# Privacy Policy

**Last updated: 1 October 2026**

This policy explains what personal data ZikkLabs ("we", "us") collects when you use LogiKFlow at https://logikflow.dev (the "Service"), why, how long we keep it, and your rights. We are the data fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the controller under the EU and UK General Data Protection Regulation ("GDPR").

LogiKFlow is built to collect as little as possible. **We never store your source code or diffs.** They're fetched from GitHub when you open a pull request, shown to you, and discarded.

## What we collect

| Data | Where it comes from | Why |
|---|---|---|
| GitHub user ID, username and avatar URL | GitHub, when you sign in | To identify your account and show who saved an order or ticked a checklist item |
| GitHub access and refresh tokens, encrypted | GitHub, when you sign in or connect an agent | To read pull requests on your behalf and post comments when you ask |
| Session records: a hash of your session token and when it expires | Created when you sign in | To keep you signed in |
| Reading orders you save: file paths, section titles, notes, checklist text, focus labels, and every version | You, or an AI agent you connect | The core feature |
| Flow diagrams: box titles and short descriptions, groups, labelled arrows, the file paths they link to, and every version | An AI agent you connect | Showing reviewers how the change fits together |
| Your review progress: files you marked viewed, checklist items you ticked | You | To sync your progress across devices and show it to collaborators on the same pull request |
| Pull requests you opened recently: repository, number and title | Your use of the Service | To show your dashboard |
| AI agent connections: the app's name, the scopes you approved, and token hashes | The agent, when you approve it | To let the agent act for you |
| Technical logs: IP address, browser user agent, request path, time and errors | Your browser, via our hosting provider | To run, secure and debug the Service |

We don't use analytics, advertising or tracking cookies, and we don't buy or sell personal data.

Content you view through the Service, such as code, pull request titles and comments, belongs to the repository's owners and is governed by their settings and GitHub's terms. We only show it to people GitHub already allows to see it.

## How we use it

We use personal data only to:

- provide the Service: sign-in, showing pull requests, saving orders and review progress;
- post a comment on a pull request when you choose **Post to PR**;
- keep the Service secure, prevent abuse and enforce our [Terms](/legal/terms) and [Acceptable Use Policy](/legal/acceptable-use);
- answer your requests and tell you about important changes to the Service or these policies;
- meet legal obligations.

**Legal bases (GDPR):**
- Performance of our contract with you: providing the Service.
- Our legitimate interests: security, abuse prevention and improving reliability.
- Legal obligation, where one applies.

Under the DPDP Act, we process your data for the purposes above, on the basis of your consent when you sign in and use the Service. You can withdraw that consent at any time by deleting your account.

## Who can see your data

- **Collaborators:** your username, the orders you save, and your viewed and checklist progress on a pull request are visible to other signed-in people who can access that pull request on GitHub.
- **Service providers** that process data for us under contract. They're listed on the [Subprocessors](/legal/subprocessors) page: Cloudflare hosts the Service and its database, and GitHub provides sign-in and the pull request data.
- **Authorities**, when the law requires it. We'll tell you unless the law forbids us.
- **A successor**, if ZikkLabs or LogiKFlow is reorganised or acquired. This policy, or one at least as protective, will continue to apply.

## Where it's stored

Data is stored with Cloudflare, whose network spans many countries, and GitHub is based in the United States. Your data may therefore be processed outside India and outside your country. Where GDPR applies, those transfers rely on our providers' Standard Contractual Clauses and data processing terms.

## How long we keep it

| Data | Kept for |
|---|---|
| Sessions | Until you sign out, or 30 days of inactivity |
| AI agent connections | Until you remove the agent, or 30 days without use (180 days at most) |
| Reading orders, flow diagrams and their history | While the pull request's team uses the Service, or until someone with write access removes a diagram. If you delete your account, they stay for the team, but your name is removed from them |
| Viewed files, checklist ticks and recent pull requests | Until you delete your account |
| Technical logs | Up to 30 days |

## Your rights

You can:

- **access and export** your data: use **Download my data** on your [dashboard](/app);
- **correct** it: your username and avatar come from GitHub and update when you next sign in;
- **delete** it: use **Delete my account** on your dashboard, or email us;
- **withdraw consent** by deleting your account. This doesn't affect processing that has already happened;
- **nominate** someone to exercise your rights if you die or become incapacitated, under the DPDP Act;
- **object to or restrict** processing, and **complain** to a supervisory authority, if GDPR applies to you.

Email privacy@logikflow.dev for anything you can't do yourself. We'll reply within 30 days.

### Grievance officer

For complaints under the DPDP Act, contact our Grievance Officer at privacy@logikflow.dev. If you're not satisfied with our response, you can complain to the Data Protection Board of India.

## Security

- GitHub tokens are encrypted with AES-256-GCM before they're stored.
- Session and agent tokens are stored only as hashes.
- All traffic uses HTTPS.
- Access to production systems is limited to people who need it.

See [Security](/legal/security) for how to report a vulnerability.

## Children

The Service is not for anyone under 18. We don't knowingly collect data from children. If you think a child has signed up, email privacy@logikflow.dev and we'll delete the account.

## Changes

If we make a material change to this policy, we'll update the date above and tell signed-in users in the Service before it takes effect.

## Contact

ZikkLabs, Kerala, India. Email: privacy@logikflow.dev
