1
Who we are
NamiFlow is a single-member LLC in the United States. The product, Nami, is an AI investigation navigator for production support. This policy covers the public website and the NamiFlow application at namiflow.ai.
Questions about this policy or your data: use the contact form. We respond personally — there is no separate privacy desk today.
2
Information we collect
Depending on how you use NamiFlow, we may process:
- Account data — email address, password (stored hashed), name or display name you provide, organization membership, and role.
- Billing identity — handled by Stripe. Card numbers never touch NamiFlow servers.
- Connector credentials and tokens — OAuth tokens, API keys, or role references you authorize so Nami can read (and, for Jira only, write) the systems you connect. Credentials are encrypted at the application layer before storage.
- Content from connected systems — documentation, code, and log excerpts retrieved during investigations. Documentation and code are also indexed into our database as text chunks so Nami can search them. Logs are queried live; we retain short evidence excerpts and signatures, not a bulk archive of your log platform.
- Investigation records — prompts, reasoning steps, answers your team provides, evidence excerpts, and conclusions. Retention of investigations is part of the product, not incidental.
- Operational logs — application and infrastructure logs needed to run and secure the service (for example AWS CloudTrail and App Runner logs).
We do not load third-party analytics, session-recording, or advertising SDKs that would capture customer content on the product.
3
Google user data
When an organization connects Google Drive in NamiFlow, we access Google user data only as described here. Connecting Drive is optional; we receive Drive content only after your organization grants access through one of the paths below.
- Access — two grant paths:
- Folders (primary) — someone in your organization shares specific Drive folder(s) with NamiFlow's Google Drive reader service account (address shown in Connections when you connect Drive; pattern
namiflow-drive-reader@….iam.gserviceaccount.com) as Viewer only. NamiFlow verifies it can read each folder before registering it, then searches only inside those registered shared folders (and their subfolders). We do not receive the rest of your Drive. The reader cannot write or change Drive content. NamiFlow does not auto-grant sharing on your behalf — a person performs the share in Google Drive. - Individual files (secondary) — a user connects Google with OAuth using the
drive.filescope and selects specific files through Google's file picker. We do not requestdrive.readonlyor full Drive access on the end-user OAuth client. The same OAuth client may also open a picker to choose folder IDs for the shared-folder flow; that selection alone is not a contents grant — folder contents become readable only after the Viewer share to the reader service account above.
- Folders (primary) — someone in your organization shares specific Drive folder(s) with NamiFlow's Google Drive reader service account (address shown in Connections when you connect Drive; pattern
- Use — to search and read granted Drive documents during investigations, and to index text from those documents into our search index so Nami can retrieve them later. The same use rules apply whether content was obtained via a shared-folder service-account grant or via
drive.file. We do not use Google user data for advertising, selling data, or training generalized AI/ML models. - Storage — OAuth tokens (when used) and service-account credentials we hold are encrypted and stored in our United States AWS environment. Document text may be stored as indexed chunks and as investigation evidence, the same way we handle other knowledge sources.
- Sharing — Google user data is not sold. It may be processed by our subprocessors listed below (notably AWS, including Bedrock for model inference) solely to provide the investigation service. We do not transfer Google user data to other apps for independent use.
- Revocation — for OAuth / individual-file access: disconnect Google in NamiFlow and revoke access under your Google Account → Security → Third-party access. For shared folders: also remove NamiFlow's reader service account from each folder's sharing settings in Google Drive (and disconnect Drive in NamiFlow). Either path stops new access; indexed chunks and past investigation evidence may remain until you ask us to delete them (see Retention).
NamiFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4
How we use information
- Provide, secure, and improve the NamiFlow service
- Run investigations: retrieve from connected sources, reason with AI models, and persist investigation artifacts
- Authenticate users, enforce organization access, and bill subscriptions
- Communicate about the service (for example security notices or replies to contact requests)
5
Hosting, storage, and AI processing
Application compute and primary data stores run on Amazon Web Services in the United States (storage and application compute in us-east-1). Model inference uses AWS Bedrock with a US cross-region inference profile, so inference stays inside the United States and AWS but is not pinned to a single region.
We call Anthropic Claude through AWS Bedrock using our own AWS credentials — not Anthropic's public API. Under AWS Bedrock's terms, prompts and outputs are not used to train foundation models and are not retained by the model provider for that purpose. We encourage you to read Bedrock's terms directly rather than rely only on this summary.
Data in transit uses TLS. Databases and object storage use encryption at rest. Connector credentials are encrypted before storage; the encryption key is held in AWS Secrets Manager.
6
Sharing and subprocessors
We share information only as needed to operate the product:
- Amazon Web Services — hosting, storage, email delivery (SES), and AI inference (Bedrock). Receives customer content as part of providing the service.
- Stripe — subscription billing. Receives billing identity, not investigation content or Google user data.
Systems you connect (for example Confluence, GitHub, CloudWatch, Datadog, Jira, and Google Drive) are your vendors; we access them on your behalf with credentials you supply. We do not sell personal information.
We may disclose information if required by law or to protect the security of the service or our users, and we will notify affected customers without delay when we are legally allowed to do so.
7
Retention and deletion
Investigation records are retained by design so your team can reuse institutional knowledge. There is no automatic retention schedule with expiry today, and disconnecting a connector does not by itself purge previously indexed documentation or code chunks.
Organization and account deletion requests are handled manually by the founder. Contact us via the contact form if you need data deleted. A formal Data Processing Agreement with contractual retention terms is not available yet (in drafting).
8
Your choices
- Connect or disconnect integrations at any time in product settings (and revoke OAuth grants at the provider).
- Update account details and leave or change organizations according to the access controls your organization admin configures.
- Request access or deletion help through Contact. We do not currently offer a self-serve data-export or data-subject portal.
9
What this policy does not claim
Honesty matters more than looking finished. Today we do not hold a SOC 2 report, we do not have a published formal GDPR/CCPA privacy program, and we do not offer a signed DPA yet. Hosting and processing are US-oriented as described above. If you have EU residency, data-subject-request automation, or single-region inference requirements, raise them before evaluation — we would rather decline than misrepresent.
A more detailed security and data-handling description for enterprise reviewers is available on request (our security questionnaire packet). If anything here conflicts with something a NamiFlow representative said verbally, tell us so we can correct the record.
10
Children
NamiFlow is a business product. It is not directed at children under 16, and we do not knowingly collect their personal information.
11
Changes
We may update this policy as the product changes. The "Last updated" date at the top will change when we do. Material changes affecting how we handle Google user data will be reflected here before we expand Google scopes or use in the product.