Security & API Guidelines
Last updated August 7, 2026.
Where things stand today: our Make.com templates don't run on any SmartSoloFlow infrastructure — your credentials and data stay entirely inside your own Make.com account. Our planned SaaS tools will have their own security architecture, described honestly below as it's actually built, not before.
Make.com Templates — Today
Our templates are automation logic only — JSON scenario files you import into your own Make.com account. SmartSoloFlow doesn't host, store, or process any of the payload data, webhook traffic, or API credentials that flow through a template once you've connected it. That data — and its security — lives entirely within your own Make.com account and whichever third-party services you connect (OpenAI, Google Ads API, Slack, Airtable, and similar). Each of those services has its own security practices, independent of us.
Traffic to our own website and support portal is encrypted over HTTPS, and we don't store payment details — those are handled entirely by Gumroad, Whop, or their payment processor.
Planned SaaS Tools — Not Yet Built
SmartSoloFlow is developing a suite of AI-powered SaaS tools. As of this writing, none of them are built, so there's no live infrastructure, encryption implementation, or data-isolation system to describe yet — and we'd rather tell you that plainly than publish claims we can't back up. Once a tool is genuinely built, we'll document its actual security measures here — real specifics, not a generic template. Reasonable baseline expectations you can hold us to as these tools launch: encrypting stored credentials, encrypting data in transit, and keeping each customer's data logically separate from others'.
Google API & Ecosystem Compliance
For workflows that interface with Google services — including the Google Ads API and Google Keyword Planner API — SmartSoloFlow's use and transfer of information adheres to the Google API Services User Data Policy, including its Limited Use requirements:
- Scoped access: OAuth scopes are requested only for the specific actions a workflow needs — nothing broader.
- No data resale: Google API user data is never sold, rented, or shared with data brokers or advertising networks.
- No AI/ML training: data retrieved via Google APIs is never used to train, tune, or improve any AI or machine learning models.
Reporting a Security Issue
If you've found a security issue or have a question about how we handle credentials or data, please report it through our support portal rather than disclosing it publicly — we'll follow up directly.
Changes to This Page
We may update, amend, or change this page at any time, at our sole discretion, without prior notice to individual users — including as our SaaS tools move from planned to built. The revised version will be posted here with an updated "Last updated" date.