Cross Platform Flow

Privacy Notice

CrossFlow processes only the data needed for accounts, trials, device licensing, Sandbox checkout, future order fulfillment, support, and product security.

Data-controller brand: Muiao / CrossFlow
Effective: 2026-08-30
Client analytics SDK: None
Paddle: controlled Sandbox testing; Live closed

01 / WEBSITE AND ACCOUNT

What the site and account service handle

  • Hosting and securityCloudflare may process IP address, time, path, User-Agent, response status, Turnstile results, and security events to deliver, protect, rate-limit, and troubleshoot the service.
  • Account and trialPasswordless sign-in stores the normalized email, verification time, trial start/end and paid-conversion times, and hashed one-time and session tokens. CrossFlow does not store account passwords.
  • Legal recordAfter the user actively checks the box and successfully verifies the email, CrossFlow stores the Terms version, Privacy Notice version, acceptance source, and time that applied to the account. This does not subscribe the user to marketing.
  • Device licensingDesktop sign-in stores a random installation identifier, user-visible device name, operating system, activation/last-seen/revocation times, and entitlement state. CrossFlow does not use a hardware fingerprint.
  • Browser preferencesLanguage preference stays in browser localStorage; the security session uses a Secure, HttpOnly cookie. Clearing site data removes local preference and session state.
  • Current boundaryThe site does not accept real payment; only authorized accounts can enter Paddle Sandbox test checkout. The site does not use advertising trackers, marketing profiles, or a client analytics SDK. An account is optional for browsing, but is required to start a trial and use account-licensed features.

02 / PADDLE

Sandbox and future Live checkout data

During controlled testing, Paddle Sandbox independently processes test name, email, address, payment method, tax, and transaction data; these transactions do not create real charges. When live sales open, Paddle is planned to process real transactions as Merchant of Record. Paddle Checkout collects payment fields; CrossFlow does not receive full card numbers. Read the Paddle Privacy Notice.

CrossFlow receives only customer and transaction fields needed for account linking, entitlement fulfillment, license management, order support, fraud prevention, refund coordination, and legal duties—for example Paddle customer/transaction IDs, purchased product, status, time, email, and necessary region data. Neither Sandbox nor future Live order data is automatically used for marketing; marketing subscription requires separate consent.

03 / FEEDBACK AND SUPPORT

GitHub feedback may be public

Ordinary issues go to a public GitHub repository, where content, usernames, and attachments are public by default. Do not submit secrets, LAN addresses, private clipboard contents, payment details, or unrelated personal data. GitHub processes account and platform data under its own privacy terms.

Security, privacy, or abuse-enabling matters must use GitHub private vulnerability reporting, never a public issue.

04 / DESKTOP APP

Application data boundary

Signed-in builds send only the data needed for OAuth sign-in, device seats, token refresh, and entitlement leases. Tokens are stored in macOS Keychain or Windows DPAPI-protected local storage; the signed offline lease contains no email address.

Keyboard/mouse events, clipboard contents, and LAN file transfers remain direct between connected devices and do not become account-database or marketing-analytics data. There is no client analytics SDK; any future diagnostic export must be user-initiated and reviewable before sending.

05 / PURPOSE, RETENTION, SHARING

Purpose, retention, and sharing

Magic links last 15 minutes and authorization codes last 5 minutes. Expired or consumed one-time records are removed by daily maintenance after an operational grace of up to 24 hours. Browser and device refresh sessions last at most 30 days; expired or revoked sessions are removed after a 7-day operational grace. Account, device, entitlement, and legal-version records remain until the user revokes or requests deletion, or contract, security, refund, tax, or legal duties no longer require them.

Data is shared only with Cloudflare for hosting and transactional email, Paddle for controlled Sandbox testing and future real payments, and necessary issue-tracking, security, or legal providers, or where law and protection of users or product security require it. Personal data is not sold.

06 / YOUR CHOICES

Access, correction, and deletion

Applicable law may grant rights to access, correct, delete, restrict, object, or export personal data. After signing in, the CrossFlow account page can export a machine-readable JSON copy of the current account, trial, devices, and billing mirror; it excludes sign-in tokens, credential hashes, and Webhook operations. Use Paddle Buyer Support first for payment and receipt data. For correction, deletion, or other CrossFlow privacy requests, use the private reporting route with “Privacy request” in the title; never put a privacy request in a public issue.

Until a dedicated privacy mailbox is configured, private GitHub reporting is the current confidential contact route. This limitation will be reviewed before live checkout opens.