1. About this notice
This notice covers our public website, web editor and browser-based viewer. Our Privacy Policy identifies the data controller and provides company and contact details. It also explains how we process personal information across the service, including Flowtropolis XR.
Cookies are small records saved by websites and sent by your browser with matching web requests. We also use local storage between visits, session storage for a browser tab, and caches for downloaded files. Rules about storing or accessing information on your device can apply to these technologies as well as cookies.
Our public website does not use advertising or analytics scripts. The sign-in and editor storage below applies when you use those parts of the service.
2. Your choices
You can inspect, block or delete cookies and other site data in your browser settings. Check the site-data entries for each Flowtropolis address you use. Blocking sign-in storage can prevent access to your account. Clearing site data can sign you out and remove preferences or local AI job information. It does not delete your account, scenes or conversations stored on our servers.
You can turn off future first-party product analytics in the editor's account settings using the toggle currently labelled "Share anonymous usage analytics". Despite that label, the records are pseudonymous: they can be linked to your account. This setting does not delete existing records or control sign-in, security logs or diagnostics.
Storage strictly necessary to provide a service you request can be used without cookie consent. Where required by law, optional storage or device access needs your prior consent, with a choice to refuse and an easy way to withdraw. An analytics opt-out or browser setting is not a substitute for that consent. Reading this notice or continuing to use the website does not give consent.
3. Sign-in and security
We use SuperTokens for sign-in and session security. These items are stored under the Flowtropolis application address in your browser. Which items appear depends on the sign-in method you use.
Sign-in storage contains session tokens, user identifiers and security verification details. For email or phone sign-in, it also remembers the address or number you enter while you complete the sign-in process.
| Name and type | Purpose | Storage duration |
|---|---|---|
sAccessTokenCookie | User authentication | Set for one year when issued or refreshed, unless cleared sooner. The token expires much sooner. |
sRefreshTokenCookie | User authentication | 100 days from issue or renewal, unless cleared sooner. Replaced when the session is renewed. |
sFrontTokenCookie | User authentication | Replaced when the session changes and cleared on sign-out. The software requests an expiry in the year 9999; browsers may impose a shorter limit. |
st-last-access-token-updateCookie | User authentication | Updated when the session changes and may remain after sign-out. The software requests an expiry in the year 9999, subject to browser limits or earlier deletion. |
supertokens-oauth-state-2Session storage | User authentication | For the browser tab's session, unless replaced or cleared sooner. Restoring a tab may also restore its session storage. |
supertokens-passwordless-loginAttemptInfoLocal storage | User authentication | Until the sign-in flow clears or replaces it, or you clear site data. The entry has no automatic expiry, even after the sign-in code expires. |
browser-tabs-lock-key-REFRESH_TOKEN_USELocal storage | User authentication | Normally removed when renewal finishes. An interrupted operation can leave an entry until a later clean-up or you clear site data. |
Cookie storage and token validity are different. Access tokens are valid for up to one hour. An expired token cannot authenticate a request, even if its cookie remains. Signing out ends the session but does not clear all editor preferences or browser storage.
4. Editor storage
This storage remembers your organisation, workspace and scene selections and editor preferences. It also holds AI prompts and job or conversation identifiers across page reloads, cached viewer files for faster loading, and any troubleshooting settings you enable.
A star in a name stands for a scene or conversation identifier, or a viewer version. Server-side account and content data have separate retention periods.
| Name and type | Purpose | Storage duration |
|---|---|---|
flowtropolis:orgIdselectedWorkspaceIdlastClickedSceneIdLocal storage | Service functionality | Until replaced, removed by the application, or cleared in your browser. No fixed expiry. |
flowtropolis.inventory.heightflowtropolis.scenePanel.widthflowtropolis.inventory.expandedFoldersflowtropolis.inventory.collapsedFoldersLocal storage | User preferences | Until replaced or cleared in your browser. No fixed expiry. |
flowtropolis.editor.cameraPoseflowtropolis.editor.modelSetupLocal storage | User preferences | No fixed expiry. The editor keeps up to 50 scene viewpoints and 200 model setups, replacing older entries at those limits. You can clear them in your browser. |
flow-ai-poll:*flow-ai-poll-index:*flow-ai-active-conv:*Session storage | Service functionality | For the browser tab's session. Job records can be removed earlier when a job finishes or is reset. Restoring a tab may also restore its session storage. |
webgl-build-cache-*Browser cache storage | Performance | Until an updated viewer replaces the cache, your browser removes it to free space, or you clear site data. No fixed expiry. |
FLOW_DEBUGft:debug:forceTiledLocal storage, when enabled for troubleshooting | Diagnostics | Until switched off, removed, or cleared in your browser. No fixed expiry. |
5. Analytics and diagnostics
We collect product-usage events to improve our services. The editor holds its analytics session identifier in page memory, without a separate persistent analytics cookie or local-storage entry. A new identifier is created after a page reload or on the next event after 30 minutes of inactivity. Events sent to our servers can still be linked to your account.
Diagnostics help us investigate errors and performance problems.
See the Privacy Policy for why we process personal information and our legal bases and how long server-side records are kept.
6. Other services
If you follow our meeting-booking link to Calendly, or choose Google or GitHub sign-in, those services may use cookies and other storage on their own websites. Their notices explain those uses. Our Privacy Policy lists our service providers, what they do and where they process information.
7. Contact and updates
For questions about cookies or browser storage, contact support@flowtropolis.com. We update this notice when our uses change.