Skip to main content
Legal · Privacy Policy

Privacy Policy

Effective: July 24, 2026

Floo AI (a product of VLMS Global) takes privacy seriously. This policy explains what data we collect, why we collect it, and the choices you have. It applies to floo.ai, our dashboards, and any service we operate.

1. Information we collect

Account data: name, email, company, billing details and authentication metadata when you create or use a Floo account.

Usage data: dashboard activity, feature usage, IP address, browser type, and standard server logs to keep the service running and secure.

Voice and call data: when you operate a Floo voice agent, we process audio, transcripts, and metadata for the duration of a call. This data is stored encrypted and tied to your tenant only.

Knowledge base content: any documents, URLs, or data sources you upload to power your agents.

Connected integration data: account identifiers, encrypted authorization credentials, resource identifiers, and the data you explicitly configure Floo to access through third-party integrations.

2. Google user data

When you connect Google Calendar or Google Sheets, Floo accesses your Google account email, encrypted OAuth tokens, and the calendar, spreadsheet, tab, range, and related identifiers you choose to configure.

Google Calendar: Floo uses free/busy data only to calculate available booking times. When booking is enabled, Floo creates booking events and may delete Floo-created events if a booking is cancelled. Floo does not use Calendar data for advertising or unrelated purposes.

Google Sheets: Floo reads only the spreadsheet and ranges that a workspace explicitly configures for a user-facing lookup, voice-agent tool, or automation, and writes only when the workspace configures an append action. Floo does not browse or use unrelated spreadsheets.

Storage and retention: OAuth tokens are encrypted. Floo stores the connected account email, configured resource identifiers, and event or action identifiers needed to operate and audit the integration. Google data intentionally copied into Floo records, call results, or workflow outputs follows the workspace's applicable retention settings.

Sharing and user control: Floo does not sell Google user data or use it for advertising or training general-purpose or shared AI models. We disclose Google user data only to service providers acting on our behalf when necessary to deliver the user-requested feature, or when required by law. You can disconnect the integration in Floo and revoke Floo's access from your Google Account.

Floo AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. How we use your data

Operate the service, provision agents, route calls, store transcripts, generate summaries, and bill correctly.

Improve the product, aggregate, anonymized usage signals help us debug issues and improve reliability. Your call audio and transcripts are never used to train shared models without explicit consent.

Communicate, send service notifications, security alerts, and (only with consent) product updates.

Comply with law, meet TCPA, DNC, HIPAA-aligned, and other applicable obligations.

4. Data we never use for training

By default, we do not use your call recordings, transcripts, or knowledge-base content to train any shared AI model.

Models you select on Floo (OpenAI or Anthropic LLMs, ElevenLabs voices, Deepgram STT, etc.) are queried via APIs that your tenant configures. Each provider's privacy terms apply on top of ours.

5. Sharing and subprocessors

We share data only with subprocessors needed to deliver the service, including LiveKit (telephony infrastructure), OpenAI and Anthropic (LLMs), Deepgram (STT), ElevenLabs (TTS), Stripe (billing), and Vercel/AWS (hosting).

A current list of subprocessors is available on request from privacy@floo.ai. We sign data-processing agreements (DPAs) with all subprocessors that touch customer data.

6. Data retention

Account and billing data is retained for the life of your account and for up to 7 years after closure for tax and legal purposes.

Call recordings, transcripts, and analytics are retained per the retention setting you configure (default 90 days). You can permanently delete any record from the dashboard.

On account closure, customer-controlled data is deleted within 30 days unless legal hold requires longer retention.

7. Your rights

Access, correct, export, or delete your personal data by emailing privacy@floo.ai or using the dashboard self-service tools.

If you are in the EU/UK, you have rights under GDPR including the right to lodge a complaint with your local supervisory authority.

If you are a California resident, you have rights under CCPA including the right to know, delete, and opt out of sale (we do not sell personal information).

8. Security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is logged, audited, and limited to the smallest team possible.

We are working toward SOC 2 Type II and HIPAA compliance. Current security documentation is available under NDA from security@floo.ai.

9. International transfers

Floo is operated by VLMS Global with infrastructure in the US and EU. Data may be transferred across regions for service delivery.

We rely on Standard Contractual Clauses (SCCs) and equivalent mechanisms for cross-border transfers where required.

10. Changes to this policy

We will notify users of material changes via email or in the dashboard at least 30 days before they take effect.

The most current version is always at floo.ai/legal/privacy-policy.

11. Contact

Privacy questions: privacy@floo.ai. Legal: legal@floo.ai. Security: security@floo.ai.

Questions? Email legal@floo.ai and we will respond inside one business day.

Build Your First AI Voice Agent

Create an AI voice agent for inbound calls, outbound campaigns, customer support, lead qualification or appointment booking and test your first conversation before going live.

Start building your first agent