Your Data
Where does your data go?
FlowPad is local-first: your sessions, skills, and context live on your machine. When you collaborate, you pick how far your data travels. Our cloud is optional at every step.
The design principle
Your machine is the trust zone.
FlowPad is built to run completely independent of any cloud, including ours. Agents, sessions, skills, and the knowledge they produce stay on your computer, where you already trust yourself completely.
Sharing that work with someone else is a question of trust: do you trust the other side, do you trust the network, do you trust us? Instead of answering for you, FlowPad gives you a dial. Each level up trades a little more trust for more speed and convenience. The dial only moves when you move it.
Four ways your data can travel.
fig. 1.0 · the trust dialYou choose the level. The first three never route your content through our cloud.
FlowPad is completely files friendly, for top security applications.
- Offline by design
- No network required
- Zero external exposure
▸ Nothing leaves your machine unless you physically move it.
All data on Git. Optional: Cloud just sends sync events for messaging.
- All data stays in Git
- Cloud used for sync events only
- No data stored in the cloud
▸ FlowPad’s cloud is never in the data path.
No public visibility. Your data stays within your infrastructure.
- Deployed on your servers
- No public visibility
- Full network control
▸ Nothing ever reaches our servers.
Your data saved on GCP, never shared or used.
- Hosted on GCP
- Your data is never shared
- Never used for training
▸ Even at full trust, our only job is moving your messages.
What our cloud can see, level by level.
| Transport | Your content | Metadata |
|---|---|---|
| Airgapped | Never | Never |
| Git only | Never | Sync events only, so peers know to pull |
| On prem | Never | Never |
| Hosted cloud | Held securely on GCP for delivery & mobile | Relayed |
note: speed of collaboration runs opposite to trust required. That trade-off is yours to make, not ours.
SOC 2 certified
Security and privacy controls audited by an independent third party, down to an audit trail on every code change.
GDPR compliant
Personal data is handled in line with GDPR. Your data-subject rights, plus CCPA and Israeli privacy law, are detailed in our privacy policy.
Open source
The code that handles your data is on GitHub, inspectable end to end. You don’t have to take our word for any of this.
Plain answers to the questions we actually get.
I work under NDA. Can I use FlowPad?
Yes. This page exists because a customer asked exactly that. Keep client work on the file or git layers and no content ever reaches our infrastructure. Your confidentiality posture stays whatever your client requires.
Can anyone at FlowPad read my data?
On the file and git layers there is nothing on our side to read. In metadata mode our cloud sees only that an update exists, not what it says. With full messages enabled, content passes through our cloud for delivery, and transferring your messages is the whole job.
Can FlowPad work with no internet at all?
Yes. Collaboration packets are built for offline use. Every message is a file you can move by hand, so two FlowPads can exchange work even with no network between them.
Start local. Turn the dial when you’re ready.
FlowPad is free, open source, and local-first. Everything runs on your machine from day one. Each step toward the cloud is a choice you make later, on your terms.