Skip to content

How Flow Studio handles your data

This page covers all Flow Studio products: Flow Studio App, Flow Studio MCP, and Flow Studio for Teams.

Flow Studio App (browser)

Flow Studio App runs in your browser. Data you open is handled locally in your browser session unless you explicitly export or share it.

  • We retain only an email address used for login and subscription verification
  • We do not store your flows, flow definitions, run history, credentials, or connections on our servers

Flow Studio does not access or transmit browser session data to our servers. To clear locally stored data, use your browser’s Clear Site Data function for flowstudio.app. On shared devices, using a private or incognito window prevents any data from being stored after the session ends.

Flow Studio MCP

Flow Studio MCP is the agent-facing gateway that lets AI agents read, debug, build, and manage Power Automate flows on your behalf.

What we store:

  • Authentication data needed to validate API requests
  • Subscription plan and billing status (starter / pro / pro+)
  • Usage records such as call counts, tool names, timestamps, and status codes

What we do not store:

  • Your flow action payload bodies, connector secrets, or full run input/output content
  • Billing and enforcement are based on call counts and plan entitlements, not on the business content inside your flows

The MCP service does not store your flow content as part of normal request handling. It brokers authenticated calls to upstream services. Billing data is managed by Stripe.

Flow Studio for Teams

Flow Studio for Teams provides tenant-wide scanning, monitoring, and governance for Power Automate flows and Power Apps.

What we store:

  • Metadata scans of flows, Power Apps, runs, environments, connectors, and makers
  • Governance metadata: business impact, ownership, support group, compliance flags
  • Minimal maker profile data for identification and role mapping

Storage options:

  • Flow Studio-managed Azure storage
  • Your own Azure storage (Bring Your Own Storage, available by request)
MCP Pro+ and Flow Studio for Teams

MCP Pro+ uses the same Azure Table Storage infrastructure as Flow Studio for Teams.

How we use error data to improve the service

We analyze error patterns from MCP tool calls (e.g. common API errors, malformed inputs) to improve validation, error handling, and agent guidance. This uses error metadata and status codes, not your flow business logic or payload content.

We do not send your data to third-party AI models for training.

Infrastructure and third parties

Across products, Flow Studio relies on:

  • Microsoft Azure — compute, storage, networking, monitoring
  • Microsoft Entra ID — identity and authentication
  • Stripe — subscription and billing
  • Google Analytics — site-level analytics on publicly accessible MCP site pages only. GA4 is not enabled on the MCP agent request path (JSON-RPC calls are not tracked)

Flow Studio does not sell personal data.

Security
  • Data is encrypted in transit and protected at rest using platform controls from Azure and Stripe
  • Access controls scoped by tenant and workspace identity
  • Separation between subscription billing data and product operational data
  • Secrets management — Customer refresh tokens are stored separately in encrypted Azure Table Storage. API keys and tokens are never logged
Retention and deletion
  • Account and subscription records: retained while the account is active and deleted or anonymized after closure
  • Usage and action logs: kept while the account is active, and may be retained longer when needed for billing, security investigation, or abuse prevention
  • Teams scan data: kept while the service is active and deleted on cancellation based on contract terms and customer instructions
  • Stripe records: retained per Stripe and financial recordkeeping requirements
Your rights

You can request to:

  • Access personal data we hold about your account
  • Correct inaccurate profile data
  • Revoke consent connections
  • Rotate or regenerate API keys
  • Request deletion of workspace-associated data

Contact: support@flowstudio.app

Legal

Flow Studio services are operated by Flow Studio Solutions, based in Sydney, New South Wales, Australia. This privacy notice is governed by the laws of New South Wales, Australia, unless mandatory consumer or privacy laws in your jurisdiction require otherwise. For privacy inquiries, complaints, or data rights requests, contact support@flowstudio.app.