flowscopeTrust Center
All docs
Understanding the engagement

Your privacy and controls

Last updated July 27, 2026

What flowscope records and does not, what stays off-limits, and the controls you keep. The Employee guide covers what is happening and what you see on screen; the FAQ has short answers to the questions people ask most.

What is recorded, and what is not

flowscope is there to understand how work flows through the applications your company put in scope, and several layers strip out personal details before anything leaves your machine:

  • Recorded: the in-scope apps you use and for how long, what you click on, common keyboard shortcuts like save, copy, and paste, and the working content you interact with inside those apps, such as the text you select or enter and the state of form fields.
  • Not recorded: your passwords, ever; audio, video, or webcam input, ever (there is no screen recording either; still screenshots are off by default and exist only if your company separately contracts them for a narrow set of applications where nothing else works, passing through the same redaction as everything else); what you do outside the apps and sites your company put in scope, beyond the fact that you were actively at your computer and for how long; and the always-off-limits categories below.

The app shows this same summary on first launch, and nothing is captured until you have read it and signed in.

What is always off-limits

Never captured, regardless of how your engagement is configured, and your company cannot widen past them:

  • Personal banking, brokerage, and payment sites, and healthcare portals.
  • Personal email.
  • Password managers.
  • Encrypted messengers, and private or incognito browser windows.
  • Legal portals and government services portals.
  • Password fields and sign-in tokens, which are never collected.

Beyond that, only the work applications and sites your company agreed to include are watched at all. Outside that list, nothing about what you do is recorded, only that you were actively at your computer and for how long.

One exception: while your company is still deciding what to include, the bare name of an app or site that is not yet on any list can be reported once to your company's engagement admin, with no times, no duration, and nothing linking it to you. Apps in the off-limits categories are never named anywhere.

Personal data is minimized before it leaves your machine

Even inside in-scope apps, the software avoids carrying personal data. Passwords are dropped where you enter them, login tokens are stripped from web addresses, and sensitive numbers like card and account numbers are masked on your computer before anything is sent. On flowscope's side, a second pass masks a broader set of details, like names and addresses, before anything is stored.

Your activity is labeled with a stand-in identifier, not your name or email; once the setup window closes, flowscope itself can no longer connect it back to you. Full detail is in the Discovery trust addendum.

When a file is opened in an in-scope app

Some work apps, like a PDF reader or a spreadsheet, hold both work and personal documents. When you open a file in one, flowscope treats it as work material for the engagement by default. A notification appears on your machine, and the flowscope window lists every file it has noticed, with the time each one has left.

For roughly fifteen minutes, you can mark the file personal instead. A file you mark personal leaves no record at all, not its contents and not any details about it; everything stays on your machine and never leaves it. If you let the window pass, the file uploads as work material. For spreadsheets, the cell activity recorded while you work is held on your machine for that same window, and is discarded along with the file if you mark it personal.

For a file that ends up as work, a short record that it was opened is kept: the file's name, type, and size, the app it was opened in, a salted identifier for the file and another for its folder, and the work classification it reached. While a file is still within its window, that record is held on your machine and is sent only if the file ends up as work. Any personal details detected within the file name are masked on flowscope's side before it is stored.

The controls you keep

  • Always visible while on. A flowscope indicator sits in your Windows system tray whenever capture is running, and the flowscope window's Capture card says the same thing in words.
  • Pause and resume yourself, with no request to IT, from that card or from the tray indicator. The control is on in the standard setup; whether it stays available is your company's decision.
  • See the scope that applies to you, including the included apps and sites and a recent record of what has been captured.
  • Remove flowscope yourself, any time, without an administrator. Uninstalling ends all capture and transmission.

flowscope provides the software, the agreement you accept before capture, and these controls. The decision to run the engagement, and any workplace-monitoring notice the law requires where you work, rest with your employer, so questions about why it is happening go to your manager or IT. Questions about the software itself: support@flowscope.com.