Privacy by Architecture

How Your Data Flows

Core workflow analysis follows a simple boundary: parsing and analysis run in your browser; optional account, AI, background-migration, and target-push features use separate server or provider requests.This page explains the main data paths. For details, see the Data Processing Agreement.

Data flow steps

Local workflow input

Client-side

Pasted or uploaded workflows can be analysed locally. Connected-platform retrieval and other optional actions use separate requests.

Core analysis and conversion

Client-side

Core parsing, data-flow analysis, security checks, diagrams, and supported workflow conversions run in your browser.

Local reports and exports

Client-side

Markdown, DOCX, PDF, PNG, standalone HTML, and JSON outputs are generated in the browser.

Browser storage

Client-side

Portfolio entries, document-version history, and manually imported blueprints can be saved in browser local storage.

Account and connected credentials

Server-side

Supabase stores account, plan, and usage records. Connected platform credentials saved for account features are encrypted at rest and decrypted server-side when used.

AI provider requests

Server-side

AI features send the requested prompt or workflow context from a server route to the custom endpoint configured in account settings. Provider terms apply.

Background migration

Server-side

After the consent disclosure and a separate action, a signed-in Pro user can send a workflow for server-side conversion. Job payloads are AES-256-GCM encrypted in Redis, removed at terminal updates, and have a 24-hour TTL backstop.

Target push

Server-side

A signed-in Pro user can push to a connected Make.com or n8n account after the consent disclosure. The server uses the encrypted-vault credential to create an inactive workflow for review.

Processing location breakdown

Core Work in Your Browser

Core local path

  • Core parsing and validation of pasted or uploaded workflows
  • Core PII analysis, data-flow graphs, and security findings
  • Diagrams, supported local workflow conversions, and report generation
  • PDF, DOCX, Markdown, PNG, standalone HTML, and JSON exports

Optional Server and Provider Paths

Optional server/provider paths

  • Supabase account, plan, and usage records
  • Connected platform credentials encrypted at rest
  • AI prompts or workflow context sent to the configured provider
  • Opt-in background migration jobs stored encrypted in Redis
  • Consented target-push requests to Make.com or n8n

Browser-Local Storage

Stored in this browser

  • Portfolio metadata and locally imported workflows
  • Document-version history and its report data
  • Browser encryption preferences and local feature state

Credential Handling

Saved Integration Credentials

  • Connected Make.com, n8n, and Zapier credentials can be stored in the server-side integration vault
  • Credential tokens are encrypted at rest with AES-256-GCM
  • The browser receives connection status, not decrypted credential values
  • The server decrypts a credential when a supported provider request needs it

Optional AI and Background Features

  • AI requests send prompts or workflow context to the configured provider
  • Background migration stores its payload encrypted in Redis
  • Background payloads have terminal cleanup and a 24-hour TTL backstop
  • Target push uses a connected credential for Make.com or n8n and explicitly requests an inactive workflow

Safeguards and documentation

Core processing

Core workflow analysis and supported conversions run in the browser. Optional server and AI-provider features are described above.

Selected encrypted storage

Connected platform credentials and background migration payloads are encrypted at rest. This is not a certification or a claim that every stored record is encrypted.

Data Processing Agreement

The public Data Processing Agreement describes the terms for data processed by Xray Flow.

View DPA →

Verify It Yourself

Network Tab

Open DevTools → Network. Filter by the Fetch/XHR type. Trigger an analysis. You'll see only the initial blueprint fetch (if using API key) — no analysis payloads.

WASM Source

The Rust analysis engine is open source. Compile it yourself and verify the WASM binary matches what loads in your browser.

Export Inspection

Export a report as Markdown. The file contains exactly what was generated client-side — no hidden server-side additions.

TLS 1.3 EncryptionAll data in transit encrypted with TLS 1.3
Stripe PCI-DSS Level 1Payments processed by Stripe (PCI-DSS Level 1 certified)
Hosted on Vercel (SOC 2, ISO 27001)Vercel infrastructure: SOC 2 Type II, ISO 27001 certified
GDPR & CCPA CompliantFull GDPR Art. 28 DPA available, CCPA rights supported

Product

  • Pricing
  • Dashboard Overview
  • Workflows
  • Create & Import
  • Migration Wizard

Platforms

  • Platform Comparison
  • Make.com Integration
  • Zapier (OAuth)
  • n8n Workflows
  • Data Flow & PII

Knowledge & Tools

  • Resources
  • AI Prompt Library
  • Guides
  • Module Reference
  • ROI Calculator
  • Workflow Editor
  • Glossary

Company

  • About
  • Contact

© 2026 Xray Flow. Not affiliated with Make.com.

All rights reserved. XrayFlow is a product of PirateApeStudios (ABN 47 340 546 246)

SecurityPrivacy PolicyTerms of ServiceDPADMCA