Flow Automation Privacy

Privacy Policy

Privacy Policy

Google Flow Automation · Last updated 19 August 2026

The developer does not receive your prompts, reference images, Google Flow page content, or generated results. The extension has no advertising, analytics, telemetry, or cross-site tracking.

Google Flow Automation handles website content only to automate the Google Flow page at your request. It may also use Firebase Authentication for account sign-in if login is enabled in the installed build.

Data the extension handles

Reference-image bytes are held in memory only while they are prepared and used for the active batch; they are not written to Chrome local extension storage. Generated files are saved to your browser's Downloads area, not to a developer server.

Network connections and sharing

DestinationPurpose
labs.google The Google Flow page you are already signed in to. At your request, the extension submits prompts and reference media, reads results, and downloads generated media. Google processes that content and ordinary request data under Google's own privacy policy, as it would when you use Flow directly.
google-flow-automation.pages.dev Fetches selectors.json, a non-executable configuration file describing Flow's current page structure. The request includes the installed extension version and ordinary HTTPS request metadata visible to Cloudflare, such as IP address and user agent. It does not include prompts, reference images, Flow page content, Google account data, or browsing history.
identitytoolkit.googleapis.com and securetoken.googleapis.com Used by Firebase Authentication for email/password account creation, email verification, sign-in, session persistence, and token refresh.
accounts.google.com and www.googleapis.com Used only when you deliberately choose Google sign-in. The extension requests openid, email, and profile scopes and does not request Gmail, Drive, Chrome profile data, or other Google APIs.

The developer does not sell user data or share it with advertising platforms or data brokers. Data is transferred only as described above to provide the extension's single purpose, when you deliberately send a support report, or when required by law or necessary to protect users and the service.

Permissions, and why each is needed

PermissionReason
debuggerGoogle Flow rejects ordinary synthetic clicks. Submitting a prompt may require browser-recognized input events. The extension attaches only to the Flow tab authorized by a user-started batch and releases the attachment when the run finishes, stops, fails, is revoked, or the tab closes.
downloadsSaves finished Google Flow images and videos at your request.
storageRemembers settings, selector configuration, sign-in state, and the latest resumable batch state.
tabs and scriptingFinds the Flow tab and runs the packaged automation script inside the declared Flow host.
sidePanelShows the control panel beside the Google Flow page.
alarms and offscreenKeep long user-started batches reliable while Chrome suspends inactive extension contexts, and refresh selector compatibility on schedule.
identityUsed only when you choose Google sign-in. Chrome opens Google's OAuth flow and returns the final redirect containing a Google ID token, which is passed to Firebase Authentication.

Diagnostics and support

Diagnostic reports are created locally and are never sent automatically. They can include extension and browser details, run status, prompts, result URLs, and error notes. If you choose to copy a report and send it to support, the developer receives the information you include and uses it only to respond to and resolve your request.

Retention, access, and deletion

Local settings, cached selector configuration, and the latest batch state remain until you clear extension data or uninstall the extension. Session authorization is removed when a run ends and does not survive the browser session. Downloaded files remain until you delete them. Firebase sign-in sessions remain until you sign out or clear extension site data. Support messages are kept only as long as reasonably necessary to resolve the request and maintain support records; you may ask for deletion by emailing the address below.

Security

Network connections use HTTPS. Automated input is authorized for one user-started run and one Google Flow tab. The extension does not read browser cookies, passwords, Chrome history, unrelated tabs, Gmail, Drive, or Chrome profile data.

Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. User data is used only to provide or improve the extension's disclosed single purpose. It is not used for personalized advertising, sold to data brokers, used to determine creditworthiness, or made available for humans to read except with your explicit consent for support, for security, or as required by law.

Children

This extension is not directed at children under 13.

Changes

Material changes to data handling will be disclosed here with a new date.

Contact

Data controller: Deepak Thapa. Questions, privacy requests, or deletion requests: thapadeepak726@gmail.com