Privacy Policy
Last updated: 4 July 2026
1. Introduction
Tesflows ("we", "our", "us") respects your privacy. This policy explains how we collect, use, store, and protect your personal information when you use the Tesflows mobile application and website (collectively, the "Service").
2. What data we collect
Account information. When you sign up, we collect your email address and a user identifier for authentication. Our authentication provider also records IP addresses and standard device metadata for security purposes.
Tesla account data. When you connect your Tesla account, we receive and store a Tesla OAuth refresh token (encrypted), your Tesla account identifier, and the OAuth scopes you granted. We never store your Tesla password.
Vehicle information. We store your vehicle identification number (VIN) in hashed form — the raw VIN is never exposed to the app and is only used server-side to call the Tesla Fleet API. We also store display name, vehicle state (online, asleep, offline), vehicle configuration (colour, model, wheels), charge state, gear position (shift state — used to confirm the vehicle is in Park before running workflows), and virtual key pairing status. Geographic coordinates (latitude, longitude, heading, speed) from the vehicle's drive state are not stored — they are stripped before saving.
Workflow data. You create workflow definitions consisting of Tesla commands and delays. We store these definitions, run history, and per-step outcomes (success, failure, status, error messages) to display progress and troubleshoot issues.
Widget tokens. We generate a scoped, revocable token stored in hashed form server-side and in your device's secure storage. We also store an optional device label and widget identifier you provide.
Service operations data. We log account activity events (workflow runs, Tesla commands, vehicle changes, widget token operations, and admin actions) to maintain service integrity, enforce usage limits, and troubleshoot issues.
Invitation data. When you receive or send an invitation, we store the email address and invitation metadata.
Usage data. We track daily workflow run counts to enforce per-tier limits. We do not use analytics SDKs, tracking pixels, or third-party analytics services.
3. How we use your data
We use your data solely to provide and improve the Service: authenticate you, send transactional emails (magic links, password resets), execute Tesla commands on your behalf, display your vehicle's cached state, enforce usage limits, and record audit events for security and troubleshooting.
4. Data sharing
We do not sell, rent, or share your personal information with third parties for their own purposes. We share data only with the following service providers who process your data solely to operate the Service:
- Supabase — database, authentication, and serverless function platform. All data is stored in Supabase's hosted PostgreSQL and accessed through row-level security.
- Tesla Fleet API — when you authorise a workflow run, we send authenticated commands to Tesla's API on your behalf using your Tesla OAuth token.
- SMTP2GO — transactional email delivery (magic links, password resets). Only the email address is shared.
- Cloudflare — web frontend hosting. Standard HTTP request metadata (IP address, user-agent) may be visible in Cloudflare's logs.
- DigitalOcean — server infrastructure for the workflow executor and Tesla command proxy.
5. Data retention
We retain your data for as long as your account is active. If you delete your account, all associated data is permanently deleted. Some anonymised audit event records may persist after deletion for security purposes.
6. Data security
Tesla OAuth refresh tokens are encrypted at rest using AES-256-GCM. All network communication uses HTTPS/TLS. Database access is governed by row-level security policies. Server-side operations use service-role authentication and signed requests.
7. Your rights
You can access, correct, or delete your data through the app Settings. A web deletion form is available at app.tesflows.com/account/deletion. To exercise any other rights, contact us at privacy@tesflows.com.
8. Cookies
The Tesflows web app uses Supabase Auth sessions, which may set a session cookie. We do not use cookies for tracking, analytics, or advertising purposes. The marketing site does not set any cookies.
Tesflows is not affiliated with Tesla, Inc. Tesla is a registered trademark of Tesla, Inc.