Privacy policy
Last updated July 31, 2026
What we collect
We collect only what the platform needs to function:
- Account data — name, username, email, organization, institution, role and research area you provide, plus a hashed password (or a Google account identifier if you sign in that way).
- Uploaded datasets — any CSV or Excel file you upload, and anything Matflow generates from it (synthetic data, predictions, optimization candidates, reports).
- Usage data — job history, run configuration, IP address and browser user-agent string for each login session (so you can see and revoke your own active sessions), and basic API request logs for rate-limiting and abuse prevention.
- Support communications — anything you send via the contact or feedback forms.
Where data is stored
Uploaded and generated files are stored on the server's filesystem, scoped to your account and never readable by another user's requests (every file path is validated against your own storage directory before it is served). Account and job metadata live in the application database.
Your data and model training
We do not use your uploaded or generated data to train any model shared with other users.Every model Matflow trains for you — the predictor, the synthesis generator, the optimizer's surrogate — is trained on your data alone, for your account alone, and is not merged into any global or shared model.
Third-party processors
The following outside services process a limited slice of your data, only for the purpose stated:
- Email delivery — transactional email (password reset, email verification, workshop registration confirmations) is sent via an SMTP relay. Only your email address and the message content are shared with it.
- Google / Firebase Authentication — if you choose "Continue with Google," your Google account identifier and the email address it discloses are shared with Firebase to verify your identity. We never see your Google password.
- The AI assistant — messages you send to the in-app assistant, plus the minimal page context needed to answer them, are sent to a third-party LLM API to generate a response. Do not paste sensitive information into the assistant that you would not want to leave the platform.
- Analytics — anonymized page-view and event data is forwarded to Google Analytics for usage measurement. This does not include dataset contents or job results.
Retention & deletion
Your data is retained for as long as your account is active. From Settings → Data & account, you can export a copy of your profile, dataset list and run history at any time, or request account deletion. Deletion deactivates the account immediately and permanently removes it after 30 days — during that window, contact support if you change your mind.
Your rights
You can access, correct, export or delete your personal data at any time from Settings, without contacting an administrator. If you believe data about you is being processed incorrectly, contact us via the Contact page.