FlowManner
Chat
Sign InGet Started
Flowmanner
Menu
  • Chat
  • Agents
  • Pricing
  • Docs
  • About
Products
  • Workflows
  • Templates
  • Changelog
  • Missions
Resources
  • Blog
  • API Reference
More
  • Careers
  • Contact
  • Security
  • Start
    • Quickstart
    • Your First Mission
    • Your First Eval
  • How-to
    • Connect Your Own Keys (BYOK)
    • Switch Models Per Task
    • Publish a Template
    • Run Evaluations
    • Chat with Artifacts & Previews
    • Automate via the API
    • Webhooks & Triggers
  • Concepts
    • Glossary
    • Execution Model
    • Models & Routing
    • Sandboxes & Previews
    • Memory & Privacy
    • Trust Model
  • Reference
    • Reference · API
      • Authentication
      • Missions & Runs
      • Chat & Sandboxes
      • Blueprints, Graphs & Templates
      • Evaluations & Feedback
      • Marketplace & Community
      • Files & Exports
      • Integrations & Webhooks
      • Agents & Orchestration
      • Auth, Workspaces & Billing
      • Memory & Knowledge
      • Notifications
      • Platform Services
    • Errors
    • Models
    • Limits

Memory & Privacy

What Flowmanner stores, how workspaces scope it, and the privacy guarantees we can actually make.

Workspace scoping

Missions, templates, chat threads, and personal memory are scoped to your workspace — queries and APIs filter by workspace membership, so members see the workspace's material, not other tenants'. Personal-memory endpoints (v2-personal-memory group) manage per-user memory explicitly: you can list and delete what's stored about your interactions.

What BYOK changes (and what it doesn't)

With BYOK, your keys drive model calls; they are encrypted at rest. All LLM traffic is relayed through Flowmanner's backend — a relay-honest framing, not "we never see your traffic". Prompts are never used for training. Claims beyond these (e.g. absolute GDPR statements) were removed from our guides precisely because we cannot verify them.

Audit trail

Administrative and sensitive actions emit audit records (audit API group) so workspace owners can reconstruct who did what — pair this with the trust rules for marketplace interactions (Trust Model).

Deletion

Deleting chat threads archives rather than hard-deletes (soft-delete shipped 2026-08-25, commit 84910e34) — deletion semantics are deliberate so that undo/audit windows exist. True erasure requests run through data-export / deletion flows (data-export API group).

Last updated 2026-08-25 (git-derived)

  • Workspace scoping
  • What BYOK changes (and what it doesn't)
  • Audit trail
  • Deletion