Effective Date: July 01, 2026
Last Updated: August 13, 2026
Who we are
Flow Inspector is a software product of LeadClick LLC, a digital marketing company formed in New Jersey. When this policy says "Flow Inspector," "we," "us," or "our," it means LeadClick LLC operating the Flow Inspector service at flowinspector.app.
If you have questions about this policy, contact us at privacy@flowinspector.app.
The short version
We built Flow Inspector to help GHL specialists diagnose automation issues. We need some of your information to make the product work. We don't sell it, share it with advertisers, or use it for anything other than running the service. That's the whole story — the rest of this document is the legal detail behind that promise.
What we collect and why
Account Information
When you create an account, Clerk (our authentication provider) collects your email address and name. We use this to identify your account, communicate with you about the service, and process your subscription. We do not store passwords — Clerk handles authentication entirely.
GHL API credentials
To connect Flow Inspector to your GoHighLevel account, you provide a Private Integration access token and location ID. These credentials are encrypted using AES-256 encryption and stored securely on Flow Inspector's servers. They are never stored in your browser after the initial save, and are never shared with any third party. The encryption key is stored separately from the encrypted data.
GHL Flow Capture Chrome Extension
Flow Inspector offers an optional Chrome browser extension called GHL Flow Capture. The extension is a companion tool that captures execution log data from GoHighLevel's web interface so you can import it into Flow Inspector for detailed step-level analysis.
What the extension captures
When you navigate to a GHL automation execution log page, the extension captures the network response containing the execution log JSON payload. This data includes automation step names, step types, timestamps, status codes, and execution metadata for the contact and workflow you are viewing. This is the same data visible to you on the GHL execution log page, just in a computer-readable format.
How captured data is handled
Captured payloads are stored temporarily in your browser's local extension storage so they can be accessed from the extension popup. When you click Copy JSON in the extension panel, the payload is written to your clipboard. You then manually paste it into Flow Inspector. The extension does not transmit captured data to Flow Inspector's servers or any third party. All data handled by the extension stays local to your browser.
Permissions
The extension requires the following browser permissions to function:
The extension does not access your browsing history, read data from non-GHL pages, or collect any information about you personally.
Data retention
Captured payloads are held in extension storage only until you copy them or close the extension popup. No execution log data is retained by the extension beyond your active session with it.
Authorization and user consent
The execution log data captured by the extension is only accessible to authenticated GoHighLevel users who have explicit permission to view it. The extension operates exclusively on GoHighLevel's web interface, where the user must already be logged in with valid credentials to access any execution log page. The JSON payload the extension captures is the same data the user is already viewing in their browser, the extension simply makes it easier to copy. No data is accessed that the user could not already see and export manually. The extension does not bypass any authentication, access any private API, or retrieve any data the user is not already authorized to view.
GHL API proxy
All API calls to GoHighLevel are routed through Flow Inspector's backend infrastructure on your behalf. When you perform actions that require GHL data (such as loading your workflow map or searching for a contact), your browser sends the request to our servers, which decrypt your stored API credentials, make the call to GoHighLevel, and return the result to your browser. Your GHL API token is never exposed in browser network traffic after the initial save.
GHL contact and automation data
The execution log data, contact records, and automation timeline data you import into Flow Inspector is processed within your browser session and may be saved to your Flow Inspector account as sessions. Saved sessions are stored on our servers so you can access them from any device. This data is used solely to provide the Flow Inspector service and is never shared with third parties. You can delete your saved sessions at any time from within the app, and all server-side session data is permanently deleted when you delete your account.
Workflow maps and account data
Your GHL workflow map (the list of automations in your connected sub-account) and connected account information are stored on our servers to enable cross-device access and faster load times. This data is refreshed when you reload your workflows and is permanently deleted when you delete your account or remove a connected account.
Data storage architecture
Flow Inspector uses a cache-first architecture. Our PostgreSQL database is the source of truth for all your account data including connected GHL accounts, saved sessions, workflow maps, and AI configuration. Your browser may store a local cache of this data in localStorage to improve performance and reduce load times. The database always takes precedence over the local cache. You can request deletion of all server-side data associated with your account at any time by emailing privacy@flowinspector.app or by using the account deletion option within the app.
AI Analysis data
If you use the AI Analysis feature, your AI provider API key is encrypted using AES-256 encryption and stored on our servers so you do not need to re-enter it on each visit. The timeline data you submit for analysis is sent directly from your browser to the AI provider of your choice (OpenRouter or OpenAI) using your stored API key. This data is governed by your agreement with that AI provider. Flow Inspector does not log or monitor the content of your AI Analysis queries or responses in real time. However, if you save a session and choose to include AI conversation history, that conversation is stored as part of your saved session data on our servers. You can exclude AI history when saving a session, and all saved session data including any AI conversation history is permanently deleted when you delete your account or delete the session.
Cookies and tracking
Flow Inspector and its landing page use cookies and similar technologies. This section explains what we use and why.
Strictly necessary cookies: These cookies are required for the service to function and cannot be disabled. They include the Clerk session cookie that keeps you logged in to go.flowinspector.app, and any cookies set by our infrastructure for security and load balancing purposes. No consent is required for these cookies.
Analytics cookies: We use Google Analytics (via Google Tag Manager) on our landing page at flowinspector.app to understand how visitors find and navigate the site. Google Analytics sets cookies including _ga and _gid which collect anonymous usage statistics such as page views, session duration, and traffic sources. These cookies are only set after you provide consent via our cookie banner. Analytics data is processed by Google LLC in accordance with Google's privacy policy at policies.google.com/privacy. You can opt out of Google Analytics tracking at any time by withdrawing your consent via the cookie settings link in our footer, or by installing the Google Analytics opt-out browser add-on at tools.google.com/dlpage/gaoptout.
localStorage: The Flow Inspector app (go.flowinspector.app) uses browser localStorage to cache account data, workflow maps, and session information for performance purposes. This is not a cookie and does not transmit data to third parties. It is cleared when you delete your account or use the "Clear all saved data" option within the app.
sessionStorage: Our landing page uses sessionStorage to temporarily carry referral codes and UTM tracking parameters through the signup flow. sessionStorage is session-only, cleared when you close your browser tab, and never transmitted to any third party.
Login activity
We log the date and time of each login to your Flow Inspector account. This information is used to identify inactive accounts for re-engagement and to monitor for unauthorized access. Login timestamps are permanently deleted when you delete your account.
Usage data
We do not currently use analytics tracking or collect usage data beyond what is necessary to operate the service. If this changes, we will update this policy and notify subscribers.
How we use your information
We use the information we collect solely to:
We do not use your information for advertising. We do not build profiles on you for marketing purposes. We do not sell your data to anyone, ever.
SMS Communications
If you provide a mobile phone number during account setup or onboarding, you may opt in to receive transactional SMS notifications from Flow Inspector. These messages are strictly account-related and may include:
Message frequency varies based on account activity. Standard message and data rates may apply. You may opt out at any time by replying STOP to any message. For help, reply HELP. Opting out of SMS does not affect your account or access to Flow Inspector.
We do not send marketing or promotional SMS messages. Your mobile number is never sold or shared with third parties.
How we share your information
We share your information only with the third-party services necessary to operate Flow Inspector. Each of these providers has their own privacy policy and security practices.
Clerk — handles user authentication and account management. Clerk stores your email address, name, and session data. Clerk's privacy policy is available at clerk.com/legal/privacy.
Stripe — handles subscription billing and payment processing. Stripe stores your payment method and billing history. Stripe's privacy policy is available at stripe.com/privacy.
GoHighLevel — when you connect a GHL sub-account, API calls are made to GoHighLevel's servers on your behalf using your stored credentials. GoHighLevel's privacy policy is available at gohighlevel.com/privacy-policy.
Your chosen AI provider — if you use AI Analysis, timeline data is sent directly to the provider whose API key you supply (OpenRouter or OpenAI). Flow Inspector is not a party to that data exchange.
We do not share your information with any other third parties. We do not use advertising networks, data brokers, or marketing platforms.
Your rights
Regardless of where you are located, you have the right to:
To exercise any of these rights, email privacy@flowinspector.app. We will respond within 30 days.
For users in the European Union and European Economic Area: We process your personal data on the following lawful bases under Article 6 of the GDPR:
You have additional rights under the GDPR including the right to restrict processing, the right to object to processing based on legitimate interests, and the right to lodge a complaint with your local supervisory authority. To find your local supervisory authority, visit edpb.europa.eu.
Our data processors Clerk and Stripe each operate under standard Data Processing Agreements and are certified under the EU-U.S. Data Privacy Framework, which provides a valid legal mechanism for transferring personal data from the EU to the United States.
For users in California: Under the California Consumer Privacy Act (CCPA), you have the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale. We do not sell personal information.
Security
We take reasonable technical and organizational measures to protect your information. All data transmission between your browser and our servers uses HTTPS encryption. GHL API credentials and AI API keys are encrypted at rest using AES-256-CBC encryption with initialization vectors stored separately from the encrypted data. Encryption keys are stored separately from the data they protect.
All database queries use parameterized statements to prevent SQL injection. Access to user data is scoped to the authenticated user — no endpoint can access another user's data. Destructive actions require explicit confirmation and are logged.
No method of transmission or storage is 100% secure. If we become aware of a security breach affecting your data, we will notify you by email within 72 hours of becoming aware of it.
Children
Flow Inspector is intended for use by professionals 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we become aware that a user is under 18, we will terminate their account and delete their data immediately.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email at least 14 days before the changes take effect. The updated policy will always be available at flowinspector.app/privacy.php. Your continued use of Flow Inspector after the effective date of any changes constitutes your acceptance of the updated policy.
Contact
LeadClick LLC