Legal / Privacy

What the site collects, and what flow holds for you.

This site counts visits and remembers which pages you have read. flow holds far more, and almost all of it belongs to the company whose team captured it.

Last updated

18 September 2026

Company

form-three Pte. Ltd.

UEN

202321123E

Contact

start@form-three.com

What this policy covers

form-three runs two things, and they hold very different amounts of data.

flow is our product, and most of this page is about it. Companies use flow to capture screens from their own products and from public websites, to score what they capture and to share what they learn. It holds a great deal, and almost all of it belongs to the company whose team captured it.

This website holds almost nothing. There is no account here and no form to fill in. Its part of this policy is the second section from the end.

flow is for people at work, acting for their employer. It is not sold to consumers and nobody under 18 should be using it. We do not knowingly collect a child's personal data.

Both are run by form-three Pte. Ltd., and where this page says "we", that is the company named above.

Two roles, and the difference matters.

Data protection law separates the company that decides what happens to personal data from the company that only follows instructions. flow puts us on both sides of that line.

For your account we decide, so we are the controller. That covers your name, your work email, the organisations you belong to and your role in each.

For everything your team captures we follow your instructions, so we are a processor. That covers the screenshots, the page text behind them, the design frames from Figma and the metrics we read from accounts you connect. All of it is yours. We hold it to run the service and we use it for nothing else.

One carve-out, and it is small. We count how flow is used: how many captures ran, how long a job took and what failed. Those counts carry no capture content, no page text, no client name and nothing that identifies a person.

The split decides who answers a request. Ask about your own account and we answer. Ask about a person whose data turned up in a capture your team made and the answer is your company's to give, with our help.

What flow stores

Eight kinds of data. The second one is the one to read closely.

  • Account and profile. Your name, your work email, the organisations you belong to and your role in each.

  • Screen captures and recordings. Full-page screenshots, the page text and DOM behind them, and, while your team is recording, the clicks, navigations and form submissions that make up a journey. A recorded click holds the text of what was clicked, so a click on somebody's name records that name.

  • Design frames. Frames sent from Figma files, where your team uses our plugin.

  • URLs and site metadata. Every address your team captures or benchmarks, and what the page reported about itself.

  • Analytics metrics. Sessions, page views, click behaviour and speed scores, read from accounts you connect or uploaded by you as a CSV.

  • AI requests and responses. What we sent to the model and what came back, so a score can be re-read and a cost explained.

  • Audit logs. Who did what and when. These record the email address of the person who acted and, where the action affected someone else, that person's address too.

  • Support correspondence. Whatever you write to us, and our reply.

Why we process it

Four purposes, and the law gives us a basis for each.

  • To give you an account and run flow for you. This is the thing you asked us for, so performing that agreement is the basis.

  • To keep the service working and not abused. Audit logs, error reports and rate limits.

  • To answer you. Support correspondence and enquiries, on the basis that you wrote to us.

  • To meet legal and accounting duties. The business records we are required to keep.

Under Singapore's Personal Data Protection Act we rely on the consent you give when you create an account. We rely on deemed consent where you hand us data to get something done, and on the legitimate interests exception for security work.

Where a capture your team made brings European or United Kingdom law into play, your company is the controller and the basis is your company's to pick. We process it on your instructions.

What the browser extension can reach

The extension installs with access to every site your team visits. A journey can cross any number of domains and flow cannot know which ones in advance, so Chrome asks for all of them. That prompt is telling you the truth.

It captures only while somebody on your team has started a recording. Outside a recording it holds nothing and sends nothing, and the extension shows when it is running.

While a recording runs it takes screenshots and reads the page text and the DOM. It also records the clicks, navigations and form submissions that make up the journey. Chrome puts up its own banner while it is driving the page, which is the plainest signal there is.

Your organisation's URL blocklist is checked before a recording starts on an address, and a blocked address records nothing.

Captures can hold personal data.

A capture runs inside your team's own browser, on whatever page they have open. So a capture of a signed-in account page holds what that account holds, and a capture of a checkout holds what was in it.

flow gives you three controls, and none of them is a guarantee.

  • A redactor in the extension, which masks matched fields in the browser before anything leaves it.

  • A pattern check on our servers, which looks for common shapes of personal data before a capture is stored.

  • A URL blocklist for each organisation, which stops named addresses being captured at all.

Automated checks find patterns. They do not read a page and understand it, so they miss what nobody wrote them to look for.

We do not inspect captures beyond those checks, unless we have to look into a suspected breach of the terms or the law requires it. What your team points the extension at is your decision, and having a lawful basis for it is your responsibility.

What happens when flow calls an AI

flow does not resell model capacity and does not pay for your inference. You supply an Anthropic or OpenAI key, we store it encrypted and we call that provider directly with it.

So the provider processes your content as your provider, under the agreement you hold with them. What they keep, how long they keep it and whether they train on it are governed by their terms and their privacy policy. This page governs none of it.

Both state that content sent through their APIs is not used to train their models by default. That is their commitment to make, so read it from them: Anthropic and OpenAI.

We send the capture, the page text it carries and the context your organisation has written. We keep the request and the response for 180 days by default.

Accounts you connect

flow reads these on your behalf, and every one of them is something you switch on.

  • Google Analytics 4 and Search Console. Connected over OAuth. You grant the access and we store the tokens encrypted.

  • Microsoft Clarity. Connected with an API token you paste in.

  • Mobbin. Connected over OAuth, for the reference screens used in benchmarking.

  • Google PageSpeed Insights. A public API, so there is no account and no token.

You can also upload a CSV of per-URL analytics, which needs no connection at all.

No token is ever returned by our API, and revoking access in the provider's own settings cuts ours immediately.

Who else processes it

Four companies process data for flow whatever you do with it.

  • Railway. Hosting for the application and the PostgreSQL database.

  • Cloudflare. Object storage for screenshots, in a private bucket reachable only through a proxy that checks who is asking.

  • Resend. Sign-in links and invitation email.

  • Sentry. Error reports. Stack traces, and no capture content.

Four more process it only because you connected them: Anthropic or OpenAI on your own key, Google, Microsoft and Mobbin.

We tell you before we add one. We do not sell or rent any of this, there is no advertising network in flow and nothing in it makes an automated decision about a person.

Where it is held

The application and the database run on Railway. Screenshots are held in Cloudflare R2, which places objects automatically and is pinned to no single region.

So data in flow is processed outside Singapore. We say so plainly because a procurement review will ask, and the honest answer is easier to give now than later.

Singapore's Personal Data Protection Act lets us send personal data abroad only where the recipient is bound to protect it to a comparable standard. Every processor named above is under a written contract with us that requires that, and the AI provider is under the agreement you hold with it.

If the country your data is held in decides whether you can use flow, write to us before you start.

How long we keep it

A scheduled job does the deleting, and two defaults govern most of it.

  • Screen captures: 365 days. Set for each organisation, so yours may be shorter.

  • AI requests and responses: 180 days. Set for each organisation too.

  • Account records: while the account is open. Deleted when it closes.

Deleting an organisation removes its screenshots from object storage and its records from the database. Our hosting provider keeps database backups on its own schedule, so a deleted record survives in those until that schedule has rolled over.

On the website side, an enquiry that does not turn into work is deleted within 12 months. If it does turn into work it becomes part of the client record, which we keep for 5 years after the engagement ends because Singapore's tax and companies legislation requires it.

Two things outlive the schedule above: a record the law requires us to hold, and anything we need for a legal claim that is already running. Nothing else does.

Your rights, and your users' rights

Under Singapore's Personal Data Protection Act you may ask us what personal data we hold about you, ask us to correct it, or withdraw a consent you have given. Email start@form-three.com and we will answer within 30 days.

Three practical notes. We will ask you to prove who you are before we answer. We may charge a reasonable fee for an access request, and we will tell you the amount before we do the work. Withdrawing a consent the account depends on means the account stops working.

That covers your own account, where we are the controller.

For a person whose data turned up in a capture your team made, the request goes to your company. Your company chose to capture it, so your company answers it. Tell us what you need and we help you find it, export it or delete it, inside the same 30 days.

An organisation owner can already remove a member, delete a flow and delete the whole organisation from inside the product.

If we handle you badly you can complain to Singapore's Personal Data Protection Commission. Tell us first and we will try to fix it.

How we keep it safe

What we do, described plainly. None of it is a certification.

  • TLS in transit, and encryption at rest.

  • API keys and connector tokens encrypted with AES-256-GCM, and never returned by our API.

  • Four roles inside an organisation: owner, admin, member and viewer.

  • Screenshots in a private bucket, reachable only through a proxy that checks who is asking.

  • Audit logging of who did what and when.

We hold no SOC 2 report, no ISO 27001 certificate and no HIPAA attestation, and nothing in flow should be read as one.

Report a vulnerability to security@form-three.com. We acknowledge one within 48 hours.

If something goes wrong

If personal data in flow is exposed, lost or reached by someone who should not have reached it, we tell the organisations affected within 72 hours of confirming it.

The notice says what happened, what data was involved and what we have done about it.

Who tells the regulator depends on whose data it is. For your account data we are the controller, so we notify Singapore's Personal Data Protection Commission ourselves inside the 3 days the law allows. For a capture your team made, your company is the controller and the notification is your company's to make. We give you what you need to make it.

This website

The site you are reading now, which is the small half. There is no account to create, no form to fill in and nothing you are asked to type.

What you send us. You might email us, message us, call one of the numbers in the footer, or book a meeting through our scheduling link. If you do, we hold what you chose to write: your name, your address or number, and what you said. We use it to answer you.

What your browser reports. Which pages you opened and in what order. How long you stayed and how far down you scrolled. What referred you. Your screen size, your language, and the rough location your network address implies. We cannot tell who you are from it, and we do not try.

Three things are stored in your browser. None of them is sold, shared or used to build a profile of you, and all three can be cleared at any time from your browser's settings.

  • _ga: a random identifier, so a reader who comes back is counted once. We set it ourselves, not a Google script. It lasts two years.

  • _f3ga: the current visit. It records when the visit started, how many came before it, and whether this one counted as engaged. Two years.

  • f3:visited: which pages you have already read, so the block at the bottom of each page can offer you one you have not. It is session storage, so it is gone when you close the tab.

The site asks for no consent before setting the first two, and we would rather say so plainly than not mention it. If that matters to you, blocking cookies for this domain costs you nothing here: every page works without them.

Google receives the page and scroll measurement, collected by our own code and sent on, so there is no Google script on the page. One case study embeds a YouTube video, which may set its own cookies once it loads. The booking link goes to cal.com, which handles your name and email under its own policy.

flow sets one cookie of its own when you sign in, and it does a different job from the three above. It keeps you signed in, it expires and it measures nothing.

Changes, and who to ask

When this policy changes, the date at the top of the page changes with it. We do not keep an archive of old versions, so if a change matters to you, the date is the thing to watch.

flow is in beta, so expect this page to move while the product does.

This site and flow are run by form-three Pte. Ltd., registered in Singapore under UEN 202321123E.

Anything you want to ask about this policy, and any request about your own data, goes to start@form-three.com. That address reaches our data protection officer, who Singapore law requires us to appoint and to name a contact for. Security reports go to security@form-three.com.

The terms covering both are on a separate page: our terms and conditions.

What's next?

Terms & Conditions

A Performance Design consultancy in Singapore. We design and build digital products and journeys that users trust and easily find.

Explore

  • Home
  • About
  • Work
  • Method
  • Services
  • Contact

Follow us

  • LinkedIn
  • Instagram
  • Facebook
  • Crunchbase
  • X

Talk to us

  • Book a meeting
  • Email
  • WhatsApp
  • Call
© form-three Pte. Ltd. 2026. Registered in Singapore: UEN 202321123E. Privacy Policy/Terms & Conditions
  • Talk to our founder
  • About
  • Work
  • Method
  • Services