What leaves your machine
Last verified: 14 August 2026
Most vendors answer "where does my data go?" with a slogan. This page answers it per feature, so you can check it rather than trust it.
Two commitments hold across every row below:
- FlowLeap does not use your inputs or outputs to train models, and our agreements with the providers listed here prohibit them from doing so either.
- Your workspace stays local. Matters, drafts, figures, and generated reports live in a folder on your own machine. FlowLeap has no copy.
Per feature
| Feature | What leaves your machine | Who processes it | Retention |
|---|---|---|---|
| Agent inference — the desktop app, the CLI, or your own harness | your prompts, and whatever you attach to them | your model provider, on your key and your account | your provider's terms, not ours |
| Document OCR | the whole document you submit | Mistral AI (mistral-ocr-latest), on FlowLeap's account — EU (France) | processed and returned; not kept as a document |
| Analyst narration on this site's patent-analytics pages | the patent or applicant you asked about, plus the PATSTAT figures already shown on that page | Anthropic, on FlowLeap's account — USA | the generated memo is cached so the same request re-serves it; the step log keeps tool names and publication numbers, never results |
| Legal reference search (EPC, EPO Guidelines, MPEP) | your search text | FlowLeap's own server — the embedding model runs locally, so no third-party model sees it | not retained |
| Patent data lookups (search, claims, family, legal status, citations) | the query and the publication numbers | EPO OPS and USPTO ODP; PATSTAT analytics run on FlowLeap's own snapshot | provider-side, under their terms |
| Your patent-data keys (EPO, USPTO) | forwarded on each request to authenticate you | the relevant patent office | never persisted, never logged |
| Your model provider key | nothing — it stays in your machine's secret storage and is used to call your provider directly | — | — |
| Workspace files, matters, drafts, outputs | nothing | — | local only |
| Account and billing | name, email, subscription and payment details | Clerk (accounts), Stripe (payments) | for the life of the account; invoices as French law requires |
| Website visits | page views, cookieless | Vercel Web Analytics | only with your consent, and only on this website |
The exceptions, named
FlowLeap's posture is that you bring your own model key and your provider bills you directly. There are exactly two exceptions — features that run on a model FlowLeap pays for rather than yours:
- Document OCR, on Mistral.
- Analyst narration, on Anthropic — the written commentary on the patent-analytics pages of this website. The charts themselves are computed from PATSTAT and involve no model at all.
That is the complete list. If a third ever appears, it appears here in the same change that ships it.
Legal reference search is worth separating out: it is processed by FlowLeap rather than by you, but its embedding model runs on our own server, so no third-party model receives your search text.
What used to be here
Until August 2026, query building and claim analysis also ran on FlowLeap's model accounts. They no longer exist server-side — the endpoints are withdrawn, and both now run on your own model, on your own key. Earlier versions of this site and its privacy policy described them as FlowLeap-processed; that is no longer true.
Client telemetry was removed entirely rather than switched off. There is no endpoint that ingests message content.
Where this fits
This page is a factual annex, not a legal document. The binding text is the Privacy Policy and the Terms of Service; this page is the per-feature detail behind them. Where the two ever disagree, the discrepancy is a bug — please tell us at contact@flowleap.co.
