HuluFlow · Security & compliance

Security & compliance

How accounts, keys, run logs, and page extracts are handled — boundaries written so you can evaluate fit.

See the principles →

Principles

The boundaries we work inside

URLs you choose

We fetch targets you configure — not open-web crawling.

Public-page boundary

No bypass of login, CAPTCHA, or access controls.

Revocable keys

Bearer tokens shown once, stored hashed, revocable anytime.

Not for resale

Snapshots and datasets exist to run the product — we don’t sell page content.

Data

Account and extracts

We store your email, workflow graphs, selected fields, run logs, and dataset rows so the product can run. Snapshots support collect and monitor; we don’t resell page content.

Account

Email, plan and credits, session-related data.

Workflows

Canvas graphs, node config, selected fields, schedules.

Runs & datasets

Run logs, node output summaries, stored rows.

Service briefs

URLs and requirements if you use the managed brief form.

Access

API keys

Bearer tokens are shown once at create time and stored hashed. Revoke a key in the console if it leaks.

Plaintext once

Full plaintext isn’t shown again — store it safely yourself.

Hashed at rest

The server doesn’t keep reversible plaintext keys long-term.

Revoke anytime

Rotate or kill a key from the console if you suspect a leak.

Fetch scope

Public pages you choose

HuluFlow fetches the URLs you configure. Use it only on pages you are allowed to collect. We do not bypass login or CAPTCHA.

You set targets

List, detail, or pagination patterns come from your graph.

Compliance is yours

Confirm site terms and local law allow your collection.

No bypass

Login walls, CAPTCHAs, and paywalls are out of scope.

Runtime

Transit, access, retention

Transit

Console and API traffic use HTTPS by default.

Account isolation

Workflows, datasets, and keys are scoped to your account.

Run history

Kept to help debug runs — not sold externally.

Deletion requests

Account or data deletion via privacy email / contact form.

Enterprise

DPA and enterprise

Need a data processing addendum or a custom region discussion? Write via the contact form or hello@huluflow.com.

DPA

We can discuss a data processing addendum for procurement.

Region & deploy

Tell us your region or deployment constraints by email.

Security questionnaires

Vendor due-diligence forms can be answered via contact channels.

Contact us hello@huluflow.com

FAQ

Questions teams ask while evaluating

Do you scrape behind login?

No. The product targets public pages you’re allowed to collect; we don’t bypass login or CAPTCHA.

Do you sell datasets to third parties?

No. Extracts exist to provide collect and monitor to you — we don’t resell page content.

What if an API key is lost?

Revoke it in the console and create a new one. Plaintext can’t be recovered after create.

How do I request privacy or deletion?

Email privacy@huluflow.com or use the contact form, and read the Privacy policy.

Clear boundaries make cloud workflows easier to trust

Questionnaires, DPA, or region topics — contact us. Day-to-day use can start on free credits.