Back to Second Flow

Legal

Privacy policy

This policy explains what Second Flow handles when it provides comprehension coverage for AI-generated code, why that information is needed, and the choices available to you.

Effective August 27, 2026

On this page

At a glanceScope and rolesInformation we collectHow we collect itHow we use itAI-assisted processingLegal basesHow we share itInternational transfersRetentionYour choices and rightsCalifornia noticeCookiesSecurityChildrenChangesContact

At a glance

What Second Flow does

Second Flow creates understanding checks from code changes and approved project context, receives authors' explanations, and gives their organization an ownership signal.

What we handle

Account and organization details, repository and pull request context, submitted explanations, results, integration data, support messages, and technical logs.

What we do not do

We do not sell personal information or share it for cross-context behavioral advertising. We do not use customer content to train general-purpose AI models.

Your controls

Depending on where you live, you may ask to access, correct, delete, restrict, object to, or export personal information. Email [email protected].

This policy is provided for transparency, but it is not a data processing agreement. If your organization has a separate order, data processing agreement, or enterprise contract with Second Flow Inc., that agreement controls where it conflicts with this policy.

1. Scope and roles

Second Flow Inc. operates the Service from Encinitas, California, United States. This policy applies to secondflow.app, the Second Flow console, the author-facing ownership experience, and related services (together, the “Service”).

An organization usually decides which repositories to connect, which people may use the Service, and why their work data is processed. For that organization-controlled data, the organization is generally the controller or business and Second Flow Inc. acts as its processor or service provider. Second Flow Inc. is the controller or business for account administration, security, support, and operation of its own website.

If you use Second Flow through your employer or another organization, contact that organization first about its use of your work data. We will help it respond to verified requests as required by law and our agreement with it.

2. Information we collect

Account and organization information

We receive identifiers and profile information needed to create and secure an account, such as your name, work email address, authentication identifier, organization name, team membership, role, and account preferences. Authentication is provided through Clerk; we do not receive your third-party account password.

Repository, change, and integration information

When an organization connects GitHub or another approved source, we may receive installation and repository identifiers, repository names, pull request metadata, commit identifiers, branch names, diffs, changed files, bounded surrounding source code, comments, check-run status, webhook events, and the identity associated with a change. We also receive authorization metadata and short-lived credentials needed to access only the connected resources.

Connected project context

At an organization's direction, Context Gateway may retrieve scoped content from selected documentation, work tracking, repository guidance, or approved internal tools. This can include architecture notes, runbooks, requirements, acceptance criteria, tickets, and metadata identifying the source. We retrieve the bounded context needed for the relevant change rather than an unrestricted copy of every connected source.

Understanding check content

We process generated questions, possible answers, your responses, the explanation you submit, completion status, immutable results, feedback, understanding-policy settings, and ownership signals. This content can be associated with you, a source revision, a repository, and your organization.

Communications

If you request beta access, contact support, or otherwise communicate with us, we receive your contact details and the contents and history of that communication.

Device and operational information

Our systems and infrastructure providers automatically process IP address, approximate location derived from IP, browser and device type, operating system, requested pages, timestamps, referring page, authentication and session events, error data, and security logs. We use this information to deliver the Service, diagnose failures, prevent abuse, and protect accounts.

Information we do not intentionally collect

The Service is not designed to collect payment card numbers, government identifiers, precise location, biometric identifiers, health information, or other sensitive personal information. Customers and users should not put secrets, production credentials, regulated personal data, or unrelated personal information in repositories, connected context, responses, or support messages.

3. How we collect information

  • From you when you create an account, choose preferences, submit an explanation, request access, or contact us.
  • From your organization when an administrator adds you, configures an understanding policy, or connects a repository or context source.
  • From integrations such as GitHub when they send authorized API responses or webhook events.
  • Automatically through essential cookies, server logs, and security systems when you use the Service.

We do not buy personal information from data brokers.

4. How we use information

  • Provide accounts, organization administration, integrations, understanding checks, explanations, results, and ownership signals.
  • Select and assemble relevant code and project context for a specific source revision.
  • Generate grounded questions and evaluate responses against the information available for that change.
  • Publish completion and policy status to the connected source control provider when the organization enables that workflow.
  • Authenticate users, enforce permissions, detect abuse, verify webhooks, investigate incidents, and keep the Service reliable.
  • Respond to support requests and communicate material product, security, policy, or account changes.
  • Analyze aggregated or de-identified operational patterns to find confusing workflows, recurring failures, and areas where the Service needs improvement.
  • Comply with law, enforce our agreements, and establish, exercise, or defend legal claims.

We do not use an individual's explanation or ownership signal for advertising. Organizations should not use Second Flow as the sole basis for employment, compensation, disciplinary, or similarly significant decisions about a person.

5. AI-assisted processing

Second Flow uses OpenAI's API to generate understanding checks and may use it to evaluate free-form responses. We send a bounded input containing the code change and context selected for that check. Our integration asks the API not to store application state. OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days unless a different approved retention control applies or law requires longer retention.

OpenAI states that API inputs and outputs are not used to train its general-purpose models by default. Second Flow Inc. does not opt in customer content for model training. We do not train a separate general-purpose model on customer repositories, context, or explanations.

AI output can be incomplete or incorrect. Second Flow validates generated content against the supplied source references, but an organization remains responsible for its review and use of results.

6. Legal bases for processing

Where the GDPR, UK GDPR, or similar law applies, we rely on the following legal bases:

  • Contract. To create your account and provide the Service requested by you or your organization.
  • Legitimate interests. To secure, support, and improve the Service; communicate with business users; prevent fraud and misuse; and protect our rights, provided those interests are not outweighed by your rights.
  • Consent. Where we ask for it, such as for optional marketing or non-essential cookies. You may withdraw consent at any time.
  • Legal obligation. To comply with applicable law and valid legal process.

For organization-controlled customer content, the organization determines the legal basis and we process the information on its documented instructions.

7. How we share information

We disclose information only as needed in these circumstances:

  • Your organization. Administrators and authorized members may see account membership, understanding checks, submitted explanations, results, and ownership signals according to their permissions.
  • Service providers. Clerk provides authentication; Cloudflare provides web delivery and security; database and infrastructure providers store service data; and OpenAI processes bounded inputs for AI-assisted features. Support and email providers process communications when used. These providers are permitted to process data only to provide services to us and under contractual obligations.
  • Connected services. At your organization's direction, we exchange information with GitHub and other enabled integrations to retrieve context and publish workflow status.
  • Legal and safety reasons. We may disclose information when we reasonably believe it is necessary to comply with law or valid legal process, protect people or the Service, investigate abuse, or establish and defend legal claims.
  • Business changes. Information may be disclosed in diligence and transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we have not done so in the preceding 12 months.

8. International data transfers

Second Flow Inc. and its providers operate primarily in the United States. If information is transferred from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with transfer restrictions, we use a recognized safeguard when required, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or a valid adequacy mechanism. Contact us to request information about the safeguard relevant to your data.

9. Retention

InformationTypical retention
Account and organization recordsWhile the account is active, then deleted or anonymized within 30 days after closure unless law requires longer.
Repository snapshots, connected context, understanding checks, explanations, results, and ownership signalsWhile the organization uses the Service, then deleted within 30 days after account closure or a verified deletion request, subject to contract and legal exceptions.
Webhook payloads and delivery recordsPayloads for up to 30 days; minimal delivery identifiers and security records for up to 12 months.
Security, access, and application logsUsually 90 days; up to 12 months when needed to investigate an incident or prevent repeated abuse.
Support and business communicationsUp to 24 months after the conversation closes, unless needed for an active account or legal claim.
BackupsRemoved through normal backup rotation within 90 days after deletion from active systems.

We may retain information longer when required by law, a litigation hold, a security investigation, or a contract with your organization. When possible, we isolate it from ordinary use. Aggregated or de-identified information may be retained if it cannot reasonably be linked back to a person or customer.

10. Your choices and privacy rights

Depending on your location and subject to legal exceptions, you may have the right to:

  • Know whether and how we process your personal information.
  • Access and receive a copy of personal information.
  • Correct inaccurate personal information.
  • Delete personal information.
  • Restrict or object to certain processing.
  • Receive portable information you provided to us.
  • Withdraw consent without affecting prior lawful processing.
  • Opt out of sale, sharing for behavioral advertising, targeted advertising, or qualifying profiling. We do not currently engage in these practices.
  • Appeal a denial where applicable state law provides that right.
  • Complain to your local data protection authority. EEA residents can find their authority through the European Data Protection Board; UK residents may contact the Information Commissioner's Office.

To make a request, email [email protected] with “Privacy request” in the subject. Describe your request and the account or organization involved. We may need to verify your identity and authority. Authorized agents may submit requests where permitted by law. We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.

If your organization controls the information, we may send the request to its administrator or ask you to submit it there. You can unsubscribe from optional promotional email through the link in the message or by contacting us. Required service and security notices are not promotional messages.

11. California privacy notice

In the preceding 12 months, we may have collected the categories described below. California law defines categories broadly, so a category can apply even when we collect only the examples listed.

California categoryExamples from Second FlowDisclosed for a business purpose to
IdentifiersName, work email, account ID, IP address, repository and integration identifiersAuthentication, hosting, security, integration, and support providers; your organization
Customer-record informationOrganization, role, and support contact detailsAuthentication, hosting, and support providers; your organization
Commercial informationService plan or account relationship, if applicableInfrastructure and business operations providers
Internet or electronic activityPages and features used, sessions, repository events, integration activity, and logsHosting, security, authentication, and integration providers; your organization
Professional informationWork identity, organization membership, authorship of code changes, submitted explanations, and resultsAI, hosting, authentication, and integration providers; your organization
InferencesOwnership signals derived from understanding checks and resultsInfrastructure providers; your organization
Sensitive personal informationAccount sign-in credentials handled by our authentication provider; contents of private repository data only to the extent California law classifies it as sensitiveAuthentication, AI, infrastructure, and integration providers as needed to provide the Service

We collect these categories from you, your organization, connected services, and automatic technical systems for the purposes in section 4. We do not use sensitive personal information to infer characteristics about California consumers. We do not sell or share these categories for cross-context behavioral advertising, and we do not knowingly sell or share personal information of anyone under 16.

12. Cookies and similar technology

Second Flow currently uses essential cookies and similar storage for sign-in, session continuity, security, load balancing, and user preferences. Clerk and Cloudflare may set or read these technologies to provide authentication and protect the Service. We do not currently use advertising cookies or third-party cookies for behavioral advertising.

Blocking essential cookies can prevent sign-in or other parts of the Service from working. If we add non-essential analytics or advertising technology, we will update this policy and request consent where required before using it.

13. Security

We use safeguards designed for the nature of the information we process, including encrypted network transport, managed authentication, role-based access, short-lived integration tokens, webhook signature verification, tenant boundaries, bounded model inputs, logging controls, and provider access restrictions. We review access and limit it to people and providers who need the information to operate or support the Service.

No online service can guarantee absolute security. If you believe you found a vulnerability or that an account may be compromised, contact [email protected].

14. Children's privacy

Second Flow is a business service for workplace software development and is not directed to children under 13 or the minimum age required in their jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can investigate and delete it.

15. Changes to this policy

We may update this policy when the Service, our providers, or legal requirements change. We will post the revised policy with a new effective date. If a change materially affects how we use personal information, we will provide additional notice through the Service or by email before it takes effect when required by law.

16. Contact

Second Flow Inc.
Encinitas, California, United States
[email protected]

Direct privacy requests to the email above with “Privacy request” in the subject. If applicable law requires a formal mailing address, data protection representative, or data protection officer for your relationship with Second Flow, we will provide the relevant contact details in your organization's agreement or upon request.

© 2026 Second Flow Inc.

PrivacyTermsContact