1. Who is responsible for your data
This service is operated by Flowtrix Private Limited, 2nd Stage, 13th Cross Road, Indiranagar, Binnamangala, Bengaluru, Karnataka 560038, India. GSTIN 29AAGCF9453R1ZL.
Flowtrix Private Limited is the data controller for your account data. For any privacy request, access, export, correction or deletion, contact [email protected]. We answer within one month.
2. Two different relationships
This matters more than anything else on the page, so it comes first:
- Your account data: we are the controller. Your name, email, password and billing details. We decide how these are handled, and this policy explains it.
- Your content and your visitors' data: we are your processor. The pages, entries, media and above all the form submissions collected on sites you publish. That data belongs to you. We process it on your instructions, never for our own purposes. You are the controller there, so you decide the lawful basis, you tell your own visitors what you collect, and you answer their requests. We help you do it.
3. Data we collect
- Account data: your name, email address, and a one-way hash of your password. If you sign in with Google or GitHub we store the identifier that provider returns. If you enable two-factor authentication or a passkey, we store the credential needed to verify it.
- Content you create: pages, content models, entries, media files and forms. This is free-form, so it may contain personal data you choose to put there.
- Form submissions: when you publish a form, we store what your visitors send to it, on your behalf. See section 2.
- AI assistant conversations: the prompts and replies exchanged with the AI features, including anything you paste into them. See section 6.
- Site analytics: pseudonymised, with no stored IP address. See section 8.
- Operational logs: server access logs, which include IP address and browser user-agent, used to run and secure the service.
- Billing data: subscription and plan information. Card details go straight to our payment processor and never reach us.
4. Where your data is processed
- Your account and content: European Union (Finland)
- Uploaded files and site assets: Cloudflare's global network
- Transactional email: India
- AI features: United States
5. Who else sees your data
These are our sub-processors. Each is linked to its own GDPR or privacy terms, so if you need to know how a particular provider handles data you can go straight to their document:
| Provider | Why we use them | What they receive | Region | Their terms |
|---|---|---|---|---|
| Hetzner Online GmbH | Hosting infrastructure | Data stored by the service, at rest | European Union (Finland) | Hetzner privacy & GDPR |
| Cloudflare, Inc. | Content delivery, network and bot protection, file storage | Request traffic including IP addresses; uploaded files | Global network | Cloudflare GDPR |
| Zoho Corporation (ZeptoMail) | Transactional email: verification, password reset, invitations, notifications | Recipient email address and message content | India | Zoho GDPR |
| Baseten Labs, Inc. | AI model inference | Prompt content, which may include your content | United States | Baseten privacy |
| Anthropic PBC | AI model inference | Prompt content, which may include your content | United States | Anthropic privacy & GDPR |
| Dodo Payments | Subscription billing and payment processing | Billing identity and payment details. Card data never reaches our systems | See provider terms | Dodo Payments privacy |
| GitHub, Inc. (Microsoft) | Source-repository integration, only if you connect one | Repository contents and your GitHub account identity | United States | Microsoft/GitHub GDPR |
| Google LLC | Google sign-in, and spreadsheet export only if you connect it | Your Google account identity; exported form data if you enable that export | United States | Google GDPR |
We are an Indian company hosting in the EU, and we state both rather than letting the EU hosting imply an EU company. Personal data crosses borders in three ways: our team administers the service from India, transactional email is processed in India, and AI inference is processed in the United States. Where data leaves the European Economic Area we rely on the appropriate Article 46 safeguards, primarily Standard Contractual Clauses. The GDPR page sets this out in full, including our establishment and EU representative position.
We do not sell your personal data, and we do not share it for advertising.
6. AI features, and what to consider before using them
When you use an AI feature, the relevant content, your prompt plus the pages or entries it works on, is sent to a third-party model provider to generate a response. Conversations are stored against your workspace so you can return to them, and they are isolated to your workspace.
Practically: do not paste anything into the AI assistant that you would not want processed by those providers. We would rather say that plainly than bury it in a list of service providers.
7. Why we are allowed to process it
- Contract: to provide the service you signed up for.
- Legitimate interests: to secure, maintain and improve the service, and to prevent abuse.
- Consent: where required, for example optional communications. You can withdraw it at any time.
- Legal obligation: to meet accounting and compliance duties.
8. Cookies, and why there is no cookie banner
Cookies are usually sorted into three buckets. Here is where we stand on each:
Necessary: yes
- Sign-in. A cookie that keeps you signed in, so each request is recognised as yours. Without it the application cannot work at all.
- Network and bot protection. Cookies set by our content delivery and bot-protection provider to tell genuine visitors from automated abuse. Set for security and availability, not to profile you.
- Anti-bot challenge. Used on public forms and, where enabled, on sign-up. We chose a provider that does not profile users or follow them across sites.
We also keep a small amount of data in your browser's own storage: your sign-in state and interface preferences such as theme and sidebar. It stays on your device and is not sent to third parties.
Analytics: no third-party tracking at all
There is no Google Analytics, no advertising pixel, no session recording and no cross-site tracker, not in the product and not in the site templates we ship.
We do give you visitor analytics for the sites you publish, and those are cookieless. No visitor IP address is ever stored. The identifier is a one-way hash of the IP and browser combined with a value that changes every day, so it cannot be reversed and cannot be used to follow a visitor from one day to the next. Alongside it we keep the page path, response status, referring domain, browser family, country, and whether the device was a phone, tablet or desktop.
Marketing: none
We set no advertising or cross-site tracking cookies.
That is why you see no cookie banner. Consent is required for cookies that are not strictly necessary, and the only ones we set are strictly necessary, so a banner would be theatre rather than a real choice. If we ever add an analytics or marketing tracker, a consent mechanism and an update to this page will ship in the same change.
You can block or delete cookies in your browser settings. Blocking the sign-in cookie will stop you signing in, since that is exactly what it is for.
9. How long we keep it
| Data | Kept for |
|---|---|
| Account data (profile, credentials) | For the life of the account |
| Content you create: pages, entries, media | For the life of the account, or until you delete it |
| Server access logs (include IP address) | Being fixed, see note ⚠️ |
| Site analytics (pseudonymised; no IP stored) | Being fixed, see note ⚠️ |
| Form submissions | Until you delete them ⚠️ |
| AI assistant conversations | Until you delete them ⚠️ |
| Billing and accounting records | As required by law after the account closes |
The rows marked ⚠️ are an honest gap: those do not yet expire automatically, so they stay until deleted. We are setting defined periods. In the meantime, if you want any of that removed sooner, ask us and we will remove it.
10. Your rights
You can access, correct, erase, restrict and port your personal data, and object to certain processing. You can edit your profile in your account settings, and export or delete individual projects from inside the product.
For a full export, or to delete your whole account, email [email protected] and we will do it manually. There is no self-service button for that yet, and we would rather tell you so than imply one exists. We answer within one month, as the GDPR requires. You can also complain to your local data protection authority.
11. Security
Summarised here, with more on the GDPR page: your workspace's data is isolated from every other workspace at the storage layer, not only in application code. Passwords are stored as slow salted hashes and are never recoverable. API keys are stored only as hashes. Any provider credentials you supply are encrypted at rest with AES-256-GCM. Everything travels over HTTPS. Uploads are validated by inspecting their actual contents rather than trusting the declared file type. Two-factor authentication and passkeys are available on every account.
12. Children
The service is not intended for children under 16, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
13. Changes to this policy
If we change this policy materially we will update the date at the top and, for changes that affect you meaningfully, tell you directly rather than relying on you to notice.
14. Contact
This service is operated by Flowtrix Private Limited, 2nd Stage, 13th Cross Road, Indiranagar, Binnamangala, Bengaluru, Karnataka 560038, India. GSTIN 29AAGCF9453R1ZL.
Flowtrix Private Limited is the data controller for your account data. For any privacy request, access, export, correction or deletion, contact [email protected]. We answer within one month.