Privacy Policy
Privacy Policy
Google Flow Automation · Last updated 19 August 2026
The developer does not receive your prompts, reference images, Google Flow page content, or generated results. The extension has no advertising, analytics, telemetry, or cross-site tracking.
Google Flow Automation handles website content only to automate the Google Flow page at your request. It may also use Firebase Authentication for account sign-in if login is enabled in the installed build.
Data the extension handles
- Prompts and reference images. The extension reads content you enter or select, then sends it to the open Google Flow page only when you start a batch.
- Google Flow page content. On
labs.google, the extension reads and changes generation controls, status messages, result cards, media identifiers, media URLs, and related metadata needed to submit work, match results, and download files. - Settings and latest batch state. Chrome local extension storage keeps panel settings and a resumable record of the latest batch. That record can include prompts, run status, timestamps, error notes, output identifiers, media URLs, and result metadata.
- Temporary run authorization. A random run ID, Flow tab ID, and expiry time are kept in Chrome session storage so only the batch you started can use automated browser input and downloads.
- Sign-in information. If authentication is enabled, Firebase Authentication handles your email address, Google profile basics, email verification state, and session tokens needed to keep you signed in.
Reference-image bytes are held in memory only while they are prepared and used for the active batch; they are not written to Chrome local extension storage. Generated files are saved to your browser's Downloads area, not to a developer server.
Network connections and sharing
| Destination | Purpose |
|---|---|
labs.google |
The Google Flow page you are already signed in to. At your request, the extension submits prompts and reference media, reads results, and downloads generated media. Google processes that content and ordinary request data under Google's own privacy policy, as it would when you use Flow directly. |
google-flow-automation.pages.dev |
Fetches selectors.json, a non-executable configuration file describing Flow's current page structure. The request includes the installed extension version and ordinary HTTPS request metadata visible to Cloudflare, such as IP address and user agent. It does not include prompts, reference images, Flow page content, Google account data, or browsing history. |
identitytoolkit.googleapis.com and securetoken.googleapis.com |
Used by Firebase Authentication for email/password account creation, email verification, sign-in, session persistence, and token refresh. |
accounts.google.com and www.googleapis.com |
Used only when you deliberately choose Google sign-in. The extension requests openid, email, and profile scopes and does not request Gmail, Drive, Chrome profile data, or other Google APIs. |
The developer does not sell user data or share it with advertising platforms or data brokers. Data is transferred only as described above to provide the extension's single purpose, when you deliberately send a support report, or when required by law or necessary to protect users and the service.
Permissions, and why each is needed
| Permission | Reason |
|---|---|
debugger | Google Flow rejects ordinary synthetic clicks. Submitting a prompt may require browser-recognized input events. The extension attaches only to the Flow tab authorized by a user-started batch and releases the attachment when the run finishes, stops, fails, is revoked, or the tab closes. |
downloads | Saves finished Google Flow images and videos at your request. |
storage | Remembers settings, selector configuration, sign-in state, and the latest resumable batch state. |
tabs and scripting | Finds the Flow tab and runs the packaged automation script inside the declared Flow host. |
sidePanel | Shows the control panel beside the Google Flow page. |
alarms and offscreen | Keep long user-started batches reliable while Chrome suspends inactive extension contexts, and refresh selector compatibility on schedule. |
identity | Used only when you choose Google sign-in. Chrome opens Google's OAuth flow and returns the final redirect containing a Google ID token, which is passed to Firebase Authentication. |
Diagnostics and support
Diagnostic reports are created locally and are never sent automatically. They can include extension and browser details, run status, prompts, result URLs, and error notes. If you choose to copy a report and send it to support, the developer receives the information you include and uses it only to respond to and resolve your request.
Retention, access, and deletion
Local settings, cached selector configuration, and the latest batch state remain until you clear extension data or uninstall the extension. Session authorization is removed when a run ends and does not survive the browser session. Downloaded files remain until you delete them. Firebase sign-in sessions remain until you sign out or clear extension site data. Support messages are kept only as long as reasonably necessary to resolve the request and maintain support records; you may ask for deletion by emailing the address below.
Security
Network connections use HTTPS. Automated input is authorized for one user-started run and one Google Flow tab. The extension does not read browser cookies, passwords, Chrome history, unrelated tabs, Gmail, Drive, or Chrome profile data.
Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. User data is used only to provide or improve the extension's disclosed single purpose. It is not used for personalized advertising, sold to data brokers, used to determine creditworthiness, or made available for humans to read except with your explicit consent for support, for security, or as required by law.
Children
This extension is not directed at children under 13.
Changes
Material changes to data handling will be disclosed here with a new date.
Contact
Data controller: Deepak Thapa. Questions, privacy requests, or deletion requests: thapadeepak726@gmail.com