1. Introduction

Nocetic Limited operates Flowly ("Flowly", "we", "our", or "us") and is the controller of personal data it determines how and why to process. This Privacy Policy applies to the Flowly website, accounts, hosted services, cloud relay, and mobile and desktop applications. It also explains the different responsibilities that apply when you configure an independent or self-hosted model provider.

2. Information We Collect

Account and permission records: We process your email address, display name, sign-in identifiers, subscription status, and dated, versioned records of privacy choices. If you use a third-party sign-in method, we receive the profile fields that provider makes available to Flowly.

Messages and requested content: Depending on the connection and feature you choose, processing may include messages, recent conversation context, system and tool instructions, tool results, attachments, audio, transcripts, response text, and relevant memory, workspace, schedule, artifact, or connected-service information selected by your personal agent for the request. Scheduled-task records can include the task instruction, schedule, delivery target, status, and delivered result.

Agent, connection, and integration data: We process the server or agent identifiers, relay or direct-gateway settings, provider and model selection, enabled capabilities, device metadata, and integration status needed to connect your apps. Secrets such as direct-gateway tokens and provider credentials are handled according to the connection method you configure.

Usage and technical data: We process timestamps, request and credit usage, selected model, feature events, approximate network information such as IP address, device and app version, browser, diagnostic records, and security events. Ordinary hosted-model proxy logs record operational metadata such as model, streaming status, message count, request status, token or cost usage, and a shortened server identifier; they are not designed to record prompt or response text.

Payments and support: Apple processes App Store purchases and Stripe processes eligible web payments. We receive transaction, product, subscription, and verification identifiers needed to provide paid features, but not full payment-card details. We also process information you include in support, contact, abuse, or legal requests.

3. Personal Agent Processing and Provider Choice

The route taken by request content depends on the provider and connection you configure:

  • Flowly provider: when you choose Flowly as the model provider, your local agent sends the request content in readable form to Flowly's hosted model endpoint. Flowly authenticates the account, applies plan, credit, and security controls, and forwards the request through OpenRouter to the model endpoint selected for the request. Depending on the model, that endpoint may be operated by OpenAI, Anthropic, Google, xAI, Moonshot AI, Z.ai, Alibaba/Qwen, MiniMax, Groq, or another provider in the available catalogue.
  • Your provider (BYOK or OAuth): when you configure your own supported provider credentials or authorization, the local agent sends the model request directly to that provider rather than through Flowly's hosted model endpoint. These independently selected providers are not operated or controlled by Flowly; their own terms, privacy notices, retention, regional processing, and training choices apply.
  • Local or self-hosted provider: when you configure a local or self-hosted OpenAI-compatible endpoint, model inference can occur on infrastructure you control. Using Flowly account, relay, synchronization, attachment, voice, or other cloud features can still send the data needed for those separate features to Flowly or the relevant service provider.
  • Voice and media: when you request speech, transcription, calling, or media generation, the relevant content may also be processed by the service configured for that feature, which may include ElevenLabs, Groq, OpenAI, Deepgram, Twilio, fal.ai, or a provider you configure.
  • Before Messages is made available on iOS, Flowly asks for permission for the disclosed third-party processing. Permission is recorded against your Flowly account. You can withdraw it in Settings; withdrawal gates Messages on that device and does not undo processing that occurred before withdrawal.
For the Flowly provider route, Flowly uses OpenRouter and the routed model endpoint to provide the feature you request. Flowly does not currently require Zero Data Retention (ZDR) routing for every request because doing so would reduce the available model catalogue. You must not assume that the Flowly provider route is zero-retention: prompt or response retention and model-training treatment can vary with OpenRouter's routing and account settings and with the routed model provider. Their handling is subject to applicable law, service arrangements, and the relevant provider terms. Providers you independently configure follow their own practices, not Flowly's. Review the provider and model route before sending sensitive data.

4. Your Conversations

Your personal agent and its primary workspace can run on your computer, and a direct gateway can connect an app directly to that agent. If you use Flowly's cloud relay, synchronization, built-in Messages, push delivery, or web chat, message content passes through the relay in readable form while it is routed and may be stored in Flowly-managed Firebase infrastructure. For eligible desktop-backed conversations marked as encrypted, the relay applies AES-256-GCM application-layer encryption to message, title, and tool text before database storage. Because Flowly's relay can derive or unwrap the storage key to provide the service, this is encryption at rest within Flowly's trust boundary, not end-to-end encryption, and Flowly infrastructure can technically decrypt that text. Conversations not marked as encrypted are stored without that application-layer encryption. Scheduled-task instructions, schedules, and delivery metadata are stored without it; messages and results in the dedicated Scheduled Tasks conversation are also unencrypted at the application layer, while a result delivered into another conversation follows that conversation's setting. Attachments and artifacts uploaded for cloud access are stored in managed object storage and are not covered by the message-text encryption described above. We do not routinely review conversation content. Where Flowly infrastructure technically has access, authorized personnel may access it only when reasonably necessary to provide support you request, operate and secure the service, investigate abuse, or comply with law.

5. How We Use Your Information

  • To perform our contract with you: create and secure your account, connect your personal agent, relay or synchronize requested data, deliver requested features, and administer subscriptions and credits
  • With your consent: send the categories disclosed in the iOS permission screen to the configured endpoint, Flowly infrastructure, and applicable model, voice, media, or connected-service providers; and operate optional analytics where consent is required
  • For our legitimate interests: maintain reliability, understand aggregate feature use, diagnose faults, improve Flowly, prevent fraud and abuse, and protect users and our systems, balanced against your rights
  • To comply with law, enforce our terms, resolve disputes, and respond to valid legal requests
  • To communicate about service, security, billing, support, and material policy changes
  • We do not sell personal information, use request content for targeted advertising, or use it to train a Flowly general-purpose model

6. Data Sharing & Disclosure

We disclose only the information reasonably necessary for the described purpose, based on the feature and route you choose:

Flowly model processing: For the Flowly provider route, request content is disclosed to OpenRouter and the model endpoint it routes to. The categories and possible operators are described in Section 3.

Cloud and delivery infrastructure: Firebase/Google Cloud, Cloudflare, and managed object-storage providers such as AWS help provide authentication, databases, relay, hosting, security, and attachment delivery. If you request hosted compute, infrastructure may also be provided through services such as Hetzner or DigitalOcean.

Feature and connected-service providers: Voice, transcription, calling, media, email, calendar, messaging, and other integrations disclose the content needed to the service you activate. Providers can include ElevenLabs, Groq, OpenAI, Deepgram, Twilio, fal.ai, Google, Telegram, WhatsApp, Gmail, and services you independently configure.

Payments, communications, diagnostics, and analytics: Apple and Stripe process purchases; Resend supports service email; Sentry supports diagnostics; and, where enabled and subject to applicable consent controls, Google Analytics and Mixpanel support product analytics. Each receives only data relevant to its function.

Legal, safety, and business events: We may disclose information when reasonably necessary to comply with law or valid legal process, protect rights and safety, investigate fraud or abuse, or complete a merger, financing, acquisition, reorganization, or asset transfer subject to appropriate confidentiality and notice requirements.

7. Law Enforcement Requests

We assess requests for user information and disclose data only where we reasonably believe disclosure is required or permitted by applicable law, including in response to:

  • Binding court orders, warrants, subpoenas, or equivalent lawful process
  • A documented emergency involving a credible and imminent risk of death or serious physical harm
  • Requests necessary to protect Flowly, our users, or others from fraud, abuse, security threats, or violations of law

Where legally permitted and reasonably practicable, we will notify the affected user. We may narrow or challenge requests that appear invalid, unlawful, or disproportionate.

8. International Data Transfers

Flowly and the providers described above may process data in the United Kingdom, European Economic Area, United States, and other countries where they operate. Privacy laws may differ from those in your country. Where required, we rely on an adequacy decision, Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, or another lawful transfer mechanism, and apply supplementary safeguards appropriate to the transfer. Providers you independently configure make transfers under their own notices and arrangements.

9. Data Security

We implement appropriate technical and organizational security measures to protect your personal information:

  • Encrypted network transport such as HTTPS or WSS where supported by the relevant connection
  • Authentication, authorization, Firestore security rules, and access controls for Flowly-managed systems
  • Application-layer encryption before database storage for eligible desktop-backed conversation text, with key access retained by the relay; this is not end-to-end encryption
  • Provider-managed protections for other stored cloud data, including uploaded attachments and artifacts, and operational monitoring designed to detect abuse and faults
  • Data minimization and restricted personnel access based on operational need

10. Data Retention

We keep account and subscription data while your account is active and for the period reasonably needed to close the account, meet tax and accounting duties, prevent fraud, resolve disputes, and enforce agreements. Data stored only in your local agent remains until you remove it or according to your configuration. Cloud-relay conversations and synchronized database records remain until deleted through available controls, the related workspace or account is deleted, or their operational lifecycle ends. Uploaded attachments and artifacts can follow a separate object-storage lifecycle and may not be removed by every conversation or account-record deletion path; contact privacy@nocetic.com if you need deletion confirmed across managed storage. Permission, transaction, security, deletion-audit, and support records are kept as needed to document choices and obligations. The Flowly hosted model endpoint is not designed to retain a separate Flowly prompt archive, but Flowly does not require ZDR for every OpenRouter request and downstream retention follows Section 3. Deletion may take time to propagate through backups and may be limited where retention is legally required.

11. Your Rights

Depending on where you live and subject to legal exceptions, you may have rights under the UK GDPR, EU GDPR, CCPA/CPRA, or other privacy laws to:

  • Access and obtain a copy of your personal data
  • Correct inaccurate or incomplete data
  • Request deletion or restriction of eligible processing
  • Receive eligible data in a portable format
  • Object to processing based on legitimate interests and opt out of marketing
  • Withdraw consent at any time without affecting processing already carried out lawfully
  • Appeal or complain to the competent data-protection authority
Use available account controls or contact privacy@nocetic.com. We may need to verify your identity. Flowly cannot fulfill rights requests for data held only by an independent provider you configured; contact that provider directly.

12. Children's Privacy

Flowly is not directed to anyone under 18. We do not knowingly collect personal data from a child. If you believe a child has provided personal data, contact us so we can investigate and take appropriate deletion or account action.

13. Cookies & Tracking

We use cookies or similar storage that are necessary for sign-in, security, language, and saved preferences. Optional analytics technologies, including Google Analytics and Mixpanel where configured, are used only in accordance with the choices and legal requirements applicable to the visitor. Flowly does not use request content for targeted advertising. Browser or device controls can limit non-essential storage, although blocking essential storage may prevent parts of the service from working.

14. Changes to This Policy

We may update this Policy as Flowly, its providers, or legal requirements change. We will post the revised version and update the date above. When required, we will provide additional in-app or email notice and request renewed permission before materially expanding consent-based processing.

15. Contact Us

For privacy questions, rights requests, or complaints, contact the controller:

  • Controller: Nocetic Limited (Flowly)
  • Company number: 16847226
  • Registered office: Unit 501 Leroy House, 434-436 Essex Road, London, United Kingdom, N1 3FY
  • Email: privacy@nocetic.com
  • Website: https://useflowlyapp.com/contact