Not yet effective. This draft describes the current prelaunch architecture and the planned organization-account foundation. It needs a final contracting entity, contact details, retention schedule, and jurisdiction-specific review before public signup opens.
1. Scope and roles
This notice explains how Wildflower Computer handles personal data when people visit the website, sign in, administer an account or project, call the API, connect a sandbox provider, or ask for support. “Wildflower,” “we,” and “us” refer to the Wildflower contracting entity identified in the final notice.
Wildflower generally acts as a controller for account, security, product, and business data needed to operate the service. When an organization uses Wildflower to process personal data in its sandbox workloads, Wildflower generally acts as that organization’s processor or service provider. The Data Processing Addendum describes that second role.
2. Data we handle
Identity and account data
Google sign-in can provide a Google account identifier, email address, email-verification status, name, and profile image. We also handle session and security data. When organization accounts are available, we expect to handle organization names, invitations, membership, roles, and project assignments.
Project, key, and provider connection data
We handle project names and identifiers; API-key prefixes, hashes, status, and timestamps; provider profile names and metadata; encrypted provider credentials; sandbox identifiers and lifecycle state; idempotency records; and operational audit records. Wildflower does not store a recoverable copy of a project API key after it is issued.
Customer Content and provider requests
Commands, environment values, files, configuration, request input, output, and other Customer Content may pass through Wildflower when an API operation requires it. In customer-connected or BYOK mode, Wildflower transmits the required data and credentials to the sandbox provider selected by the customer. Inline credential overrides are used for the requested operation and are not intentionally persisted by Wildflower.
Device, network, cookie, and service data
We may handle IP address, request time, route, response status, user agent, error details, cookie and session identifiers, rate-limit events, and security signals. The current API telemetry is designed to avoid request and response bodies, authorization values, provider credentials, and sandbox output. See the Cookie Notice for browser storage details.
Support and communications
If you contact us, we handle the contact details, message, and any diagnostic information you choose to provide. Do not include API keys, provider credentials, session cookies, sandbox output, or unnecessary personal data in a support message.
3. Why we use data
We use the data described above to:
- authenticate people and maintain sessions;
- create and administer accounts, organizations, projects, and roles;
- issue, validate, rotate, and revoke project API keys;
- connect providers and perform requested sandbox operations;
- protect the service, enforce limits, investigate abuse, and debug errors;
- maintain records needed for reliability, recovery, and legal compliance;
- provide support and communicate material service or policy changes; and
- understand and improve the service using content-minimized operational data.
Wildflower does not use Customer sandbox content to train AI models. The current website does not use advertising cookies or behavioral advertising.
4. Organization administration
When you use an Organization Account, authorized organization owners and administrators may manage membership, roles, projects, provider connections, API keys, sandbox resources, and related operational metadata. The organization controls its projects and is responsible for notices and permissions concerning its Authorized Users.
Project API keys and organization-owned resources do not automatically disappear when the person who created them leaves. A project transferred to an organization moves with its associated provider profiles, sandbox records, idempotency records, and lifecycle history.
5. When data is disclosed
We disclose data only as needed for the purposes described here:
- Infrastructure providers. Cloudflare supports the website, same-origin API proxy, and protected database backups. Fly.io supports the API and private PostgreSQL infrastructure.
- Identity provider. Google Identity Services handles the Google sign-in flow under Google’s own terms and privacy practices.
- Customer-selected sandbox providers. We send credentials, requests, and Customer Content required for an operation to the provider selected by the customer.
- Legal and safety recipients. We may disclose information where reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a corporate transaction subject to appropriate safeguards.
The Service Providers and Subprocessorspage describes the current service chain and distinguishes Wildflower vendors from customer-directed services.
6. Retention
| Data | Current retention approach |
|---|---|
| Login transaction cookie | Expires after ten minutes. |
| Browser session and CSRF cookies | Configured for up to thirty days; the server session expires after twenty-four hours of inactivity. |
| Account, project, and provider profile data | Kept while the applicable account, organization, project, or connection remains active, then deleted or de-identified subject to operational and legal needs. |
| Operational, security, and audit records | Kept only as long as reasonably needed for security, reliability, dispute prevention, and legal compliance. Final production periods will be published before launch. |
| Protected backups | Removed through the backup rotation after primary data is deleted, unless longer retention is legally required. |
We will replace the remaining purpose-based periods with a reviewed production schedule before these documents become effective.
7. Deletion and account changes
Account controls and support channels will provide deletion paths as the product reaches public availability. Deletion may be delayed while active or outcome-unknown sandboxes remain, when a user is the sole owner of an Organization Account, or where records must be kept for security, legal, or contractual reasons.
Deleting or removing a User Profile does not delete resources controlled by an Organization Account. Limited audit and security records may survive in de-identified form, and deleted data may remain temporarily in protected backups until rotation.
8. Choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal data, and to appeal or complain to a regulator. These rights may be limited by law and by the role Wildflower plays. For organization-controlled workload data, direct the request to the relevant organization first.
You can disconnect a provider profile, rotate or revoke project API keys, sign out, and control cookies through available product and browser settings. Blocking necessary cookies prevents console sign-in but does not prevent access to the public documentation.
9. Security
Wildflower uses measures designed for the current service, including transport encryption, hashed project API keys, role- and project-scoped access, encrypted stored provider credentials, bounded requests, secret redaction, content-minimized telemetry, and protected backups. No service can guarantee absolute security.
10. International use
Wildflower and its service providers may process data in countries other than the one where a user lives. Before public launch, the final notice and DPA will identify the applicable transfer mechanism and any required regional disclosures.
11. Children
The Services are for people able to enter a binding contract and are not directed to children. Do not use the Services to collect children’s data without an appropriate legal basis and written agreement covering that use.
12. Changes and contact
We will date material updates and provide reasonable notice before they take effect. For privacy questions or rights requests, email legal@wildflower.computer. For product or security help, follow the support guidance. The contracting legal entity and mailing address will be added before signup opens.
