Privacy policy for DiFlowRin Research
Applies to the DiFlowRin Research app for Windows · Last updated 26 September 2026
The short version
Your research stays on your PC. Your questions, notes, PDFs and reports are saved in a folder on your computer, and we never receive them. The app has no account, no cloud storage, no analytics, no telemetry and no ads.
We receive only what licensing needs: a random install ID when you claim your free report, and your licence key when you use a paid licence. If you buy, Gumroad tells us your email address so we can issue the licence.
To do the research, the app sends your question and the material it analyses to the AI provider you chose (Anthropic or OpenRouter) under your own account, and it fetches sources from websites and scholarly databases. Those requests go straight from your PC to those services, not through us.
Who we are and how to contact us
DiFlowRin Research is published by Dragan Florin, an independent software developer trading as Diflowrin, based in Arad, Romania. Diflowrin is a trading name, not a separate company. In the Microsoft Store the publisher is shown as Ns5. For the purposes of the EU General Data Protection Regulation (GDPR), Dragan Florin is the controller of the personal data described in the licensing and payments sections below.
- Email: admin@diflowrin.com
- Phone: +40 757 465 012
- Web: diflowrin.com
There is no Data Protection Officer. The app is made by one person, and that person answers privacy requests directly at the address above.
This policy covers the app and its licensing. The diflowrin.com website has its own policy, which covers the contact form and the website itself: diflowrin.com/privacy-policy. The product page for this app sets no cookies and loads nothing from other websites.
What stays on your computer
Everything below is stored only on your PC. None of it is sent to us.
- Your research library: notes, downloaded web pages and PDFs, reports and run logs, saved in a folder on your PC. Uninstalling the app or deleting its data folder removes them.
- A run report that measures the time and cost of each step. It is written to a local file and never sent anywhere.
-
Keys and settings in Windows Credential Manager, Windows' own encrypted
store, never in plain files:
- your Anthropic (Claude) API key, if you add one;
- your OpenRouter API key, if you add one;
- optional keys for sources and search: OpenAlex, CORE, FRED, Voyage AI, OpenAI;
- an optional contact email for scholarly sources (explained below);
- your licence key, if you bought one.
- Browser sign-in profiles. If you choose to sign in to a website (for example a paywalled news site) through the app's visible browser, that site's cookies are saved in a local browser profile on your PC. We never see them.
-
A random install ID: 32 hexadecimal characters in a local file named
device-id.json. It is random, not derived from your hardware, and contains no personal information. - The signed licence token our server sends back (see the next section).
What we receive: licensing only
The app contacts our licence server at diflowrin.com in two situations, and
sends only these fields:
research, so the free report
is given once per PC.
research,
to check that the licence is valid and to count how many PCs use it.
The server answers with a signed token, which is stored on your PC. Like any web request, each of these also reaches us with your IP address and your app's user-agent (a short technical description of the software making the request).
What the licence server keeps, and for how long
Legal basis: licence checks are needed to provide the licence you bought (performance of a contract, GDPR Art. 6(1)(b)). Logs, the check history and the free-report record serve our legitimate interest in keeping the service secure and in preventing abuse of the free report (Art. 6(1)(f)).
Payments (Gumroad)
Licences are sold through Gumroad. Gumroad collects your name, email address and payment details under its own privacy policy. We receive from Gumroad your email address and the status of your purchase, and we use them to issue and check your licence. Your email address is also included inside the signed licence token stored on your PC. We never see your card details.
Third-party services the app connects to
These requests go directly from your PC to each provider, not through us. Each provider handles what it receives under its own terms and privacy policy.
- Anthropic (Claude), through Claude Code, or OpenRouter. Your research question and the source material being analysed are sent to the AI provider you chose, under your own account. Usage is billed by that provider, not by us. (Anthropic privacy policy, OpenRouter privacy policy)
- Websites and scholarly databases. To collect sources, the app requests pages from websites and from OpenAlex, CORE, DOAB, RePEc, Unpaywall, Europe PMC, ClinicalTrials.gov, SEC EDGAR, FRED and similar services. They see your IP address and the search terms or page address, as with any web visit.
- Your contact email (optional). Unpaywall and SEC EDGAR require a contact email in every request. If you enter one in Settings, it is sent to those services with each request.
- Embedding providers (optional). If you add a Voyage AI or OpenAI key for semantic search, text from your notes is sent to that provider to compute search vectors.
- Downloads you start. The “Install Claude Code” button downloads Anthropic's official installer from claude.ai. The visible browser feature downloads Google Chrome for Testing through Playwright the first time you use it.
- Microsoft Store. Microsoft handles distribution and updates of the app under the Microsoft Privacy Statement.
What we don't do
- No analytics, telemetry or crash reporting. The app sends us nothing about how you use it.
- No accounts and no cloud storage. We never receive your questions, notes, PDFs or reports.
- No selling or sharing. We do not sell or share personal data, and we do not use it for advertising.
- No ads, in the app or on its product page.
Your rights, and how to delete your data
Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or deleted, to object to its processing, and to receive it in a portable form. We hold very little: at most your purchase email, your licence record and the licensing records described above. Send requests to admin@diflowrin.com; we answer within 30 days. If a licence record is deleted, that licence stops working.
You can also complain to a data protection authority. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP); you can also contact the authority in the EU country where you live.
Deleting what is on your PC
- Uninstall the app and delete its data folder. This removes your library, logs, the install ID and browser profiles.
-
Remove your keys with the Clear buttons in Settings, or in Windows
Credential Manager, where the entries are named
xyz.diflowrin.research.
Security
Your keys are kept in Windows Credential Manager, not in plain files. Licence traffic between the app and our server uses HTTPS. Licence tokens are cryptographically signed, so they cannot be altered without detection.
Children
The app is not directed at children under 16 and we do not knowingly collect personal data from them.
Changes to this policy
If the app or its licensing starts handling data in a way this page does not describe, this page is updated first and the “Last updated” date at the top changes with it.
DiFlowRin Research is independent and is not affiliated with or endorsed by Anthropic, OpenRouter, Microsoft or Gumroad.