At PR Flow, we believe your data is yours. We built PR Flow with a local-first architecture to ensure your privacy.
PR Flow runs entirely on your local machine. It connects directly to the APIs of your version control and issue tracking platforms using the authentication provided by your local, officially supported command-line tools (such as the gh, glab, acli, and claudeCLIs) or credentials you enter yourself — for example, Gerrit HTTP passwords, Azure DevOps personal access tokens, Trello API keys, and any AI provider API keys. Credentials you enter are encrypted at rest using your operating system's secure storage (Keychain on macOS, and the equivalent on Windows and Linux) and never leave your machine except to authenticate directly with the service they belong to.
We do not have a central backend server that proxies your data. Your code, pull requests, and diffs never touch our servers.
PR Flow's AI features — such as deep reviews, thread summaries, and standup drafts — are optional. They run only when you configure an AI provider and trigger an action. When you do, the relevant pull-request content (the diff, the title and description, and any linked issue-tracker context such as Jira ticket summaries) is sent to the provider you choose, using your own account or credentials. This content is never routed through, received by, or stored on our servers.
You control which provider is used, and where your data goes depends entirely on that choice:
If you never enable an AI feature, none of your pull-request content is sent to any AI provider.
Desktop application: The PR Flow desktop app contains no product analytics, telemetry, or tracking of any kind. We do not log what repositories you work on, and no usage data leaves your machine.
This website: We use Umami, a privacy-focused, open-source analytics tool, to understand general website traffic (page views, referrer, country, device type). Umami does not use cookies, does not collect personal data, and does not track you across sites. All data is aggregated and anonymous — we cannot identify individual visitors.
When you purchase a license, Polar processes checkout, payment, tax, invoices, and receipts. PR Flow's commerce service receives the order and minimal customer information needed to fulfill and support it. Keygen issues and validates the license, and Resend sends the license and access email. Your source code, pull requests, and diffs are never part of this commerce flow. We do not sell your contact information or use purchase data for profiling.
PR Flow licenses are node-locked to a device. When you activate or validate a license, the app sends a device fingerprint and your operating-system type (e.g. "darwin") to Keygen, our licensing provider, solely to bind your license to your device and enforce your seat count. This identifier is used only for license and seat validation — never for analytics, tracking, profiling, or advertising — and it is not associated with your code, pull requests, or any activity inside the app.
If you have any questions about this privacy policy, please contact us at [email protected].
To learn more about how we technically secure your data locally, read our Security Policy, or view our Terms of Service.