Skip to content

legal

privacy policy

How floo labs Inc collects, uses, protects, and shares data when you use floo.

last updated: July 10, 2026

who we are

floo is owned and operated by floo labs Inc. In this policy, "floo", "we", and "us" refer to floo labs Inc.

what we collect

Account and contact data. When you sign up, request access, or contact us, we collect information such as your name, email address, organization, role, and message content.

Authentication data. Authentication is handled through WorkOS. We do not store passwords. We store the account, organization, session, and API-key records needed to operate floo.

Application data. With your permission, floo accesses connected GitHub repositories to download source code for builds and deploys. We store app configuration, deploy history, build logs, runtime logs, request metadata, metrics, and managed-service data. Environment variables and managed-service credentials are encrypted at rest.

Billing data. Payments, subscriptions, invoices, and the customer portal are handled by Stripe. We do not store card numbers or bank account details.

Usage and device data. We collect API usage, billing usage, request counts, status codes, latency, error data, IP-derived request metadata, and similar operational signals to run, secure, debug, and bill the platform.

how we use data

  • To build, deploy, and serve your applications
  • To provide monitoring, logging, and analytics dashboards
  • To authenticate users, protect accounts, and enforce access controls
  • To process billing, send invoices, and manage plans
  • To send deploy notifications, service alerts, and support messages
  • To debug issues, improve reliability, and prevent abuse
  • To respond to support requests and feedback

Where required by law, we rely on the legal bases that fit the context: contract performance, legitimate interests in operating and securing floo, legal obligations, and consent where consent is required.

subprocessors

We share data with service providers only as needed to operate floo. Those services fall into these categories:

  • cloud infrastructure and managed services
  • source control and code delivery
  • authentication and identity
  • payments and billing
  • transactional email
  • monitoring and observability
  • customer support and operational communications

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use tracking cookies or third-party advertising analytics.

See the current named list on the trust page. For a Data Processing Agreement, email privacy@getfloo.com.

security

Customer workloads run as separate Cloud Run services with app-scoped service accounts. Customer environment variables, managed-service credentials, webhook signing secrets, and shared passwords are encrypted at rest. Traffic to floo endpoints uses TLS. Access to production systems is restricted to authorized personnel.

retention

  • build logs and deploy history: 90 days
  • runtime logs: 7 days
  • account and app records after account closure: deleted from active systems within 30 days

We retain account data while your account is active. Some encrypted backups may remain until they age out of normal backup rotation. We may retain limited records longer when needed for security, abuse prevention, billing, legal, or audit reasons.

your choices and rights

You can access much of your account, app, deploy, and usage data in the dashboard and CLI. You can request access, correction, export, deletion, objection, or other applicable privacy rights by emailing privacy@getfloo.com. We will not discriminate against you for exercising privacy rights.

cookies

The dashboard uses a session cookie named __floo_session for authentication. floo does not use tracking cookies or third-party advertising analytics.

international use

floo is operated from the United States. If you use floo from outside the United States, your data may be processed in the United States and in other locations where our subprocessors operate.

changes

We may update this policy as floo changes. We will update the date above and notify customers of material changes through email, dashboard notice, or another appropriate channel.

contact

Questions about privacy, data processing, or subprocessors? Email privacy@getfloo.com.