AWFlow runs in your browser. Most of what you create stays on your device. This page explains what leaves it, where it goes, and how to remove it. The legal details are in the privacy policy, linked from Settings › Privacy.
Where your data lives
Section titled “Where your data lives”AWFlow keeps data in two places:
- This browser: a database inside the browser, on this device only. Nothing here is uploaded.
- Your AWFlow account (cloud): only when you’re signed in, and only for the items you save to the cloud.
| What | Where it is kept |
|---|---|
| Workflows and their versions | This browser, or your account if you save them to the cloud |
| Credentials | This browser, or your account if you save them to the cloud |
| Run history (status, timing, log lines) | Same place as the workflow |
| Chats and conversations | This browser only |
| Agents, teams and projects | This browser only |
| Agent memory and facts | This browser only |
| Knowledge bases | This browser only |
| AI providers and their API keys | This browser only |
| Data Store values | This browser only |
| Assistant traces | This browser only, 7 days |
| Safe mode, site permissions, privacy choices | This browser only |
| Profile, avatar, settings | Your account (signed in) |
In a local workspace there is no account, so everything stays in the browser.
What syncs
Section titled “What syncs”There is no background sync between devices. Items saved to the cloud are loaded from your account wherever you sign in. Local items stay in the browser profile where you made them; the extension and the web app each have their own local storage.
To move items between local and cloud, use Move to cloud / Move to local. See Local or cloud.
Credentials and secrets
Section titled “Credentials and secrets”- Local credentials are encrypted in the browser. By default the key is stored on the same device, which guards against casual inspection. Turn on the local secret vault to lock them with a passphrase only you know.
- Cloud credentials are sent to AWFlow over an encrypted connection and stored encrypted on the server. The server holds that key, so it can decrypt them to give them back to you. If you want secrets that never leave your device, keep those credentials local.
- Workflow export checks for secrets written into a workflow and offers to strip them before the file is saved.
AI: on your device or with a provider
Section titled “AI: on your device or with a provider”- On-device models (Local AI) run entirely in your browser. Your prompts and data don’t leave the device. The model files are downloaded once from the internet, for example from Hugging Face.
- Model search on the Local AI page sends your search text to Hugging Face. Turn off Discover models on Hugging Face in Settings › Local models to keep the page fully offline.
- Cloud AI providers (OpenAI, Anthropic, Google and others) are called directly from your browser with your own API key. Your prompt goes to that provider and is covered by its privacy terms. AWFlow does not run or relay these AI calls.
- Ollama runs on your own computer; calls go to it locally.
- Knowledge bases marked device-only are never sent to a cloud model.
Usage statistics and error reports
Section titled “Usage statistics and error reports”AWFlow collects anonymous usage statistics and crash reports to improve the product. Both are on by default and you can switch them off in Settings › Privacy. A notice tells you about this the first time you open the app.
- Events are counts such as “the app was opened”, “a workflow ran (succeeded or failed, number of steps)” or “a Marketplace listing was viewed”.
- Each event is tied to a random install ID, not to you or your account. You can reset it.
- Never sent: workflow names, steps or data, credentials, page URLs, search text, your email or name.
- Error reports contain the error message and technical trace, with emails, URLs, quoted text and long tokens removed.
- Statistics go only to AWFlow’s own server. There are no third-party analytics, advertising IDs or tracking cookies.
- The switches apply whether you’re signed in or not. On Firefox, nothing is sent until you also allow Firefox’s data-collection permission.
Other things that go online
Section titled “Other things that go online”- Your workflows’ own requests: when a workflow calls an API, a website, an integration or a webhook, the data goes where that step points. Safe mode lets you approve each website.
- Marketplace: browsing, installing, reviews, reports and requests talk to AWFlow’s server. Before an installed workflow runs, the app checks a public list of workflows removed for safety.
- Newsletter: if you subscribe, your email is used to send it. Every email has an unsubscribe link.
Browser permissions and why
Section titled “Browser permissions and why”When you install the extension, the browser asks for these permissions:
| Permission | Why AWFlow needs it |
|---|---|
| Read and change data on websites | Workflows read pages, click, fill forms and call web APIs. |
| Storage | Save your settings, keys and paused runs. |
| Side panel | Open AWFlow next to the page you’re on. |
| Tabs, tab groups | Run triggers on page events; keep agent tabs in their own group. |
| Scripting | Run page steps such as extracting text or clicking. |
| Context menus | Start workflows and save to knowledge from the right-click menu. |
| Alarms | Run schedules and long waits on time. |
| Notifications | Tell you when a run needs your approval, and power the notification step. |
| Identity | Sign in to integrations such as Google with their own login window. |
Screenshot Page needs one more permission (access to all pages). AWFlow asks for it only the first time you take a screenshot.
On top of the browser’s permissions, AWFlow asks before installed workflows contact a website or use a connected app. Review and remove these in Site access.
Delete your data
Section titled “Delete your data”| What | How |
|---|---|
| A workflow and its runs | Delete in the workflows list. Its run history goes with it. |
| A credential | Delete in Credentials. |
| Chats | Select them on the Chats page and delete. |
| Agent memory | Settings › Privacy › Forget everything, or per fact in Memory. |
| Traces | Settings › Privacy › Clear traces. |
| Data Store values | Settings › Preferences › Data store. |
| Local AI models | Remove on the Local AI page. |
| Everything in this browser | Clear the browser’s site data for AWFlow, or uninstall the extension. |
| Your account and cloud data | Email hello@awflow.io. There is no delete-account button in the app yet. |