Privacy policy
Last updated October 7, 2026
What we collect
We collect only what the platform needs to function:
- Account data — name, username, email, organization, institution, role and research area you provide, plus a hashed password (or a Google account identifier if you sign in that way).
- Uploaded datasets — any CSV or Excel file you upload, and anything Matflow generates from it (synthetic data, predictions, optimization candidates, reports).
- Usage data — job history, run configuration, IP address and browser user-agent string for each login session (so you can see and revoke your own active sessions), and basic API request logs for rate-limiting and abuse prevention.
- Support communications — anything you send via the contact or feedback forms.
Where data is stored
Uploaded and generated files are stored on the server's filesystem, scoped to your account. Every file path is validated against your own storage directory before it is served, so your files are never readable by another user's requests. Account and job metadata live in the application database. Where object storage is configured, files are also mirrored to Backblaze B2 as durable infrastructure storage; the local copy remains the working cache.
Your data and model training
We do not use your uploaded or generated data to train any model shared with other users.Every model Matflow trains for you — the predictor, the synthesis generator, the optimizer's surrogate — is trained on your data alone, for your account alone, and is not merged into any global or shared model.
Third-party processors
The following outside services process a limited slice of your data, only for the purpose stated:
- Email delivery — transactional email is sent via an SMTP relay: we send a verification email to confirm address ownership, plus password-reset and workshop-registration confirmations. Only your email address and the message content are shared with it.
- Google / OpenID Connect (OIDC) — if you choose "Continue with Google," the platform redirects you to Google through its own server-side OpenID Connect flow to verify your Google account identifier and the email address it discloses; some deployments route this verification through their own OIDC provider instead. We never see your Google password.
- Backblaze B2 (infrastructure storage) — where the deployment configures it, uploaded and generated files are mirrored to a Backblaze B2 bucket as durable object storage, and are restored or served from it on demand. Only your files and their storage paths are held there; they are not used for any other purpose.
- The AI assistant — messages you send to the in-app assistant, plus the minimal page context needed to answer them, are sent to a third-party LLM API to generate a response. Do not paste sensitive information into the assistant that you would not want to leave the platform.
- Analytics — page-view and event data keyed to pseudonymous identifiers (not your name or email) is forwarded to our analytics providers (Google Analytics / Firebase Analytics, and PostHog Cloud where configured, with PostHog's default personal-data sending disabled) for usage measurement. This does not include dataset contents or job results.
Retention & deletion
Your data is retained for as long as your account is active. From Settings → Data & account you can:
- Export a copy — download your profile, dataset list and run history at any time.
- Request account deletion — the account is deactivated immediately and all sessions are signed out; the request is then actioned by our operations team, who run the permanent purge. The purge removes the account and the rows and files it owns (organization or project ownership is transferred to the oldest remaining member where one exists), while the audit record that the deletion happened is retained. Contact us via the Contact page or [email protected] to check on a request or to reverse it before the purge runs.
Your rights
You can access, correct and export your personal data at any time from Settings. To delete your account, use Settings → Data & account; the request is actioned by our operations team as described above. If you believe data about you is being processed incorrectly, contact us via theContact page.