All legal documents
Legal & Compliance
AI Disclosure
Version1.0UpdatedJun 20, 2026Reading time7 min read
1. Purpose
This page describes how FLOW FN PTE. LTD. (UEN 202617303Z, Singapore) uses artificial intelligence ("AI") within the FlowFn Service. It is intended to satisfy our transparency obligations under the EU AI Act (Regulation (EU) 2024/1689), the OECD AI Principles, and analogous AI guidance issued by the Singapore Personal Data Protection Commission (PDPC) and the U.S. National Institute of Standards and Technology (NIST AI Risk Management Framework).
2. AI-Powered Features
FlowFn includes the following AI-powered features: (a) AI-assisted text generation in workflow nodes (e.g. summarisation, drafting, classification); (b) AI-assisted image generation, editing, and background removal in our creative tools; (c) AI-assisted story, voice, and video generation in the AI Story tool; (d) AI-assisted code or data transformation suggestions (the workflow Code Generator and workflow AI Assistance), including an AI builder that can scaffold complete FlowFn artifacts — workflows, playgrounds, forms, visualizers, agents, and streams — from a natural-language description, returned as a draft the user reviews and explicitly creates; (e) the Playground AI assistant — a chat-driven assistant inside the Playground editor that reads the user's current HTML / CSS / JavaScript, @keys, asset list and data-sheet schemas, then proposes code changes and Data Sheet / row mutations (mutations are surfaced as a Pending Changes card that the user must explicitly approve before any sheet or row write occurs); (f) AI-assisted moderation signals to detect prohibited content uploaded to the Service; and (g) the Agents module — autonomous AI workers configured by the user with a single task description, optional support documents (used to produce a calibration brief reviewed and approved by the user), an allow-list of platform-tool actions / MCP servers / workflows the agent may invoke, and optional approval rules that pause a run for the agent owner's sign-off. Agents run in one of four modes (interactive chat widget, webhook-triggered, schedule-triggered, playground-triggered) and operate within the same plan-limit, audit-log, and AI-provider machinery as the rest of the Service. The in-product AI Assistant and the Playground AI assistant additionally accept user-supplied image attachments (PNG, JPEG, WEBP or GIF, up to a small per-message limit) on chat messages, which are forwarded inline to the relevant model provider for that request. These are user-initiated features: AI processing only runs when you (or a workflow you authored) explicitly invokes a feature.
3. Models and Providers
We do not train or fine-tune our own foundation models on customer data. The model providers we use fall into two categories. (a) FlowFn-managed: OpenAI, L.L.C., Anthropic, PBC, Google LLC (Gemini and Veo APIs), and X.AI Corp. (Grok family) are engaged by FlowFn as sub-processors for platform-managed AI inference. The specific provider used for a given request is determined by the model selected on the user's or team's AI preferences. These providers power the in-product AI Assistant, the workflow Code Generator and workflow AI Assistance, the Playground AI assistant, and (where your subscription plan includes platform-managed model access) workflow nodes that invoke a platform-managed model. All four are listed on our Sub-Processors page. Inputs and outputs are transmitted under enterprise terms that prohibit using customer content to train their models. (b) Customer-connected (bring-your-own-key, BYOK): a wider set of third-party AI service providers is available as workflow nodes for tasks such as text, image, video, audio, and code generation, but production use requires you to configure your own API key on your team. In that case the request is sent under your contract with that provider, the provider is your processor (not ours), and that vendor's privacy policy and terms govern how the data is handled. The current BYOK AI catalog includes: Anthropic, PBC (when you connect your own Anthropic key); Cohere Inc.; Fal.ai; Fireworks AI, Inc.; Google LLC (when you connect your own Gemini / Veo key); Groq, Inc.; Mistral AI SAS; OpenAI L.L.C. (when you connect your own OpenAI key); Replicate, Inc.; Runway AI, Inc.; Stability AI Ltd.; and Together AI. The complete and current catalog of supported AI providers is published in the product. The specific model used for a given feature may change over time as providers release new versions; we choose models based on quality, cost, latency, and safety.
4. Transparency When Interacting With AI
In compliance with EU AI Act Article 50, the Service clearly labels AI-generated outputs and AI-assisted interactions: (a) UI surfaces that invoke an AI model display an "AI" badge or comparable indicator; (b) generated images, audio, and video are watermarked or otherwise marked as AI-generated where the underlying provider supports it; (c) generated text is presented in a draft state and clearly attributed to AI assistance; and (d) any chat or assistant feature discloses that the user is interacting with an AI system.
5. Risk Classification
Under the EU AI Act risk taxonomy, FlowFn's AI features are classified as limited-risk general-purpose AI uses. We do not knowingly deploy AI for any prohibited practice listed in Article 5 of the EU AI Act (e.g., social scoring, untargeted biometric scraping, exploitation of vulnerabilities, real-time remote biometric identification in public spaces). We do not deploy AI for high-risk uses such as recruitment scoring, credit scoring, biometric categorisation of sensitive attributes, or law-enforcement decision support. Customers must not use the Service to build or operate prohibited or unregistered high-risk AI systems.
6. Human Oversight
All AI outputs in FlowFn are advisory. A human user remains in the loop and must review, edit, and approve AI-generated content before publishing, sending, or otherwise relying on it. We do not make solely automated decisions that produce legal or similarly significant effects on individuals. Customers are responsible for reviewing AI outputs for accuracy, bias, intellectual-property compliance, and suitability for their jurisdiction.
7. Data Used by AI Features
When you invoke an AI feature, the prompt, context, and any uploaded files necessary to fulfil the request are transmitted to the relevant model provider. For chat-style assistants (the in-product AI Assistant and the Playground AI assistant) this includes any image attachments you add to a chat message, which are forwarded inline to the model provider for that request. For the Playground AI assistant, the prompt context also includes a schema-only summary of your Data Sheets (slug, column key, column name, column type, and row count) so the assistant can propose code and Data Sheet mutations against the real shape of your data; row contents are not sent to the model. We do not use customer prompts or outputs to train models. Providers retain inputs only for the duration of the request plus any short-term abuse-monitoring window described in their terms. Outputs are returned to your account and stored alongside the rest of your workspace data, subject to our standard retention policy.
8. AI Use Is User-Initiated
AI features in FlowFn are strictly user-initiated: an AI model is only invoked when you (or a workflow you have authored and saved) explicitly triggers an AI-enabled action. We do not run AI processing on your data in the background, do not profile you with AI, and do not use AI to make solely automated decisions producing legal or similarly significant effects on you. Because AI processing only happens on demand, simply not using the AI-enabled features means no inputs are sent to any model provider — there is no separate account-level kill-switch to maintain. If you want to remove AI-generated outputs that already exist in your workspace, delete them from the workflow, asset, or template that holds them; you can also exercise your right to deletion under our Privacy Policy and PDPA / GDPR / CCPA Compliance pages.
9. Accuracy, Bias, and Limitations
AI models can make mistakes. Outputs may be inaccurate, incomplete, biased, or out-of-date. The Service is not designed for, and must not be used for, decisions in domains such as medical diagnosis, legal advice, financial-advisory recommendations, employment screening, or safety-critical control. Customers must independently verify AI outputs before acting on them and remain solely responsible for any reliance placed on AI-generated content.
10. AI Usage, Credits, and Stopping a Response
Most AI features in FlowFn consume account credits or count toward your plan's AI usage at our then-current rates, as described in the Service, your billing settings, and our Terms of Service. Because an AI request begins processing as soon as it is sent, the Stop (or Cancel) control in a chat-style AI feature is a client-side action: it stops the response from being shown to you and re-enables the input, but the underlying request may still complete on our servers, and its usage is still counted and charged. Stopping a response therefore does not guarantee that no credits are consumed or that any charge is refunded. This applies to FlowFn-managed AI usage; where you connect and use your own provider key (bring-your-own-key), charges and cancellation behaviour are governed by your contract with that provider.
11. Intellectual Property
Ownership and licensing of AI-generated outputs depend on the model provider's terms and applicable law. As between FlowFn and the customer, customers retain rights in their inputs and outputs to the maximum extent permitted by the underlying provider's terms. Customers must not submit content to AI features that they are not authorised to process and must respect third-party rights when reusing AI outputs.
12. Reporting Issues
If you encounter an AI output that is harmful, unlawful, infringing, or otherwise problematic, please report it to legal@flowfn.com. We will investigate, remove or restrict the relevant content where appropriate, and feed the report into our AI risk-management process.
13. Changes
We will update this AI Disclosure as we add, remove, or materially change AI features, or when applicable AI laws (such as the EU AI Act phased application timeline) require additional disclosures.