Data and security

How WorkflowMD handles your workflow information.

This page describes what actually happens to the information you submit — what is stored, what is sent to AI processing, what deletion removes, and what we have not yet confirmed. It is written to be specific rather than reassuring.

Last reviewed 17 August 2026

Ownership

Your data remains yours.

You, or the client whose workflow you are describing, own the workflow information you submit: the descriptions, interview answers, supporting documents and the business knowledge inside them. WorkflowMD does not acquire ownership of your processes or documents.

We take only the rights needed to run the service: hosting your content, sending it for analysis, returning the assessment, and storing it if you choose to save it. WorkflowMD owns the platform — the software, scoring engine and report methodology — not your material.

Storage

What WorkflowMD stores.

  • Your account: name, email, company, and your workspace.
  • Saved assessments: the workflow description, your interview answers and the generated report.
  • Improvement actions and progress notes derived from a saved report.
  • A record of each automated analysis — the input it received and the output it produced — kept so a report can be explained and audited later.
  • Subscription status, plan and renewal dates. Card details never reach us.

If you run an assessment without saving it, the report stays in your browser. It is not written to your workspace until you save or claim it.

AI processing

How AI is used.

WorkflowMD analyses your workflow using third-party AI processing. Your content is sent over an encrypted connection to the Lovable AI Gateway, which routes it to Google Gemini models. The structured result comes back to WorkflowMD, which turns it into the report you read.

We do not claim that these providers never retain or train on content routed to them. We have not independently confirmed their retention or training posture for our traffic, and we would rather say so than imply a guarantee we cannot evidence. If that matters to your engagement, take it into account before submitting sensitive client material.

Want to understand how AI reasoning, deterministic scoring and validation interact during an assessment? Read how WorkflowMD reaches a conclusion.

Supporting documents

What happens to a document you upload.

When you attach a supporting document or paste text, it is read from the request and sent to the AI processing service, which returns a structured summary — the process steps, people, systems and issues it found — for you to review.

The source file is not persisted in WorkflowMD application storage after extraction; we operate no file storage for uploaded documents. What we cannot claim is that the file is never stored anywhere: it is transmitted to the AI processing service, and provider-side handling is outside our verification.

Security

Security controls we can evidence.

Encryption in transit

Traffic between your browser, WorkflowMD and its providers uses HTTPS/TLS.

Row-level database access controls

Every table holding your content is restricted to your account at the database itself, not just in the interface. Another account cannot read your reports.

Authenticated workspace access

Saved reports, improvement progress and settings require a valid signed-in session.

Restricted administrative access

Privileged credentials are server-side only and are never sent to the browser. Elevated roles are held separately and checked server-side.

We do not hold SOC 2, ISO 27001 or HIPAA certification, and we do not describe WorkflowMD as certified, penetration-tested or zero-retention. Those claims would need independent assessment we have not done.

Subprocessors

Who else processes your data.

ProviderRoleData involved
LovableApplication hosting and platformTraffic to and from the application
Lovable AI GatewayRoutes AI analysis requestsWorkflow content sent for analysis
Google (Gemini models)Produces the AI analysisWorkflow content sent for analysis
Lovable Cloud (Supabase)Database and sign-inAccounts, saved reports, analysis records
PaddlePayments, as Merchant of RecordBilling details and subscription records
Lovable managed emailTransactional emailEmail address and message content

We do not use third-party error-monitoring, session-replay or advertising tracking services. Processing regions for the providers above have not been confirmed and are not stated here.

Deletion

What deletion actually removes.

  • Deleting a report removes the report and the improvement actions, metrics and snapshots attached to it.
  • “Delete my data” in Settings removes every saved report in your workspace. Your account, sign-in and subscription stay as they are.
  • The record of each automated analysis is kept in an append-only audit table so past reports remain explainable. It is not linked to the report record and is not removed when you delete a report.
  • Account deletion is currently handled as a request through the contact page rather than a self-serve button.

We do not claim immediate permanent deletion everywhere. Backups exist, and we have not yet documented how long deleted data can persist in them — so we say that plainly instead of promising otherwise.

Consultants

Submitting a client's workflow.

If you are a consultant or adviser submitting a client's workflow, only do so where you have the authority or permission to share it. Describing roles rather than named individuals, and leaving out personal data the analysis does not need, is usually enough for a good assessment.

We will not publish client-specific information or use it as a case study, testimonial or public example without permission. Our published sample assessments are constructed scenarios, not customer material.

The Consultant Data Addendum sets this out in full.

Transparency

What we are still verifying.

  • Retention and training posture of the AI gateway and model provider.
  • Processing regions for our infrastructure providers.
  • Backup retention, and how long deleted data can persist in backups.
  • Retention of hosting and email delivery logs.
  • Self-serve account deletion, which is not yet built.

This page will be updated as each item is confirmed. In the meantime, see the Privacy Notice and Terms, or ask us a question.