Last updated: August 31, 2026
This Privacy Policy describes how roadflow (“we”, “our”, or “the Service”) collects, uses, and protects your information when you use Roadflow Plans (roadmap editor), Roadflow Artifacts (document/note graph), Roadflow Model (parameter register), optional sharing features, optional Slack Connect integration (Plans), and optional Model Context Protocol (MCP) access for AI agents (Plans, Artifacts, and Model).
localStorage on your device. We do not receive this data unless you explicitly use Share, Slack Connect, or an MCP client that sends content to our servers.roadflow.io and give you links with ids. Anyone with an edit link can change the snapshot; anyone with a view link can view it (read-only UI). Shared data is associated with the link id, not with an account.https://roadflow.io/mcp), Plans roadmap JSON/markup and/or Artifacts graph JSON may be held in server memory for that MCP session (ephemeral drafts) and may be written to shared map storage when a shared map or graph is opened or created. The MCP endpoint is currently unauthenticated: request metadata may appear in ordinary server logs (for example IP, URL, timestamp). See MCP documentation.We use information to: provide the editors (including local save, share links, Slack-synced view maps, and MCP tools); refresh Slack-connected maps; keep the Service secure and reliable; and improve the product. We do not use your roadmap, graph, or Slack List content for advertising or to build marketing profiles.
When you use Share, Slack Connect, or MCP shared/ephemeral features that touch our servers, data is sent to and stored on infrastructure operated for roadflow.io. Slack Connect also exchanges data with Slack’s APIs under OAuth scopes you approve (typically reading Lists, related file metadata, and user display names used for grouping labels). We do not sell your local or shared workspace data. We do not send your local-only Plans or Artifacts content to third parties unless you initiate sharing, Connect, or MCP usage that uploads content, or your browser makes a normal HTTPS request to load the app.
Local data remains on your device until you clear site data or use New. Shared snapshots remain available at their link until we remove them for operational, security, or abuse reasons. Ephemeral MCP workspaces are discarded when the MCP session ends or is discarded; they are not durable cloud maps unless you create or open a shared map. Slack connections and encrypted tokens remain until you disconnect (where available), until we remove them for the same reasons, or until Slack access is revoked. We may retain minimal backup or log data for a limited period. Contact us to request removal of a shared snapshot or Slack connection you control.
We use HTTPS for the app, shared links, and MCP. Slack tokens are encrypted at rest on our servers when Connect is configured. The MCP endpoint is currently open (no API key); do not put secrets in Plans or Artifacts content sent through MCP or share links. Local data is only as secure as your browser and device. No system is completely secure; you use the Service at your own risk. Do not put secrets or highly sensitive personal data in shared, Slack-synced, or MCP-managed workspaces.
Depending on where you live, you may have rights to access, correct, or delete personal data we hold. For shared links, the practical way to stop sharing is not to distribute the link; contact us if you need a shared snapshot removed. For Slack Connect, revoke the app in your Slack workspace and/or contact us to delete the stored connection.
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Last updated” date. Continued use of the Service after changes constitutes acceptance of the updated policy.
For questions about this Privacy Policy or your data, contact admin@roadflow.io.