Privacy Policy

Effective 2026-08-12

Data Controller:Floburn Inc. ("Floburn," "we," "us," "our"), the operator of the Agent Floburn platform (the "Service").
Contact: privacy@floburn.com

1. Information We Collect

1.1 Information You Provide Directly

  • Account details (name, email address, password)
  • Workspace content you and your team create in the Service: CRM contacts and leads, campaigns, calendars, email drafts and sends, social and ad copy, ad creatives, brand assets (logos, photos, fonts, colors), notes, and related records
  • Credentials for integrations you connect (stored encrypted; see Section 6)
  • Payment and billing information, only if we introduce paid plans in the future
  • Support communications

1.2 Information We Collect Automatically

  • Usage data and interaction patterns
  • Device information (IP address, browser, operating system)
  • Sign-in events and audit-log entries recording actions taken in your workspace
  • Performance metrics, error reports, and crash logs
  • Cookies (see Section 11)

1.3 Information From Integrations and Third Parties

  • Services you connect at your direction: Google (sign-in, Gmail, Google Calendar), Metricool, Google Ads, and Meta (Facebook / Instagram) advertising accounts
  • Information that prospects and customers of your organization submit through lead-capture forms and landing pages hosted by the Service
  • Analytics and infrastructure providers

2. Data We Process on Behalf of Your Organization

Agent Floburn is a business tool. For the contacts, leads, and campaign-recipient data that your organization imports into or collects through the Service, your organization is the data controller and Floburn acts as a processor on your organization's instructions. If you are a customer, prospect, or contact of an organization that uses Agent Floburn and you want to exercise privacy rights over data that organization holds about you, please contact that organization directly; we will assist and forward any requests we receive to them.

3. How We Use Your Information

3.1 Service Provision

  • Operate, maintain, and secure the Service
  • Provide AI-assisted features (drafting, recommendations, analysis — see Section 13)
  • Send and receive email, publish content, and manage advertising campaigns on your behalf through integrations you connect
  • Provide customer support

3.2 Service Improvement

We analyze aggregated, de-identified usage data to improve the Service and develop new features. We do not use your workspace content to train AI models, and our AI providers are contractually prohibited from doing so (see Section 13).

3.3 Communication

  • Transactional and security notifications
  • Service or policy change notifications
  • Support responses
  • Marketing communications (opt-in only)

3.4 Legal Compliance and Safety

  • Comply with legal obligations and law-enforcement requests
  • Protect rights and property, prevent fraud and abuse
  • Enforce our Terms of Service

4. Legal Basis for Processing (GDPR)

  • Contract performance: processing needed to provide the Service under our Terms of Service.
  • Legitimate interest: business operations, service improvement, fraud prevention, security, and support.
  • Consent: marketing communications and non-essential cookies (withdrawable at any time).
  • Legal obligation: tax, regulatory, and law-enforcement requirements.

5. How We Share Your Information

5.1 Subprocessors

We rely on third-party infrastructure providers (hosting, database, email delivery, AI inference) to deliver the Service. The current list, with purposes and data residency, is maintained at /legal/subprocessors. All providers are contractually obligated to protect your data. We do not sell personal data and we do not share it with third parties for advertising.

5.2 Integrations You Connect

When you connect an integration (Google, Metricool, Google Ads, Meta), we transmit data to and from that provider as needed to perform the actions you request — for example sending email through your Gmail account, syncing calendar events, or publishing and reading metrics for ad campaigns. Each provider processes that data under its own terms and privacy policy. You can disconnect an integration at any time from your workspace settings.

5.3 Legal Requirements

We may disclose information when required by subpoenas, court orders, warrants, or other lawful government requests.

5.4 Business Transfers

Data may transfer to a successor entity in a merger, acquisition, or bankruptcy.

5.5 Aggregated Data

We may share anonymized, aggregated statistics that cannot reasonably identify you.

6. Google User Data and Limited Use

Agent Floburn's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Gmail and Google Calendar data is accessed only to provide user-facing features you request (sending and receiving email on your behalf, two-way calendar sync) and is never used for advertising or transferred to third parties except as necessary to provide those features, comply with law, or as part of a business transfer.
  • Humans do not read this data except with your explicit consent, for security purposes, or to comply with applicable law.
  • Google Ads account data is used solely to create, manage, and report on advertising campaigns at your direction.
  • OAuth tokens are stored encrypted. Disconnecting an integration deletes the stored tokens; you can also revoke access at myaccount.google.com/permissions.

7. Data Retention

  • Account data: retained while your account is active; deleted or de-identified when your account is deleted (see Section 8).
  • Workspace content: retained until you or your workspace admins delete it or the workspace is deleted.
  • Audit logs: membership and action records are retained in de-identified (tombstoned) form after account deletion to preserve the integrity of workspace audit trails.
  • Payment records (if any): 7 years (tax compliance).
  • Support communications: 3 years after resolution.
  • Backups: deleted data ages out of encrypted backups on our standard backup-rotation schedule.

We may retain data longer when required by law, for legal proceedings, or to enforce our Terms.

8. Account and Data Deletion

You can delete your account and data in two ways:

  • Self-serve: go to /me/account. From there you can download a full JSON export of every record attributed to your user, and permanently delete your account. Deletion removes your personal information; workspace memberships are tombstoned (de-identified) for audit-trail integrity. If you are the only admin of a workspace, promote another admin first — the request will otherwise be refused to avoid orphaning your team's data.
  • By email: send a request to privacy@floburn.com from the email address registered to your account. We complete deletion within 30 days; residual copies age out of backups on our standard rotation schedule.

Disconnecting an integration from your workspace settings deletes the stored credentials for that integration. Content your organization has already published to external platforms (sent emails, live ads, posted content) is governed by those platforms and is not recalled by account deletion.

9. Your Privacy Rights

9.1 GDPR Rights (EEA, UK Users)

  • Access, rectify, or erase your personal data
  • Restrict or object to processing
  • Data portability
  • Withdraw consent
  • Request human review of automated decisions

9.2 CCPA Rights (California Residents)

  • Know what information is collected and how it is used
  • Request deletion
  • Opt out of sales of personal information (note: Floburn does not sell personal information)
  • Non-discrimination for exercising privacy rights

9.3 Exercising Your Rights

Use your account settings, or email privacy@floburn.com. We respond within 30 days (GDPR) or 45 days (CCPA).

10. Data Security

  • Encryption in transit (TLS) and at rest
  • Integration credentials stored encrypted
  • Role- and permission-based access controls per workspace
  • Audit logging of workspace actions
  • Continuous monitoring and error reporting

While we use reasonable security measures, no system is 100% secure. Keep your password confidential, use a strong unique password, and report unauthorized access immediately.

11. Cookies

The Service uses essential cookies (authentication, security) and preference cookies (settings such as theme). We do not use third-party advertising cookies. You can manage cookies through your browser settings; disabling essential cookies will prevent sign-in.

12. International Data Transfers

Your data may be transferred to and processed in the United States and other countries. For transfers from the EEA or UK we rely on Standard Contractual Clauses, adequacy decisions, or your explicit consent, and we maintain the same standards of protection regardless of location.

13. AI Processing and Third-Party AI Providers

13.1 AI Features and Content Sent

AI powers drafting and editing of campaign content, ad copy and creative suggestions, CRM and campaign analysis, recommendations, and the in-app assistant. Processing relies on contract performance (GDPR Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)). Content transmitted may include your prompts, workspace content (contacts, campaigns, drafts), brand assets, and uploaded images — only for the features you request, never for advertising, and never sold or shared.

13.2 Our AI Provider

AI features are provided through Anthropic (Claude models) Data Processing Addendum. Anthropic acts as a processor under GDPR Article 28, processing content only on our instructions to return results. Under our paid API agreement, Anthropic is contractually committed not to use the content we submit to train or improve its models.

13.3 AI Outputs Are Informational Only

AI-generated drafts, recommendations, and analyses are provided "as is," for informational purposes only, without warranties of accuracy or completeness, and do not constitute professional, financial, or legal advice. Review AI-generated content before sending, publishing, or acting on it.

13.4 No Solely-Automated Decisions

The Service does not make legally binding or similarly significant decisions about you solely through automation (GDPR Art. 22). AI outputs inform decisions that you make and approve.

14. Children's Privacy

The Service is a business tool for users 18 and older and is not directed to children under 13. We do not knowingly collect information from children under 13; if discovered, it is deleted immediately. Contact privacy@floburn.com with any concerns.

15. Third-Party Links and Services

This Privacy Policy does not apply to third-party websites or services, including platforms you publish to through the Service. Review their privacy policies separately.

16. Changes to This Privacy Policy

We may update this policy to reflect changes in the Service, legal requirements, or security measures. Material changes will be announced by email, in-app notification, or a website banner; minor changes update the effective date on this page. Continued use constitutes acceptance.

17. California "Do Not Sell My Personal Information"

Floburn does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. Sharing occurs only as described in Section 5. California residents can direct questions to privacy@floburn.com.

18. Contact Us

Privacy questions and GDPR inquiries: privacy@floburn.com
General support: support@floburn.com

Floburn Inc.
600 1st Ave, Ste 330, PMB 404288
Seattle, WA 98104
United States

EEA/UK residents may also lodge complaints with their local data protection supervisory authority.