Commander Flow
FeaturesSavingsBrain OffenceFAQBlogFor BusinessAndroid
Buy License
DownloadFree
Menu
  • Features
  • Savings
  • Brain Offence
  • FAQ
  • Blog
  • For Business
  • Android
  • Buy License
Buy License
DownloadFree
Home/Privacy Policy

Commander Flow — Privacy Policy

Version 1.7 — 17 August 2026

This document describes how Commander Flow ("the Software") and its publisher process Your personal data. The guiding principle: Your voice and Your text stay on Your device. Anything that does leave the device is listed below in plain language, with the legal basis on which it is processed.


1. Data controller

The data controller for the processing described in this Policy is:

Peter's Engineering JDG (Piotr Bahdasaran, sole proprietor — przedsiębiorca jednoosobowy) NIP: 9512534689 KEN 19, 02-797 Warszawa, Poland Privacy contact: inbox@commander-flow.pro

The Software is below the threshold at which Article 37 of the GDPR requires the appointment of a Data Protection Officer; the controller handles privacy requests directly through the email above.

2. What this Policy covers

This Policy covers (a) data processed locally on Your device by the Software; (b) data sent over the network by the Software (model downloads, license activation, anonymous lifecycle telemetry, opt-in diagnostics, checkout); (c) data we receive about You as a customer of the Pro tier (license key, billing email, payment metadata); and (d) data processed when You browse the commander-flow.pro marketing website (cookies, analytics — see §11).

3. Data we process — and what we do not process

3.1 We do not process

  • Your dictated text
  • Your audio recordings
  • Your microphone input
  • Your clipboard contents
  • The contents of any files You open or edit
  • Telemetry containing Your content — the only telemetry is the anonymous lifecycle pings described in §3.2(e); they contain nothing You type or say, and You can switch them off

The voice-to-text pipeline runs entirely on-device. Audio is captured, processed by local machine-learning models, converted to text, and discarded. Nothing leaves Your computer in this flow.

3.2 We process the following data — categorised by purpose

(a) License activation and Pro-tier service. When You purchase or activate a Pro license, the Software sends to our license server (license.ptrs.ltd):

  • Your license key (issued by us at purchase);
  • Your email address (used to activate the license);
  • A hardware fingerprint (a hash of stable hardware identifiers of Your device — used to bind the license to one machine and to detect license sharing);
  • The Software version.

In return we issue a signed JWT trust artefact, which is stored locally on Your device (DPAPI-encrypted) and re-validated periodically.

Legal basis: contract performance (GDPR Art. 6(1)(b)) — necessary to provide the Pro service You purchased.

(b) Payment processing. Pro-tier purchases are handled by Stripe Payments Europe, Ltd. ("Stripe"). When You purchase, Stripe collects the data necessary to take payment (card data, billing address, country of residence for VAT calculation). Under Stripe's published roles, Stripe acts as an independent data controller for fraud prevention, anti-money-laundering and regulatory reporting, and as joint or processor-style controller for the payment instructions You give us. The Licensor receives only the payment metadata required to issue Your invoice and license: customer email, country of residence, the amount paid, the Stripe customer ID, and the invoice ID. Stripe's own privacy policy is available at https://stripe.com/privacy and forms a complementary disclosure for Stripe's processing.

We do not receive or store full card numbers.

Legal basis: contract performance (GDPR Art. 6(1)(b)) and compliance with tax obligations (GDPR Art. 6(1)(c) — Polish VAT-OSS).

(c) Diagnostic reports (opt-in). If a problem occurs, You may choose to send a diagnostic report through the in-app "Report a problem" dialog. Nothing is sent until You press the Send button. The report contains: a generated report ID, app version, .NET runtime version, Windows version, CPU/GPU model, active settings, the last ~200 redacted event-log lines, and Your optional free-text note. The report excludes dictated text, audio, voice commands, selected text, clipboard contents, file contents, email, login, license key and any account credentials.

Legal basis: Your explicit consent (GDPR Art. 6(1)(a)), given by clicking Send. You may withdraw consent at any time by simply not sending further reports.

(d) Model downloads. On first run, ML model files are downloaded over HTTPS from commander-flow.pro (public CDN-style endpoint). Only the request itself is logged at server level (IP address, timestamp, URL); no account information is associated with these requests.

Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — delivering the Software You installed.

(e) Anonymous lifecycle telemetry. The Software sends a small set of lifecycle pings to our license server (license.ptrs.ltd) so that we can count installations and see where the trial loses users:

  • Lifecycle events — one install ping, one update_applied ping when the installed version changes, at most one startup ping per 24 hours, and one uninstall ping. These carry: a random install identifier (generated locally on Your device — not derived from Your hardware, email or any account), the Software version (plus the previous version, for updates), the Windows build number, the app interface language, and — only while a valid Pro license is active on the machine — the serial number of Your license token, so that licensed installs can be told apart from trial installs (for Pro users this makes the ping pseudonymous rather than fully anonymous). The uninstall ping carries only the install identifier, the version and the Windows build number.
  • Funnel events — trial_started, trial_expired, nag_shown (a purchase reminder was displayed; at most one ping per 24 hours) and pricing_opened_from_app (You opened a pricing/buy screen from the app). These carry the install identifier and the Software version only — nothing else.

These pings contain no dictation audio, no text, no chat content and no file names — nothing You type or say ever leaves Your device. You can switch the entire channel off at any time with the anonymous telemetry toggle in the Software's settings; while it is off, no events are sent at all.

Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — measuring installations and trial conversion so that we can maintain, improve and sustainably price the Software. You may object (Art. 21) at any time by switching the toggle off — no email required.

(f) Automatic crash reports (all users, opt-out). When the Software crashes or hits an internal fatal error, it automatically submits a diagnostic report. This applies to every installation — free and licensed alike — and is enabled by default; You can turn it off at any time (see below). This report has the same content shape and the same exclusions as the opt-in "Report a problem" report described in §3.2(c) — it contains the report ID, app version, .NET runtime, Windows version, CPU/GPU model, active settings, redacted event-log lines and the exception stack trace. Before submission, the redaction layer strips Windows username paths and known user-profile folder paths (replacing them with neutral placeholders such as %LOCALAPPDATA%), replaces e-mail addresses with <email> and GUIDs with <guid>, and drops any log line the Software has marked as user-content. Lines that carry dictated text, clipboard contents or chat messages are never collected.

A stable hash of the top stack frames is computed locally so the server can deduplicate repeat reports of the same crash, and the Software remembers which signatures it has already sent so a single recurring fault is not reported twice. The Software also caps automatic reports at 5 per device per day to defend against crash-loops generating a flood.

If You hold an active license, we attach its JWT identifier (a 32-character opaque value — not the license key itself) to each automatic report so that the developer can correlate clusters of crashes to specific versions or affected customers and reach out for follow-up. Reports from installations without a license carry no license identifier and no other account handle.

You can turn automatic crash reports off at any time using the same "Share anonymous diagnostics & crash reports" checkbox in the About window referenced in §3.2(e) — the one control governs this channel too. The checkbox defaults to on because rapid feedback on production crashes is what lets a small team find and fix faults quickly for everyone; turning it off shifts You back to the manual "Report a problem" flow.

We retain automatic crash reports for 30 days for active debugging, then delete the full payload. Aggregated counts (number of times a given stack signature occurred, in which versions) are retained for 12 months for regression-tracking purposes; the aggregated data does not contain identifying information.

Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — software quality, security and stability. The opt-out toggle, the strict redaction, the short retention and the absence of user-content together keep the processing within the legitimate-interest balancing test.

4. Local data on Your device

The Software stores the following data locally, in %LOCALAPPDATA%\CommanderFlowApp\ (and the user-data subdirectory %LOCALAPPDATA%\CommanderFlow\):

  • settings.json — Your preferences (UI language, hotkey, audio device, etc.);
  • models/ — downloaded AI models (~2 GB);
  • logs/ — Serilog rolling log files (7-day retention; no user content is recorded — only diagnostic events and errors);
  • license.dat — DPAPI-encrypted license trust artefact (only when You hold a Pro license).

Uninstalling Commander Flow removes the application binaries; You may also delete the data folders above to remove Your settings, models and license artefact.

5. Subprocessors and data recipients

The following parties process personal data on Our behalf or in connection with the Software and the marketing website:

Subprocessor Role Country Data
Stripe Payments Europe, Ltd. Payment processing & tax (Stripe + Stripe Tax) Ireland (EU) Card data, billing address, country of residence — for purchases only
Time4VPS VPS hosting (license.ptrs.ltd, commander-flow.pro model CDN, mail server) Lithuania (EU) License key, email, hardware fingerprint, model-download request logs, mail traffic
Google Ireland Ltd. (Google Analytics 4) Anonymous website-traffic analytics, only with cookie consent Ireland (EU) with onward transfer to the United States under the EU-US Data Privacy Framework adequacy decision Pseudonymous client identifier, page URL, referrer, coarse geo, browser metadata
Google Ireland Ltd. (Google Ads) Purchase-conversion measurement ("enhanced conversions" and server-side conversion reporting), only with marketing-cookie consent Ireland (EU) with onward transfer to the United States under the EU-US Data Privacy Framework adequacy decision SHA-256-hashed buyer email, ad-click identifier, order ID, amount and currency — for consented purchases only
Google Ireland Ltd. (Google Fonts) Web-font delivery for the marketing site Ireland (EU) with onward transfer possible to the United States Browser-supplied IP address (not stored or correlated to any account)

Activation and other transactional emails are sent from a self-hosted mail server on the commander-flow.pro domain, operated on the same VPS as the licence backend. No external email-marketing provider is used; no third party receives Your email address from us for that purpose.

6. Data retention

  • License records (license key, email, fingerprint, purchase metadata): retained for the lifetime of Your license plus 24 months after expiration, after which they are deleted unless retention is required by tax law (Polish tax law typically requires invoice retention for 5 years).
  • Server access logs (model CDN, license server): retained for 30 days for security and debugging, then deleted.
  • Diagnostic reports that You opted to send: retained for 180 days for debugging, then deleted.
  • Anonymous diagnostic events (install/startup/update/uninstall, §3.2(e)): retained for 90 days.
  • Automatic crash reports (all users, §3.2(f)): full payload retained for 30 days; aggregated stack-signature counts retained for 12 months without identifying data.
  • Application logs on Your device: 7-day rolling retention, controlled entirely by You.

7. Your rights

If You are an EU/EEA data subject, You have the following rights under the GDPR:

  • Right of access (Art. 15) — to obtain a copy of the personal data we hold about You;
  • Right to rectification (Art. 16) — to correct inaccurate data;
  • Right to erasure (Art. 17) — "right to be forgotten";
  • Right to restriction of processing (Art. 18);
  • Right to data portability (Art. 20) — to receive Your data in a structured, machine-readable format;
  • Right to object (Art. 21) — including objection to processing based on legitimate interests;
  • Right to withdraw consent (Art. 7) — for opt-in diagnostic reports;
  • Right not to be subject to automated decision-making (Art. 22) — we do not engage in such processing.

To exercise any of these rights, contact inbox@commander-flow.pro. We will respond within 30 days.

You also have the right to lodge a complaint with the Polish data- protection supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (UODO) ul. Stawki 2, 00-193 Warszawa, Poland https://uodo.gov.pl +48 22 531 03 00

If You reside in another EU/EEA country, You may also lodge a complaint with Your local supervisory authority.

8. International transfers

All license-related processing is performed within the European Union (VPS in Lithuania, Stripe in Ireland), and the anonymous lifecycle telemetry described in §3.2(e) is received and stored on the same Lithuanian VPS. The marketing website integrates Google Analytics 4, Google Ads conversion measurement and Google Fonts; when You consent to analytics cookies, Your pseudonymous interaction data — and, when You consent to marketing cookies and complete a purchase, the hashed conversion data described in §10 — may be onward-transferred by Google from Ireland to the United States. This transfer relies on the EU-US Data Privacy Framework adequacy decision adopted by the European Commission on 10 July 2023, on which Google LLC is certified. No other transfers outside the EEA take place.

9. Security

  • License-server traffic is encrypted with TLS;
  • License trust artefacts on Your device are protected by Windows DPAPI bound to Your user account;
  • The license server runs on a hardened VPS with restricted SSH access;
  • Stripe is PCI-DSS compliant for all card-data handling;
  • Diagnostic reports are signed (HMAC) before submission to prevent tampering in transit.

10. Cookies and website analytics

The marketing website at commander-flow.pro uses cookies and the localStorage of Your browser as follows:

  • Strictly necessary (always on, no consent required, ePrivacy Directive Art. 5(3) "strictly necessary" exemption): remember the language You picked, store Your cookie-consent decision, dismiss the announcement banner. No third party reads these.
  • Analytics — Google Analytics 4 (only with Your consent): pseudonymous traffic statistics. Default state is "denied" via Google Consent Mode v2; GA receives anonymous, cookie-less pings only until You opt in.
  • Marketing — Google Ads conversion measurement (only with Your consent): used solely for the purchase measurement described below. If You do not opt in, this category stays off and no data is sent to Google for advertising purposes.

Purchase measurement ("enhanced conversions"). When a purchase completes on our website and You have consented to marketing cookies, we report that single conversion to Google so that our advertising can be measured:

  • Your checkout email address is passed to Google's gtag user-data interface, which hashes it (SHA-256) before it is sent — Google receives the hash, never the plain address;
  • we may additionally report the purchase to Google Ads server-side: the click identifier of the ad that brought You to the site, the order ID and the amount paid (with currency). This server-side report honors the same cookie-consent choice You made in the banner.

Without Your marketing consent, no purchase data is sent to Google at all.

Legal basis: Your consent (GDPR Art. 6(1)(a)), given in the consent banner and withdrawable at any time via the "Cookie settings" link in the footer.

You can review and change these choices at any time via the "Cookie settings" link in the website footer, which re-opens the consent banner. Withdrawing consent is as easy as giving it.

11. Children

Commander Flow is a productivity tool for working adults and is not directed at children. We do not knowingly collect personal data of children below the age of digital consent applicable in their jurisdiction (16 years under the GDPR baseline; some EU/EEA Member States have lowered this to 13). If You believe a child below that age has provided personal data to us, please contact inbox@commander-flow.pro and we will delete the data without undue delay.

12. Changes to this Policy

If this Privacy Policy materially changes, the next version of the Software will display the updated text and require Your acceptance before it runs. We will note the version and date at the top of this document on every update.

13. Contact

  • Email: inbox@commander-flow.pro
  • Postal address: Peter's Engineering JDG, KEN 19, 02-797 Warszawa, Poland
  • Website: https://commander-flow.pro

© 2026 Peter's Engineering JDG (Piotr Bahdasaran).

Commander Flow

Voice-first productivity

© 2026 Commander Flow™ — Peter's Engineering JDG (Piotr Bahdasaran) · NIP 9512534689. All rights reserved.

Made in PolandPTRS Ltd↗YouTube↗
Product
  • Features
  • How it works
  • Buy License
  • Download
  • Early accessBeta
Legal
  • Contact
  • Imprint
  • Privacy
  • Terms
  • Withdrawal form
  • Transparency & AI
Language