Privacy Policy

How LerniFlow collects, uses, and protects your data

Effective Date: [EFFECTIVE DATE]

Data Controller: [LERNIFLOW LLC NAME] ("LerniFlow," "we," "us," or "our")

Contact: privacy@lerniflow.com
General Support: support@lerniflow.com


1. Introduction and Scope

This Privacy Policy explains how LerniFlow collects, uses, discloses, and protects information when you use our business-to-business software-as-a-service platform, websites, and related services (collectively, the "Service").

This Policy applies to:

  • Organization administrators, members, and viewers who access a LerniFlow workspace
  • Consultants and partners who access client tenants through delegation grants
  • Visitors to our marketing website and beta program pages

This Policy does not apply to third-party websites, services, or integrations that you connect to LerniFlow under your own agreements with those providers.

LerniFlow is designed for business use. The Service is not directed to individuals under sixteen (16) years of age.

2. Information We Collect

We collect information in the categories below. The specific data we collect depends on how your organization uses the Service and which features are enabled.

2.1 Account Information

When you register or are invited to a workspace, we may collect:

  • Name and email address
  • Organization name and workspace slug
  • Job title or role (if provided)
  • Authentication identifiers and session metadata
  • Preferences and notification settings

Tenant Owners may provide additional user profile information for members of their organization.

2.2 Usage Data

We collect information about how the Service is used, including:

  • Workflow definitions, runs, and execution history
  • Feature usage and configuration changes
  • AI feature interactions (e.g., validation requests, recommendation calls)
  • Active seat counts and role assignments
  • Audit and activity logs within your workspace

This data helps us operate the Service, enforce plan limits, and improve product functionality.

2.3 Payment Data

Subscription billing is processed by Stripe. When you subscribe, Stripe collects payment card and billing details on our behalf.

LerniFlow does not store full payment card numbers. We may receive and store limited billing information from Stripe, such as:

  • Customer name and billing address
  • Last four digits of card
  • Subscription status, invoices, and transaction references

For more information, see Stripe's Privacy Policy.

2.4 Technical Data

When you access the Service, we automatically collect certain technical information, including:

  • IP address and approximate location derived from IP
  • Browser type, device type, and operating system
  • Session identifiers and authentication logs
  • Error reports, performance metrics, and security event logs

2.5 Content Data (Customer Data)

You and your users may submit content to the Service, including:

  • Workflow definitions, forms, and templates
  • Form submissions and operational records
  • Documents, attachments, and comments
  • Consultant suggestions and client approvals

Customer Data is owned by the customer organization that submits it. LerniFlow processes Customer Data solely to provide the Service as described in this Policy and our Terms of Service.

We do not use Customer Data to train third-party foundation models for general public AI products unless explicitly agreed in writing.

3. How We Use Information

We use collected information for the following purposes:

3.1 Provide and Improve the Service

  • Authenticate users and enforce role-based access
  • Operate multi-tenant workspaces and workflow execution
  • Deliver AI-assisted features (workflow review, validation, recommendations)
  • Provide support, troubleshooting, and account administration
  • Develop new features and improve reliability

3.2 Billing and Subscription Management

  • Process subscriptions, trials, seat overages, and consultant commissions
  • Send invoices, payment confirmations, and billing notices
  • Manage beta and promotional pricing eligibility

3.3 Security and Fraud Prevention

  • Detect and prevent unauthorized access, abuse, and fraud
  • Monitor for violations of our Terms of Service
  • Maintain audit logs and investigate security incidents

3.4 Communications

By default, we send transactional communications necessary to operate the Service, such as:

  • Account verification and password reset messages
  • Security alerts and service notifications
  • Billing and subscription updates

Marketing communications (product updates, newsletters, event invitations) are sent only where permitted by law and, where required, with your opt-in consent. You may opt out of marketing emails at any time using the unsubscribe link or by contacting privacy@lerniflow.com.

4. Data Sharing

We do not sell Customer Data or personal information.

We share information only in the following circumstances:

4.1 Service Providers (Subprocessors)

We use trusted third-party providers to operate the Service. These providers process data on our instructions and under contractual obligations:

ProviderPurpose
SupabasePostgreSQL database, authentication infrastructure, and data storage (US-based)
StripePayment processing and subscription billing
OpenAIAI features including workflow validation and recommendations (GPT-4o)
Vercel / cloud hosting providersApplication hosting, content delivery, and infrastructure

We may update subprocessors from time to time. Enterprise customers with specific contractual requirements may request subprocessor information via privacy@lerniflow.com.

4.2 Legal and Safety Disclosures

We may disclose information if we believe in good faith that disclosure is necessary to:

  • Comply with applicable law, regulation, legal process, or governmental request
  • Enforce our Terms of Service or protect our rights
  • Protect the safety, rights, or property of LerniFlow, our customers, or the public

4.3 Business Transfers

If LerniFlow is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections.

4.4 With Your Direction

We may share information when you or your Tenant Owner instructs us to do so, such as enabling integrations or granting consultant delegation access to a client workspace.

5. Data Retention

We retain information according to the following general practices:

5.1 Active Accounts

While your subscription is active, we retain Account Information, Usage Data, and Customer Data as needed to provide the Service and comply with our legal obligations.

5.2 Post-Cancellation

After subscription cancellation or termination, we retain Customer Data for up to thirty (30) days to allow export, account recovery, or reactivation. After that period, we delete or anonymize data according to our retention schedule, unless you request earlier deletion (subject to legal or contractual holds).

5.3 Audit Logs

Security and administrative audit logs are retained for up to twelve (12) months, unless a longer period is required for security investigations, legal compliance, or an active Business Associate Agreement.

5.4 Backups

Deleted data may persist in encrypted backups for a limited period before being overwritten according to our backup rotation schedule.

6. Security

We implement technical and organizational measures designed to protect information, including:

  • Row-level security (RLS) and tenant isolation in our database layer
  • Encryption in transit (TLS) and encryption at rest for stored data
  • Role-based access controls (RBAC) within customer workspaces and for LerniFlow personnel
  • Authentication controls, logging, and monitoring

No method of transmission or storage is completely secure. You are responsible for maintaining strong credentials and configuring appropriate access within your organization.

6.1 Incident Notification

If we become aware of a material security breach affecting personal information or Customer Data in our control, we will notify affected customers within seventy-two (72) hours of confirming the breach, to the extent required by applicable law and contractual obligations (including HIPAA breach notification under an executed BAA).

7. HIPAA and Protected Health Information

LerniFlow offers HIPAA Business Associate Agreement availability on eligible tiers (including Scale and Partner).

  • PHI is handled only under a signed BAA between LerniFlow and the covered entity or business associate customer.
  • PHI must not be stored or processed in workspaces or tiers without an executed BAA.
  • When a BAA is in place, we process PHI only as permitted by the BAA and applicable HIPAA regulations.

Customers are responsible for determining whether their use case involves PHI, executing a BAA before uploading PHI, and configuring workspaces and user access appropriately.

8. Customer Data Rights

Depending on your location and role, you may have rights regarding personal information we process.

8.1 General Rights

Subject to applicable law, you may request to:

  • Access personal information we hold about you
  • Correct inaccurate information
  • Export Customer Data from your workspace
  • Delete personal information, subject to retention requirements and legal obligations

Organization administrators (Tenant Owners) should submit requests on behalf of their organization where appropriate. Individual users may contact us directly for account-specific requests.

To exercise these rights, contact privacy@lerniflow.com. We may verify your identity before fulfilling requests.

8.2 European Economic Area and United Kingdom (GDPR)

If you are located in the EEA or UK, you may have additional rights under the General Data Protection Regulation ("GDPR"), including:

  • Right of access and data portability
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict or object to processing
  • Right to lodge a complaint with a supervisory authority

Our legal bases for processing may include contract performance, legitimate interests (such as security and product improvement), and consent where required.

For GDPR inquiries: privacy@lerniflow.com

8.3 California (CCPA/CPRA)

If you are a California resident, you may have rights under the California Consumer Privacy Act and California Privacy Rights Act ("CCPA/CPRA"), including:

  • Right to know what personal information is collected and how it is used
  • Right to delete personal information (subject to exceptions)
  • Right to correct inaccurate personal information
  • Right to opt out of the "sale" or "sharing" of personal information

We do not sell or share personal information for cross-context behavioral advertising.

To submit a CCPA request: privacy@lerniflow.com

9. Cookies and Tracking

9.1 Session Cookies

We use strictly necessary session cookies to authenticate users, maintain workspace sessions, and protect against cross-site request forgery. These cookies are required for the Service to function.

9.2 No Third-Party Advertising Cookies

We do not use third-party advertising cookies or sell data to ad networks.

9.3 Analytics

We may use privacy-preserving analytics to understand product usage in aggregate. Where analytics tools are used, we configure them to minimize collection of personally identifiable information and avoid cross-site tracking for advertising purposes.

You can control cookies through your browser settings. Disabling necessary cookies may limit your ability to use the Service.

10. Children's Privacy

The Service is intended for business and professional use. We do not knowingly collect personal information from children under sixteen (16). If you believe we have collected information from a child, contact privacy@lerniflow.com and we will take appropriate steps to delete it.

11. International Data Transfers

LerniFlow stores and processes data using infrastructure located in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.

Where required, we implement appropriate safeguards for international transfers, such as Standard Contractual Clauses or equivalent mechanisms.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email, in-product notice, or by posting an updated Policy with a revised effective date.

Your continued use of the Service after the effective date constitutes acceptance of the updated Policy, except where applicable law requires additional consent.

13. Contact and Data Protection

For privacy questions, data subject requests, or security concerns:

Data Controller: [LERNIFLOW LLC NAME]
Privacy Email: privacy@lerniflow.com
Support Email: support@lerniflow.com
Website: https://lerniflow.com

If we appoint a Data Protection Officer or EU/UK representative before publication, their contact details will be added here: [DPO / EU REPRESENTATIVE β€” PLACEHOLDER]


Last updated: [EFFECTIVE DATE]
Entity placeholder: [LERNIFLOW LLC NAME]