Schema API Flow logo Schema API Flow
Home User Guide Support Privacy Terms
Legal

Privacy Policy

Effective: June 9, 2026 · Last updated: June 9, 2026 (disconnect & browser storage)

This policy explains how Appsrow collects, uses, stores, and protects information when you install, authorize, or use Schema API Flow from the Webflow Apps Marketplace or at app.appsrow.com.

This Privacy Policy applies to Schema API Flow (the “App”), operated by Appsrow (“we”, “us”, “our”), including:

  • App UI: https://app.appsrow.com
  • Product page: https://app.appsrow.com/
  • API & OAuth: https://api.appsrow.com
  • Install: https://api.appsrow.com/auth/install

Who we are

Data controller: Appsrow
Publisher: Appsrow (independent Webflow Marketplace developer — not Webflow, Inc.)
Website: https://appsrow.com
Support: hello@appsrow.com (send email) · Support page

Schema API Flow is published on the Webflow Apps Marketplace (install link). Your use of Webflow’s platform is also governed by Webflow’s Terms of Service and Webflow’s Privacy Policy. Our app’s use of Webflow APIs is subject to the Webflow Developer Terms of Service.

Marketplace install & OAuth

When you install from the Marketplace, you are redirected to Webflow to approve OAuth access. We request only the scopes needed to read and write schema and SEO data on sites you authorize:

  • sites:read — list and identify your sites
  • pages:read / pages:write — read page SEO fields and save updates you request
  • custom_code:read / custom_code:write — attach or remove registered JSON-LD scripts on static pages
  • cms:read / cms:write — read/write CMS fields for collection-item schema
  • authorized_user:read — identify your Webflow user for session management

We do not request payment scopes. Install OAuth is initiated at api.appsrow.com/auth/install; the callback is api.appsrow.com/auth/webflow/callback. After authorization you may see install-complete.html with instructions to open the app in Webflow Designer.

Information we collect

Information you provide

  • Webflow OAuth authorization when you install or connect the App.
  • Email and message content if you contact support.

Information from Webflow (with your permission)

Depending on approved scopes, we may access:

  • Workspace and site identifiers, site names, and domains
  • Page metadata, URLs, SEO fields, and custom code / schema fields
  • CMS collection structure and item field data you select in the App

We access only data needed to provide features you use. We do not read your Webflow password.

Automatically collected

  • Server logs (IP address, timestamps, request paths, error codes) for security and operations
  • Session cookies required for OAuth and keeping you signed in to the App

Schema API Flow is a Webflow Hybrid App (Data Client + Designer Extension). The app UI loads in an iframe inside Webflow Designer; we do not manipulate the Designer canvas directly. We read and write schema and SEO fields only through the official Webflow Data API v2 when you use the app.

Cookies & browser storage

  • Session cookies on api.appsrow.com (and shared domain cookie when configured) to complete OAuth and optional token handoff after Marketplace install.
  • localStorage in your browser may store an app Bearer token (wfApiToken) so the Designer panel stays connected between sessions on the same device.
  • localStorage may also cache non-personal SEO health flags per page (whether title, description, and schema appear present — keys prefixed safPageHealthV1) so the page list can show status immediately while a fresh check runs in the background. This data stays on your device and is cleared when you disconnect.
  • sessionStorage may hold your AI consent choice for the current browser session and a short-lived page-list cache to speed up reloads.
  • We do not use third-party advertising or cross-site tracking cookies in the app.

Custom code and schema on your sites

When you save from the App, we write JSON-LD structured data and related SEO fields to your Webflow pages through the official Data API. For static pages, JSON-LD is attached as a registered inline script via the Custom Code API (Page settings → Custom code → Apps).

For CMS collection items, JSON-LD is stored in a CMS Plain Text field you select. You add a one-time Embed on the Collection template in Webflow Designer (see Support). The App does not call our API from your published pages on each visitor page load and does not collect visitor telemetry from your site.

We do not inject arbitrary or user-supplied executable code. Legacy app scripts on older installs are removed when you save again. You choose when to save and publish.

After uninstall or revoke: Click Disconnect in the App before uninstalling. Disconnect is immediate in the UI; removal of app-registered custom code on authorized sites continues in the background while your OAuth token is still valid. CMS template Embeds you added manually may still need a Designer edit. See Support — Uninstall & custom code.

AI-assisted features

When you run generate actions, excerpts such as page titles, meta descriptions, and content you load may be sent to our AI provider to produce JSON-LD or SEO suggestions. You initiate each generation; we do not train public models on your data.

How we use information

  • Authenticate and connect your Webflow workspace (including when you use Disconnect and connect again to switch account or workspace)
  • Generate, preview, and save schema and metadata at your request
  • Write approved static JSON-LD and SEO fields to your Webflow site when you click Save
  • Operate, secure, monitor, and improve the App
  • Respond to support requests and comply with legal obligations

We do not sell your personal information.

Legal bases (EEA / UK)

Where GDPR applies, we process data based on:

  • Contract — to provide the App you requested
  • Legitimate interests — security, abuse prevention, reliability
  • Consent — where required by law

Third-party processors

  • Webflow, Inc. — OAuth, hosting of your site content, and Data API (Webflow Privacy)
  • OpenAI — when you click Generate in the app, we send page title, description, URL, and schema context to OpenAI to produce SEO or JSON-LD. Data is not sent until you click. We do not use your content to train public models. (OpenAI Privacy)
  • Hosting & database — secure VPS hosting (HTTPS) and MongoDB (or equivalent) for OAuth tokens, app sessions, and operational logs

Processors handle data only to deliver the service and under contractual safeguards where applicable.

Retention, uninstall & deletion

  • OAuth tokens and app session data are kept while you are connected. When you click Disconnect in the App, you are signed out immediately in the UI; we revoke your app token on our servers and remove app-registered custom code on authorized sites in the background while the token remains valid. Local storage (including the app token and cached SEO health flags) is cleared on disconnect.
  • Marketplace uninstall: Revoking the app in Webflow workspace settings ends authorization. Use Disconnect before uninstall when possible. We also accept POST api.appsrow.com/webhooks/uninstall with your app Bearer token for the same cleanup.
  • Schema or Custom Code already published on your Webflow site remains under your Webflow account until you change or remove it; uninstall alone may not remove published markup until you publish again or edit the site.
  • We do not operate a public runtime schema endpoint for visitor page loads. OAuth and app session data are deleted on request or after revoke, subject to limited security log retention.
  • Support emails are retained as needed to resolve inquiries.
  • Request deletion by emailing hello@appsrow.com from your Webflow account email, clicking Disconnect, or revoking the App in Webflow.

Security

We use HTTPS, access controls, and industry-standard practices. No online service is 100% secure; we encourage strong Webflow account security and prompt revocation if you stop using the App.

International transfers

Data may be processed in countries where we or our providers operate. We use appropriate safeguards where required by applicable law.

Your rights

Depending on your location, you may have the right to access, correct, delete, restrict, or object to processing, and to complain to a supervisory authority. Contact hello@appsrow.com.

California residents: We do not sell personal information. You may request access to or deletion of personal information we hold about you by emailing hello@appsrow.com. We will verify requests using your Webflow account email where practical.

Children

The App is not directed to children under 16. We do not knowingly collect their data.

Changes

We may update this policy by posting a new version here and updating the date above. Continued use after the effective date means you accept the updated policy.

Contact

Privacy questions

hello@appsrow.com

Send email

appsrow.com

© 2026 Appsrow · Schema API Flow Privacy · Terms · User Guide · Support · Appsrow