Legal

Privacy Policy

Last updated July 26, 2026

Mockflow is a studio for designing and simulating system behavior. This policy explains what information we collect when you use Mockflow, how we use it, and the choices you have. We collect the minimum needed to run the product, and we do not sell your data.

Information we collect

When you sign in with GitHub or Google, we receive your name, email address, and avatar from that provider so we can create and secure your account. We never see or store your provider password.

As you use the product, we store the content you create in your workspace, including:

  • Diagrams, components, connections, and deployment views you author.
  • Scenarios, runs, checkpoints, and the notes or tags attached to them.
  • Contract summaries, implementation links, and other supporting context you add.
  • Workspace settings, including sharing and agent-access preferences.

If you send product feedback, we store what you write and the page path it was sent from. When you are signed in, we also store your account name and email with that feedback so we can understand its context. To prevent abuse, we store a one-way identifier derived from your account or network address. It is kept separately from submitted feedback and used only to enforce submission rate limits; we do not store the raw network address with your feedback.

We also keep routine operational records — such as sign-in events and API request logs — to keep the service secure and reliable.

Agent access and MCP keys

If you create an Agent Access Key, Mockflow records the key’s scope, the resources you selected for it, and when it is used, so you can audit and revoke access at any time. Approved MCP clients can only read — or, when you explicitly allow it, draft — the material you scoped to that key. Keys are stored hashed and can be rotated or revoked from your settings.

How we use information

  • To provide the product: storing, rendering, and running your diagrams and scenarios.
  • To secure accounts: authenticating sign-ins and detecting misuse.
  • To operate the service: debugging, capacity planning, and support.
  • To improve the product: reviewing the feedback you choose to send.
  • To communicate essential service information, such as security notices.

We do not sell your personal information or your workspace content, and we do not use your workspace content to train machine-learning models.

Cookies and sessions

Mockflow uses essential cookies to keep you signed in and to protect against cross-site request forgery. We do not use third-party advertising or tracking cookies.

When information is shared

Your workspace content stays private to you unless you share it. If you publish or share a diagram, scenario, or run, the people or clients you share it with can view that material. We use a small number of infrastructure providers (hosting, database, and email) to run the service; they process data only on our behalf.

We may disclose information when required by law, or to protect the rights, safety, or security of Mockflow and its users.

Retention and deletion

We keep your account information and workspace content while your account is active. If you delete content, it is removed from your workspace and purged from routine backups on a rolling basis. You can request deletion of your account and its data at any time, and we will complete the deletion within 30 days.

Feedback associated with your account is deleted with your account. Anonymous feedback is kept only while it remains useful for improving and supporting the product.

Your choices and rights

  • Access and export the content you have created.
  • Correct account details by updating them with your sign-in provider.
  • Revoke any Agent Access Key from your settings at any time.
  • Request deletion of your account and associated data.

Changes to this policy

If we make material changes to this policy, we will update the date at the top of this page and, where appropriate, notify you in the product or by email before the changes take effect.

Contact

Questions about this policy or your data can be sent to hello@dethink.co.uk. See also our Terms & Conditions.