Effective Date: June 26, 2026
Last Updated: June 26, 2026
Welcome to Autoflow ("we," "our," or "us"). Your privacy is critically important to us. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Autoflow Chrome Extension ("the Extension") and associated services.
By installing and using the Extension, you agree to the terms of this Privacy Policy.
We are committed to data minimization. The Extension operates primarily within your browser and limits data collection to what is strictly necessary for functionality.
The following data is stored locally on your device using the Chrome Storage API. This data never leaves your browser:
Automation Preferences: Your selected model, generation settings, and configuration options.
Prompt Queues: The text prompts you enter or upload for batch processing.
UI Settings: Panel layout preferences, dismissed notification states, and similar UI state.
Cached Content: A temporary cache of remote configuration data (described below) to enable offline functionality and faster panel loading.
We do not collect personal information, names, email addresses, or account credentials.
We do not track browsing history, keystrokes, or page content outside of labs.google.
We do not collect analytics, telemetry, crash reports, or usage statistics.
We do not require account creation, sign-up, or login.
The Extension makes a single read-only network request to our server to fetch display configuration data:
Endpoint: https://inov8ing.xyz/wp-json/autoflow/v1/remote-content
Method: GET (read-only)
Purpose: To retrieve updated promotional banners, service listings, announcements, and feature flags for display within the Extension's side panel.
Frequency: Once when the side panel opens, and no more than once per hour (cached locally to minimize network usage).
Data Sent: No personal data, cookies, authentication tokens, or user-identifiable information is sent with this request. The request contains only standard HTTP headers (Accept: application/json).
Data Received: A JSON object containing display content (text, colors, URLs) only. No executable code is received or executed from this endpoint.
Offline Support: If the network request fails, the Extension gracefully falls back to locally cached data or built-in defaults. The Extension remains fully functional offline.
This request is essential to deliver timely content updates to users (such as new feature announcements or service offerings) without requiring a full Extension update through the Chrome Web Store.
Your prompts and automation workflows are processed directly on your machine and passed only to the Google services (labs.google) that you actively interact with.
The remote content data is used exclusively for UI display purposes within the Extension's side panel.
We do not sell, rent, trade, or share any user data with third parties.
We do not use your data for advertising, profiling, or behavioral targeting.
The Extension interacts with the following external services:
Service
Domain
Purpose
Google Flow (Labs)
labs.google
The target platform where automation runs. Prompts are entered and media is generated.
Autoflow Content API
inov8ing.xyz
Read-only remote configuration for UI display content (described above).
When the Extension interacts with Google Flow on your behalf, Google's own privacy policies and terms of service apply. We are not responsible for the privacy practices of third-party platforms.
Our Extension requests only the permissions necessary for its core functionality. Each permission and its specific purpose:
Permission
Purpose
activeTab
Interact with the currently active Google Flow tab to enter prompts and trigger generation.
tabs
Open, detect, and manage the Google Flow tab for automation workflows.
storage
Save your prompt queue, preferences, and cached remote content data locally in your browser.
sidePanel
Display the Autoflow control interface in Chrome's side panel.
downloads
Automatically download completed videos and images to your Downloads folder.
debugger
Simulate keyboard and mouse input on the Google Flow page for reliable, human-like automation. This permission is used exclusively on labs.google and never on any other website.
cookies
Clear session cookies on labs.google to resolve "Unusual Activity" errors that block automation.
background
Run the service worker in the background to coordinate automation tasks between tabs.
Host Pattern
Purpose
*://labs.google/*
Required to inject the automation content script and interact with the Google Flow page.
The Extension does not request broad host permissions (e.g., <all_urls>) and operates exclusively on labs.google.
We employ the following security measures:
Local-first architecture: All user data (prompts, settings, preferences) is stored locally on your device using Chrome's encrypted storage APIs and is never transmitted to our servers.
Read-only remote access: The remote content endpoint is read-only (GET requests only). No user data is ever uploaded.
No authentication tokens: The Extension does not generate, store, or transmit authentication tokens, API keys, or user credentials to our servers.
HTTPS only: All network communication uses encrypted HTTPS connections.
The security of locally stored data also depends on the physical and digital security of your own device.
Local data is retained on your device until you uninstall the Extension or manually clear Chrome's storage for the Extension.
No server-side data about individual users is collected or retained. The remote content endpoint serves the same public data to all users.
Our Extension is not intended for use by children under the age of 13. We do not knowingly collect personal information from children. If you believe a child under 13 has provided us with personal information, please contact us at the email below and we will take steps to delete such information.
You have the right to:
Access your data: All data is stored locally on your device and accessible through Chrome's extension storage.
Delete your data: Uninstalling the Extension removes all locally stored data. You can also clear extension data from Chrome Settings → Extensions.
Opt out of remote content: The Extension functions fully with built-in defaults if the remote content endpoint is unreachable.
We may update this Privacy Policy from time to time. Significant changes will be communicated by updating the "Last Updated" date at the top of this document. We encourage you to review this policy periodically.
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
Email: memrrizwan@gmail.com
Website: https://inov8ing.xyz