Privacy Policy

Last updated 29 July 2026

Draft, pending legal review

This document is a working draft. It describes what the product actually does today, but it has not yet been reviewed by a lawyer and is not yet binding. Highlighted TODO markers are details only Flowtiq's owners can supply. We will replace this notice with the reviewed version and update the date above.

1Who is responsible

The controller for personal data handled by Flowtiq is TODO: registered legal entity name, at TODO: registered business address. Write to hello@flowtiq.ai about anything in this policy.

TODO: confirm whether a Data Protection Officer or an EU/UK representative is required and, if so, name them here

This policy covers flowtiq.ai and the Flowtiq application. It does not cover Google, LinkedIn, Meta, or Paddle, who each publish their own policy.

2What we collect

Your account. The name, work email, and company name you enter at sign-up, or the name, email address, and profile picture Google returns if you sign in with Google. Your password is hashed by Supabase Auth and we never see it. We also store your role in the workspace (owner, admin, or member), whether you have finished onboarding, and any avatar or company logo you upload.

What you create in the app. Tasks, contacts, deals, pipelines and boards, invoices and their line items, emails and email templates, social posts, meetings, time entries, and notifications.

From a connected Gmail account. For your recent messages: sender, recipients, subject, timestamp, folder, read and starred state, a snippet, and the message body. These are copied into your workspace so the email hub works without calling Gmail on every screen.

From a connected Google Calendar. Event titles, start and end times, attendees, location or meeting link, and the identifiers needed to keep both sides in step.

From a connected LinkedIn or Meta account. The account or Page identifier and display name, and the engagement figures those platforms return for posts you published through Flowtiq.

Connection credentials. The OAuth access and refresh tokens for each account you connect, plus the short-lived value used to protect the connect flow against forgery.

Technical records. Our hosting and database providers log requests, including IP address, user agent, timestamps, and error details, which we use for security, abuse prevention, and debugging.

Billing. Handled entirely by Paddle. We never receive or store card numbers.

We run no advertising or analytics trackers, and we do not buy or sell personal data.

3Why we use it, and our legal basis

  • To run the workspace you signed up for, including syncing and sending mail, syncing your calendar, publishing posts, and producing invoices. Performance of a contract, GDPR Article 6(1)(b).
  • To reach your mail, calendar, or social account. Your consent, given at the provider's own screen and withdrawn by disconnecting the account, Article 6(1)(a).
  • To keep the service secure, prevent abuse, enforce plan limits, debug faults, and improve reliability. Our legitimate interests, Article 6(1)(f).
  • To take payment and keep the records tax law requires. Contract and legal obligation, Article 6(1)(b) and (c).
  • To send you product email you asked for. Consent, withdrawable at any time.

We do not make automated decisions that have a legal effect on you.

4What the AI features send, and where

The AI features are the dashboard assistant, the CRM assistant and deal coach, contact enrichment, follow-up email drafting, brand analysis, and social post generation. They send data only when you use them.

  • Dashboard assistant: a snapshot of your workspace, currently up to 25 open tasks, up to 20 unpaid invoices, your next 10 meetings, your contact count, hours logged in the last 14 days, and your 15 most recent notifications.
  • CRM assistant and deal coach: the contact or deal record you have open, including name, email, phone, company, job title, tags, and notes, plus its recent activity history.
  • The other features: the specific text or record you are working on, such as the email thread being answered or the brand details behind a social post.

That data goes to Google's Gemini models through the Lovable AI gateway. Two commitments hold: your data is not used to train AI models (we pay for the platform plan that guarantees this), and we do not build models of our own from your content. AI output is generated, not verified, so check it before you act on it.

5Who processes data for us

Supabase
Postgres database, authentication, and file storage for the avatars and company logos you upload.
Cloudflare
Hosting and the edge network that serves the app.
Lovable
The platform Flowtiq runs on, and the gateway that routes every AI request.
Google Gemini
Runs the models behind every AI feature.
Google (Gmail, Calendar)
Only if you connect a Google account. Mail and calendar data flows both ways.
LinkedIn
Only if you connect it, to publish posts on your behalf.
Meta (Facebook, Instagram)
Only if you connect it, to list Pages, read engagement, and publish posts.
Paddle
Takes payment as merchant of record and handles sales tax and VAT. We never receive card details.

TODO: confirm the Supabase hosting region, and countersign a data processing agreement with each processor above before launch

TODO: confirm the Paddle go-live date. Paddle is a decided part of the product but is not collecting payments yet.

We also disclose data where the law compels us, and we will tell you when that happens unless we are forbidden from doing so.

6Where your data goes

Our processors are largely United States based, so personal data is transferred outside the UK and EEA. Those transfers rely on the standard contractual clauses and equivalent safeguards in each processor's data processing terms.

TODO: confirm the data residency options each processor offers, and record the choice

7How long we keep it

While your workspace is active we keep your data so the app works. Synced mail and calendar entries stay until you delete them or disconnect the account. Disconnecting an integration deletes the stored tokens for it. When a workspace is closed we delete its data, except records we are required to keep for tax and accounting.

TODO: confirm the exact retention windows: the grace period after a workspace is closed, how long backups persist, and how long request logs are held

8How we protect it

  • Workspace records are scoped to an organisation and isolated by Postgres row-level security, so one workspace cannot read another's data.
  • OAuth access and refresh tokens are encrypted with AES-256-GCM before they are written to the database. The encryption key lives only in server-side configuration.
  • Traffic is served over HTTPS. Passwords are hashed by Supabase Auth.
  • Privileged operations run only in server-side code. The browser never holds a service-level key.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator as the law requires.

9Your rights

If you are in the UK or EEA you can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, or have it sent to another provider, and you can withdraw consent at any time. Email hello@flowtiq.ai and we will answer within one month. You can also complain to your national data protection authority.

TODO: name the lead supervisory authority once the legal entity is registered

Comparable rights apply under other privacy laws. Tell us which one you are relying on and we will honour it.

10Data about other people that you import

The contacts, emails, and invoices you bring into Flowtiq usually describe other people. For that data you are the controller and we act as your processor: we handle it on your instructions and only to run the service. You need your own lawful basis for holding it, and requests from those people come to you first.

TODO: publish a data processing agreement that customers can sign

11Cookies and browser storage

Flowtiq sets no advertising or analytics cookies. What it does keep in your browser:

  • your signed-in session, held in local storage by Supabase Auth rather than in a cookie, so you stay logged in between visits;
  • your light or dark theme choice;
  • small interface preferences, such as the CRM layout you last used and whether a panel was collapsed.

Clearing your browser storage signs you out and resets those preferences. Connecting a Google, LinkedIn, or Meta account sends you to that provider, where their own cookies apply.

12Children

Flowtiq is a business tool and is not intended for children. We do not knowingly collect data from anyone under 16. TODO: confirm the minimum age for the governing jurisdiction

13Changes to this policy

We will update this policy as the product changes. Material changes get notice by email or in the app, and the date at the top always shows the version in force.

14Contact

Privacy questions, requests, and corrections go to hello@flowtiq.ai. The commercial terms are in the Terms of Service.