Last updated: 10 August 2026
1. Who is responsible for your data
The owner of the EWM Flow project (howtoewm.com) is the data controller for your personal data. EWM Flow is a personal project: it is not currently incorporated as a company or registered as a business. If that changes, this page will be updated.
Contact: howtoewm@outlook.com
2. What data we collect
Account data
Your email address and your password. The password is never stored in plain text or in any form we can read: it is stored as a hash generated by our authentication provider. Nobody — including us — can recover it, only reset it.
Chat usage data
We store the full content of your conversations: the questions you write and the answers you receive, with their date and time. We also record how many questions you have asked, the date of your last activity, your chosen language, and for each answer which AI provider generated it and how long it took.
Important about what you type into the chat. Your questions are sent to external AI providers in order to generate the answer (see section 5). Do not include confidential data in your questions: credentials, other people’s personal data, or identifiable information about systems or clients you work with. Keep questions generic.
Technical data
Your IP address is used only in memory and temporarily, to apply usage limits and prevent abuse. It is not stored in our database and is never linked to your account or your conversations. The providers hosting the site and the server may keep their own access logs under their own policies.
3. What we use it for
- Providing the chat service and keeping you signed in.
- Applying fair usage limits and preventing abuse.
- Remembering your conversation context to give better answers.
- Improving the technical quality of the service.
We do not use your data for advertising, and we do not sell it or hand it to third parties for their own purposes.
4. Legal basis
- Performance of the service you request when you register.
- Legitimate interest in preventing abuse and keeping the service secure.
- Consent for analytics cookies (see section 9).
5. Who we share your data with
We use the following providers to operate the service. They process data on our behalf, under their own security safeguards:
| Provider | Purpose | What it receives |
|---|---|---|
| Supabase | Accounts and database | Email, hashed password, conversations |
| Anthropic (USA) | Generating answers | Your question and conversation context |
| Microsoft Azure OpenAI | Generating answers | Your question and conversation context |
| Voyage AI (USA) | Semantic search over the technical content | Your question |
| Resend | Sending confirmation and recovery emails | Your email address |
| Railway (USA) | Backend server hosting | Service traffic |
| Automattic / WordPress.com | Website hosting | Site browsing |
| Google Analytics | Site usage analytics | Browsing data via cookies |
Some of these providers are located outside the European Economic Area, mainly in the United States. Specifically for Azure OpenAI: although the resource is created in the Sweden region, the deployment type we use is Global Standard, so processing may take place in data centres outside the EEA. For these international transfers, providers rely on the legal mechanisms available for them, such as standard contractual clauses.
6. How long we keep your data
- Your account and profile, for as long as the account is active.
- Conversation history is deleted automatically after 90 days without activity. This is a scheduled deletion that runs daily, not a manual review.
- If you delete your account, your profile and all your conversations are removed permanently and immediately.
7. Your rights
You have the right to access your data, correct it, delete it, restrict or object to its processing, and request its portability. You can exercise those rights as follows:
- Delete your account and data: directly from the chat, via the account icon → «Delete my account». It is immediate and permanent.
- Any other request: write to howtoewm@outlook.com.
If you believe your rights have not been respected, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es).
8. Security
We apply reasonable technical measures: encryption in transit (HTTPS) on all communications, passwords stored as hashes, database access restricted to the server through credentials that never reach the browser, and database-level security rules that prevent one user from reading another user’s data. No system is completely secure, and we keep improving it.
9. Cookies
The site uses Google Analytics to understand in aggregate how the site is used, which involves analytics cookies. The chat also stores information in your browser’s local storage (not cookies) to keep you signed in and to remember your conversation thread and language; that information is essential for the chat to work.
10. Minors
The service is not aimed at people under 16. If we find an account belonging to someone under that age, we will delete it.
11. Changes to this policy
We may update this policy. Relevant changes will be reflected here along with the update date.