Skip to content
BetterCMS
FeaturesSolutions
Join our Discord
FeaturesSolutions
Join our Discord

Legal

Privacy Policy

Last updated: 27 July 2026

What personal data we collect, why we collect it, who else sees it, and what you can do about it.

1. Who is responsible for your data

This service is operated by Flowtrix Private Limited, 2nd Stage, 13th Cross Road, Indiranagar, Binnamangala, Bengaluru, Karnataka 560038, India. GSTIN 29AAGCF9453R1ZL.

Flowtrix Private Limited is the data controller for your account data. For any privacy request, access, export, correction or deletion, contact [email protected]. We answer within one month.

2. Two different relationships

This matters more than anything else on the page, so it comes first:

  • Your account data: we are the controller. Your name, email, password and billing details. We decide how these are handled, and this policy explains it.
  • Your content and your visitors' data: we are your processor. The pages, entries, media and above all the form submissions collected on sites you publish. That data belongs to you. We process it on your instructions, never for our own purposes. You are the controller there, so you decide the lawful basis, you tell your own visitors what you collect, and you answer their requests. We help you do it.

3. Data we collect

  • Account data: your name, email address, and a one-way hash of your password. If you sign in with Google or GitHub we store the identifier that provider returns. If you enable two-factor authentication or a passkey, we store the credential needed to verify it.
  • Content you create: pages, content models, entries, media files and forms. This is free-form, so it may contain personal data you choose to put there.
  • Form submissions: when you publish a form, we store what your visitors send to it, on your behalf. See section 2.
  • AI assistant conversations: the prompts and replies exchanged with the AI features, including anything you paste into them. See section 6.
  • Site analytics: pseudonymised, with no stored IP address. See section 8.
  • Operational logs: server access logs, which include IP address and browser user-agent, used to run and secure the service.
  • Billing data: subscription and plan information. Card details go straight to our payment processor and never reach us.

4. Where your data is processed

  • Your account and content: European Union (Finland)
  • Uploaded files and site assets: Cloudflare's global network
  • Transactional email: India
  • AI features: United States

5. Who else sees your data

These are our sub-processors. Each is linked to its own GDPR or privacy terms, so if you need to know how a particular provider handles data you can go straight to their document:

ProviderWhy we use themWhat they receiveRegionTheir terms
Hetzner Online GmbHHosting infrastructureData stored by the service, at restEuropean Union (Finland) Hetzner privacy & GDPR
Cloudflare, Inc.Content delivery, network and bot protection, file storageRequest traffic including IP addresses; uploaded filesGlobal network Cloudflare GDPR
Zoho Corporation (ZeptoMail)Transactional email: verification, password reset, invitations, notificationsRecipient email address and message contentIndia Zoho GDPR
Baseten Labs, Inc.AI model inferencePrompt content, which may include your contentUnited States Baseten privacy
Anthropic PBCAI model inferencePrompt content, which may include your contentUnited States Anthropic privacy & GDPR
Dodo PaymentsSubscription billing and payment processingBilling identity and payment details. Card data never reaches our systemsSee provider terms Dodo Payments privacy
GitHub, Inc. (Microsoft)Source-repository integration, only if you connect oneRepository contents and your GitHub account identityUnited States Microsoft/GitHub GDPR
Google LLCGoogle sign-in, and spreadsheet export only if you connect itYour Google account identity; exported form data if you enable that exportUnited States Google GDPR

We are an Indian company hosting in the EU, and we state both rather than letting the EU hosting imply an EU company. Personal data crosses borders in three ways: our team administers the service from India, transactional email is processed in India, and AI inference is processed in the United States. Where data leaves the European Economic Area we rely on the appropriate Article 46 safeguards, primarily Standard Contractual Clauses. The GDPR page sets this out in full, including our establishment and EU representative position.

We do not sell your personal data, and we do not share it for advertising.

6. AI features, and what to consider before using them

When you use an AI feature, the relevant content, your prompt plus the pages or entries it works on, is sent to a third-party model provider to generate a response. Conversations are stored against your workspace so you can return to them, and they are isolated to your workspace.

Practically: do not paste anything into the AI assistant that you would not want processed by those providers. We would rather say that plainly than bury it in a list of service providers.

7. Why we are allowed to process it

  • Contract: to provide the service you signed up for.
  • Legitimate interests: to secure, maintain and improve the service, and to prevent abuse.
  • Consent: where required, for example optional communications. You can withdraw it at any time.
  • Legal obligation: to meet accounting and compliance duties.

8. Cookies, and why there is no cookie banner

Cookies are usually sorted into three buckets. Here is where we stand on each:

Necessary: yes

  • Sign-in. A cookie that keeps you signed in, so each request is recognised as yours. Without it the application cannot work at all.
  • Network and bot protection. Cookies set by our content delivery and bot-protection provider to tell genuine visitors from automated abuse. Set for security and availability, not to profile you.
  • Anti-bot challenge. Used on public forms and, where enabled, on sign-up. We chose a provider that does not profile users or follow them across sites.

We also keep a small amount of data in your browser's own storage: your sign-in state and interface preferences such as theme and sidebar. It stays on your device and is not sent to third parties.

Analytics: no third-party tracking at all

There is no Google Analytics, no advertising pixel, no session recording and no cross-site tracker, not in the product and not in the site templates we ship.

We do give you visitor analytics for the sites you publish, and those are cookieless. No visitor IP address is ever stored. The identifier is a one-way hash of the IP and browser combined with a value that changes every day, so it cannot be reversed and cannot be used to follow a visitor from one day to the next. Alongside it we keep the page path, response status, referring domain, browser family, country, and whether the device was a phone, tablet or desktop.

Marketing: none

We set no advertising or cross-site tracking cookies.

That is why you see no cookie banner. Consent is required for cookies that are not strictly necessary, and the only ones we set are strictly necessary, so a banner would be theatre rather than a real choice. If we ever add an analytics or marketing tracker, a consent mechanism and an update to this page will ship in the same change.

You can block or delete cookies in your browser settings. Blocking the sign-in cookie will stop you signing in, since that is exactly what it is for.

9. How long we keep it

DataKept for
Account data (profile, credentials)For the life of the account
Content you create: pages, entries, mediaFor the life of the account, or until you delete it
Server access logs (include IP address)Being fixed, see note ⚠️
Site analytics (pseudonymised; no IP stored)Being fixed, see note ⚠️
Form submissionsUntil you delete them ⚠️
AI assistant conversationsUntil you delete them ⚠️
Billing and accounting recordsAs required by law after the account closes

The rows marked ⚠️ are an honest gap: those do not yet expire automatically, so they stay until deleted. We are setting defined periods. In the meantime, if you want any of that removed sooner, ask us and we will remove it.

10. Your rights

You can access, correct, erase, restrict and port your personal data, and object to certain processing. You can edit your profile in your account settings, and export or delete individual projects from inside the product.

For a full export, or to delete your whole account, email [email protected] and we will do it manually. There is no self-service button for that yet, and we would rather tell you so than imply one exists. We answer within one month, as the GDPR requires. You can also complain to your local data protection authority.

11. Security

Summarised here, with more on the GDPR page: your workspace's data is isolated from every other workspace at the storage layer, not only in application code. Passwords are stored as slow salted hashes and are never recoverable. API keys are stored only as hashes. Any provider credentials you supply are encrypted at rest with AES-256-GCM. Everything travels over HTTPS. Uploads are validated by inspecting their actual contents rather than trusting the declared file type. Two-factor authentication and passkeys are available on every account.

12. Children

The service is not intended for children under 16, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.

13. Changes to this policy

If we change this policy materially we will update the date at the top and, for changes that affect you meaningfully, tell you directly rather than relying on you to notice.

14. Contact

This service is operated by Flowtrix Private Limited, 2nd Stage, 13th Cross Road, Indiranagar, Binnamangala, Bengaluru, Karnataka 560038, India. GSTIN 29AAGCF9453R1ZL.

Flowtrix Private Limited is the data controller for your account data. For any privacy request, access, export, correction or deletion, contact [email protected]. We answer within one month.

More legal documents

  • Privacy Policy
  • GDPR
  • Terms of Service
  • Back to home
BetterCMS

The Content Operating System for teams building modern websites with AI.

System status

Company

FeaturesSolutionsContact usDemo
Email usJoin our discordLinkedInXInstagram
Privacy PolicyTerms & ConditionGDPR Compliant

Built withlovein Bengaluru, IndiaIndian flag