Privacy Policy

Last updated: 14 September 2026

Introduction

squeed.co (“Squeed”, “we”, “us”) operates Squeed Flow at squeed.co and app.squeed.co (the “Service”): the diagram editor, saved documents, workflow runs, the MCP bridge, API keys and support channels. This policy explains what we collect, how we use it, how long we keep it and the choices you have.

This policy describes our data practices; it does not request blanket consent to processing. Terms not defined in this policy have the meaning given in our Terms of Service.

Definitions

  • Personal data is information about a living individual who can be identified from it, such as an email address.
  • Content is what you create or paste in the Service: workflow definitions, form values, node and edge metadata, templates, bindings and execution inputs and outputs.
  • Usage data is collected automatically when you use the Service, such as pages visited, timestamps, browser type and IP address.
  • Local storage means data the editor keeps in your browser (drafts, layout and theme preferences) rather than on our servers.
  • Service providers are third parties that process data on our behalf, for example hosting and email delivery.

Our role and customer content

We act as a controller for personal data we use to manage accounts, administer billing, secure the Service and respond to inquiries. Where we process personal data within a customer’s workflow on that customer’s behalf and instructions, we act as a processor or service provider, as applicable. The relevant customer determines the purpose of that processing and is responsible for the necessary notices, permissions and lawful basis.

This policy does not replace a data processing agreement where one is required. Contact us to discuss applicable data processing terms before submitting personal data on behalf of an organization. For requests concerning data in another customer’s workflow, contact that customer; we can assist as appropriate to our role.

Information we collect

Account and support data. When you use account features, we process your email address, account or workspace identifiers, authentication events and settings. We also receive information you provide in support requests. Where email-code sign-in is available, your address is used to deliver the code.

Content. Information you submit to hosted features, such as cloud saving, sharing, workflow execution or agent requests, may include diagrams, form values, node and edge metadata, MCP commands and execution results. Do not include sensitive personal data in a diagram or workflow unless you are authorized to process it.

Execution and bridge records. Depending on the features you use, records may include submitted workflow definitions, step inputs and outputs, MCP commands and their results. This content is distinct from activity metadata such as timestamps, execution status, request counts and account events. Records are associated with the account used for the request or run; retaining execution content is not the same as collecting every local canvas interaction.

API key records. These include key identifiers, prefixes, permissions, status and lifecycle timestamps used to authenticate requests and manage access. Treat a full API key as a secret; do not put it in diagram content or support messages.

Usage data. IP address, browser and device type, the pages and features you use, request timestamps, bridge request counts and diagnostic data such as error reports.

Billing data. If you buy bridge credit, we keep the amount, date, transaction reference and payment status, together with billing or invoice information supplied to us. Payment processors handle payment credentials; see the Payments section below.

Data you paste into the editor

  • Parsing and rendering run in your browser. Local drafts and local file exports are distinct from content you submit to hosted features; local editing does not itself require uploading the whole document as an execution record.
  • Cloud saving, sharing, running a workflow or using an agent feature can send the relevant content and metadata to our backend and to services you connect. The information transmitted depends on the action, workflow configuration and permissions. Availability of these features may vary.
  • Bridge requests carry the tool call and its result between your agent and your open editor tab. They are logged with your account for service operation, audit, security, troubleshooting and billing, subject to the retention criteria in this policy.

How we use data

  • to provide, maintain and secure the Service;
  • to render, save, run, replay and troubleshoot your diagrams;
  • to authenticate you and deliver one-time sign-in codes;
  • to meter bridge requests and bill for what you use;
  • to detect, prevent and address abuse and technical issues;
  • to respond to support requests;
  • to notify you about changes to the Service, your account or these policies;
  • to comply with legal obligations and enforce our agreements.

We do not sell personal data, content or execution data, and we do not use your content to train models. This describes Squeed’s use of data, not the independent practices of AI providers or other services you choose to connect. Review their policies and settings.

Legal bases for processing

For processing where we act as a controller and applicable data protection law requires a legal basis, we rely on the basis appropriate to each purpose:

  • Performance of a contract: processing necessary to perform a contract with you, or take steps you request before entering one, such as providing requested Service features, managing your account and administering billing.
  • Legitimate interests: maintaining the security and reliability of the Service, investigating technical issues, preventing abuse and protecting our rights, where those interests are not overridden by your rights and freedoms.
  • Legal obligations: processing required to comply with applicable accounting, tax and other legal requirements.
  • Consent: where required for a specific purpose, we request consent separately. You may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Using the Service does not itself constitute consent.

Retention of data

We keep personal data only as long as needed for the purposes above, then delete or anonymize it, except where retention is required to comply with law, resolve disputes or enforce our agreements.

Retention depends on the type and sensitivity of the information, the purpose for which it was collected, whether it is needed for an ongoing support request or security investigation, and applicable legal requirements. Ending a workflow run does not automatically delete its execution records.

  • Account data and saved content are retained while your account is active. After you request deletion, account data, saved work and associated personal data are removed after a 30-day grace period, except for specific records that must be retained for legal obligations, disputes or security investigations as described below. Those exceptions do not justify retaining all workflow content indefinitely.
  • Sign-in codes are single use and expire shortly after they are sent.
  • API key records are retained while needed to manage access. Revocation disables use of a key but may not erase related audit metadata, which follows the criteria for security and audit records below.
  • Execution and bridge content, including recorded definitions, inputs, outputs and command results, is retained as needed to provide execution history, replay and troubleshooting. Where specific records are needed for an investigation, dispute or legal obligation, they may be retained for that purpose.
  • Usage, security and audit metadata, including timestamps, request counts, execution status and account events, is retained as needed to operate and secure the Service, investigate misuse and verify usage charges. These purposes may require different retention periods from execution content.
  • Billing records are kept for as long as tax and accounting rules require.
  • Local storage stays in your browser until you clear it or the editor removes it.

Export anything important before asking us to delete an account.

Sharing and disclosure

We share information only:

  • with service providers that host, deliver email for, secure or bill for the Service, under agreements that limit their use of the data to those tasks;
  • with AI providers, MCP clients and third-party services you connect, which receive the content and metadata your configured actions send them and handle it under their applicable agreements and privacy policies;
  • when required by law or a valid request from a public authority;
  • to protect the rights, property or safety of Squeed, our users or others;
  • as part of a merger, acquisition or asset sale, in which case this policy continues to apply to the transferred data;
  • with your consent.

Transfer of data

Your information may be processed on servers outside your country, where data protection laws may differ. Where required, transfers must rely on an applicable adequacy decision or appropriate safeguards, such as approved contractual clauses. Contact us for information about relevant processing locations, recipients and transfer safeguards.

Security

  • Local editing is separate from server-side processing. Connected features and third-party scripts may transmit data as described in this policy.
  • Hosted Service connections use HTTPS. We use access controls to restrict access to personal data to authorized people who need it for the purposes described in this policy.
  • Protect your account and API keys, review agent permissions and revoke credentials you no longer need. Contact us if you suspect unauthorized access or cannot use an available access control.

No method of transmission or storage is completely secure. We use commercially reasonable safeguards but cannot guarantee absolute security.

Cookies, local storage and analytics

The website and editor use browser storage for preferences, local drafts and authentication. Clearing site data may remove drafts, reset preferences or sign you out; it does not delete records held on our servers.

The editor includes Google Tag Manager, which can load configured analytics or measurement tags. Loading third-party scripts can disclose device and request metadata, such as an IP address and page URL, to their providers. Additional data collection depends on the tags enabled. Google explains its processing in its Privacy Policy. Local document storage does not mean that the Service makes no third-party requests.

Browser settings can limit cookies and some tracking technologies, although blocking essential storage may affect functionality. Consent for optional processing, where required, must be obtained through a separate choice; acceptance of the Terms does not authorize it. Contact us with questions about tracking or your privacy choices.

Payments

Bridge credit is paid through a third-party payment processor that handles payment credentials under its own privacy policy. We receive transaction and billing information needed to administer the purchase, reconcile charges and meet accounting obligations. The payment provider may retain records for its own legal obligations. Review the provider’s policy presented at checkout.

Links to other sites

The Service may link to sites we do not operate. We have no control over their content or privacy practices and encourage you to review their policies.

Your rights and choices

You may request access to, correction, export or deletion of your personal information, request restriction of processing, object to certain processing or withdraw consent where we rely on it, subject to applicable law, by contacting [email protected]. Use available account or document controls where supported, or contact us for assistance. We may request information reasonably necessary to verify your identity and authority, and will respond within the time limits required by applicable law. You may also lodge a complaint with your local data protection authority.

Clearing local storage, revoking a key and requesting account deletion are separate actions. Data already sent to an independent third-party service is subject to that service’s retention policy; deleting it from Squeed does not necessarily delete those separate records.

Changes to this policy

We may update this policy as Squeed Flow changes. We will post the new version on this page and update the Last updated date; material changes will also be announced in the editor or by email. Where a new processing purpose requires consent, we will request it separately rather than treating a policy update as consent.

Contact

Questions about this policy go to [email protected].