Privacy policy
Last updated: August 2026 · Draft for legal review
Walkflow ("we", "us") operates walkflow.app from Australia. This policy explains what personal information we collect, why we collect it, and how we handle walkthrough content processed on your behalf.
Information we collect
- Account data: email address, authentication identifiers, billing customer ID (via Stripe), credit balance, and usage metadata.
- Walkthrough content: video, audio, snapshots, titles, transcripts, captions, summaries, and share-link access logs (hashed IP and user-agent for analytics).
- Device data: browser type, approximate location if you grant geolocation on snapshots, and technical logs for security and debugging.
How we use information
We use your information to provide recording, upload, assembly, AI enrichment, sharing, billing, and support. We do not sell your personal information. We use service providers (Supabase, Stripe, AssemblyAI, Google Gemini, hosting providers) under contracts appropriate to their role.
Third-party AI services
Walkflow uses third-party services to process your walkthrough content:
- AssemblyAI transcribes assembled walkthrough audio. We send a time-limited signed URL to your assembled video so AssemblyAI can fetch it for transcription. Processing is subject to AssemblyAI's terms and policies.
- Google Gemini (paid API) generates snapshot captions, chapter markers, and summary text from your snapshots, transcript, and related metadata. API usage is subject to Google's API terms. Paid Gemini API data is not used to train Google's models per Google's API terms (verify current terms at launch).
We do not expose AssemblyAI or Gemini API keys in the client app. AI processing runs on our servers and worker infrastructure only.
What we send to AI providers
- Assembled video (for transcription)
- Snapshot images and nearby transcript context (for captions)
- Transcript and captions (for chapters and summary)
Do not include sensitive personal information in walkthroughs unless you accept that this content is processed by the providers above.
Storage and retention
Walkthrough media is stored in private cloud storage (Supabase, AU region). Raw upload chunks are deleted after successful assembly. When you delete a walkthrough, we remove associated database rows and storage objects. Backups may retain deleted data for a limited operational window before purge.
Share links and recipients
Recipients who open a share link can view walkthrough content you chose to share. Share pages are not indexed by search engines. We log aggregated view counts and hashed identifiers for analytics shown to you in the product.
Cookies and local storage
We use session cookies for authentication. Recording uses IndexedDB on your device before publish. Our service worker caches app shell assets only — not walkthrough media.
Your choices
- Access and update account details in the app.
- Delete walkthroughs and revoke share links.
- Opt out of web push notifications in Account settings.
- Contact us to request account deletion or data questions.
Security
We use encryption in transit, row-level security on owner data, hashed share tokens, and short-lived signed media URLs. No system is perfectly secure; report concerns to hello@korijacobsen.au.
Changes
We may update this policy. Material changes will be reflected on this page with an updated date.
Contact
Privacy enquiries: hello@korijacobsen.au.