Skip to content
FLOWPILOTS

Privacy policy

Updated 2026-07-30

The short version: your data stays yours. We never sell it, and we never train any model on it. You approve every action the cockpit takes.

This policy says what FlowPilots collects, why, and the controls you hold.

What FlowPilots collects

  • Account basics: your name, email address, and a hashed password (or your Google identity, where Google sign-in is offered).
  • Two-factor sign-in data: the authenticator secret and recovery codes that verify it is you. They protect your account and are used for nothing else.
  • What you create in the cockpit: organizations, squadrons, members, invitations.
  • Session cookies that keep you signed in. There are no advertising trackers.
  • Operational records: server logs and an audit trail of account actions.
  • Error and product telemetry (Sentry, and PostHog on EU Cloud behind a first-party proxy), where we have turned them on.

Connected tools

When you connect a tool, FlowPilots reads only what you authorize. Connectors are read-only wherever the job allows and request the narrowest scope that works. FlowPilots holds tokenized references issued by each provider, never your passwords and never full account or card numbers. Content read from a connected tool is treated as data, never as instructions, and no action that reaches outside the cockpit runs without your in-app approval. Disconnecting a tool purges what it ingested.

How data is protected

  • Encrypted in transit and at rest.
  • Isolated per organization at the database layer.
  • Never sold, never shared for advertising, never used to train any model.

Where your data lives

The whole path your work takes through FlowPilots runs in the EU. Recorded as of 30 July 2026; each leg below is a decision of record.

  • The store: Postgres, in Frankfurt.
  • The compute over it: the functions that read your data, in Frankfurt.
  • The model that reads it: an EU inference endpoint, by default.
  • Product analytics: EU Cloud, in Frankfurt.

One leg is not ours to place: the tools you connect run where their own providers run them, so FlowPilots does not count that leg as its own. What the cockpit keeps from what it reads is stored in the EU, on the path above.

This promise is scoped on purpose: it covers your accounts, your messages, and the model that reads them. The CRM FlowPilots runs its own sales on is a separate system on an EU portal, held to the same standard, and this promise is not stretched to cover it.

Your controls

  • When you connect a tool, you can disconnect it in one click and its ingested data is purged.
  • Write to support@flowpilots.io to export your data or have your account deleted.

Changes and contact

Changes are posted at this address. Questions and requests go to support@flowpilots.io.