Effective: June 9, 2026 · Last updated: June 9, 2026 (disconnect & browser storage)
This policy explains how Appsrow collects, uses, stores, and protects information when you install, authorize, or use Schema API Flow from the Webflow Apps Marketplace or at app.appsrow.com.
This Privacy Policy applies to Schema API Flow (the “App”), operated by Appsrow (“we”, “us”, “our”), including:
Data controller: Appsrow
Publisher: Appsrow (independent Webflow Marketplace developer — not Webflow, Inc.)
Website: https://appsrow.com
Support: hello@appsrow.com
(send email) ·
Support page
Schema API Flow is published on the Webflow Apps Marketplace (install link). Your use of Webflow’s platform is also governed by Webflow’s Terms of Service and Webflow’s Privacy Policy. Our app’s use of Webflow APIs is subject to the Webflow Developer Terms of Service.
When you install from the Marketplace, you are redirected to Webflow to approve OAuth access. We request only the scopes needed to read and write schema and SEO data on sites you authorize:
sites:read — list and identify your sitespages:read / pages:write — read page SEO fields and save updates you requestcustom_code:read / custom_code:write — attach or remove registered JSON-LD scripts on static pagescms:read / cms:write — read/write CMS fields for collection-item schemaauthorized_user:read — identify your Webflow user for session management
We do not request payment scopes. Install OAuth is initiated at
api.appsrow.com/auth/install; the callback is
api.appsrow.com/auth/webflow/callback. After authorization you may see
install-complete.html with instructions to open the app in Webflow Designer.
Depending on approved scopes, we may access:
We access only data needed to provide features you use. We do not read your Webflow password.
Schema API Flow is a Webflow Hybrid App (Data Client + Designer Extension). The app UI loads in an iframe inside Webflow Designer; we do not manipulate the Designer canvas directly. We read and write schema and SEO fields only through the official Webflow Data API v2 when you use the app.
api.appsrow.com (and shared domain cookie when configured) to complete OAuth and optional token handoff after Marketplace install.wfApiToken) so the Designer panel stays connected between sessions on the same device.safPageHealthV1) so the page list can show status immediately while a fresh check runs in the background. This data stays on your device and is cleared when you disconnect.When you save from the App, we write JSON-LD structured data and related SEO fields to your Webflow pages through the official Data API. For static pages, JSON-LD is attached as a registered inline script via the Custom Code API (Page settings → Custom code → Apps).
For CMS collection items, JSON-LD is stored in a CMS Plain Text field you select. You add a one-time Embed on the Collection template in Webflow Designer (see Support). The App does not call our API from your published pages on each visitor page load and does not collect visitor telemetry from your site.
We do not inject arbitrary or user-supplied executable code. Legacy app scripts on older installs are removed when you save again. You choose when to save and publish.
After uninstall or revoke: Click Disconnect in the App before uninstalling. Disconnect is immediate in the UI; removal of app-registered custom code on authorized sites continues in the background while your OAuth token is still valid. CMS template Embeds you added manually may still need a Designer edit. See Support — Uninstall & custom code.
When you run generate actions, excerpts such as page titles, meta descriptions, and content you load may be sent to our AI provider to produce JSON-LD or SEO suggestions. You initiate each generation; we do not train public models on your data.
We do not sell your personal information.
Where GDPR applies, we process data based on:
Processors handle data only to deliver the service and under contractual safeguards where applicable.
POST api.appsrow.com/webhooks/uninstall with your app Bearer token for the same cleanup.We use HTTPS, access controls, and industry-standard practices. No online service is 100% secure; we encourage strong Webflow account security and prompt revocation if you stop using the App.
Data may be processed in countries where we or our providers operate. We use appropriate safeguards where required by applicable law.
Depending on your location, you may have the right to access, correct, delete, restrict, or object to processing, and to complain to a supervisory authority. Contact hello@appsrow.com.
California residents: We do not sell personal information. You may request access to or deletion of personal information we hold about you by emailing hello@appsrow.com. We will verify requests using your Webflow account email where practical.
The App is not directed to children under 16. We do not knowingly collect their data.
We may update this policy by posting a new version here and updating the date above. Continued use after the effective date means you accept the updated policy.