Introduction
GenAI Unplugged ("we," "us," or "our") operates SubflowAI, a Chrome browser extension for scheduling and managing Substack Notes. This Privacy Policy explains how we collect, use, and protect your information.
Information We Collect
Data We Collect
| Data Type | Where Stored | Purpose |
|---|---|---|
| License Key | Chrome sync storage | Validate your subscription |
| Trial ID | Chrome local storage | Track trial period |
| Scheduled Notes | Your device only | Enable scheduling features |
| Draft Notes | Your device only | Save your work |
| Settings/Preferences | Your device only | Remember your choices |
| AI Usage Count | Our server (encrypted) | Enforce monthly limits |
| Uploaded Images | Cloudflare R2 (temporary) | Include images in your Substack Notes |
| License Validation Logs | Our server (30 days) | Prevent abuse |
Data We Do NOT Collect
- Substack passwords or login credentials
- Email addresses (unless you contact support)
- Browsing history
- Content of your Substack articles
- Personal identification information
- Data for sale to third parties
How We Use Your Information
We use collected data solely for:
- License Validation - Verify your subscription status
- Usage Tracking - Count AI generations to enforce limits
- Service Improvement - Anonymous analytics to fix bugs and improve features
- Abuse Prevention - Detect and prevent fraudulent license use
Data Storage and Security
Local Storage (Your Device)
- Notes, drafts, and settings are stored locally in your Chrome browser
- We cannot access this data
- Data persists until you delete it or uninstall the extension
Server Storage (Our Infrastructure)
- License validation and usage counts are stored on Cloudflare Workers
- Data is encrypted in transit (HTTPS) and at rest
- Servers are located globally via Cloudflare's network
- Validation logs are automatically deleted after 30 days
Image Storage (Cloudflare R2)
- When you upload images to include in notes, they are temporarily stored on Cloudflare R2
- Images are automatically deleted after your note is successfully posted to Substack
- Images are accessible only via unique, non-guessable URLs
- We do not access, analyze, or use your images for any purpose other than enabling the posting feature
Security Measures
- All server communications use HTTPS encryption
- License keys are validated server-side, never exposed to third parties
- No passwords or sensitive credentials are ever stored
Third-Party Services
SubflowAI integrates with the following third-party services, each with their own privacy policies:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Cloudflare Workers | API hosting, license validation | cloudflare.com/privacypolicy |
| Cloudflare R2 | Temporary image storage | cloudflare.com/privacypolicy |
| Google Gemini API | AI content generation | policies.google.com/privacy |
| Lemon Squeezy | Payment processing | lemonsqueezy.com/privacy |
| Substack | Publishing platform (your account) | substack.com/privacy |
Note: When you use AI features, your input text is sent to Google's Gemini API for processing. Google may process this data according to their privacy policy.
Your Rights and Choices
All Users
You have the right to:
- Access - View what data we have about you
- Delete - Remove all local data by uninstalling SubflowAI
- Export - Download your notes via the extension's export feature
- Cancel - Cancel your subscription anytime via Lemon Squeezy
- Opt-out - Disable analytics in extension settings (if available)
To Exercise Your Rights
Email us at support@genaiunplugged.com with your request. Include your license key or order number for faster processing.
International Users
European Economic Area (EEA) - GDPR
If you are in the EEA, you have additional rights under the General Data Protection Regulation (GDPR):
Legal Basis for Processing:
- Contract Performance - License validation is necessary to provide the service you purchased
- Legitimate Interest - Usage analytics help us improve the service and prevent abuse
Your GDPR Rights:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to data portability
- Right to object to processing
- Right to lodge a complaint with a supervisory authority
Data Controller:
GenAI Unplugged
Email: support@genaiunplugged.com
California Residents - CCPA
If you are a California resident, under the California Consumer Privacy Act (CCPA):
- You have the right to know what personal information we collect
- You have the right to request deletion of your data
- You have the right to opt-out of the sale of personal information
- We do not sell personal information
To exercise your CCPA rights, email support@genaiunplugged.com.
International Data Transfers
Your data may be processed on servers located outside your country of residence. By using SubflowAI, you consent to the transfer of your information to:
- Cloudflare's global network (for API and license validation)
- Google's servers (for AI processing)
- Lemon Squeezy's servers (for payment processing)
We ensure appropriate safeguards are in place for international transfers.
Data Retention
| Data Type | Retention Period |
|---|---|
| Local notes/drafts | Until you delete them |
| Uploaded images | Deleted after posting to Substack (typically within minutes) |
| License validation cache | 30 days |
| Usage logs | 30 days |
| Payment records | Handled by Lemon Squeezy per their policy |
Children's Privacy
SubflowAI is not intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children.
If you believe a child has provided us with personal information, please contact us immediately at support@genaiunplugged.com and we will delete it.
Cookies and Tracking
SubflowAI (the Chrome extension) does not use cookies.
Our website (genaiunplugged.com) uses Google Analytics 4 cookies to understand site usage. These cookies are only set after visitors provide consent through our cookie consent banner. See our website's Privacy Policy for details.
Data Breach Notification
In the unlikely event of a data breach affecting your personal information, we will:
- Investigate and contain the breach
- Notify affected users within 72 hours (where required by law)
- Report to relevant authorities as required
- Take steps to prevent future breaches
Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- The "Last Updated" date at the top will be revised
- For material changes, we will notify you via email or in-app notification
- Continued use of SubflowAI after changes constitutes acceptance
We encourage you to review this policy periodically.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data:
GenAI Unplugged
Email: support@genaiunplugged.com
Website: genaiunplugged.substack.com
We aim to respond to all inquiries within 48 hours.
Summary
| Question | Answer |
|---|---|
| Do you sell my data? | No, never. |
| Can you see my notes? | No, they're stored locally on your device. |
| What do you store on your servers? | License validation, AI usage counts, and uploaded images (temporarily). |
| What happens to my uploaded images? | Deleted automatically after posting to Substack. |
| How long do you keep data? | Logs are deleted after 30 days. |
| Can I delete my data? | Yes, uninstall the extension or contact us. |
| Is my data encrypted? | Yes, in transit and at rest. |