Effective Date: 2026-08-02
Last Updated: 2026-08-02
This Privacy Policy explains how flowtoid ("we", "us", "our") collects, processes, stores, and protects your personal data when you use the flowtoid web application and related services (collectively, the "Service"). flowtoid is an AI agent orchestration platform that enables users to configure autonomous agents, connect external services (Telegram, GitHub, HTTP endpoints, and custom Model Context Protocol servers), and automate tasks via LLM providers.
We are committed to transparency and full compliance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR").
The data controller responsible for your personal data under the GDPR is:
[INSERT FULL LEGAL NAME]
[INSERT STREET ADDRESS]
[INSERT CITY, POSTAL CODE, COUNTRY]
Email: adambartos.dev@proton.me
Representative (if applicable): [INSERT NAME AND CONTACT]
If you have any questions about this policy or wish to exercise your data protection rights, please contact us at the email address above.
We process your personal data under the following legal bases pursuant to Article 6(1) GDPR:
| Data Category | Legal Basis | Purpose |
|---|---|---|
| Account data | Contract (Art. 6(1)(b)) | Account creation, authentication, personalization |
| API keys & connector secrets | Contract (Art. 6(1)(b)) | Integration functionality you requested |
| Agent configurations & results | Contract (Art. 6(1)(b)) | Core agent orchestration service |
| Memory / conversation history | Contract (Art. 6(1)(b)) | Context-aware agent operation |
| Uploaded files | Contract (Art. 6(1)(b)) | File-based agent operations |
| Runtime data (webhooks, Telegram) | Contract (Art. 6(1)(b)) | Trigger processing and agent execution |
| Webhook keys | Contract (Art. 6(1)(b)) | Routing inbound automation events |
| IP addresses & technical logs | Legitimate Interest (Art. 6(1)(f)) | Security monitoring and debugging |
We do not process special categories of personal data (Art. 9 GDPR) as a matter of design. However, if you choose to upload files or send prompts containing sensitive data, you do so voluntarily and are responsible for ensuring you have the necessary rights to do so.
Your data is used exclusively to provide and improve the Service:
We do not sell your personal data to third parties, use your data for advertising or marketing purposes, or share your data with third parties except as necessary to provide the Service (see Section 7).
| Data Type | Retention |
|---|---|
| Account data | Until you delete your account |
| API keys & connector secrets | Until you delete them or your account |
| Agent configurations | Until you delete the agent |
| Memory / conversation history | Until you delete the agent or manually reset it |
| Agent execution results | Until you delete the agent or the specific result |
| Trigger configurations | Until you delete the trigger |
| Uploaded files | Until you delete the file |
| Runtime data (webhooks, Telegram) | Transient — cleared after execution |
| Server logs | Indefinite (see Section 15 for change notice) |
You are responsible for managing your data lifecycle. We recommend periodically reviewing and deleting agents, connectors, triggers, and files you no longer need.
Role: LLM inference and audio transcription provider.
Data transferred: Prompts, system prompts, conversation memory, runtime data, audio data (base64-encoded), and your OpenRouter API key.
Transfer mechanism: HTTPS API (https://openrouter.ai/api/v1).
Safeguards: OpenRouter acts as an independent data controller for its own processing.
Role: Messaging platform for inbound triggers and outbound message delivery.
Data transferred: Bot tokens, target user IDs, outbound message text, and (temporarily) voice message files.
Transfer mechanism: HTTPS Bot API (https://api.telegram.org).
Role: Code repository integration for reading, creating, editing, and deleting files.
Data transferred: GitHub personal access tokens, repository URLs, file contents, and commit messages.
Transfer mechanism: HTTPS GitHub API (https://api.github.com).
Role: User-defined external tool servers connected via the Model Context Protocol.
Data transferred: User-defined authentication headers, tool arguments, and tool results.
Transfer mechanism: HTTP or Server-Sent Events (SSE) to URLs you provide.
jsDelivr: Delivers static JavaScript libraries (HTMX, AlpineJS, Tailwind). May log IP addresses.
Google Fonts: Delivers web fonts. May set cookies and log IP addresses. See our Cookie & Tracking Policy for details and opt-out mechanisms.
We implement the following technical and organizational security measures:
No method of electronic storage or transmission is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
You have the following rights regarding your personal data:
Right of Access (Art. 15)
You may request confirmation of whether we process your personal data and, if so, a copy of that data together with information about the processing purposes, categories of data, recipients, retention periods, and your rights.
Right to Rectification (Art. 16)
You may request correction of inaccurate personal data or completion of incomplete data.
Right to Erasure / "Right to be Forgotten" (Art. 17)
You may request deletion of your personal data. You can delete individual agents, connectors, triggers, files, and results through the Service interface. To request full account deletion, contact us at adambartos.dev@proton.me. We will delete your account and associated data within 30 days, except where we are required to retain certain data for legal or security purposes.
Right to Restriction of Processing (Art. 18)
You may request that we limit processing of your data in certain circumstances (e.g., while we verify accuracy).
Right to Data Portability (Art. 20)
You may request your personal data in a structured, commonly used, machine-readable format (JSON). To request a data export, contact us at adambartos.dev@proton.me.
Right to Object (Art. 21)
You may object to processing based on legitimate interests (Art. 6(1)(f)). To object, contact us at adambartos.dev@proton.me.
Right to Withdraw Consent
Where we process data based on consent (if applicable in future features), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
To exercise any of the above rights, please contact us at adambartos.dev@proton.me with the subject line "GDPR Request — [Right Name]". We may request verification of your identity before processing your request. We will respond within one month of receipt (extendable by two further months where necessary, and we will inform you of any such extension).
In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and we will inform you without undue delay where required by GDPR Art. 34.
You may delete the following at any time through the Service: Agents (and their associated memory, results, and runtime data), Connectors, Triggers, Files, and your OpenRouter API key.
To delete your account and all associated data, contact adambartos.dev@proton.me. Account deletion will remove your user record, all agents, connectors, triggers, files, results, and any other linked data.
Server logs (IP addresses, request metadata) are retained indefinitely unless we configure automated log rotation. We will update this policy once automated rotation is implemented.
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States (OpenRouter, GitHub) and the United Arab Emirates (Telegram). Where such transfers occur, we rely on the necessity of the transfer for the performance of a contract between you and us (Art. 49(1)(b) GDPR).
You are advised that some non-EEA countries may not provide the same level of data protection as the EEA.
The Service uses LLM-based agents to process your inputs and generate outputs. This constitutes automated decision-making in a broad sense. However:
If you believe an automated output has adversely affected you, please contact us so we can review and, if necessary, remove or correct the output.
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately.
We may update this policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated policy on the Service and update the "Last Updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
For privacy-related inquiries, data subject requests, or concerns about this policy, please contact:
[INSERT FULL LEGAL NAME]
Email: adambartos.dev@proton.me
Postal Address: [INSERT FULL ADDRESS]
You may also contact your local data protection supervisory authority.