Privacy Policy
AutoFlo · https://www.autoflo.cloud
Drafted for production SaaS publication and outside counsel review. Bracketed placeholders must be completed before final counsel-approved publication.
Effective date: [EFFECTIVE DATE] Website: https://www.autoflo.cloud Company/legal entity: AutoFlo Contact: [LEGAL/PRIVACY CONTACT EMAIL]
2.1 Scope
This Privacy Policy explains how AutoFlo collects, uses, discloses, retains, and protects personal information for global users when you use the Service, visit https://www.autoflo.cloud, create an account, connect integrations, upload files, run workflows, use AI agents, contact support, or purchase subscriptions.
2.2 Definitions
For this Privacy Policy, "personal information" or "personal data" means information that identifies, relates to, describes, can reasonably be associated with, or could reasonably be linked to an individual or household. "Customer Data" means information submitted to the Service by or for a customer, including files, prompts, workflow configurations, API data, and Outputs. "Processing" means any operation performed on personal information, including collection, storage, use, disclosure, transmission, deletion, or analysis.
2.3 Information we collect
AutoFlo may collect the following categories of information:
- Account information: name, email address, password hash, workspace name, role, profile details, authentication data, and account preferences.
- Customer Data: files, documents, prompts, workflow configurations, automation steps, workflow logs, AI agent instructions, data imported from connected APIs, generated outputs, and related metadata.
- Integration data: OAuth tokens, API keys, connected account identifiers, scopes, third-party API responses, webhook payloads, and integration configuration. This may include Google authentication data, GitHub authentication data, OAuth identity provider data, connected API data, and credentials needed to execute customer workflows. Sensitive credentials are used to provide the Service and should be handled according to our security controls.
- Billing data: subscription plan, invoices, payment status, billing address, tax information, transaction metadata, Stripe customer identifiers, Stripe subscription identifiers, checkout events, and payment processor identifiers. AutoFlo does not store full payment card numbers when payments are processed by Stripe or another third-party payment processor.
- Usage data: pages viewed, features used, workflow execution activity, API usage, errors, logs, device and browser data, IP address, approximate location, timestamps, diagnostics, analytics events, referral data, and cookie identifiers.
- Communications: support tickets, emails, feedback, surveys, sales communications, and administrative messages.
- Security data: audit logs, access logs, authentication events, IP addresses, user agents, abuse signals, and fraud prevention data.
- Deletion-request records: uploaded photos, generated videos, account identifiers, verification context, and data_deletion_requests intake rows needed to process user-initiated deletion requests.
2.4 How we use information
AutoFlo uses information to:
- provide, operate, secure, and improve the Service;
- create and manage accounts and workspaces;
- run workflows, AI agents, document processing, integrations, and API calls;
- generate, store, and display Outputs;
- process payments, invoices, subscriptions, refunds, and taxes;
- provide support and respond to requests;
- monitor usage, debug errors, prevent abuse, and enforce policies;
- send service, security, billing, and product communications;
- comply with law, legal process, and regulatory obligations;
- protect the rights, safety, and property of AutoFlo, users, and others.
2.5 AI providers and model processing
To provide AI features, AutoFlo may send prompts, files, workflow context, documents, metadata, and other Customer Data to AI model providers or infrastructure providers. These providers process data on AutoFlo's behalf or as otherwise described in their terms. AutoFlo designs workflows to send the data needed for the requested feature, but users control what they upload, connect, and include in prompts.
AutoFlo does not use Customer Data for model training, including training AutoFlo foundation models or third-party foundation models unless you provide explicit opt-in consent or a signed agreement authorizes that processing. AutoFlo may use anonymized and aggregated usage data, or de-identified usage data for analytics, security, capacity planning, product development, and service improvement.
Do not submit sensitive personal data, protected health information, payment card data, government identifiers, children's data, biometric data, trade secrets, or regulated data unless your plan and written agreement expressly allow it and you have a lawful basis to process it.
AutoFlo is preparing for AI governance obligations, including EU AI Act readiness where applicable. This may include documenting AI features, prohibited use restrictions, human review expectations, risk controls, transparency notices, logging, and customer responsibilities for high-risk use cases.
2.6 Legal bases for processing
For users in the European Economic Area, United Kingdom, or Switzerland, AutoFlo processes personal data under one or more legal bases, including performance of a contract, legitimate interests, consent, compliance with legal obligations, and, where applicable, your instructions as a processor acting on behalf of a customer.
2.7 How we share information
AutoFlo may share information with:
- service providers that host, secure, support, analyze, or operate the Service;
- AI model providers and infrastructure providers used to process workflows and Outputs;
- payment processors, tax providers, and billing platforms, including Stripe where used;
- authentication and identity providers, including Google, GitHub, and other OAuth providers where enabled;
- cloud infrastructure providers, database providers, storage providers, content delivery networks, logging providers, and security monitoring providers;
- analytics providers used to measure website traffic, product usage, conversion, reliability, and errors;
- integration providers you connect or instruct us to use;
- professional advisers, auditors, insurers, and legal counsel;
- authorities, courts, or third parties when required by law or to protect rights and safety;
- parties involved in a merger, acquisition, financing, reorganization, or asset transfer.
AutoFlo does not sell personal information for money. If AutoFlo uses advertising or analytics that constitutes a "sale" or "sharing" under California law, AutoFlo will provide legally required notices and opt-out controls.
2.8 Cookies and similar technologies
AutoFlo may use cookies, local storage, pixels, SDKs, and similar technologies for authentication, security, preferences, analytics, performance, and marketing. See the Cookie Policy for details.
2.9 Retention
AutoFlo retains information for as long as needed to provide the Service, comply with law, resolve disputes, enforce agreements, maintain security, prevent fraud, meet tax and accounting obligations, and maintain backups. Retention periods vary by data type. See the Data Retention & Deletion Policy.
Typical retention schedules are: account records for the life of the account and a reasonable closure period; Customer Data until deleted by authorized users or the customer relationship ends; OAuth tokens and API credentials until disconnected or deleted; billing records for the period required by tax, accounting, chargeback, and audit laws; security logs for a limited security and fraud-prevention period; support records for the period needed to resolve requests and maintain business records; backups until overwritten under backup cycles.
2.10 Security
AutoFlo uses administrative, technical, and organizational safeguards designed to protect personal information. These may include encryption in transit, access controls, logging, monitoring, vendor review, least privilege access, backups, and incident response processes. No method of transmission or storage is completely secure.
2.11 International transfers
AutoFlo may process information in countries other than where you are located. Where required, AutoFlo uses appropriate safeguards such as Standard Contractual Clauses or equivalent transfer mechanisms.
2.12 Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing of personal information, and to appeal or complain to a regulator. You may submit requests to privacy@autoflo.cloud. AutoFlo may need to verify your identity and may deny or limit requests as permitted by law.
2.13 Children
The Service is not directed to children under 13, or under the age required by local law. Users must not submit children's personal information unless permitted by law and authorized by AutoFlo in writing.
2.14 Changes
AutoFlo may update this Privacy Policy. Material changes will be posted on the website or communicated through the Service.
2.15 Contact
Privacy questions and requests may be sent to privacy@autoflo.cloud.
---
