RSTR
PrivacyTermsCookiesSign in

Legal

Privacy Notice

This notice explains what RSTR collects, why we use it, which services help us operate the app, and the controls available to you.

Effective and last updated: July 28, 2026 · Version 2026-07-28

At a glance

  • RSTR is designed for people of different ages.
  • We use account details and the content you choose to provide to run the features you request.
  • Selected conversation and project context is sent to OpenAI to generate responses; API content is not opted in for model training.
  • We do not sell personal information or use behavioral advertising.
  • You can request access, correction, or deletion by emailing info@flowwweb.com.
On this page
  1. Scope and who is responsible
  2. Information we collect
  3. How we use information
  4. AI and connected services
  5. When we disclose information
  6. Cookies and local storage
  7. Retention and deletion
  8. Your choices and rights
  9. Security and transfers
  10. Audience
  11. Changes and contact

1. Scope and who is responsible

This notice applies to the RSTR responsive web app, its public pages, support, and optional features that RSTR makes available to you. RSTR is responsible for deciding how personal data is used for the service. Questions and privacy requests can be sent to info@flowwweb.com.

RSTR is an invitation-only experimental service. Optional creator, connected-service, file, and image features are covered only when they are actually available to and used by you.

2. Information we collect

Account and profile

We collect sign-in identity data such as your email address, an authentication-provider identifier, display name, birth date, confirmed broad location, optional country code, locale, timezone, selected reasons for using RSTR, AI-personalization preference, account state, the accepted Terms version and time, the acknowledged Privacy Notice version, and security/session information. A country inferred from your connection is shown as a suggestion for you to keep or change. RSTR does not write the raw IP address, coordinates, or an unconfirmed location into your profile. If you use Google sign-in, Google provides the identity data needed to authenticate you.

Content and product activity

We collect the content and state you create in RSTR, including agents, conversations, messages, projects, team roles, tasks, reactions, feedback, marketplace drafts, usage and cost records, and safe failure information. When an available feature lets you add media or files, we also collect the file, filename, type, size, ownership and project links, and the information needed to validate, display, download, or delete it.

Agents may also produce a private Skill-opportunity diagnostic made only from bounded categories such as work domain, reusable method, friction type, and whether the pattern appears agent-specific or broadly reusable. The diagnostic does not store the message, answer, source content, names, URLs, credentials, or free-form instructions. We associate it with the account, agent, invocation, and model-attempt identifiers needed to prevent duplicates, enforce isolation, measure value, and support deletion.

Optional connections, creation, and billing

If you deliberately connect an external service, we collect the account and authorization metadata needed for that connection and the specific source or action you select. Credentials are encrypted and are not returned to the client. If paid account plans are offered, we collect plan, subscription, credit, transaction, and limited Stripe identifiers; RSTR does not receive your full payment-card number. When RSTR AI runs, we also keep the session-level activity and settled credit totals shown in your private Profile Usage history. We do not expose private diagnostic categories or per-step charges there. When you use a referral link, we also keep the referral code, inviter/invitee attribution, account-verification state, and reward record needed to issue credits, enforce the reward limit, and prevent duplicate or abusive claims.

Technical and support information

Our hosting, security, and error-monitoring services process technical data such as IP address, request and device information, app version, session state, timestamps, provider request identifiers, and redacted error telemetry. If you contact us, we collect the message and contact details you provide.

3. How we use information

We use personal data to:

  • create and secure your account and keep you signed in;
  • provide conversations, Agents, projects, tasks, selected context, media, and other features you request;
  • route your request to the selected AI or connected service;
  • personalize an AI response with only relevant profile details when you leave that preference enabled;
  • enforce account isolation, permissions, rate limits, usage credits, and cost controls;
  • process subscriptions when paid plans are offered;
  • prevent abuse, investigate failures, recover interrupted work, and keep the service reliable;
  • identify reusable agent-work patterns and automatically quarantine, evaluate, improve, promote, update, or discard instruction-only Skills;
  • respond to support, privacy, and deletion requests; and
  • comply with law and protect people, RSTR, and the service.

Where data-protection law requires a legal basis, we rely on performance of our agreement with you, our legitimate interests in operating and securing the service, your consent for an optional connection or action where required, and compliance with legal obligations.

RSTR does not use personal data to make solely automated decisions that produce legal or similarly significant effects about you.

4. AI and connected services

RSTR sends a bounded part of the conversation and selected project context to OpenAI to generate the response you request. When AI profile context is enabled, RSTR may also include only the profile fields relevant to that request—for example, timezone for a schedule or confirmed location for a local question. OpenAI can also process an image direction when that feature is available. RSTR sets OpenAI Responses requests to store: false and does not opt in to use API content to train OpenAI models. OpenAI may still retain content in abuse-monitoring logs for up to 30 days, or longer when legally required or necessary to protect services or others.

RSTR does not give the model general access to your account. A request includes only the thread, project summary, source, file excerpt, relevance-selected profile field, or other context that the product contract authorizes for that turn. You can review and correct the stored profile in RSTR and turn AI profile context off. AI responses can be inaccurate; do not treat them as verified professional advice.

Skill-opportunity diagnostics are operational product-improvement records, not training examples or executable instructions. RSTR may aggregate the bounded categories across accounts and use a separate RSTR AI request to refine or evaluate a candidate Skill. Candidate content remains quarantined unless automated privacy, injection, authority, usefulness, runtime, maintenance, and cost checks pass. We do not copy conversation or connected-source content into a shared Skill, and a candidate Skill cannot inherit your credentials, connections, approvals, or external-action authority.

Activity may summarize this internal work only as “Calibrating the agent.” Your private Profile Usage history counts the originating user turn as one session even when RSTR retries an internal attempt, and reports shared-credit use at the session and account level without exposing the private diagnostic.

Connected context is foreground and user-directed. When you select a Google Workspace, GitHub, or Slack item, the relevant provider processes that request under its own terms and privacy notice, and RSTR stores only the selected snapshot and connection/action records needed for the feature. RSTR sends a Google Workspace snapshot to OpenAI only when you explicitly attach that source to an AI turn. A connected BytePlus video request uses your provider account.

RSTR's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. RSTR does not use Google user data for advertising, sell it, use it to determine creditworthiness, or allow humans to read it except when you explicitly ask us to, when needed for security or abuse investigation, or when required by law.

5. When we disclose information

We disclose information only to provide, secure, support, or comply with law for the service. Current processor and recipient categories include:

Supabase
Authentication, database, and private object storage.
Google Cloud and Firebase
Web and API hosting, delivery, and infrastructure security.
OpenAI
Text and, when available, image inference.
Resend
Delivery of email sign-in codes through Supabase Auth.
Sentry
Redacted error and reliability telemetry when enabled.
Stripe
Subscription checkout and payment records when paid plans are offered.
Connected providers
Google Workspace, GitHub, Slack, or BytePlus only when you connect or direct the relevant feature.

We may also disclose information to professional advisers, authorities, or a successor to the service when reasonably necessary and permitted by law. We do not sell personal information or share it for cross-context behavioral advertising. RSTR has no advertising network.

6. Cookies and local storage

RSTR uses one first-party session cookie that is necessary for authentication and security. We do not use advertising cookies, third-party behavioral tracking, or local or session storage to persist product data. Blocking the necessary cookie will prevent sign-in and core account features from working.

See the Cookie Policy for the current cookie inventory, duration, controls, and the consent standard that applies before RSTR can introduce optional storage.

7. Retention and deletion

We keep account and product data while your account is active and as needed to provide the feature, recover failures, secure the service, resolve disputes, and meet legal obligations. Short-lived security, upload, session, and processing records expire according to their purpose. We retain only bounded operational and billing records for as long as reasonably needed for accounting, fraud prevention, and legal obligations.

Active Skill Nursery diagnostics are retained only while needed to aggregate and evaluate the reusable pattern. When RSTR discards a nursery item, it removes the diagnostic payload and keeps only a bounded tombstone, aggregate counts, and reason needed to prevent duplicate processing and audit the quality decision. Related credit records follow the billing and accounting retention described above.

You can remove supported feedback, files, media, credentials, and connections through their available controls. To request account deletion, contact info@flowwweb.com. RSTR may require a fresh email code and disconnection of external providers before deletion can finish. Account deletion removes RSTR product data and the authentication identity, subject to limited records that we or our processors must retain for security, payment, dispute, or legal reasons. Provider-controlled copies follow the provider's own deletion and retention rules.

8. Your choices and rights

Depending on where you live, you may have rights to know, access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to appeal or complain to a data-protection authority. You may withdraw consent for an optional connection by disconnecting it. We will not discriminate against you for exercising applicable privacy rights.

Send a request to info@flowwweb.com. We will verify that the request concerns your account. An authorized agent may submit a request where local law permits, but we will require proof of authority and may still verify your identity directly.

9. Security and international transfers

RSTR uses access controls, encryption in transit, private storage, row-level account isolation, encrypted provider credentials, bounded model context, and server-owned authorization checks. No online service can guarantee absolute security, so please protect your sign-in method and report suspected misuse promptly.

RSTR and its providers may process information in countries other than yours. Where required, we use contractual or other recognized safeguards for international transfers. Contact us for information relevant to your location.

10. Audience

RSTR does not impose a separate product age ceiling. We handle personal data under the laws that apply to the service and the person using it. Contact us with a privacy question or to request access, correction, or deletion.

11. Changes and contact

We will update this notice when RSTR's data practices materially change and will show the new date and version here. Where law requires additional notice or consent, we will provide it before the change applies.

Privacy questions or requests: info@flowwweb.com

Your use of RSTR is also governed by the Terms of Service.

RSTR© RSTR
ProductSpecialistsPricingPrivacyTermsCookiesContact

Build what comes next.✦