Privacy policy
Flow Digital AI ("the Service") gives businesses automated replies and a customer management system on top of Meta's WhatsApp Business Platform. This document explains what data we process, what for, and how it can be removed.
Who is responsible for the data
The Service is operated by Tal Fisher, licensed dealer 316527530, Amnon Lipkin Shahak 12, Netanya, Israel. Privacy enquiries: office.flowdigital@gmail.com.
The business that signs up for the Service is the data controller for the customers who message it. Flow Digital AI acts as a data processor on its behalf, and processes the data solely to provide the Service.
What data we collect
- The phone number and display name of whoever messages the business on WhatsApp
- Message content — text, images and voice notes — in both directions
- Delivery data (sent, delivered, read) and message timestamps
- What the business enters itself: business details, business rules and knowledge-base documents
- Details of the business's own users who sign in: email and name
We don't collect location, contacts from the device, or anything beyond what is sent in the conversation itself.
What the data is used for
To generate an automated reply, to keep conversation history so replies stay coherent, to manage the lead in the CRM, and to show the business its usage figures. We don't sell data and we don't use it for advertising.
Third-party services
- Meta (WhatsApp Business Platform) — sending and receiving the messages.
- Google Gemini — message content is sent to the model to generate a reply. It is not used to train the model.
- Supabase — database and file storage.
- Railway — server hosting.
- Sentry — error monitoring for the service.
Google Calendar access
A business that chooses to connect its Google Calendar grants us access through Google's own consent screen. This section sets out exactly what is and is not collected, and it applies only to businesses that connected a calendar themselves.
- What we read: the list of calendars you can add events to (name and id), so you can choose which one appointments go into, and a free/busy query for a date range — when you are busy, without what you are busy with.
- What we write: appointments booked through the service, by the bot or by a member of your team from the dashboard. Each event has the service and the customer's name in its title (an appointment still waiting for your approval is marked as such), the customer's phone number, the price and any notes in its description, and the service's location. When an appointment is moved we create a new event and delete the old one; when it is cancelled we delete it. We only ever delete events we created.
- What we do not read: the content of existing events in your calendar — titles, descriptions, guests or locations. We never request it, so it never reaches us and is never stored by us.
What we store: the connected Google account address, the id and name of the chosen calendar, the permissions you granted, and the access tokens, encrypted; and, for each appointment we book, the id of the event we created. The busy intervals themselves are not stored: they are used to work out the open times at that moment and discarded immediately afterwards.
The open times worked out from your free/busy information are passed to Google Gemini, the model that writes the bot's reply, and are sent to the customer in that reply on WhatsApp; the reply is kept in the conversation like any other message. Error reports sent to Sentry may include the id of a calendar or an event. Beyond that, Google Calendar data is never sold, never used for advertising, never transferred to anyone for any other purpose, and never used to develop, improve or train generalized AI or machine-learning models — neither by us nor by Google Gemini, which we use under Google's paid terms.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect the calendar at any time from the Calendar screen in the dashboard. Disconnecting deletes the access tokens on our side and revokes the grant with Google. You can also remove it directly from your Google account's security settings.
How we measure site traffic
We measure traffic on the marketing site ourselves, with no third-party analytics tool and no cookies. The purpose is to know which pages get read and which buttons get pressed — not who read them.
- What is stored: the page address on our site, the page language, the name of the button pressed, the domain you arrived from (google.com, for example — without the full address and without any search terms), whether the visit was from a phone or a computer, and a campaign label if you arrived through an ad
- What is not stored: your IP address, your exact browser or device, and any persistent identifier. We therefore cannot identify you and cannot follow you between visits
- Each page load is given a random number that lives in the browser’s memory only, is never written to your device, and disappears when the tab closes. It lets us tell that a button was pressed during that same load, and nothing more. Reading two pages counts as two separate visits
- Measurement data is deleted automatically after 180 days
- If your browser sends a Do Not Track or Global Privacy Control signal we do not measure at all. You can also switch measurement off by hand at any time through “Privacy preferences” at the foot of the page — even though it is not personal and stores nothing on your device
What is stored in your browser
The site uses no cookies and carries no third-party trackers. On your first visit you are asked what may be stored, and you can change that at any time through the “Privacy preferences” link at the foot of every page. These are the only things that can be kept in your browser’s local storage, and all of them are ours:
- Your light/dark and interface language preference — stored only if you actually chose one, so the choice survives to your next visit
- The campaign label you arrived through — kept only if you explicitly allowed it, so we know which ad led to a signup. It survives the email verification round-trip, is deleted the moment signup completes, and is deleted immediately if you withdraw that permission
- Inside the product itself your session credentials are also stored, as is necessary to keep you signed in
Screen recording
So that we can see where the product gets in the way of the people using it, we record how the product's screens are used — navigation, scrolling and clicks — and replay them ourselves to improve it. On the marketing site recording runs only after separate, explicit consent, which you can give and withdraw at any moment through “Privacy preferences” at the foot of every page.
- What is recorded: which screens were opened, how far you scrolled, what you pressed, and the structure of the page as it was shown
- What is not recorded: your own customers' material. The conversation list, the messages, the lead cards, the notes and the appointments are blocked in the browser before anything is sent, and appear in a recording as an empty rectangle. Every input field is masked as well, so what was typed — including passwords and replies to customers — never leaves the browser
- Recordings are deleted automatically after 30 days, and are visible only to the people running the service
- You can switch it off: in “My account” inside the product, by unticking “Allow my screens to be recorded”. It takes effect immediately
Security
Traffic is encrypted with HTTPS. Each business's access tokens are encrypted in the database (AES-256-GCM), so a database backup on its own does not expose them. Every inbound request is cryptographically verified against Meta, and permissions are separated so one business cannot reach another's data.
Opting out
Anyone messaging the business can send "הסר" or "STOP" and the system will stop contacting them. To resume, they send "התחל" or "START".
Deletion and your rights
You can ask to see, correct or delete your data. An end customer's deletion request is handled through the business they were messaging. Deleting a business account deletes all of its conversations, media and knowledge base.
Privacy enquiries: office.flowdigital@gmail.com
Changes to this policy
We'll update this document as needed, and the date of the last update appears at the top.
© 2026 Flow Digital AI · Operated by Tal Fisher, licensed dealer 316527530