Security: your code stays with you
TeamFlow never sees your code. The local plugin does the work on your machines and sends TeamFlow derived state only, such as a ticket key, a stage and a status. Your code and files stay where they are.
What every report carries
- The ticket key and the stage it reached.
- A status and a summary of up to 180 characters.
- Up to eight evidence links, such as a build or a pull request.
- Execution ids and timestamps.
The allowlist is a document you can read. The service rejects anything outside it before it is charged. What a report carries has the full list.
What is never sent
- Prompts and model output.
- Diffs and source code.
- Shell commands and their logs.
- Jira, Linear and GitHub issue bodies.
Test videos
Test videos go from your machine straight to your own tracker. They never pass through TeamFlow.
One team cannot see another team's work
The tenant a report lands in comes from the credential, never from the request. So one team's work cannot appear on another team's board.
How TeamFlow uses your data
- Your code, prompts and files never reach TeamFlow. The plugin sends only the stage and status of the work.
- Test videos go from your machine straight to your own tracker. They never pass through TeamFlow.
- TeamFlow learns from your organisation's own data, and never shares it.
- That learning stays with your organisation. No other organisation's autofix uses it.
- An owner or admin can switch the learning off at any time. TeamFlow then deletes what it learned.
- "Your data" means what TeamFlow already holds: stages, statuses, check results, decisions and their outcomes.
The privacy notice and terms say the same in full.