Privacy Policy

Last updated: March 16, 2026

1. Introduction

This Privacy Policy explains how Reflow, operated by Lucas Martin Guarnieri ("we", "us", "our"), collects, uses, and protects your information when you use the Reflow Chrome extension ("Extension") and the Reflow website at reflow.website ("Website"). By using our services, you agree to the practices described in this policy.

2. Information We Collect

We collect the following types of information: • Account information: When you sign in via Google OAuth, we receive your name, email address, and profile picture from Google. • Bubble.io page structure data: When you use AI-powered features, the structure of your current Bubble.io page (element hierarchy, responsive properties, and layout data) is sent to our servers for analysis. We do not collect the content or data displayed on your pages. • Usage data: We collect anonymous usage metrics such as feature usage frequency and error logs to improve the Extension. • Payment information: Payment details are processed by Paddle.com, our Merchant of Record. We do not store your credit card information. Paddle handles all payment processing in accordance with their privacy policy.

3. How We Use Your Information

We use your information to: • Provide and maintain the Extension and Website services. • Authenticate your account and verify your subscription plan. • Process AI analysis requests by forwarding page structure data to our AI provider (Anthropic). • Process payments and manage subscriptions via Paddle. • Send important service notifications (e.g., plan changes, security alerts). • Improve and develop new features based on aggregated usage patterns.

4. AI Data Processing

When you use AI features (Pro plan), your Bubble.io page structure data is sent to our servers and forwarded to Anthropic's Claude API for analysis. This data includes element names, types, dimensions, and responsive properties. It does not include user-generated content, database data, or personal information stored in your Bubble.io application. Anthropic processes this data according to their privacy policy and does not use it for model training.

5. Data Sharing

We do not sell your personal information. We share data only with: • Anthropic: Page structure data for AI analysis (Pro plan only). • Supabase: Authentication and account data storage. • Paddle.com: Payment information for subscription management (as Merchant of Record). • Law enforcement: When required by applicable law or legal process.

6. Data Storage and Security

Your account data is stored securely in Supabase (hosted on AWS). Authentication tokens are stored locally in your browser's Chrome storage. We use industry-standard security measures including encrypted connections (HTTPS), server-side token validation, and rate limiting. Page structure data sent for AI analysis is not permanently stored on our servers; it is forwarded to the AI provider and discarded.

7. Data Retention

We retain your account information for as long as your account is active. Usage data is retained in aggregated form. If you delete your account, your personal data will be removed within 30 days. AI analysis data is not stored after processing is complete.

8. Your Rights

You have the right to: • Access the personal data we hold about you. • Request correction of inaccurate data. • Request deletion of your account and associated data. • Export your data in a portable format. • Withdraw consent for data processing. To exercise these rights, contact us at martinlucasmguarnieri@gmail.com.

9. Cookies and Local Storage

The Website uses essential cookies for authentication and session management. The Extension uses Chrome's local storage API to store authentication tokens and user preferences. We do not use tracking cookies or third-party advertising cookies.

10. Children's Privacy

Our services are not directed to children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. For material changes, we will notify you via email or through the Extension. Continued use of our services after changes constitutes acceptance of the updated policy.

12. Contact

For questions or concerns about this Privacy Policy, contact us at martinlucasmguarnieri@gmail.com.