal information. Email [email protected].
This policy is provided for transparency, but it is not a data processing agreement. If your organization has a separate order, data processing agreement, or enterprise contract with Second Flow Inc., that agreement controls where it conflicts with this policy.
1. Scope and roles
Second Flow Inc. operates the Service from Encinitas, California, United States. This policy applies to secondflow.app, the Second Flow console, the author-facing ownership experience, and related services (together, the “Service”).
An organization usually decides which repositories to connect, which people may use the Service, and why their work data is processed. For that organization-controlled data, the organization is generally the controller or business and Second Flow Inc. acts as its processor or service provider. Second Flow Inc. is the controller or business for account administration, security, support, and operation of its own website.
If you use Second Flow through your employer or another organization, contact that organization first about its use of your work data. We will help it respond to verified requests as required by law and our agreement with it.
2. Information we collect
Account and organization information
We receive identifiers and profile information needed to create and secure an account, such as your name, work email address, authentication identifier, organization name, team membership, role, and account preferences. Authentication is provided through Clerk; we do not receive your third-party account password.
Repository, change, and integration information
When an organization connects GitHub or another approved source, we may receive installation and repository identifiers, repository names, pull request metadata, commit identifiers, branch names, diffs, changed files, bounded surrounding source code, comments, check-run status, webhook events, and the identity associated with a change. We also receive authorization metadata and short-lived credentials needed to access only the connected resources.
Connected project context
At an organization's direction, Context Gateway may retrieve scoped content from selected documentation, work tracking, repository guidance, or approved internal tools. This can include architecture notes, runbooks, requirements, acceptance criteria, tickets, and metadata identifying the source. We retrieve the bounded context needed for the relevant change rather than an unrestricted copy of every connected source.
Understanding check content
We process generated questions, possible answers, your responses, the explanation you submit, completion status, immutable results, feedback, understanding-policy settings, and ownership signals. This content can be associated with you, a source revision, a repository, and your organization.
Communications
If you request beta access, contact support, or otherwise communicate with us, we receive your contact details and the contents and history of that communication.
Device and operational information
Our systems and infrastructure providers automatically process IP address, approximate location derived from IP, browser and device type, operating system, requested pages, timestamps, referring page, authentication and session events, error data, and security logs. We use this information to deliver the Service, diagnose failures, prevent abuse, and protect accounts.
Information we do not intentionally collect
The Service is not designed to collect payment card numbers, government identifiers, precise location, biometric identifiers, health information, or other sensitive personal information. Customers and users should not put secrets, production credentials, regulated personal data, or unrelated personal information in repositories, connected context, responses, or support messages.
3. How we collect information
- From you when you create an account, choose preferences, submit an explanation, request access, or contact us.
- From your organization when an administrator adds you, configures an understanding policy, or connects a repository or context source.
- From integrations such as GitHub when they send authorized API responses or webhook events.
- Automatically through essential cookies, server logs, and security systems when you use the Service.
We do not buy personal information from data brokers.
4. How we use information
- Provide accounts, organization administration, integrations, understanding checks, explanations, results, and ownership signals.
- Select and assemble relevant code and project context for a specific source revision.
- Generate grounded questions and evaluate responses against the information available for that change.
- Publish completion and policy status to the connected source control provider when the organization enables that workflow.
- Authenticate users, enforce permissions, detect abuse, verify webhooks, investigate incidents, and keep the Service reliable.
- Respond to support requests and communicate material product, security, policy, or account changes.
- Analyze aggregated or de-identified operational patterns to find confusing workflows, recurring failures, and areas where the Service needs improvement.
- Comply with law, enforce our agreements, and establish, exercise, or defend legal claims.
We do not use an individual's explanation or ownership signal for advertising. Organizations should not use Second Flow as the sole basis for employment, compensation, disciplinary, or similarly significant decisions about a person.
5. AI-assisted processing
Second Flow uses OpenAI's API to generate understanding checks and may use it to evaluate free-form responses. We send a bounded input containing the code change and context selected for that check. Our integration asks the API not to store application state. OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days unless a different approved retention control applies or law requires longer retention.
OpenAI states that API inputs and outputs are not used to train its general-purpose models by default. Second Flow Inc. does not opt in customer content for model training. We do not train a separate general-purpose model on customer repositories, context, or explanations.
AI output can be incomplete or incorrect. Second Flow validates generated content against the supplied source references, but an organization remains responsible for its review and use of results.
6. Legal bases for processing
Where the GDPR, UK GDPR, or similar law applies, we rely on the following legal bases:
- Contract. To create your account and provide the Service requested by you or your organization.
- Legitimate interests. To secure, support, and improve the Service; communicate with business users; prevent fraud and misuse; and protect our rights, provided those interests are not outweighed by your rights.
- Consent. Where we ask for it, such as for optional marketing or non-essential cookies. You may withdraw consent at any time.
- Legal obligation. To comply with applicable law and valid legal process.
For organization-controlled customer content, the organization determines the legal basis and we process the information on its documented instructions.
8. International data transfers
Second Flow Inc. and its providers operate primarily in the United States. If information is transferred from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with transfer restrictions, we use a recognized safeguard when required, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or a valid adequacy mechanism. Contact us to request information about the safeguard relevant to your data.
9. Retention
| Information | Typical retention |
|---|---|
| Account and organization records | While the account is active, then deleted or anonymized within 30 days after closure unless law requires longer. |
| Repository snapshots, connected context, understanding checks, explanations, results, and ownership signals | While the organization uses the Service, then deleted within 30 days after account closure or a verified deletion request, subject to contract and legal exceptions. |
| Webhook payloads and delivery records | Payloads for up to 30 days; minimal delivery identifiers and security records for up to 12 months. |
| Security, access, and application logs | Usually 90 days; up to 12 months when needed to investigate an incident or prevent repeated abuse. |
| Support and business communications | Up to 24 months after the conversation closes, unless needed for an active account or legal claim. |
| Backups | Removed through normal backup rotation within 90 days after deletion from active systems. |
We may retain information longer when required by law, a litigation hold, a security investigation, or a contract with your organization. When possible, we isolate it from ordinary use. Aggregated or de-identified information may be retained if it cannot reasonably be linked back to a person or customer.
10. Your choices and privacy rights
Depending on your location and subject to legal exceptions, you may have the right to:
- Know whether and how we process your personal information.
- Access and receive a copy of personal information.
- Correct inaccurate personal information.
- Delete personal information.
- Restrict or object to certain processing.
- Receive portable information you provided to us.
- Withdraw consent without affecting prior lawful processing.
- Opt out of sale, sharing for behavioral advertising, targeted advertising, or qualifying profiling. We do not currently engage in these practices.
- Appeal a denial where applicable state law provides that right.
- Complain to your local data protection authority. EEA residents can find their authority through the European Data Protection Board; UK residents may contact the Information Commissioner's Office.
To make a request, email [email protected] with “Privacy request” in the subject. Describe your request and the account or organization involved. We may need to verify your identity and authority. Authorized agents may submit requests where permitted by law. We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.
If your organization controls the information, we may send the request to its administrator or ask you to submit it there. You can unsubscribe from optional promotional email through the link in the message or by contacting us. Required service and security notices are not promotional messages.
11. California privacy notice
In the preceding 12 months, we may have collected the categories described below. California law defines categories broadly, so a category can apply even when we collect only the examples listed.
| California category | Examples from Second Flow | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Name, work email, account ID, IP address, repository and integration identifiers | Authentication, hosting, security, integration, and support providers; your organization |
| Customer-record information | Organization, role, and support contact details | Authentication, hosting, and support providers; your organization |
| Commercial information | Service plan or account relationship, if applicable | Infrastructure and business operations providers |
| Internet or electronic activity | Pages and features used, sessions, repository events, integration activity, and logs | Hosting, security, authentication, and integration providers; your organization |
| Professional information | Work identity, organization membership, authorship of code changes, submitted explanations, and results | AI, hosting, authentication, and integration providers; your organization |
| Inferences | Ownership signals derived from understanding checks and results | Infrastructure providers; your organization |
| Sensitive personal information | Account sign-in credentials handled by our authentication provider; contents of private repository data only to the extent California law classifies it as sensitive | Authentication, AI, infrastructure, and integration providers as needed to provide the Service |
We collect these categories from you, your organization, connected services, and automatic technical systems for the purposes in section 4. We do not use sensitive personal information to infer characteristics about California consumers. We do not sell or share these categories for cross-context behavioral advertising, and we do not knowingly sell or share personal information of anyone under 16.
13. Security
We use safeguards designed for the nature of the information we process, including encrypted network transport, managed authentication, role-based access, short-lived integration tokens, webhook signature verification, tenant boundaries, bounded model inputs, logging controls, and provider access restrictions. We review access and limit it to people and providers who need the information to operate or support the Service.
No online service can guarantee absolute security. If you believe you found a vulnerability or that an account may be compromised, contact [email protected].
14. Children's privacy
Second Flow is a business service for workplace software development and is not directed to children under 13 or the minimum age required in their jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can investigate and delete it.
15. Changes to this policy
We may update this policy when the Service, our providers, or legal requirements change. We will post the revised policy with a new effective date. If a change materially affects how we use personal information, we will provide additional notice through the Service or by email before it takes effect when required by law.
16. Contact
Second Flow Inc.
Encinitas, California, United States
[email protected]
Direct privacy requests to the email above with “Privacy request” in the subject. If applicable law requires a formal mailing address, data protection representative, or data protection officer for your relationship with Second Flow, we will provide the relevant contact details in your organization's agreement or upon request.
