What ClientFlow accesses
ClientFlow accesses only Notion pages and databases selected during OAuth authorization. The product reads mapped client, project, task, and service metadata needed to preview and execute delivery workflows.
Privacy
This policy explains the data ClientFlow reads and stores to connect Notion, validate mappings, preview delivery plans, execute approved work, and retain Delivery Receipts.
ClientFlow accesses only Notion pages and databases selected during OAuth authorization. The product reads mapped client, project, task, and service metadata needed to preview and execute delivery workflows.
ClientFlow stores account identity, workspace identifiers, encrypted Notion OAuth tokens, database role mappings, schema hashes, templates, rules, preview runs, action records, and Delivery Receipts.
Notion access tokens are encrypted at rest with AES-256-GCM and are never exposed to the browser.
ClientFlow is designed to retain operational identifiers and execution evidence, not a full copy of customer workspace content.
Customers can request disconnection and deletion of retained workspace data through support. Disconnecting a workspace pauses automation and keeps rules for recovery until deletion is requested.
ClientFlow is in a private/founding pilot stage. Enterprise controls such as SOC 2, regional residency, and a public status page are roadmap items, not current claims.