aflowbeta

Privacy Policy

Last updated: July 30, 2026

1. What Aflow is

Aflow (aflow.ai) is a hosted platform for building and running AI agents. You bring your own AI-provider keys, connect integrations you choose, and your agents work inside workspaces. Workspaces can be personal (visible to you and anyone you explicitly add) or shared (visible to their members). This policy explains what personal data is processed to provide that service, on what legal basis, and how you can exercise your rights.

2. Who is responsible

The controller for the processing described here is Kareem Elmansi (postal address in the Impressum), contactable at support@aflow.ai. Where a customer uses Aflow to process personal data of their own end users inside a shared workspace, that customer is the controller for that data and Aflow acts as a processor; a data processing agreement is available for such use.

3. Data we process

  • Account data — email address, display name, and authentication identifiers, handled through our identity provider (Auth0). An account is required to use the service; without it we cannot create your workspace or provide the beta.
  • Workspace content — conversations, agent configurations, skills, memories, uploaded files, and run history you create in your workspaces.
  • Collaboration data — workspace membership and roles, invitations you send or receive, and the identity of members with whom content is shared.
  • Credentials and connected accounts — API keys and OAuth tokens you provide for AI providers and integrations. These are encrypted at rest and never displayed after entry.
  • Technical data — server logs, IP addresses (for rate limiting and abuse prevention), and the cookies and browser storage described in section 12.

4. Purposes and legal bases (GDPR)

  • Providing the service you signed up for — creating and running your workspaces, agents, and integrations — Art. 6(1)(b) GDPR (performance of contract).
  • Security, abuse prevention, and service integrity — Art. 6(1)(f) GDPR (legitimate interest). The specific interests we rely on are keeping the platform secure and available, preventing abuse and fraud, diagnosing and fixing faults, and establishing or defending legal claims. You may object to this processing (section 11).
  • Optional features you explicitly enable — for example connecting a particular third-party integration — Art. 6(1)(a) GDPR (consent). You can withdraw consent at any time by disconnecting the integration or emailing us; withdrawal does not affect processing that already took place.

5. Who can see your content

Content is scoped to the workspace it lives in. In a personal workspace, only you — and any member you explicitly add — can read its chats, memories, files, run outputs, and connected resources. In a shared workspace, every member can see that workspace’s content according to their role. Tenant administrators have management visibility (workspace lists, membership, counts, quotas, error and abuse signals) but cannot read the content of a personal workspace they are not a member of; this exclusion is enforced in the authorization layer and covered by automated tests. You decide whom you invite, and you are responsible for having the right to upload any third-party personal data you place in a workspace.

6. Where data is stored

Workspace content, run artifacts, and credentials are stored and processed on Google Cloud in Frankfurt, Germany (europe-west3). The web application is delivered via Vercel; identity is managed by Auth0 on an EU tenant; DNS and network protection are provided by Cloudflare.

7. Processors (sub-processors)

ProviderPurposeRegion
Google Cloud (Google Ireland Ltd.)Application hosting, database, file storage, agent executionEU (Frankfurt)
Auth0 (Okta)Authentication and account identityEU tenant
Vercel Inc.Web application delivery, cookieless page analyticsEU/US (edge network)
Cloudflare Inc.DNS, TLS, network protectionEU/US (edge network)
Salesforce (Heroku)Hosting of the MCP connectivity endpointEU
Amazon Web Services (SES)Transactional and invitation email deliveryEU/US
OpenAIMemory-index embeddings (section 8); voice text-to-speech, if you use voice modeUS
DeepgramSpeech-to-text, if you use voice modeUS
LiveKitReal-time audio transport, if you use voice modeEU/US

Where processors operate outside the EU/EEA, transfers rely on the EU–US Data Privacy Framework (for certified recipients) and/or the European Commission’s Standard Contractual Clauses. You can request a copy of the relevant safeguards by emailing support@aflow.ai.

8. AI providers and integrations you configure

Aflow is bring-your-own-key: content your agents send to an AI provider (for example OpenAI, Anthropic, or Google) is sent using your key, at your instruction, under that provider’s own terms and privacy policy. The same applies to integrations you install and authorize — data flows to those services only within the scopes you approve. Aside from the two platform-operated exceptions below (memory embeddings and, if you use it, voice mode), Aflow does not send your content to third parties on its own initiative.

Memory-index embeddings.To make your workspace memory searchable, Aflow computes vector embeddings of memory documents using the platform’s embedding provider (currently OpenAI). This is automatic, spend-bounded, used solely for search inside your workspace, and the resulting index is stored in Frankfurt alongside your data.

Voice mode.If you start a voice conversation, your audio is streamed through the platform’s voice providers — LiveKit (transport), Deepgram (speech-to-text), and OpenAI (text-to-speech) — for the duration of that conversation. If you never use voice mode, no audio is processed.

9. Google user data

If you connect a Google integration, Aflow accesses only the data covered by the scopes shown in Google’s consent screen, and only to provide the user-facing features of that integration inside your workspace.

Aflow’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: Google user data is used only to provide features you invoke; it is not transferred to third parties except as necessary to provide those features, to comply with law, or as part of a merger or acquisition with notice; it is never used for advertising; and no humans read it except with your explicit consent, for security purposes, or to comply with law.

10. Retention and deletion

  • Account data — retained while your account is active; removed when your account is deleted.
  • Workspace content, including uploaded files and run artifacts — retained until you delete the item or purge the workspace. Workspace purge is permanent and cannot be undone.
  • Credentials and connected accounts — retained until you remove them or delete your account.
  • Database backups — the primary database is backed up daily; backup copies are retained for a short rolling window (currently about seven days) and then overwritten, so deleted data also rolls out of backups within that window.
  • Technical logs — short-lived and used only for operations and security.
  • Account deletion during the beta — email support@aflow.ai. Deletion covers your account identity, your personal workspaces, stored credentials, and connected accounts, and is carried out within the statutory time frame (without undue delay, and at the latest within one month of a verified request).

11. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interest. To exercise any right, contact support@aflow.ai.

You also have the right to lodge a complaint with a supervisory authority. The authority competent for the controller is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), datenschutz-berlin.de. You may also complain to the authority of your own federal state or country of residence.

12. Cookies and browser storage

  • Authentication cookies set by Auth0 and by the app to keep you signed in. These are strictly necessary for the service.
  • A workspace-preference cookie (preferredSpaceSlug) that remembers the workspace you last opened so you land there next time. It stores only a workspace slug, contains no tracking identifier, and is set as part of using the app.
  • Temporary browser storage used briefly during the sign-in and invite flow to carry your invitation through authentication.

We use no advertising or cross-site tracking cookies. Page analytics are provided by Vercel Web Analytics, which measures aggregate usage (page views, referrers, coarse device and region) without cookies and without building a cross-site profile; the legal basis is our legitimate interest in understanding and improving the service (Art. 6(1)(f)).

13. Automated decision-making

Aflow does not make automated decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR. Agents act on your configuration and instructions and produce outputs for your review; you remain in control of consequential actions.

14. Changes

This policy will be updated as the service evolves; material changes are announced in the app. The current version always lives at this address.

15. Contact

For any question about this policy or to exercise a right, email support@aflow.ai. The controller and its postal address are given in section 2 and the Impressum.

Trust & SecurityPrivacyTermsImpressum