legal
privacy policy
How floo labs Inc collects, uses, protects, and shares data when you use floo.
last updated: July 10, 2026
who we are
floo is owned and operated by floo labs Inc. In this policy, "floo", "we", and "us" refer to floo labs Inc.
what we collect
Account and contact data. When you sign up, request access, or contact us, we collect information such as your name, email address, organization, role, and message content.
Authentication data. Authentication is handled through WorkOS. We do not store passwords. We store the account, organization, session, and API-key records needed to operate floo.
Application data. With your permission, floo accesses connected GitHub repositories to download source code for builds and deploys. We store app configuration, deploy history, build logs, runtime logs, request metadata, metrics, and managed-service data. Environment variables and managed-service credentials are encrypted at rest.
Billing data. Payments, subscriptions, invoices, and the customer portal are handled by Stripe. We do not store card numbers or bank account details.
Usage and device data. We collect API usage, billing usage, request counts, status codes, latency, error data, IP-derived request metadata, and similar operational signals to run, secure, debug, and bill the platform.
how we use data
- To build, deploy, and serve your applications
- To provide monitoring, logging, and analytics dashboards
- To authenticate users, protect accounts, and enforce access controls
- To process billing, send invoices, and manage plans
- To send deploy notifications, service alerts, and support messages
- To debug issues, improve reliability, and prevent abuse
- To respond to support requests and feedback
Where required by law, we rely on the legal bases that fit the context: contract performance, legitimate interests in operating and securing floo, legal obligations, and consent where consent is required.
subprocessors
We share data with service providers only as needed to operate floo. Those services fall into these categories:
- cloud infrastructure and managed services
- source control and code delivery
- authentication and identity
- payments and billing
- transactional email
- monitoring and observability
- customer support and operational communications
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use tracking cookies or third-party advertising analytics.
See the current named list on the trust page. For a Data Processing Agreement, email privacy@getfloo.com.
security
Customer workloads run as separate Cloud Run services with app-scoped service accounts. Customer environment variables, managed-service credentials, webhook signing secrets, and shared passwords are encrypted at rest. Traffic to floo endpoints uses TLS. Access to production systems is restricted to authorized personnel.
retention
- build logs and deploy history: 90 days
- runtime logs: 7 days
- account and app records after account closure: deleted from active systems within 30 days
We retain account data while your account is active. Some encrypted backups may remain until they age out of normal backup rotation. We may retain limited records longer when needed for security, abuse prevention, billing, legal, or audit reasons.
your choices and rights
You can access much of your account, app, deploy, and usage data in the dashboard and CLI. You can request access, correction, export, deletion, objection, or other applicable privacy rights by emailing privacy@getfloo.com. We will not discriminate against you for exercising privacy rights.
cookies
The dashboard uses a session cookie named __floo_session for authentication. floo does not use tracking cookies or third-party advertising analytics.
international use
floo is operated from the United States. If you use floo from outside the United States, your data may be processed in the United States and in other locations where our subprocessors operate.
changes
We may update this policy as floo changes. We will update the date above and notify customers of material changes through email, dashboard notice, or another appropriate channel.
contact
Questions about privacy, data processing, or subprocessors? Email privacy@getfloo.com.