Mark Flow · Home

Privacy Policy

Pre-release version · updated 1 October 2026

Internal preview. Data retention periods are still being finalised before the official release.

Scope and purpose

Mark Flow is a Chrome extension that helps users automate content-creation steps on AI platforms and manage tasks and workflows. This policy covers the extension, the website, accounts and the related integrations.

Data we process

Account information includes your name, email, authentication information and plan. The server stores data needed for sign-in, quotas, settings, tasks, workflows and run status. Task and workflow content may contain prompts, references to images or videos and the configuration you enter. Payment data includes the order code, amount, status, bank transfer note and the transaction details needed for reconciliation. If you join the affiliate program, the system may store the payout details you provide.

Data in your browser and on AI platforms

The extension reads and interacts with the content of supported pages to send prompts, follow jobs and collect results as you direct. Settings, history and assets may be stored in the extension's storage or in your downloads folder. The prompts and assets you choose are sent to the AI platform concerned and are subject to that platform's policies. Mark Flow uses the sign-in session already present in your browser to carry out these features.

MCP, Telegram and Mark Bridge

When you enable or use MCP, commands and results pass through the Mark Flow server and the AI client application connected over MCP. Media may be uploaded to the server under a hard-to-guess link that does not require sign-in and, under the current configuration, expires after 48 hours. Anyone holding a link that is still valid can open it; do not share links with people who should not have access. Telegram receives the content you configure to be sent to your bot or chat. Mark Bridge is a separately installed application that processes media locally for the features that use it.

Payments through PayPal

If you choose PayPal, an internal account reference and the plan details are sent to PayPal to create the subscription. PayPal handles buyer information and the payment method on its own pages. Mark Flow receives the subscription ID, transaction ID, amount, currency and status in order to confirm entitlement, renewals, cancellations and refunds; it does not store your PayPal password or full card number/CVC.

Payments through Polar

If you choose Polar, Mark Flow sends an internal account ID, your name and email to create the checkout session and attach the plan to the right account. Polar handles payment information on its own pages; Mark Flow does not collect full card numbers or CVC codes. Mark Flow stores the customer ID, checkout session, subscription and plan status for activation, renewal and support.

How data is used and shared

Data is used to run the features you request, authenticate your account, enforce entitlements, process payments, provide support and protect the service. Recipients may include the AI platform you choose, the hosting services that run Mark Flow, payment processors, Telegram and the MCP applications you connect. Do not send passwords, tokens or unnecessary data when you contact support.

Limited Use

Mark Flow uses user data only to provide or improve the user-facing features described here. It does not sell personal data, does not use data for personalised advertising and does not transfer data for unrelated purposes. The use and transfer of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

Retention and deletion

Browser data is kept until you delete it through the relevant feature or remove the extension; downloaded files are not deleted when the extension is removed. Tasks and workflows on the server can be deleted through the relevant management feature. Removing the extension does not delete your account, orders or server-side copies. MCP media uses the 48-hour expiry; copies already downloaded or passed to another platform follow the recipient's retention. Retention periods for accounts, transactions, logs and backups are to be finalised by the operator before release.

Your choices and data requests

You can stop automation, turn off integrations, revoke MCP tokens or optional permissions, delete content through the available features and remove the extension. To request access to, correction of or deletion of account data on the server, contact admin.markflow@gmail.com. Requests need to be verified as coming from the account owner; transaction data may need to be kept to meet applicable obligations.

Security and updates

Public services must use HTTPS. Tokens and authentication information must be kept secret. This policy will be updated when data handling changes; the effective date and contact details will be published with the release.

Operator and contact

Operator: Ngô Mạnh Dũng
Support and data-request email: admin.markflow@gmail.com