Skip to content
PRELAUNCH Product, pricing and legal pages are being prepared for launch.
Open workspace
Home/Privacy
PRIVACY · REVIEW DRAFT

Privacy notice

How the Marsward local review build handles repository scans, inventory records, exports and operational data; draft for launch review.

Draft for review · not finalized for commercial launch.

Jurisdiction-specific terms and the actual hosted data flow require review before publication. No effective date has been set.

Scope and operator

This draft describes the current local review build of FlowState Marsward. It is not a finalized notice for a hosted service. Legal operator: Cinderway Interactive LLC. LLC registration jurisdiction: Florida, United States.

A hosted privacy notice must be reviewed and completed before collecting account, billing or provider-connection information. This page separates current behavior from planned features.

Intended markets

Initial online sales are planned for the United States, Canada and other primarily English-speaking countries. Sales markets do not establish the company’s legal jurisdiction or data-hosting locations. Country-specific privacy obligations will be reviewed before hosted launch.

What the local build processes

You may enter workspace and application names, owners, resource descriptions, links, notes and runbooks. These records and manual activity are sent to the loopback API and saved in a local inventory file on the machine running that API.

Owner names, URLs and notes may contain personal or confidential information. Enter only what you need for operational context and never enter credentials.

Optional Supabase account setup

When configured, Supabase processes account email addresses and authentication credentials; Google or GitHub sign-in supplies identity information through the chosen provider. Marsward saves the verified user ID, workspace name and owner membership in the dedicated Supabase database. Server-managed session cookies keep you signed in. This account setup does not upload the existing local inventory or grant repository access.

Account deletion tooling and the hosted retention policy remain launch work. This optional setup is for owner testing before hosted release.

Local folder discovery

The browser reads eligible files from the folder you choose and extracts supported provider signals. It does not upload source text or collect secret values. Confirmed references send limited evidence, such as relative file paths, line numbers and known signal names, to the local API.

Unconfirmed scan results are transient browser state. Closing or refreshing the page clears that state; this is not a claim of forensic erasure from device memory.

GitHub repository discovery

An optional, separately installed GitHub App reads only the repositories granted to it. Requested scans process eligible source files on the server and save provider names, relative file paths, line numbers and known signal names with the inspected commit. Source bodies are not saved.

The latest report per application also stores CI and deployment observations with the check time. A new scan replaces it; deleting the application removes it. Disconnect hides prior reports but retains the rows until replacement or deletion. Scans stage references for review and never authorize detected providers. Checks are on demand; these observations do not establish application uptime.

Website scanning

When you request a website scan, the homepage URL is sent to the local API. It reads public HTML and a limited number of same-origin scripts. The target site and DNS resolver receive requests and may log the scanner’s network address and request metadata.

No browser cookies, authorization tokens or login sessions are sent. Downloaded document contents and headers are processed transiently, not saved as inventory. Only confirmed provider clues, the site origin and safe document labels are retained. Website discovery is separate from on-device repository scanning.

Storage, exports and deletion

Local inventory persists until you remove its records or delete the local inventory file. Resource and application removal are available in the interface. Removing an application removes its local resource bindings and application events; a workspace-level removal event may remain.

Exports create a file on your device. Deleting an inventory record does not delete earlier exports, backups or copies you shared. You control those copies. No hosted retention period is active in this build.

Endpoint health monitoring

When you start a health monitor, the local API makes recurring HTTPS GET requests to your selected public endpoint while the API and computer remain running. The destination sees the network address and Marsward monitor User-Agent. Checks send no credentials or cookies and follow no redirects. Application endpoint checks stop after response headers; Vercel platform checks read up to 32 KB of public status JSON.

The endpoint, check interval and resource association are saved in local inventory. The latest 60 check timestamps, HTTP statuses, response times and sanitized results remain in server memory. Restarting the API or editing the monitor clears that history. Pause monitoring to stop further checks. No external alert messages are sent.

Optional Vercel deployment reads

When configured by the operator, the local API sends an authorization credential and selected project/team parameters to Vercel on request, including optional auto-refresh while Overview is visible and online. Vercel may log these requests under its own policies. Only deployment identifiers, project references, states and timestamps are returned to the browser; raw responses are processed transiently.

Linked project and account identifiers persist with the resource record. Credentials remain in API process memory (OAuth) or the process environment (manual setup) and are not saved to inventory or exported. Deployment observations remain transient; historical snapshot persistence is not implemented. Removing a resource unlinks it locally but does not revoke the credential at Vercel.

Workspace accounts and Vercel authorization

Account identity, owner membership, workspace inventory and an explicitly imported recovery copy are stored in the configured Supabase project. Workspace Vercel authorization is encrypted with AES-256-GCM before storage and bound to its workspace; the key remains in server configuration. The server decrypts it only to make authorized provider requests.

Deployment access checks return normalized deployment identifiers, project references, states and timestamps. Observations remain transient in the page; the database retains the connection time and most recent read time for rate limiting. Disconnect removes the stored authorization but does not revoke the Vercel installation. Remove the integration in Vercel to revoke provider access. Account deletion and cloud backup/retention procedures remain launch work.

Cookies, analytics and third parties

Marsward currently includes no advertising or analytics integration. Supabase account sign-in uses HttpOnly, SameSite=Lax session cookies with a 30-day sliding lifetime and Secure on HTTPS, plus PKCE cookies for account authorization. Local and workspace Vercel OAuth use separate ten-minute HttpOnly, SameSite=Lax cookies to bind authorization to the initiating browser. Development tooling and the browser may maintain technical state. Opening a provider dashboard takes you to a third party governed by its own policies.

The local folder scanner makes no provider calls. GitHub repository discovery makes authorized, read-only requests through its separate GitHub App. An explicitly requested website scan makes public HTTPS requests to the selected website through the local API. An optional server-configured Vercel connector makes authorized deployment reads on request. Workspace credentials are encrypted before Supabase storage; the encryption key stays in server configuration. See the cookie notice for the current storage boundary.

Planned hosted processing

Owner accounts, workspace inventory and encrypted Vercel credentials now use Supabase. Planned normalized historical metrics, reports and security logs will require a revised notice. Before launch, document purposes, lawful bases where applicable, hosting regions, subprocessors, transfers, retention, request procedures and deletion behavior.

Historical metric snapshots are planned; raw customer records, source files and provider payloads are not intended as retained dashboard data. No hosted data-processing agreement or international transfer arrangement is represented as in force.

Questions and requests

Contact support@cinderwayinteractive.com with privacy questions. Do not include sensitive records in your initial message.

Applicable rights depend on your location and the actual processing context. This draft does not limit rights provided by applicable law. The service is being designed for business operations, not for use by children.