Privacy Notice

Last updated: January 2026

1. Introduction

FlowBot ("we", "our", or "us") is committed to protecting your privacy. This Privacy Notice explains how we collect, use, disclose, and safeguard your information when you use our WhatsApp flow builder platform.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, password when you register
  • Payment Information: Billing details processed through Paddle (we do not store card numbers)
  • API Credentials: WhatsApp API tokens, AI provider API keys (stored encrypted)
  • Flow Data: Workflows, messages, and automation rules you create
  • Knowledge Files: Documents you upload for AI training

2.2 Information Collected Automatically

  • Usage Data: Features used, flows created, messages sent/received
  • Analytics: Flow performance metrics and engagement statistics
  • Device Information: Browser type, IP address, device identifiers
  • Log Data: Access times, pages viewed, error logs

2.3 WhatsApp Message Data

When you connect your WhatsApp Business account, we process messages sent and received through your flows. This includes message content, sender/recipient phone numbers, and timestamps. This data is used solely to provide the Service and is handled according to WhatsApp's Business API terms.

3. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Process transactions and send related information
  • Send technical notices, updates, and security alerts
  • Respond to your comments, questions, and support requests
  • Monitor and analyze usage patterns and trends
  • Detect, prevent, and address technical issues and fraud
  • Comply with legal obligations

4. Data Sharing and Disclosure

We may share your information with:

  • Service Providers: Third parties that help us operate the Service (hosting, payment processing, analytics)
  • AI Providers: When you use AI features, relevant data is sent to your configured AI provider (OpenAI, Anthropic, or Google)
  • WhatsApp/Meta: Message data is transmitted through WhatsApp's API infrastructure
  • Legal Requirements: When required by law or to protect our rights

We do not sell your personal information to third parties.

5. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption of sensitive data at rest and in transit (TLS/SSL)
  • Encrypted storage of API keys and access tokens
  • Regular security assessments and updates
  • Access controls and authentication requirements
  • Secure data centers with physical security measures

6. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. After account deletion, we may retain certain data for a limited period for legal compliance, dispute resolution, and enforcement of our agreements. Message logs and analytics data may be anonymized and retained for aggregate statistics.

7. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data
  • Portability: Request transfer of your data
  • Objection: Object to certain processing activities
  • Withdrawal: Withdraw consent where processing is based on consent

To exercise these rights, contact us at privacy@flowbot.app

8. Cookies and Tracking

We use essential cookies for authentication and session management. We may use analytics cookies to understand how you use the Service. You can control cookie preferences through your browser settings, though disabling cookies may affect functionality.

9. International Data Transfers

Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses where applicable.

10. Children's Privacy

The Service is not intended for children under 16. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

11. Changes to This Notice

We may update this Privacy Notice from time to time. We will notify you of any material changes by posting the new notice on this page and updating the "Last updated" date.

12. Contact Us

If you have questions about this Privacy Notice or our data practices, please contact us at: