Last updated 12 July 2026.
AuditFlow OS is an independently built, private beta product, not a commercial service with a dedicated legal or compliance team behind it. This page explains what data the application collects and how it's handled, in plain terms, so anyone using it during the beta knows exactly where they stand.
Creating an account collects a name, email address, and password (stored hashed by the underlying authentication provider, never in plain text). Using the product beyond that stores whatever audit content you or your organisation enters or uploads: audit records, evidence files, findings, risk ratings, management responses, actions, and reports.
Data belonging to one organisation is kept separate from every other organisation's data at the database level, not only in the application's own logic.
Account and audit data is used only to run the product for the organisation that entered it: authenticating sign-in, displaying dashboards and reports, and sending transactional email (confirmation, password reset, invitations, evidence requests) related to your own account and organisation. It isn't sold, shared with advertisers, or used to train any model.
The application runs on Vercel and Supabase, and transactional email is sent through Resend. These are the only third parties involved in running the product.
This is early-stage, actively-changing software, tested primarily by its own builder. It's provided as-is, without any warranty of uptime, data durability, or fitness for a particular purpose. Don't store the only copy of anything you can't afford to lose.
To have an account or an organisation's data deleted, email ibrahimojoye@outlook.com and it will be actioned directly, there's no self-service deletion flow in the product yet.
Questions about this page or how your data is handled: ibrahimojoye@outlook.com.