Privacy & data handling

Last updated: August 2026

How your library, AI requests, and billing information are handled.

How data moves

Your library stays on the device. Cloud calls happen only when you use an AI feature, and only with the context you chose for that request.

  1. 01

    Local PDF

    Imported files stay on your computer.

  2. 02

    Local index

    Searchable passages are built on-device.

  3. 03

    You choose snippets

    Only the attached text—or a boxed figure—can leave the device.

  4. 04

    Flowing backend

    Requests are proxied over HTTPS. You do not add your own API keys.

  5. 05

    Model providers

    DeepSeek for keyword recall tasks; Kimi (Moonshot) for Ask, polish, and figures.

  6. 06

    Result returned

    The suggestion comes back to the desktop app, with evidence cards when applicable.

Published retention commitments for request bodies and third-party model providers are not yet available. Labs and institutions should contact [email protected] before using Flowing with restricted or confidential material.

Your PDF library stays local

Reference PDFs you import are stored and indexed on your device. Flowing parses text locally so you can search and attach passages without uploading your entire library to the cloud by default.

When you use AI features, only the passages and context you attach for that request are sent to Flowing’s backend for processing—not your full library.

Cloud AI models

Flowing routes AI requests through its backend to third-party models. Automatic snippet recall and related retrieval tasks use DeepSeek; Ask with context and evidence-grounded revision use Kimi (Moonshot), including multimodal understanding when figures are cited.

You do not configure API keys yourself. Default model versions may change with releases. Pro+ subscribers can access stronger model options.

What leaves your device

When you use AI features, Flowing sends the prompt plus the passages you attached for that action. If you box a PDF figure as context, that image may be sent to Kimi for multimodal understanding.

Your full PDF library, local search index, and draft files are not uploaded by default.

Web paper recommendations

Auto-recommend papers from the web is off by default. The first time you turn it on, you confirm a privacy notice. Keywords are sent to Flowing’s recommendation service; paragraph body text is sent only if you opt in.

OpenAlex metadata is used to verify that recommended works exist. Links are not invented.

Deletion and institutional use

Local PDFs, drafts, and indexes can be removed on your machine. To ask us to delete server-held account or billing records, email [email protected]. Stripe retains payment records under its own policies.

A DPA and full sub-processor retention schedule are not yet published. Research groups that require written compliance terms should contact [email protected] before using Flowing with restricted or confidential material.

Billing and account data

Paid plans and prepaid token packs are processed through Stripe. Checkout uses claim codes generated in the desktop app. We store only what is needed to verify entitlements and complete transactions.

For billing questions, contact [email protected].

Website analytics

This marketing site may use Google Analytics when enabled. The desktop application’s usage metering for AI features is separate from website analytics.

Back to home