AIFlow Privacy Policy
Shenzhen Mingzhan Information Technology Co., Ltd., also known as M5Stack ("M5Stack", "we", "us", or "our"), respects your privacy. This Privacy Policy explains how we handle information when you use the AIFlow software ("AIFlow" or the "App").
AIFlow is software that helps you manage M5Stack UIFlow/MicroPython projects, AI conversations, device files and terminals, local Skills, and MCP configurations.
Please read this policy carefully before using the App. Some features require permissions or external services. When a feature needs your authorization, the App or your operating system will ask for it.
In-app consent summary: When this policy is displayed in AIFlow, tapping Agree means that you understand and authorize AIFlow to process the information described below. This includes sending the data needed for the features you use to M5Stack services, your paired M5Stack device, the AI model provider or custom endpoint you select, and MCP or Skill services you enable. You can withdraw permission later by disabling system permissions, removing API keys or external service configurations, deleting local data, or uninstalling the App.
Contents
1. Scope
This policy applies to information processed when you use AIFlow. It does not apply to independent third-party products or services, including AI model providers, MCP servers, SkillHub or ClawHub services, device-side services, websites, or custom endpoints that you choose to connect to the App. Those services process information under their own privacy policies and terms.
2. Information We Process
We process information only as needed to provide AIFlow's features. The App does not include an advertising SDK and does not collect information for cross-app advertising tracking.
Project, file, and code information
When you create, import, edit, or run a project, the App stores project names, project IDs, project files, resource files, active file state, project settings, chat records, and timestamps locally on your device. When you choose to run, upload, or push code, relevant Python files, images, audio files, or other resources may be sent to your paired M5Stack device or to M5Stack backend services used for device file management, file preview, resource upload, code push, deletion, and run operations.
AI conversation and model request information
When you use AI chat, code generation, image input, or tool calling, AIFlow processes the data needed to complete that request. This may include your prompt text, selected images, previous messages in the current conversation, model responses, project names, project file tree, resource paths, relevant project file contents, enabled Skill documents, MCP tool results, active device context, tool call arguments, token usage, and response timing. This information is used to generate answers, edit project files at your request, maintain conversation context, and show usage statistics.
AIFlow does not send AI chat content to a model service until you choose or configure a model and use an AI feature. The request is sent to the AI model provider or endpoint you select, such as Anthropic, OpenAI, Google Gemini, Nano Banana, an OpenAI-compatible service, an Anthropic-compatible service, or a custom endpoint you enter. Those services may be operated by third parties or located outside your country or region. Please avoid entering sensitive personal information in prompts, project files, images, or MCP tool data unless you intend for the selected service to process it.
When this policy is shown in the App, your agreement authorizes AIFlow to send the AI request data described above to the model provider or endpoint you select only when you use AI features. If you do not want this data sent to a third-party AI service, do not configure an AI model, remove saved AI credentials, or do not use AI chat, code generation, image input, or AI tool calling.
Device binding, device files, and terminal information
When you bind or manage an M5Stack device, the App may process pairing codes, device IDs, device names, device types, online status, device file paths, file trees, file preview content, run status, terminal input, and terminal output. This information is used for device binding, unbinding, naming, file browsing, resource upload, entry-code push, real-time terminal connections, and REPL command interaction.
Model, Skills, and MCP configuration information
When you configure models, Skills, or MCP services, the App stores model names, model providers, API base URLs, API keys, Skill lists, Skill documents, MCP server URLs, transport types, and request headers you provide. API keys and MCP authorization headers are used only to make requests to the services you configure. You should connect only trusted model and MCP services.
Voice, images, and media
When you use voice input, the App accesses the microphone and performs speech recognition locally using the bundled sherpa_onnx model. We do not upload your raw microphone recording for local speech recognition.
When you take a photo or choose an image from your photo library, the App processes the image you selected or captured. The image is used only for the action you choose, such as sending it to an AI model or adding it as a project resource. The App does not scan your photo library in the background.
Network diagnostics and logs
The App uses network connections to reach M5Stack services, model services, SkillHub or ClawHub services, MCP servers, and custom services you configure. To support reliability and troubleshooting, the App may generate diagnostic information such as request origin, request method, status code, error type, and data-shape summaries. We aim to avoid logging API keys, authorization headers, cookies, full chat content, large payloads, or binary data.
3. Device Permissions
The App may request the following permissions. You can deny or disable them in your system settings, but related features may stop working.
- Network access: used to connect to M5Stack services, AI model services, device APIs, real-time terminal WebSocket services, SkillHub or ClawHub, MCP servers, and custom endpoints.
- Microphone: used only when you tap voice input to convert speech to text on your device. For example, you can dictate an AI chat prompt with local speech recognition. Voice input will not work without this permission.
- Camera: used only when you choose to attach a photo to an AI chat or import an image resource. For example, you can photograph a device screen or component so the selected AI model can help generate UIFlow2 code.
- Photo library: used only when you choose images to attach to an AI chat or import as project resources. For example, you can select a component photo so the selected AI model can help generate UIFlow2 code. AIFlow does not scan your photo library in the background.
- File selection: used to import projects, resources, Skills, or MCP packages. The App processes only files or folders you select.
4. Local Storage and Credentials
AIFlow stores project indexes, project files, chat records, resource files, Skills, MCP configuration, and model settings in the App's local storage area on your device. It also stores preferences such as language, theme, active project, selected model, client identifier, and cached device information.
Important: API keys are currently stored locally in a base64-encoded form. Base64 is not encryption and should not be treated as secure encrypted storage. Avoid saving highly sensitive credentials on shared, rooted, jailbroken, or otherwise untrusted devices. If you believe a credential has been exposed, revoke or rotate it with the relevant service provider.
5. External Services and Transfers
Some AIFlow features depend on services that you choose to use or configure. When you use those features, relevant information may be sent to:
- M5Stack or AIFlow services: for device pairing, device file management, file preview, resource upload, code push, run operations, and preset Skill downloads.
- AI model services: including Anthropic, OpenAI, Google Gemini, Nano Banana, OpenAI-compatible APIs, Anthropic-compatible APIs, or custom model endpoints you configure, for model listing, chat completion, streaming responses, image understanding, code generation, and tool calls.
- SkillHub, ClawHub, or similar services: for searching, downloading, or synchronizing Skills and MCP packages.
- MCP servers: for calling external tools you enable. MCP requests, responses, and headers may contain sensitive information, so configure only trusted servers.
- Your paired M5Stack device or device proxy service: for file synchronization, code execution, and terminal interaction.
These services may be located outside your country or region. We transmit data only as needed for the feature you use, and we recommend reviewing the privacy policy, data processing terms, and security documentation of any external service you enable.
For third-party services that we choose or integrate directly, we require appropriate privacy and security protections through the relevant service terms or agreements. For model endpoints, MCP servers, or services that you configure yourself, you are responsible for choosing providers you trust and for reviewing their privacy practices before sending data to them.
After data is transmitted to a third-party AI model service, MCP server, custom endpoint, or other external service you choose or configure, that provider controls its own processing, retention, model training, disclosure, and security practices. To the maximum extent permitted by applicable law, M5Stack is not responsible for losses, claims, data use, unauthorized access, API key leakage, privacy leakage, service breach, or other incidents caused by a third-party service, a custom endpoint or MCP server you configure, your account or key management, your device environment, or your decision to submit sensitive data. This does not limit any rights or responsibilities that cannot be excluded by law.
7. Retention and Deletion
Information stored locally in the App is generally retained until you delete the relevant project, chat, file, model configuration, Skill, MCP configuration, or uninstall the App. You can also clear App data through your operating system settings.
Information already sent to third-party model services, MCP servers, M5Stack device services, or other external services is retained according to those services' own policies. You may need to contact the relevant service provider to request access, correction, or deletion.
8. Your Choices and Rights
Subject to applicable law, you may have the following choices and rights:
- Access: view projects, files, chats, model settings, Skills, and MCP configurations in the App.
- Correction: edit project files, project names, device names, model settings, Skills, and MCP configurations.
- Deletion: delete projects, files, chats, device bindings, model settings, Skills, and MCP configurations.
- Withdraw permission: disable microphone, camera, or photo permissions in system settings, remove API keys, authorization headers, and external service URLs from the App, or stop using AI features that send data to a third-party model service.
- Stop using the App: AIFlow currently does not require an AIFlow account. You can stop using it by deleting local data or uninstalling the App.
If you need assistance with information controlled by M5Stack, contact us using the methods listed below. To protect your information, we may need to verify your identity and the scope of your request.
9. Children
AIFlow is intended for users who work with programming, device development, or AI tools. If you are a minor, use the App only with the consent and guidance of a parent or guardian. If you are the guardian of a child, please help ensure that the child does not submit sensitive personal information in prompts, project files, images, or external service configurations.
If we learn that we have processed a child's personal information without appropriate consent where required, we will take reasonable steps to delete it or otherwise address the issue as required by law.
10. Security
We use reasonable technical and organizational measures designed to protect information we process against unauthorized access, disclosure, alteration, or loss. These measures include limiting sensitive content in logs, validating paths and file operations, using HTTPS or the secure transport method you configure where available, and parsing external data defensively.
No Internet or mobile environment is completely secure. Please protect your device passcode, system account, API keys, MCP authorization headers, device pairing codes, and project files. Avoid connecting the App to untrusted networks, model services, or MCP servers.
11. Changes to This Policy
We may update this Privacy Policy to reflect product changes, legal requirements, or security practices. If we make material changes, we will provide notice through the App, the publication page, app store materials, or another reasonable method. Where required by law, we will ask for your consent again.
12. Contact Us
Personal information controller: Shenzhen Mingzhan Information Technology Co., Ltd. (M5Stack)
If you have questions, complaints, suggestions, or requests related to this Privacy Policy or personal information protection, please contact us through the contact methods published on the official M5Stack website, the developer contact information listed on the app distribution platform, or other contact methods provided in the product.
We will respond as soon as reasonably possible after receiving your request and completing any necessary identity verification.