1. Who we are & scope
FlowTruss LLC (a Kentucky limited liability company, “FlowTruss,” “we,” “us”) builds the FlowTruss Network Dataflow Analyzer (“NDA”). This Privacy Notice covers the desktop NDA application, the browser-based Web Version, the marketing website, and our support channels. NDA is local-first: packet captures and related analysis data stay with you.
2. Roles (controller vs. processor/service provider)
For account, billing, website, analytics, and support data, FlowTruss acts as a controller (or “business” under certain U.S. state privacy laws). For packet-capture content and derived analysis in both the desktop app and the Web Version, FlowTruss does not receive, host, or persist that data. The Web Version executes entirely in your browser; we are only a processor/service provider for capture content you voluntarily share with us for support.
3. Information we collect
- Account & billing: name, email, organization, plan, subscription status, payment metadata (payment details handled by our payment processor), invoices.
- Support: ticket or email content, plus logs or sample files you choose to provide.
- Website & Web Version analytics: device/browser info, IP address, timestamps, pages/features used, and cookie or similar identifiers for analytics/diagnostics.
- Optional telemetry/feedback: crash reports, performance metrics, and in-app feedback only if you opt in.
- Customer Data (your network data): processed locally on desktop and in-browser for the Web Version. We do not receive or retain packet captures unless you explicitly share them with us.
We do not intentionally collect sensitive personal information unless you provide it (for example, in a support request).
4. How we use information
- Provide, maintain, and secure NDA and related services.
- Manage subscriptions, billing, and renewals.
- Support you (troubleshooting, responding to requests).
- Send service communications (renewal reminders, security advisories, important updates).
- Improve NDA and our site through diagnostics, analytics, and feedback.
- Comply with legal obligations (tax, accounting, fraud prevention).
We do not sell personal information or share it for cross-context or targeted advertising.
5. Local-first & Web Version behavior
The desktop app processes packet captures, topology files, and workspace data locally or within your environment. The Web Version runs entirely in your browser; packet captures and analysis do not upload to our servers and may only live in your browser memory or storage. Requests that load app code/assets from FlowTruss or a CDN may generate standard server logs (IP, user agent), but they do not include your packet contents.
6. Cookies & analytics
We use essential cookies to operate the website and account portal. Analytics cookies or similar technologies help us understand usage and improve the Service. Where required, we request consent before setting non-essential cookies and provide controls to adjust preferences. Browser settings may limit cookies, but certain features may not function without them. We do not currently respond to “Do Not Track” signals.
7. Subprocessors & third parties
We work with a short list of trusted vendors (for payment processing, site hosting, email delivery, support tooling, analytics). Vendors receive only what they need to perform their services and are bound by confidentiality and security obligations. A current list of core subprocessors is available on request.
8. Data retention
- Account & billing: kept while your account is active and as required for tax, accounting, and legal obligations.
- Support artifacts: deleted within 90 days after a ticket closes unless you ask us to retain them longer.
- Telemetry/analytics: retained only as long as necessary for the purposes described above.
- Customer Data: desktop data remains on your systems; Web Version data remains in your browser storage/session. We do not retain it and cannot access or delete what we do not hold.
9. Security
We apply commercially reasonable measures (encryption in transit, access controls, least-privilege, monitoring) to protect the personal information we handle. No method is 100% secure, so some residual risk remains. See the Security page for more detail.
10. International transfers
FlowTruss is U.S.-based. If personal information (such as account or support data) is transferred from the EEA or UK, we rely on appropriate safeguards like Standard Contractual Clauses and supplementary measures where required. Packet captures processed locally or in-browser are not transferred to FlowTruss.
11. Your choices & rights
Depending on your jurisdiction, you may have rights to access, port, correct, delete, restrict/object, withdraw consent (where applicable), appeal a denial (certain U.S. states), and opt out of sale/share for targeted advertising (FlowTruss does not sell/share for those purposes). Submit requests to privacy@flowtruss.com. We will verify your request and respond within applicable timelines. Because we do not control desktop or in-browser packet data, we cannot access or delete it on your behalf.
12. Children’s privacy
NDA is intended for professional users. We do not knowingly collect personal information from children. If you believe a child provided personal information to us, email privacy@flowtruss.com.
13. How we share information
We share personal information only (a) with service providers/subprocessors described above; (b) with your consent or on your instructions (for example, integrations you enable); (c) to comply with law, enforce agreements, or protect rights, safety, or security; or (d) as part of a corporate transaction subject to continued protections. Vendors are not permitted to use personal information for unrelated advertising.
14. Data processing addendum (DPA)
Because packet captures are processed locally (desktop) or in-browser (Web Version) and are not sent to FlowTruss, a DPA is typically unnecessary for that dataset. If you need a DPA covering account/support data or materials you share with us, contact privacy@flowtruss.com.
15. Third-party links
Our website or Web Version may link to third-party sites or services with their own privacy practices. Review those policies before interacting with their content.
16. Changes to this Notice
We may update this Notice periodically. We will post updates with a new “Last updated” date and provide additional notice where required. If we introduce server-side features that handle packet data, we will update this Notice before those features launch.
17. Contact
Questions or requests can be sent to privacy@flowtruss.com.