Skip to content
Flow Pass annual — every template in the library for one price
Maven Flow
Join now

Privacy policy

What we collect, why we collect it, and who else can see it.

Last updated 27 August 2026

There is no analytics script, advertising pixel, or session recorder on this site. The storefront is static files; the only server we run is the one that holds your library.

What we collect

  • Your email address. It identifies your account and is how licences and sign-in codes reach you. It is the only personal detail we require.
  • Purchase records. What you bought, when, the amount, and the provider order reference — needed for your receipts, your licences, and our tax records.
  • Library activity. Which licences you hold and when a delivery link was first revealed. The reveal timestamp is what the refund policy turns on, so it has to exist.
  • Sign-in security data. A keyed hash of each session token and sign-in code, plus the IP address and browser string of a sign-in, kept to detect abuse. We never store the token or the code itself.

What we do not collect

  • Card numbers or any payment details — those never touch our servers.
  • Browsing behaviour, page-view analytics, or cross-site tracking of any kind.
  • Your name, address, or phone number, unless you put them in an email to us.

Who else sees your data

  • Lemon Squeezy is our merchant of record. They process the payment, hold the payment details, and issue the invoice. They are a separate controller for that data, under their own policy.
  • Our email relay transmits sign-in codes and licence messages.

That is the full list. We do not sell data, and we do not share it for advertising.

Cookies

One cookie: an http-only session cookie set when you sign in, so the library knows it is you. It expires after 30 days, is not readable by JavaScript, and is not used to track you anywhere else. There are no other cookies, so there is no cookie banner to dismiss.

How long we keep things

  • Account and licence records: for as long as the account exists — a licence is permanent, so its record has to be too.
  • Order records: retained as long as tax and accounting law requires.
  • Sign-in codes: minutes. They are consumed or expired and then only the hash of a spent code remains.
  • Sessions: 30 days, or until you sign out.

Your rights

You can ask for a copy of everything we hold about you, ask us to correct it, or ask us to delete your account. Write to [email protected] from the address on the account and we will act within 30 days. Deleting an account removes your personal data; order records that tax law requires us to keep are retained in a minimised form.

Security

Private delivery links are encrypted at rest. Sign-in codes and session tokens are stored only as keyed hashes. All traffic is over HTTPS. Access to the production database is limited to the least-privileged role the application needs.

Changes

If this policy changes in a way that affects you, we will email account holders rather than quietly editing the page.

Privacy policy — Maven Flow