1. Who is responsible
OptiFlowz LLC is responsible for the OptiFlowz platform. Contact us at office@optiflowz.com or 30 N Gould St Ste R, Sheridan, WY 82801, USA.
2. Information we handle
- Account data: email address or recovery account identifier, verification status, account status, and authentication records.
- Device and security data: product and browser identifiers, device public keys, session records, and security/audit events.
- Purchase data: selected products and plan, amount, currency, Stripe customer and transaction references, subscription status, entitlement status, and refund history.
- Optional shared hosted-AI content: only when you explicitly invoke a hosted feature, Gist (015), ToneUp (019), Simpl (021), Brief (028), Aska (029), Cardz (110), or Tubey (112) sends the text, page passages, question, prompt, or transcript needed for the summary, rewrite, prompt improvement, grounded answer, card generation, or transcript summary you requested. Aska also sends the bounded conversation history needed for the current grounded answer.
- Optional Pismenko content: only when you explicitly request a Pismenko (044) Pro cloud suggestion, the selected Serbian text fragment and the local suggestion are sent for that request. Automatic background sending is not used for any hosted-AI feature.
- Kursko rate lookups: Kursko (043) requests active-currency metadata and the selected base/quote currency pair directly from
https://api.frankfurter.dev/v2. It does not send the amount being converted; multiplication is performed locally in the extension. - Affiliate data: display name, contact email and verification state, referral code, terms acceptance, qualified visit totals, safe attributed sale references, sales and commission ledger entries, hold and reversal status, payout readiness, and hosted-provider references. Affiliate dashboards do not expose buyer PII or raw order IDs.
- Support data: messages, refund reasons, and information you choose to provide.
- Technical data: request metadata needed for security, reliability, attribution integrity, and abuse prevention, which may include IP address, user agent, timestamps, and error logs.
OptiFlowz extensions and affiliate forms must not send card numbers, bank credentials, tax identifiers, or identity documents to the OptiFlowz API.
3. Why we use it
We use information to create and secure accounts, authenticate devices, provide and restore purchased access, return explicitly requested hosted-AI results, create Stripe checkout and billing sessions, process eligible refunds, validate referral attribution, calculate and mature commission, present affiliate ledgers, support hosted payout onboarding, prevent fraud and abuse, troubleshoot failures, meet legal obligations, and improve service reliability.
4. Payment processing
Stripe processes checkout, card details, billing, tax-related payment information, and refunds under its own privacy terms. OptiFlowz receives identifiers and payment status needed to provide access; it does not receive the full card number from Stripe-hosted Checkout.
5. Service providers and disclosure
We share data only as needed with service providers such as Stripe for payments and hosted payout onboarding, Cloudflare for hosting, database, networking, and security, and OpenAI for the optional hosted-AI actions in Gist, ToneUp, Simpl, Brief, Aska, Pismenko, Cardz, and Tubey that you explicitly request. Hosted-AI generation requests use store:false, do not use background processing, and do not use OpenAI Files, Conversations, or Vector Stores. OpenAI may nevertheless retain request or response content for up to 30 days for safety and abuse monitoring under its standard API data controls.
Pismenko Pro is enabled only when its separate, dedicated OpenAI project is configured with input/output data sharing and evaluation data sharing disabled. OptiFlowz does not represent that configuration as eliminating OpenAI's separate safety and abuse-monitoring retention described above.
Kursko contacts Frankfurter directly for public currency metadata and requested reference-rate pairs. Frankfurter may receive the requested currency codes and ordinary network metadata such as IP address and user agent, but not the amount being converted. No Frankfurter API key is bundled, and the current Kursko rate lookup does not pass through the OptiFlowz backend. Service providers process information under their own terms. A hosted payout provider may independently collect identity, tax, and bank information under its own terms; OptiFlowz does not ask you to place that information in its affiliate enrollment form. We may also disclose information when required by law, to protect users or the service, or in connection with a business reorganization subject to appropriate safeguards. We do not sell personal information.
6. Storage, retention, and security
For the shared hosted-AI features in Gist, ToneUp, Simpl, Brief, Aska, Cardz, and Tubey, OptiFlowz stores a request fingerprint and may cache the returned result or status for safe retry handling. The cached response is configured to expire after 24 hours; non-reserved request, status, quota, budget, and security records are configured for deletion after 40 days through scheduled cleanup.
OptiFlowz does not retain submitted Pismenko text, the local suggestion, or the generated cloud result in its application or database after returning the requested suggestion. Minimal request status, fingerprint, quota, consent, and security records do not contain that plaintext or result. OpenAI's separate safety and abuse-monitoring retention described above may last up to 30 days.
Kursko keeps a bounded currency list, settings, and dated reference-rate pairs in browser storage. OptiFlowz does not receive or store the amount converted or the Frankfurter rate lookup. We keep account, transaction, entitlement, refund, affiliate attribution, commission, payout-reference, terms-acceptance, and audit data for as long as needed to provide the service, maintain security and financial records, resolve disputes, enforce program rules, and meet legal obligations. We use access controls, encrypted transport, signed tokens, hashed refresh credentials, and separated test and production systems. No system can guarantee absolute security.
7. Cookies and local storage
The website uses security and account session mechanisms needed to sign you in and protect requests, plus short session storage for retrying the same direct product-and-plan checkout after an interruption or email sign-in return. The current marketplace does not store a cart or global billing cadence. A first-party referral preference is stored for up to 30 days only after an explicit choice; a referral can instead be used for the current checkout only. See the Cookie and storage policy and its Referral settings control. Browser tools may store preferences, device credentials, and entitlement state locally. None of these mechanisms proves that a payment or payout completed before the backend confirms it.
8. International use
OptiFlowz and its providers may process data in the United States and other locations. Where required, transfers are handled using applicable contractual or legal safeguards.
9. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to complain to a regulator. Email office@optiflowz.com. We may need to verify the request and may retain information required for security, payment records, disputes, or law.
10. Children and changes
The platform is not directed to children under 16, and we do not knowingly collect their personal information. We may update this policy as the platform or law changes; the posted effective date identifies the current version.