Intentflow
What personal data we collect, why, and what rights you have over it.
Last updated: September 3, 2026
This policy covers intentflow.co and app.intentflow.co (the "Service"), operated by Intentflow, a sole proprietorship based in Poland (NIP 7692052599, REGON 543317392) ("Intentflow," "we," "us"). For most of the personal data described below, we act as the data controller under the EU General Data Protection Regulation (GDPR). Where you store your own data (including data about other people) inside your NetBox instance, or where the network configurations you upload for analysis contain personal data, we act as a data processor on your behalf - see "Your NetBox instance data" and "Configurations you upload" below.
Contact for privacy questions: support@intentflow.co.
| Data | Why |
|---|---|
| Email address, password (hashed) | Creating and securing your account |
| Billing details (via Stripe - we don't store card numbers ourselves) | Processing subscription payments |
| Subdomain/instance name you choose | Provisioning your NetBox instance (Hosted NetBox plans only) |
| Network device configurations you upload | Producing the Verify or Reconcile analysis you asked for - see "Configurations you upload" below |
| The reports and reconciliation data we derive from them | Showing you the result, and letting you download it while it is retained |
| The address and API token of a NetBox instance you operate yourself (standalone Reconcile), stored encrypted | Comparing your configurations against that NetBox, and writing the changes you confirm |
| Support emails and contact-form messages | Responding to you |
| Basic request logs (IP address, timestamp, page requested) | Security, abuse prevention, debugging |
| Website traffic analytics (via Cloudflare Web Analytics - cookieless, doesn't identify individual visitors) | Understanding site traffic |
We process account, billing, provisioning, and analysis data - including the configurations you upload - because it's necessary to perform our contract with you (delivering the Service you asked for). We process security/abuse logs and respond to support requests based on our legitimate interest in operating the Service reliably and securely.
A single Verify run can be bought without signing up. That's a real difference in what you have to do, but not a claim that we hold nothing: we still create a customer record containing your email address, so that we can send you the link to your report and make sure only you can open it. Everything in this policy applies to that record exactly as it does to a full account, including your right to have it deleted.
Whatever you store inside a NetBox instance we host for you - device inventory, IP addressing, site/location data, contact records, or anything else - remains yours. We don't access, read, or use the contents of your instance except: (a) as strictly necessary to provide support you've requested, (b) to operate backups, (c) to carry out a reconciliation you have asked for, or (d) where required by law. For this data, you are the controller and we are the processor - see our Data Processing Addendum for the terms that govern that processing.
If you use standalone Reconcile, the NetBox is one you operate and we do not host. We reach it over its API using the token you provide, reading it to compare against your configurations and writing to it only the changes you have confirmed, or where you have explicitly enabled automation to do so. You control the scope of that token and can revoke it at any time.
Verify and Reconcile work from device configuration you upload - running-configs and the command output around them. We treat it as the most sensitive thing you hand us, because for most networks it is. A running-config commonly contains local usernames, SNMP community strings, and free-text description or contact fields, so it may well contain personal data; where it does, you are the controller and we are the processor, and our Data Processing Addendum governs that processing.
What we do with it:
The full technical lifecycle is described on our Security & Infrastructure page.
We don't sell personal data. We share it only with the service providers needed to run Intentflow - see our Subprocessors page for the full list, what each one does, and where they're located.
We use one essential cookie to keep you logged in - it can't be disabled without breaking the Service. We don't use any analytics, advertising, or tracking cookies, so there's nothing here that requires a consent banner.
Account and billing data is kept for as long as your account is active, plus a reasonable period afterward for legal/tax record-keeping. Request-log data is retained for a limited operational window and then discarded.
Everything you upload, and everything we derive from it, is on its own automatic clock. These run independently of each other and of whether your subscription is still active:
| What | Kept for |
|---|---|
| Configurations you upload for Verify | 7 days from upload |
| Verify report, one-time purchase | 7 days |
| Verify report, subscription or add-on | 30 days |
| Configurations uploaded to Reconcile, and the reconciliation data derived from them | 30 days |
| Hosted NetBox instance, after cancellation | 7 days, then deleted |
The raw configuration is deliberately kept for less time than the report derived from it, so it is never left in storage after the thing you actually wanted is gone. Residual copies inside encrypted backups are deleted once that backup reaches the end of its own retention schedule - see our Terms of Service for the exact timeline, and how to request an export or reactivate within the 7-day window.
What outlives the above. A small record of each run and each import - when it happened, the file name you uploaded, and summary counts - stays on your account after the report and the configuration have been deleted, so your history list still means something. It holds no configuration content. Ask us and we will delete it along with the rest of your account data.
Under GDPR, you have the right to access, correct, delete, restrict, or export (data portability) your personal data, and to object to certain processing. To exercise any of these, email support@intentflow.co. If you're not satisfied with our response, you have the right to lodge a complaint with your national data protection authority - for Poland, that's the Urząd Ochrony Danych Osobowych (UODO).
We may update this policy from time to time. We'll post the updated version here with a new "Last updated" date, and for material changes we'll make reasonable efforts to notify active account holders by email.
Questions about this policy: support@intentflow.co.