Privacy Policy
Last updated: 5 August 2026
What we collect
When you create a Flowa account we store your email address (via AWS Cognito) and, optionally, two-factor authentication settings. To power the "active sessions" list in your settings — so you can review and sign out devices — we keep a record of each device you sign in from: its browser/OS, the IP address of that sign-in and an approximate city derived from it, and the sign-in time; these session records are deleted automatically after 40 days. When you connect a channel — Telegram, Slack, WhatsApp, Teams or Discord — we store the bot's name and its access token; the token is encrypted with a dedicated AWS KMS key the moment it arrives and is never displayed or logged afterwards.
If you share a bot template with another Flowa user, the recipient sees who it came from: your profile name or, if you have not set one, your account email — both in their "Shared with me" list and in the notification about the share. Picking a recipient works by searching registered account emails, so another user who types your exact email can see that a Flowa account with it exists.
Email we send you
We use your account email for two things: account mail (sign-up verification, password reset) and notifications about your own bots — a bot failure, a plan limit, a billing issue, and, if you keep it on, a weekly summary. You control the notification classes and channels in your notification settings; the weekly summary contains a one-click unsubscribe link in every email. Transactional messages (verification, reset, "your bot is down", billing) cannot be unsubscribed from, because they are how the service tells you something you need to know. To keep delivery working we also process delivery events from our email provider (Amazon SES): if a message to your address bounces or you mark one as spam, we record that status against your account and stop sending to that address.
End-user data your bots collect
Answers that people send to your bot (for example replies to Question steps) are stored so your scenarios can use them, together with a chat identifier. Chat state expires automatically after 30 days of inactivity. You are the controller of this data; Flowa processes it on your behalf to run the bot you designed.
If your bot uses an AI assistant with a knowledge base, and it cannot answer a question from that knowledge base, we log the wording of the question so you can see which topics your knowledge base is missing. We store the question text only — never who asked it (no chat or user identifier is attached) — and these knowledge-gap entries expire automatically after 30 days.
If your bot offers a referral programme, we store which chat invited which — the inviting chat and the new chat, by their chat identifiers — so referral counts work. This linkage is kept while the bot uses referrals.
So you can see what your bot has been doing, we keep an activity log of its events — messages received, replies sent, actions run, moderation decisions and errors — each with the chat identifier it belongs to. Both the message a person sent and the reply your bot sent back are stored as text previews of up to 500 characters each, not in full; a moderation entry also records the affected participant's username, and — where the decision came from the AI classifier rather than one of your own rules — the reason it gave. Where a reply was produced by an AI assistant, we additionally record whether it was based on your knowledge base and which of your documents it drew on, so you can check why the bot answered as it did. Every activity entry expires automatically after 14 days.
In group chats where you have switched moderation on, we count who replies to whom, so you can see how your community interacts and spot coordinated spam. These records hold participant identifiers and counts only — never message text, usernames or forwarded metadata — and they are aggregated: we store how many times one participant replied to another on a given day, not the individual messages. They are kept for 30 days and are collected only in chats where your moderation rules are active; a chat with no moderation configured produces no such records at all.
What we do not do
- We do not sell or share personal data with advertisers.
- We do not read your bot conversations except as needed to operate the service.
- We do not use marketing or analytics cookies. Signing in to the dashboard sets strictly-necessary session cookies (they keep you signed in and protect against request forgery); the site itself keeps only a theme preference locally.
Payments
Paid subscriptions are processed by Paddle as merchant of record. Your payment details go to Paddle directly and never touch Flowa servers. See Paddle's privacy policy for details.
Where data lives
All data is stored in Amazon Web Services (region eu-central-1, Frankfurt) encrypted at rest.
Your rights
You can delete a bot at any time — its token and scenario are removed. To delete your account and all associated data, or to exercise any GDPR right, contact us at support@flowa.click. We answer within 30 days.