Graphwell for Webflow: Privacy Policy
Last updated: October 1, 2026
Graphwell is a Webflow app made by Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA (hello@greatwork.company). This policy covers what Graphwell collects, why, where it goes, how long we keep it and how to delete it.
What Graphwell stores
| What | Why | Kept for |
|---|---|---|
| Your site's Webflow access token, encrypted (AES-256-GCM) | To read your collections, items and pages and to write the one field Graphwell adds | Until you remove Graphwell, uninstall it or revoke access; then deleted |
| Site id, workspace id, site name and published domains | To apply your plan and to build page URLs in the markup | As long as Graphwell is connected |
| Settings: your organization's name, logo address and website, and which domain page URLs use | Publisher and provider details in the markup | Until you remove Graphwell |
| Mappings: for each collection you map, the schema type and where each property comes from (field names, and any fixed values or templates you typed), plus the id of the field Graphwell added | To build the markup the way you set it | Until you stop syncing the collection or remove Graphwell |
| A SHA-256 fingerprint of the markup written to each item, and when | To skip items whose markup hasn't changed | With the mapping |
| Page schemas: the page, the type, the values you typed (for example your address, opening hours or FAQ text for that page) and the built markup | So you can edit and copy them again | Until you delete them or remove Graphwell |
| Live check results: for each page read, its address, the schema types found, and the problems (issue codes and messages) | The Live check tab | The last 12 checks per site |
| Server request logs: time, method, path, status, duration | Security and troubleshooting | 30 days. Not logged: query strings, tokens, request bodies |
What we don't store. No CMS item content (Graphwell reads your items to build their markup, writes the markup to your own CMS field and keeps only a fingerprint of it), no page HTML (the live check reads your published pages, extracts the schema blocks and keeps only its findings), and no visitor data of any kind. Graphwell adds no code, banner or cookies to your published site, and calls no AI service.
Personal data, in short. Your Webflow user email (from Webflow's sign-in, for receipts), and anything personal in the values you type (for example a contact phone number) or in your CMS content that the markup carries (an author's name). We don't sell personal data, don't use it for advertising, don't use it to train AI models and don't send it to any AI service. For personal data in your site, you are the controller and Great Work is your processor (Terms, section 6).
Third parties and every domain Graphwell talks to
| Domain | Who | What |
|---|---|---|
| api.webflow.com, webflow.com | Webflow, Inc. | Your site's collections, items and pages through the Data API; writing the Schema JSON-LD field and publishing items when you allow it; the sign-in (OAuth) screen |
| Your site's published domain | You | The live check: reads the published home page, pages with a saved schema and a sample of item pages when you press Check (GraphwellBot) |
| addons.greatwork.company | Great Work LLC (our server, hosted at DigitalOcean, New York) | Graphwell's backend, and our licensing service (your site id, workspace id and verified email, to run your trial and plan) |
| checkout.stripe.com, billing.stripe.com | Stripe, Inc. | Payment and billing, only when you click a plan or Manage billing. Stripe holds your card details; we never see them |
| greatwork.company | Great Work LLC | Product page, documentation and this policy |
Our server runs on DigitalOcean (United States). Data is encrypted in transit (TLS) everywhere and the token is encrypted at rest.
Retention and deletion
- Remove Graphwell (Settings) revokes the Webflow token and deletes everything Graphwell stored for your site at once: settings, mappings, fingerprints, page schemas and check results. The Schema JSON-LD fields in your CMS and the markup in them are your content and stay; delete the field in Webflow if you want it gone, or use Stop syncing with "empty the field" first.
- Uninstall or revoke access in Webflow: we delete the token and your site's data the next time Webflow tells us the access is gone (on our next request or hourly sync, and at the latest by the next daily check).
- If your trial or plan ends, syncing stops and nothing is deleted for 30 days. After 30 days without a plan, everything Graphwell stored for the site is deleted.
Your rights
Depending on where you live (for example the EU, UK or California), you can ask to access, correct, delete or export your personal data, and object to or restrict its use. Email hello@greatwork.company; we answer within 30 days. For data we process for a site owner, we pass your request to them. Our legal basis for your account data is the contract with you and our legitimate interest in keeping the service secure.
Children
Graphwell is a business tool and isn't meant for children under 16.
Changes
We'll post changes here and update the date above. If a change matters, we'll say so in the app.
Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company