Privacy
Privacy Policy
This Privacy Policy describes how Flow Forge AI collects, uses, discloses, and protects personal information when you use our website and services.
Effective Date: September 19, 2026
Last Updated: October 4, 2026
1. Introduction
Flow Forge AI ("we," "us," or "our"), based in Los Angeles, California, operates the website flowforgeaiagency.com and related services.
This Privacy Policy describes how Flow Forge AI collects, uses, discloses, and protects personal information when you use our website and services. It is provided as a notice of our practices; it is not a contract.
By using our website, you acknowledge that you have read and understood this Privacy Policy.
2. Information We Collect
Information You Provide Directly
| Category | Examples | Purpose |
|---|---|---|
| Contact Information | Name, email address, company name | Respond to inquiries, provide services |
| Project Information | Project type, business problem description, systems/tools, budget range, timeline, description | Provide automation services, prepare proposals |
Information Collected Automatically
| Category | Examples | Purpose |
|---|---|---|
| Technical Information | IP address, browser type, access timestamps | Security, troubleshooting, service improvement |
Information We Do NOT Collect
- Payment card numbers (Stripe handles all payment data)
- Cookies (none used in current implementation)
- Analytics data (none collected in current implementation)
- Social Security numbers or government IDs
- Biometric data
- Health information
3. How We Use Information
| Purpose | Legal Basis (where applicable) |
|---|---|
| Respond to inquiries | Legitimate interest |
| Provide automation services | Contract |
| Process payments via Stripe | Contract |
| Send transactional emails via Resend (if activated) | Legitimate interest |
| Improve our services | Legitimate interest |
| Comply with legal obligations | Legal obligation |
We do not:
- Sell your personal information
- Share your information for cross-context behavioral advertising
- Train AI models on your data (current chatbot implementation is local-only)
4. Data Processors and Subprocessors
| Processor | Purpose | Location | Active? |
|---|---|---|---|
| Self-managed VPS (development) | Website hosting and workflow automation | United States | Yes (development) |
| Supabase | Database and authentication | United States | Planned |
| Stripe | Payment processing | United States | Planned |
| Resend | Transactional email | United States | Planned |
| n8n (self-hosted; hosting provider to be confirmed) | Workflow automation | To be confirmed | Planned |
| SMS/telecom provider (Automated Receptionist service) | Delivering text messages for business customers | United States | Planned |
| OpenAI | Chatbot AI processing | United States | Optional, not activated |
We use these service providers to operate our services. We require service providers to handle personal information in accordance with this Privacy Policy and applicable law.
We update this table when processors change. Material changes will be communicated via our website.
5. Data Retention
| Data Type | Retention Period | Rationale |
|---|---|---|
| Contact form submissions | 12 months | Long enough to follow up on leads; short enough to limit exposure |
| Chatbot conversations | Not permanently stored | Current implementation |
| Payment and transaction records | Retained for the period reasonably necessary to satisfy applicable tax, accounting, contractual, fraud-prevention, and legal obligations | Tax/legal/contractual requirement |
| Customer project data | Duration of customer relationship + 6 months | Post-project support and handover |
| Server/operational logs | 30 days | Security/incident investigation |
| Security/audit logs | 90 days | Longer retention for security incident detection |
| Backups | 3 months rolling | Rolling backup retention |
| Failed workflow records | 30 days | Troubleshooting period |
| Support communications | 12 months | Customer service continuity |
At the end of the retention period, data is deleted or anonymized.
6. California Consumer Rights
California Residents — Your Privacy Rights
Flow Forge AI does not currently meet the statutory thresholds that would make the California Consumer Privacy Act (CCPA) or California Privacy Rights Act (CPRA) mandatory. However, Flow Forge AI voluntarily provides the following rights to California residents:
| Right | Description |
|---|---|
| Right to Know | Request disclosure of categories and specific pieces of personal information collected about you |
| Right to Delete | Request deletion of personal information (subject to legal exceptions) |
| Right to Correct | Request correction of inaccurate personal information |
| Right to Opt-Out | Flow Forge AI does not sell or share personal information; opt-out will be provided if this changes |
| Right to Non-Discrimination | Flow Forge AI will not discriminate against you for exercising your privacy rights |
How to Submit a Request
Contact: privacy@flowforgeaiagency.com
Response time: Within 45 days
Verification: We may need to verify your identity before processing
Authorized agents: You may designate an authorized agent to submit requests on your behalf.
7. Sale and Sharing Disclosure
Flow Forge AI does not sell personal information. Flow Forge AI does not share personal information for cross-context behavioral advertising.
If Flow Forge AI begins selling or sharing personal information in the future, a prominent "Do Not Sell or Share My Personal Information" link will be provided, and California residents will be able to opt out.
8. Do Not Track Disclosure
Some browsers offer a "Do Not Track" (DNT) setting. There is currently no universally accepted standard for how companies should respond to DNT signals.
Flow Forge AI does not currently track users over time and across third-party websites, and does not allow third parties to perform such tracking on this website.
Flow Forge AI does not currently alter its practices when receiving a DNT signal. If our tracking, analytics, cookie, or privacy-signal practices change, this Privacy Policy will be updated to accurately describe how applicable browser signals and legally recognized privacy preference mechanisms are handled.
9. Security
Current Security Measures (Live System)
Flow Forge AI implements appropriate technical and organizational measures to protect personal information, including:
- HTTPS/TLS encryption for all data in transit
- Input validation and sanitization
- Regular dependency and security audits
Planned Security Measures (Configuration-Gated)
The following security controls have been implemented in code but are not yet active in production:
- Encryption at rest for stored data
- Row Level Security on database access
- Production authentication/access controls
- Webhook signature verification
No method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
10. International Transfers
Flow Forge AI is based in Los Angeles, California. Your data may be processed in:
- United States (Vercel, Supabase, Stripe, Resend, OpenAI if activated)
- European Union (n8n Cloud if activated)
Where required by applicable law, international transfers may be protected through appropriate contractual or other legally recognized safeguards.
11. Children's Privacy
Our services are general-audience and are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13.
If we become aware that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information promptly.
If you believe we may have collected information from a child under 13, please contact us.
12. AI Processing Disclosure
Current implementation: Deterministic local-only chatbot. No AI processing of user data.
The chatbot provides informational responses only and does not create contractual obligations. Conversations are not permanently stored.
If OpenAI is activated in the future: Chat messages would be sent to OpenAI API for processing. Users would be informed of AI processing before use and could choose not to use the chatbot.
Automated Receptionist (customer service data)
When a business customer uses the Automated Receptionist, Flow Forge AI processes the caller's phone number, call time and status, text message content, and appointment details on that customer's behalf, to reply to the call, book appointments, and notify the business. The service does not record calls or answer by voice, does not use AI to process messages, does not sell this information, and does not use messages to train AI models. Texts are limited to the call and the booking. The business customer is responsible for its callers' messages; requests about this data are best sent to that business, or to privacy@flowforgeaiagency.com. Retention follows the customer agreement and deletion on request.
13. Google User Data
Flow Forge AI offers a connection page where our clients can connect their Google account so we can run the automations described in their agreement. When a client connects, we receive a refresh token for the specific Google permissions the client approves (for example Google Calendar, Google Sheets, or files our automations create in Google Drive).
- How we use it. Only to run the workflows the client has hired us to build and operate, and to provide support for those workflows. We do not use Google user data for advertising, we do not sell it, and we do not use it to train AI models.
- Storage. The refresh token is stored encrypted. Data accessed through a client's connected account is processed inside that client's own automation environment and is not copied to other clients' environments.
- Sharing. We do not share Google user data with third parties except as needed to run the client's workflows at the client's direction, or if the law requires it.
- Human access. Our staff do not read a client's Google data unless the client asks for support that requires it, or it is needed for security or to meet legal requirements.
- Removing access. A client can remove access at any time at myaccount.google.com/permissions, or by emailing info@flowforgeaiagency.com, and we will delete the stored token.
Flow Forge AI's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by:
- Posting a notice on our website
- Updating the "Last Updated" date
- Email notification to registered users (if applicable)
Continued use after changes constitutes acknowledgment of the revised policy.
15. Contact Information
Flow Forge AI
Los Angeles, California
General inquiries: info@flowforgeaiagency.com
Privacy requests: privacy@flowforgeaiagency.com
We aim to respond within 30 days.
