Grok Flow · Updated 23 September 2026

Privacy notice

This notice covers the Grok Flow website, account tools and Chrome extension. For privacy requests, email reachforsupport@proton.me.

Account access is limited to approved testers. Public registration and live checkout are disabled. The contact page explains the current support arrangements.

Visiting this website

This public information site has no sign-in form, checkout, advertising, mailing list or analytics script. We do not add tracking cookies or browser-storage tracking. Cloudflare hosts these pages and receives ordinary web requests, including IP addresses, browser information and requested pages, to deliver and protect the site. Its infrastructure logging and retention follow Cloudflare’s policies. See Cloudflare’s privacy policy.

Using the extension

Your Chrome profile stores prompts, source text, job history, settings and captured results. Reference images and captured image files are stored in the extension’s local browser database. Filenames may appear in queue exports and download names.

When you start a job, the extension sends that job’s inputs to your connected Grok page using its normal website controls. Grok processes these inputs under its own terms and privacy policy. Media downloads request files from Grok or xAI’s media hosts.

The extension uses Supabase for account authentication, job authorization and subscription status, and Stripe for checkout and subscription management. Billing is currently in sandbox mode, which does not collect real payments. The account service receives account identifiers, job and attempt identifiers, mode, authorization counts and timestamps; prompts and media are not sent to that account service. Session tokens are stored in trusted extension storage. We have not added creative-content telemetry. It uses your existing Grok session; it does not request cookie access, read your passwords or ask for an xAI API key.

Your controls

You can remove jobs and clear finished history in the extension. Uninstalling the extension removes its local storage. Downloaded files and exported history remain where you saved them and must be deleted separately. Exported history may contain private prompts, answers and result links, so share it carefully.

Account and billing records

Google shares your email and basic profile information during sign-in. Grok Flow does not receive your Google password. The OAuth exchange can include provider tokens; the extension does not persist or use them and retains its Supabase session instead.

Supabase stores your account identifier, email, Google-linked authentication data, job authorization records and subscription status. These records provide sign-in, enforce the shared 10-job allowance and prevent duplicate submissions or billing updates. Stripe handles checkout and billing management; card details do not enter the extension or this website. Test and live subscription records are kept separate.

We keep account and job authorization records while your account exists to provide access, track the lifetime allowance and prevent duplicate billing or job authorization. Removing the extension does not delete these server records. The extension includes a Delete account control that asks you to confirm with Google again. If the control cannot complete your request, contact reachforsupport@proton.me.

Account deletion removes your sign-in identity and associated Grok Flow account, job-authorization and subscription-link records. It does not cancel a subscription for you: cancel renewal first and wait until the subscription has ended, or contact support for help with closure. An unfinished checkout must also be resolved before deletion. Browser queues, downloaded files, Grok conversations and Stripe’s own records are separate; deleting the Grok Flow account does not erase those copies.

Support correspondence is kept while a request is unresolved and while necessary to handle a related dispute or legal duty, then deleted. Payment providers may retain transaction records to meet their own accounting, fraud-prevention and legal requirements. Any records we must retain after an erasure request are limited to that purpose; we will explain the reason and retention criteria in our response. Provider-managed logs and backups follow the relevant provider’s retention arrangements and are not instantly erased by the account control.

Why we use information and who receives it

We use account and service records to provide the service you request and administer your account. We use limited security and duplicate-prevention records for our legitimate interest in operating a reliable service, and keep records required to meet legal obligations. Supabase supplies authentication and the account database, Stripe supplies billing, and the website host delivers these pages. Grok receives your creative inputs only when you run a job on its website. Email providers process support messages and account emails where configured. We do not sell your information or use your creative inputs for advertising.

The account database is configured in London. Providers can process some information in other countries under their own safeguards and contractual arrangements. You can read Supabase’s privacy policy, Stripe’s privacy policy and xAI’s privacy policy for their processing practices.

Privacy rights

UK data protection law can give you rights to access, correct, erase, restrict or object to use of your personal information, and to portability where applicable. You can raise a concern with the Information Commissioner’s Office. See the contact page for the current support arrangements.