Privacy Policy
LAST UPDATED · September 2026
What we store
IntakeFlow stores the account details you give us, your clients' names and emails, the content clients submit through their portal links (text answers, uploaded files, and credential entries), and operational logs (email sends, webhook deliveries, credential-reveal audits).
Credentials and files
Credential-type answers are encrypted with AES-256-GCM before they touch the database. Files live in private storage buckets (or your own connected cloud storage) and are served only through authenticated, signed links. Every reveal of a credential is logged with who and when.
Client links
Clients never create an account. They access their portal through a signed, expiring link that you control — resend or pause it any time.
Data sharing
We don't sell data. Data leaves the platform only when you send it somewhere: emails to your clients, webhook deliveries to endpoints you configure, or API/MCP access through keys you create. Revoking a key or deleting a webhook endpoint stops that flow.
Deletion
Deleting a client, portal, or your account removes the underlying rows, files, and logs per the platform's retention settings. Contact your workspace owner or the platform operator for urgent erasure requests.