CGPT Flow — Privacy Policy
This policy covers CGPT Flow, the Toolvai Chrome extension, and the Toolvai account you use with it. It doesn't cover other Toolvai products, which have their own policies.
1. What we collect
| Data | Why |
|---|---|
| Email address | Account login, receipts, and service emails (for example renewal reminders) |
| Display name (optional) | Shown back to you in the extension |
| Password | Stored hashed by our authentication provider, Supabase — we never see or store it in plain text |
| Device identifier, browser user-agent, extension version | Enforcing your plan's device limit and troubleshooting support requests |
| Plan, credit balance, credit history | Metering your usage and showing you your balance |
| Subscription and payment status, and your payment processor's customer reference | Keeping your subscription in sync with what you bought |
| The first 120 characters of each prompt you submit, plus the mode used, status, and time | Usage records for support, abuse prevention, and your own history |
| Terms acceptance record (version and time) | Proof of what you agreed to and when |
The prompt preview is limited to the first 120 characters of each prompt and is visible to Toolvai staff who handle support. Without an account, CGPT Flow keeps a small free-use counter on your own browser only; nothing is sent to us.
2. What stays on your device
Your queue, prompts, reference images, results list, and settings are stored locally in your browser by the extension, and generated images are saved to your Downloads folder. This data never leaves your device through CGPT Flow. Removing the extension deletes it.
3. What the extension can access
- chatgpt.com — the only website it reads and types into, and only while you run a batch, to enter your prompts, attach your reference images, send them, and find the finished image.
- Downloads — to save the images you generate.
- Notifications — to tell you when a batch finishes or needs attention.
- Tabs — to find your ChatGPT tab in the same window as the side panel, and to open the checkout, billing, and other pages you click on.
It doesn't read your browsing history, other tabs, or any other website.
4. Who we share it with
- Supabase — hosts our database and handles sign-in.
- Creem — processes payments for subscriptions and credit packs. Creem handles your card details directly; we only receive confirmation of payment and a customer or subscription reference.
- Brevo — sends transactional emails on our behalf, such as receipts and renewal reminders.
We don't sell your data, we don't use it for advertising, and we don't transfer it to anyone except as needed to run CGPT Flow (the providers above), to comply with the law, or with your consent. We use it only to provide and support CGPT Flow.
5. Retention and deletion
We keep your account data for as long as your account is active. To have your account and associated data deleted, email us and we'll process the request, subject to what we must keep for legal, tax, or fraud-prevention purposes (for example, billing records).
6. Security
Data is encrypted in transit (HTTPS/TLS). Access to account data is restricted by row-level access controls in our database, and administrative access is limited to authorized staff for support and abuse prevention.
7. Children's privacy
CGPT Flow requires account holders to be at least 18, or the age of majority in their jurisdiction (see the CGPT Flow Terms). It isn't directed at children, and we don't knowingly collect data from anyone under that age.
8. Changes to this policy
We may update this policy as CGPT Flow changes. We'll update the "Last updated" date above, and announce significant changes inside the extension.
9. Contact
Questions about this policy or your data: toolvaisupport@gmail.com