Privacy Policy

Effective date: April 6, 2026  ·  Last updated: April 6, 2026

Plain English summary: We collect your email and usage data to run Flowki Labs. We don't sell your personal data. You can export or delete your data anytime from Settings. This policy explains the details.

Contents

  1. Who We Are
  2. What We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing (GDPR)
  5. Data Sharing & Sub-processors
  6. International Data Transfers
  7. Data Retention
  8. Your GDPR Rights
  9. California Privacy Rights (CCPA)
  10. Cookies & Tracking
  11. Security
  12. Children's Privacy
  13. Policy Changes
  14. Contact Us

1. Who We Are

Flowki Labs ("Flowki Labs", "we", "us", "our") is an AI-powered process automation platform operated by Flowki Labs. Our service is available at flowkinexus.com.

For GDPR purposes, Flowki Labs is the data controller of your personal data. For questions about this policy, see Section 14.

2. What We Collect

2.1 Account Data

2.2 Process & Automation Data

2.3 Integration Data

When you connect third-party services (Google, Slack), we store encrypted OAuth tokens to act on your behalf. We store only what's necessary and delete tokens immediately on disconnect.

2.4 Usage & Analytics Data

2.5 Waitlist Data

If you submit your email on our waitlist, we store that email and the source of submission.

2.6 Consent Records

We log cookie consent decisions (accept/reject) with timestamp and anonymized IP to maintain compliance records.

3. How We Use Your Data

PurposeData UsedLegal Basis
Provide and operate the serviceAccount data, process data, integration tokensContract performance
Authenticate you and prevent fraudEmail, password hash, IP, session dataContract performance + legitimate interest
Execute your automationsProcess config, integration tokensContract performance
Send transactional emails (e.g. invites)Email addressContract performance
Send product updates and marketingEmail addressConsent (opt-in)
Improve the service and fix bugsUsage data, error logsLegitimate interest
Comply with legal obligationsAs required by lawLegal obligation

5. Data Sharing & Sub-processors

We do not sell, rent, or trade your personal data. We share it only with the following sub-processors to operate our service:

Sub-processorPurposeLocationData Shared
Render (render.com)Web hosting & infrastructureUnited StatesAll app data transits through Render servers
Neon (neon.tech)PostgreSQL databaseUnited States (AWS us-east-1)All structured data (accounts, processes, runs)
Polsia (polsia.com)Platform infrastructure & analyticsUnited StatesAnonymized visitor analytics, subscription management
Anthropic (anthropic.com)AI processing (Claude API)United StatesProcess descriptions you submit for AI parsing
OpenAI (openai.com)AI processing (GPT-4o mini)United StatesProcess descriptions you submit for AI parsing
Google (google.com)OAuth integration (user-controlled)United StatesOnly when you connect Google — OAuth tokens
Slack (slack.com)OAuth integration (user-controlled)United StatesOnly when you connect Slack — OAuth tokens

We may disclose data if required by law, court order, or to protect the safety of users or the public.

6. International Data Transfers

Flowki Labs is operated from the United States. If you are located in the EEA, UK, Switzerland, or another region with data transfer restrictions, your data will be transferred to and processed in the United States.

We rely on the following transfer mechanisms:

By using Flowki Labs, you acknowledge that your data may be transferred to the US. You may withdraw consent at any time by deleting your account.

7. Data Retention

Data TypeRetention PeriodReason
Account data (email, name, password hash)Until account deletionRequired to operate service
Process definitionsUntil deleted by user or account deletionUser's work product
Process run history90 days rolling windowDebugging, analytics; older runs purged automatically
OAuth tokens (Google, Slack)Until disconnected or account deletedRequired for integrations to function
Usage / error logs30 daysSecurity, debugging
Consent records3 yearsRegulatory compliance
Waitlist emailsUntil product launch or deletion requestProduct communications
Team invite tokens7 days from creationSecurity (auto-expired)

When you delete your account, all data listed above is permanently deleted within 30 days, except for consent records retained for legal compliance and anonymized aggregate analytics that cannot be tied back to you.

8. Your GDPR Rights (EEA / UK Users)

If you are in the EEA, UK, or Switzerland, you have the following rights:

To exercise any right: Go to Settings in the app for self-service options, or email us at privacy@flowkilabs.com. We respond within 30 days.

9. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you specific rights.

Categories of Personal Information We Collect

CategoryExamplesCollected?
IdentifiersName, email address, IP addressYes
Personal info (Cal. Civ. Code 1798.80)Name, email addressYes
Internet / network activityBrowsing history within app, feature usageYes
Inferences drawnAutomation preferences, feature patternsYes (internal only)
Financial informationCredit card, bank accountNo (handled by Stripe)
GeolocationPrecise locationNo
BiometricFingerprints, face IDNo
Sensitive personal informationSSN, health data, etc.No

Do We Sell or Share Personal Information?

No. Flowki Labs does not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising.

However, if you would like to formally opt out of any future sale or sharing of your personal information, use the link below:

Do Not Sell or Share My Personal Information →

Your California Rights

To exercise California rights, email privacy@flowkilabs.com or use the self-service options in Settings. We respond within 45 days (extendable to 90 days with notice).

10. Cookies & Tracking

Essential Cookies

We set one essential cookie: your authentication token stored in localStorage under the key lc_token. This is required to keep you logged in. It cannot be disabled without breaking the service.

Analytics

With your consent, we use Polsia Analytics (a first-party, privacy-focused analytics tool) to count page visits and track feature usage. This sets a polsia_vid identifier in localStorage. No data is shared with third-party advertising networks.

Managing Cookies

When you first visit, a cookie consent banner gives you the choice to accept or reject non-essential analytics. You can change your preference at any time in Settings → Privacy Preferences.

You can also clear cookies and localStorage through your browser settings. Note that clearing lc_token will log you out.

11. Security

Despite these measures, no system is 100% secure. If you discover a security vulnerability, please email security@flowkilabs.com.

12. Children's Privacy

Flowki Labs is not directed to children under 16 (or 13 in the US). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will delete it promptly.

13. Policy Changes

We may update this policy from time to time. Material changes will be communicated via email (if you have an account) or a notice on our website at least 14 days before taking effect. The "last updated" date at the top of this page reflects the most recent version.

Continued use of Flowki Labs after the effective date constitutes acceptance of the updated policy.

14. Contact Us

Privacy Inquiries

For data requests, privacy questions, or to exercise your rights:

📧 privacy@flowkilabs.com

For GDPR-specific inquiries from EEA residents:

📧 dpo@flowkilabs.com

We aim to respond to all privacy requests within 30 days. For complex requests, we may extend this by an additional 60 days with written notice.