Privacy Policy
How Flowra collects, uses, and safeguards personal data and client content, including Google OAuth scopes and platform monitoring.
- Last updated
- August 5, 2026
- Contact
- hello@withflowra.com
01Introduction
Flowra ("we", "us", or "our") operates the Flowra visual backend, API composition, and headless CMS platform. We respect your privacy and are committed to protecting the personal data and client content processed through our platform.
This policy explains what we collect, why we collect it, and what we do with it — when your account is provisioned, when you sign in with Google, and while you build schemas and serve content through Flowra.
02Account access & Google OAuth
Flowra has no public self-registration. Access is granted either by contacting our team at hello@withflowra.com or by being invited by an authorized administrator inside an existing workspace. Once provisioned, you sign in with Google OAuth single sign-on.
What Google data we receive
We request only basic profile information:
- Primary email address
- Full name
- Profile picture URL
We do not request access to Google Drive, Gmail, Contacts, Calendar, or any other sensitive or restricted scope.
How we use it
Google profile data is used strictly for identity verification, account creation, session management, and essential service communications.
Flowra's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never sell, rent, trade, or transfer your Google user data to data brokers, advertisers, or automated profiling systems.
We never use Google user data to train generalized artificial intelligence or machine learning models, for advertising, or for credit or lending decisions.
Revoking access
You can disconnect your Google account from the Profile page inside Flowra at any time, or revoke Flowra's access directly from your Google account at myaccount.google.com/permissions.
03Client content & administrative access
Flowra is a managed cloud backend. Clients create their own data models, resources, API endpoints, and content entries, and retain full ownership of everything they submit. We claim no intellectual property rights over client content.
Administrative monitoring notice
Authorized Flowra system administrators and infrastructure engineers retain administrative access to inspect, monitor, and audit data and content stored on the platform.
Why we monitor
- Operational stability, system health, and database performance
- Technical support, schema troubleshooting, and endpoint debugging
- Detecting and mitigating malware, security breaches, and platform abuse
- Legal compliance and preventing prohibited or illegal content
05How we safeguard and store data
Data in transit to and from Flowra infrastructure is encrypted in transit over HTTPS, and stored at rest on managed cloud infrastructure with encryption enabled. Flowra is a multi-tenant platform: workspace data shares infrastructure and is separated by access controls in the application rather than by a database instance per customer.
06Your data rights & deletion
You may request access to your stored personal data, request corrections, or request account deletion at any time.
Your content is readable through the API at any time, and we will provide a full export of your workspace data on request. To permanently delete your account and its platform data, contact our team.
How long we keep it
We retain your account data for as long as your workspace is active. After you request deletion, personal data and workspace content are permanently removed from our systems within 30 days, except where we are required to retain records by law.
07Contact
For questions, data protection inquiries, or anything about our Google OAuth integration:
hello@withflowra.com