Who runs IEFlow?
The intended operator is Top Around LLC. Contact ieflow@victorgurbani.com about privacy and account requests. Complete entity and contact details will be published before the commercial service launches.
What stays out of our membership backend
Your university passwords, session cookies, grades, documents, messages and application contents are not sent to IEFlow’s subscription backend. University connections run locally. Results are passed to the assistant you chose, which may use a remote AI provider. That provider’s practices are separate from ours.
Product-account information
We process your verified email, first name and surname, optional study level/programme, display name, membership status, device labels, trial dates, referral attribution, subscription identifiers and feedback to provide the service, secure accounts and administer billing. Stripe handles payment details; we do not store full card numbers. Supabase provides authentication, database and package storage; Vercel hosts the website.
Sign-in and security
Sign-in uses a verified supported email provider or IE address. You can optionally add authenticator protection. Password sign-in is available only with an authenticator and requires both factors. Device access and refresh tokens are stored hashed on our server; your local credential store keeps the usable tokens. Device labels describe your assistant and OS, not hardware fingerprints or personal machine names.
Optional usage reporting
Usage reporting is off by default. If enabled, reports contain a random resettable installation identifier, software version, OS family, event or tool name, outcome and coarse duration. We never include prompts, arguments, results, university identities, raw exceptions or filenames. You can disable reporting in your account; doing so deletes the stored raw usage associated with your account. Raw events expire after 30 days.
Package download totals are aggregate request counts, not a count of people or installed devices. Infrastructure providers necessarily process network information to deliver and secure requests; this is not a claim that no provider ever sees an IP address.
Cookies and local storage
We use essential authentication cookies and local storage for your sign-in, a referral you chose to follow (for up to 30 days before account linkage) and account setup. No advertising cookies are used. Fonts are served with the website rather than fetched from a third-party font service.
Retention and your choices
Device requests expire after ten minutes and are cleaned up; revoked/expired device sessions and short-lived rate-limit records are periodically removed. Account information is retained while you use the service. Feedback and billing records may need different retention periods; legally required transaction records are not erased with a simple profile deletion.
You can export product-account data, revoke devices and request deletion from your account. We will confirm completion and explain any information that must be retained. Depending on the applicable law, you may also have rights to access, correct, restrict or object to processing, withdraw consent, portability and complain to a supervisory authority.
International providers and updates
The service uses providers that may process information internationally. Provider arrangements, appropriate transfer safeguards and final retention periods will be documented for production. Material changes will be disclosed here; optional analytics will not be enabled silently.