Privacy Policy
What we collect, why, and the choices you have — including how FongFlow uses Google user data. Last updated September 30, 2026.
1. Who we are
This Privacy Policy explains how FongFlow (“we”, “us”) collects, uses, and protects personal information when you visit fongflow.com or use the FongFlow workspace and its apps (the “Service”).
2. Information we collect
Account information — your name, email address, password (stored only as a secure hash), avatar, and the teams and workspaces you belong to.
Content — the notes, documents, tasks, files, images, messages, flows, and other material you or your teammates create or upload. This Content belongs to you; we process it only to run the Service for you.
Usage and device data — pages visited, features used, approximate location derived from IP address, browser type, and similar technical information collected through logs and analytics.
Billing information — plan, billing history, and the details needed to process payments. Card numbers are handled by our payment processor and never stored on our servers.
Connected services — when you connect third-party accounts or credentials (for example GitHub, Jira, Telegram, or an AI provider key), we store the tokens needed to act on your behalf. Secrets are encrypted at rest and are never shown back in the interface.
3. How we use information
We use your information to provide, maintain, and secure the Service; to authenticate you and keep your workspace private; to process billing; to send transactional emails such as invitations, password resets, and notifications you have enabled; to respond to support requests; and to understand how the Service is used so we can improve it.
We do not sell your personal information, and we do not use your Content to train AI models.
4. AI features
When you use AI-assisted features (chat, agents, summaries, flow AI nodes), the relevant prompt and context are sent to the AI model provider that powers that feature, only for the purpose of generating a response. If you bring your own API key, your request is governed by your agreement with that provider.
5. How FongFlow uses Google user data
FongFlow can connect to a user's Google account so the FongFlow Flow app can read from and write to Google Sheets as part of workflows (automations) the user builds. Connecting is optional. It happens only when the user clicks “Connect with Google” on a Flow credential and approves Google's consent screen.
Data accessed
https://www.googleapis.com/auth/spreadsheets — the contents of Google Sheets spreadsheets the user's workflows are configured to use: cell values, rows, sheet (tab) names and spreadsheet titles.
https://www.googleapis.com/auth/drive.file — only the specific Drive files the user picks or that FongFlow creates for the user. FongFlow cannot see or list any other files in the user's Google Drive.
https://www.googleapis.com/auth/userinfo.email — the email address of the connected Google account.
FongFlow also receives an OAuth access token and refresh token from Google for the connected account.
Data usage
Spreadsheet data is used only to perform the workflow steps the user configures: appending, reading, finding, updating or deleting rows in the chosen spreadsheet, and passing the result to the next step of that user's workflow.
The email address is used only to show the user which Google account a credential is connected to.
The OAuth tokens are used only to call the Google Sheets and Drive APIs on the user's behalf when the user's workflows run or when the user tests the connection.
FongFlow does not use Google user data for advertising, does not sell it, does not use it to build user profiles, and does not use it to develop, train or improve generalized AI or machine-learning models.
Data sharing
FongFlow does not share Google user data with third parties, except: (a) when the user's own workflow sends it to another step the user added — for example an AI step that uses the user's chosen AI provider, or a message step to Telegram — which happens only at the user's direction; (b) with infrastructure providers that host FongFlow (such as Amazon Web Services), under contracts that limit their use to providing services to us; (c) when required by law; or (d) as part of a merger, acquisition or sale of assets, with notice to the user.
FongFlow staff do not read Google user data unless the user gives explicit permission (for example, for support), it is necessary for security purposes such as investigating abuse, or it is required by law.
Data storage and protection
OAuth tokens are stored encrypted at rest (AES-GCM) in FongFlow's database, are never shown back in the interface, and are only decrypted inside FongFlow's servers when a workflow step needs them. All traffic to FongFlow and to Google's APIs is encrypted in transit with HTTPS/TLS. Access to production systems is limited to authorized FongFlow staff.
Spreadsheet data read or written by a workflow is stored only as part of that workflow's run history, so the user can see what each step did.
Data retention and deletion
OAuth tokens are kept until the user deletes the credential or their account. Deleting the credential in Flow → Credentials permanently deletes the stored tokens immediately.
Run history containing spreadsheet data is kept while the user's account is active and is deleted when the account is deleted. Users can ask for earlier deletion of any Google user data by emailing [email protected]; we complete requests within 30 days.
Users can revoke FongFlow's access at any time from their Google Account at https://myaccount.google.com/permissions.
Limited Use disclosure
FongFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
6. Cookies and analytics
We use local browser storage to keep you signed in and remember your preferences. On our public pages we use Google Analytics and Umami, a privacy-focused analytics tool, to measure traffic in aggregate. You can block analytics cookies in your browser without affecting core functionality.
7. How we share information
We share information only with service providers that help us operate the Service — such as cloud hosting and file storage (Amazon Web Services), email delivery, payment processing, analytics, and AI model providers — under contracts that limit their use of the data to providing services to us.
Within the Service, Content is visible to the people you share it with: members of your team, or anyone holding a public share link you create. We may also disclose information if required by law or to protect the rights and safety of our users.
8. Data retention
We keep your information for as long as your account is active. Items you move to trash can be restored for a limited time before permanent deletion. When you delete your account or workspace, we delete or anonymize the associated data within a reasonable period, except where we must retain it for legal, tax, or security reasons.
9. Security
We protect data with encryption in transit (HTTPS), encrypted storage for credentials, access controls, and regular review of our infrastructure. No system is perfectly secure, so please use a strong, unique password and let us know right away if you suspect unauthorized access.
10. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can update most information directly in your account settings, or contact us to make a request. We will respond within the timeframe required by applicable law.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. If a change is material, we will notify you through the Service or by email before it takes effect.
13. Contact
Questions about your privacy? Reach us through the contact page or write to [email protected].