Flowser
Privacy Policy
Last updated: 2026-09-12
This Privacy Policy explains how Flowser (“we”, “us”) collects, uses, and shares information when you use https://flowser.net and related services. Flowser is an AI web page generation product: you sign in with Google, generate HTML lessons through conversation, publish them, and earn or spend in-service points. Please read this policy together with how the product actually works. If you do not agree, do not use the service.
1. Who we are
The service is operated under the name Flowser at https://flowser.net. For privacy requests, email [email protected]. For general questions, email [email protected].
This website is the overseas web edition. It is technically separate from any desktop or China-market edition and does not share login or points with those products.
We operate as a SaaS service. Paid subscriptions are processed by our payment provider (a merchant-of-record service), which handles payments, taxes, and billing on our behalf. We are not a payment processor and never see your full card number.
2. Information we collect
Account data from Google Sign-In: when you sign in, Google may provide your name, email address, and profile photo. We create an account on first sign-in. We do not offer email-and-password registration and we do not store your Google password.
Account records we create: an internal user ID, a public user number, points balance, ban status, and a session stored in an httpOnly cookie (about 30 days, renewed while you keep using the site).
Pages and prompts: titles, teaching attributes you set (such as country, stage, subject, form, language), your chat instructions, generated HTML, optional cover images (uploaded or AI-generated), publish status, and price. Private drafts are stored for you only. Published free lessons may be readable by anyone, including search engines.
Points and incentives: a ledger of point changes (sign-up bonus, daily-login reward for free accounts, spend to unlock a paid lesson permanently, income when someone buys your lesson, AI-generation usage, points purchased through our payment provider, and administrator adjustments), plus purchase records (payment through our payment provider for a subscription or points).
Usage data: page views and likes on published lessons, generation quota counters, and operational logs (sign-in, generate, publish, unlock, admin actions, errors) kept for about 30 days.
Approximate location for language and filters: we read the country code Cloudflare attaches to the request (Cf-IPCountry) to suggest interface language and a default country filter. We do not use GPS. A language choice may be stored in your browser (localStorage). A filter preference cookie is written only after you change filters yourself.
Technical data: IP address, browser type, and similar request metadata may be processed by our hosting and security provider (Cloudflare) as part of delivering the site.
Payment and subscription data: we do not process or store your card number. When you subscribe or pay, the transaction is handled by our payment provider. Through its webhooks we receive records used to provide and manage access, such as a customer ID, subscription ID, price/plan, subscription status, and billing details, as well as the email you used.
3. How we use information
To create and keep your account, show your profile and points, and keep you signed in.
To generate, save, iterate, publish, unpublish, and delete page; to show the public gallery and your private drafts.
To run the points economy: grant the one-time sign-up bonus (100 points), grant a daily login reward (30 points per day) to free accounts, deduct points when you purchase another author’s paid lesson (author-set price from 0 to 50; 0 means free), credit those points to the author, deduct points for AI generation, and grant points purchased through our payment provider (a subscription or a points add-on).
To manage paid subscriptions: use subscription and customer records we receive from our payment provider to confirm your Pro access, support your account, and manage cancellation or billing issues you raise with us.
To enforce limits (for example daily private-draft quota and generation rate limits, and to stop AI generation when a user’s points balance is too low), detect abuse, ban accounts, and operate the service.
To set language and gallery filters, measure traffic, and fix errors.
4. Points are not money
Points are an in-service balance used for the points economy and for AI generation. They can be purchased (through our payment provider) or granted as promotional bonuses. Points are not a currency, a stored-value card, or e-money, and they cannot be withdrawn, transferred for cash, or exchanged for currency. Because purchased points are a paid, prepaid in-service balance, we keep records of point purchases.
Typical rules (they may change): 100 points on first Google sign-in; free accounts receive 30 points once per day when they visit, while subscribers receive their points with each subscription period instead (the two do not stack); paid lessons can be watched for free but show a watermark and fullscreen is disabled; purchasing (paying the author’s price once) removes the watermark and unlocks fullscreen forever, and the author is paid in full; authors do not spend points to view their own lessons; free lessons (price 0) can be viewed without an account. AI generation consumes points from your balance based on the model’s actual token usage (charged per model call, rounded up).
We may adjust balances, freeze accounts, or refuse rewards if we reasonably believe there is abuse (for example multi-accounting to farm sign-up or browse rewards). Point history is kept so we can audit the economy.
5. AI processing
When you generate or revise a lesson, we send your instruction, recent conversation history, and the current HTML to our AI provider (currently DeepSeek) so the model can return a new complete HTML file.
Do not paste secrets, student personal data, exam papers you are not allowed to upload, or anyone’s private information into prompts. You are responsible for the content you submit and publish.
AI output may be inaccurate. Published HTML is not human-reviewed by default. You are responsible for classroom use.
6. When we share information
Service providers that process data for us: Google (Sign-In, Google Analytics 4, and Google AdSense when ads are shown), Cloudflare (hosting, database, file storage, CDN, security, and optional Web Analytics), DeepSeek (model inference), and our payment provider (payment processing, subscriptions, and merchant-of-record services). They process data under their own terms and only as needed to provide those functions. Google may use cookies or similar identifiers to show ads, including personalized ads. See how Google uses data from sites that use its advertising services: https://policies.google.com/technologies/partner-sites
Payment processing: when you subscribe, your payment details (including card number) are entered directly with our payment provider and processed by it and its payment partners. We never see or store your full card number. Our payment provider may record transaction details such as amount, currency, tax, and billing address in accordance with its own privacy policy.
The public: if you publish a free lesson, its title, attributes, cover, HTML, view and like counts, and link may be visible worldwide and may appear in search results. Paid pages are visible to everyone (with a watermark until purchased); we still store view/like and points records.
We do not sell your personal information. We do not rent your email list.
We may disclose information if required by law, to protect the service or other users, or in a merger or transfer of the service, in which case this policy will still apply or you will be notified.
7. Cookies and similar technologies
Essential: an httpOnly session cookie so we know you are signed in. The service cannot keep a login without it.
Preferences: a filter cookie (set only after you change gallery filters) and language in localStorage.
Analytics: Google Analytics 4 (measurement ID G-ZCG69FKM6D) may set cookies or use similar identifiers to count visits and basic usage. Cloudflare may collect aggregated traffic statistics for us.
Advertising: we may use Google AdSense to show ads on public pages (for example the home gallery). AdSense and its partners may set cookies or use device identifiers to measure ads and, where allowed, to personalize them. You can review ad settings in your Google account. Blocking advertising cookies does not stop essential login cookies.
If we detect that you are in the EEA, UK, or Switzerland (or we cannot tell your country), we show a cookie banner before loading analytics or advertising cookies. You can accept analytics and ads, or keep essential cookies only. You can change this later with Cookie settings in the footer. Login and language still work if you refuse.
You can clear cookies and site data in your browser. Signing out ends the session on that browser. Blocking analytics or advertising cookies does not stop essential login cookies.
8. Retention
Account, page, messages, covers, points ledger, and unlock records are kept while the account exists so you can resume drafts and so the points economy can be audited.
Operational logs are intended to be kept for about 30 days.
If you delete a lesson, we remove its stored HTML and related files that we control. Published copies stop being served after you unpublish or delete.
If an account is deleted (by you on request, or by us for abuse), we delete or anonymize account data, drafts, published lessons we still host, likes, unlocks, and point records associated with that account, except information we must keep for security, dispute, or legal reasons for a limited time.
9. International transfers
We host on Cloudflare’s global network. Google and DeepSeek may process data in other countries. If you use the service from the EEA, UK, or similar regions, this means your data may be processed outside your country. We rely on these providers’ published transfer mechanisms where applicable.
10. Your choices and rights
You can sign out, change language, change or clear gallery filters, unpublish or delete your lessons, and stop using the service.
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. Email [email protected] from the Google account you use on Flowser.
We may need to verify that you own the account. We will respond within a reasonable time required by applicable law.
Google Sign-In permissions can also be reviewed or revoked in your Google account settings. Revoking access will stop new sign-ins until you grant them again.
11. Children
Flowser is built for teachers and adult creators. You must be old enough to have a Google account and to consent to this policy in your country (in many places this is 13 or 16). We do not knowingly collect personal data from children below that age. If you believe a child has created an account, email [email protected] and we will delete it.
12. Security
API keys stay on the server. Sessions use httpOnly cookies. Private drafts are readable only by the owner through authenticated APIs. Paid lesson HTML is not placed on a public cache that would skip the purchase check.
No method of transmission or storage is completely secure. You should not upload highly sensitive personal data into lessons.
13. Changes
We may update this policy when the product or the law changes. The “Last updated” date at the top will change. Material changes will be indicated on this page. Continued use after the update means you accept the revised policy.