Data deletion request
Flowroid runs on your phone, and almost everything it creates stays there. The exceptions are a licence record proving this install is in its trial or entitled, and — if you own Flowroid or have Flowroid AI — the meters behind your AI allowance. This page is how you have them deleted.
What we hold on our server
Flowroid has no accounts. There is no sign-up, no password, and no e-mail address on file. Every record below is keyed by a device key: a one-way SHA-256 hash of a device identifier and a secret salt, computed on your phone before anything is sent. The raw identifier never leaves the device, and the hash cannot be turned back into it.
| Record | What it holds | How long we keep it |
|---|---|---|
| Device record | A one-way SHA-256 hash of an Android device identifier combined with a secret salt, computed on your device; the date your trial started; integrity flags returned by Google Play Integrity; the date this install first ran a real automation; and the app version it first registered with and first ran an automation on. The version is a release number shared by every install of that release, not an identifier. | Kept for the life of the product, and deleted on request. This record is what makes the trial one per device. |
| Purchase record | A one-way SHA-256 hash of the Google Play purchase token, the obfuscated account identifier Google Play supplies, the device keys the purchase is linked to (at most 10), which product it is, its state and renewal date, and whether it has been revoked. This covers the one-time unlock, a Flowroid AI subscription, an unlock bought before 17 August 2026, and a legacy Flowroid Pro subscription. | Kept while the entitlement is active, then for 90 days. |
| AI usage meter | A running tally of the AI credits spent in the current billing period, keyed by an anonymous metering id and the calendar month. The metering id is a hash of your purchase once you own Flowroid, and of the device key during the trial. It counts usage. It holds nothing you asked, and nothing that was answered. | 12 months, then deleted automatically. |
| AI credits (balance and ledger) | A running balance of the AI credits you have bought, and an append-only ledger with one row per top-up bought and per AI request paid from purchased credits: the same anonymous metering id, the number of credits added or spent, and — for a top-up — a hash of that purchase’s Play token so the same purchase can never be redeemed twice. It belongs to your purchase, and is shared by every device the purchase is restored on. | Kept while the credits are yours to spend — purchased credits do not expire. Deleted on request when the device asking is the last one linked to the purchase. |
| Redeemed credit-pack record | A one-way hash of each credit-pack purchase, with its product and date. Once your AI credits are erased it has no link to you, your device or your purchase. | Kept permanently, so the same pack purchase can never be redeemed twice. Not deletable on request, because it identifies no one. |
| Request logs | The HTTP method, route, response status, and latency of each call to our server, plus a truncated or hashed IP address. Request and response bodies are never logged — including the assistant’s and every AI step’s. | 30 days, then deleted automatically. |
These are the same records described in Privacy Policy Section 5. They are stored on Google Cloud infrastructure in the europe-west1 region (Belgium). Nothing else about you is held server-side: no flows, no variables, no execution logs, no location, no contacts — and nothing you have said to the AI assistant and no AI step’s prompt, which are never stored or logged at all (Privacy Policy Section 7). The two AI rows count what your allowance has spent, not what you asked.
What deletion removes, and what it costs you
A deletion request removes, for the device key you quote:
- Your device record. The trial resets, and the trial’s AI meter goes with it.
- If this is the only device on your purchase: the purchase record, its AI usage meter, and any unspent purchased credits are erased.
- If other devices still use your purchase: this device is only unlinked. The purchase, its meter and its credits stay for those devices.
What stays: a one-way hash of each credit pack you bought, with its product and date, unlinked from you, your device and your purchase. It is kept so the same purchase can’t be redeemed twice, and it identifies no one.
Request logs are not part of a request: they expire on their own within 30 days and hold no key we could search them by.
Consequences worth knowing first
Your trial resets. The device record is what keeps the trial to one per device, so it deliberately survives an uninstall, a clear-data, and Settings → Reset App Data. That persistence is the anti-abuse mechanism, and it is the reason resetting the app is not deletion. Removing the record gives that device a fresh14-day trial.
What you paid for detaches from this device. Deleting the purchase record unlinks whatever you hold — the one-time unlock and any Flowroid AI subscription, or an earlier lifetime unlock or Flowroid Pro subscription — from this device. The purchase itself is not lost: Google holds it against your Google account. Open Flowroid and use Restore purchase and it is re-linked. Skip that step and the app will behave as though it were never bought.
Your AI credit balance may go with it. Credits belong to your purchase, not to one phone. If this is the only device on the purchase, any unspent purchased credits are erased, and Restore purchase brings back the unlock (Google holds it) but not the credits — spend them first if they matter to you. If other devices still use the purchase, they keep the credits, and Restore purchase on this device re-links it, balance included. Your monthly allowance is unaffected either way: it is granted afresh each period.
Deletion is irreversible. Once the rows are gone we cannot restore them, and we keep no backup copy that would let us.
Analytics is a separate control, and a faster one
A deletion request covers the records above. It does not cover analytics, because we hold none: Privacy Policy Section 8 describes what Google receives if you allow it — and what Meta receives if the choice you allowed was ad measurement — and they, not we, are where it is held. Three things are in your hands and take effect at once, with no request to anyone:
- Settings → Privacy — withdraw Product analytics, Ad measurement, or both. Collection stops immediately — for Meta as well as Google — and withdrawing a choice also deletes the analytics identifiers stored on your device.
- Settings → Privacy → Delete analytics data — clears those identifiers on its own, without changing either choice.
- Neither reaches what has already been received, and the two recipients differ there. Google expires the user- and event-level rows after 2 months by itself; to ask for them sooner, write to support@flowroid.com and we will make the request on your behalf. Meta’s copy we cannot delete for you — it is held by Meta as its own controller, on Meta’s retention, and the request has to go to Meta. See Section 4.
How to request deletion
- Copy your device key. In Flowroid, open Settings → About and copy the device key. It is a 64-character hexadecimal string, and it is the only thing that identifies your record: with no account and no e-mail address on file, we cannot look you up from the address you write to us from. If your version of the app does not show it yet, update to the latest release from Google Play first.
- Send the request. Use the button below, or e-mail support@flowroid.com yourself with the subject Data deletion request and the device key in the message. Please send it from the device that owns the key where you can, so we can be confident the request is yours.
- We confirm what was deleted. You get a reply telling you which records were removed. We log the deletion as a timestamp and the device key, and nothing else; your e-mail address is not added to any list and is not kept once the request is closed.
Opens a draft addressed to support@flowroid.com, subject Data deletion request. Nothing on this page is submitted to us: the draft is assembled in your browser and sent from your own mail app.
Write it yourself instead
Address it to support@flowroid.com with the subject Data deletion request
Please delete the licence records for the device key below. Device key: (paste the key from Settings → About) I understand that this resets the trial for this device, and that if I have bought Flowroid I will need to use Restore purchase afterwards.
What a request to us does not cover
Your Google Play order
The purchase itself belongs to Google, not to us. We receive a hashed purchase token and the purchase state; the order record, including your payment details, is held by Google as its own controller and we have no way to reach or erase it. Manage it from your Google account:
Analytics data, if you allowed any
Analytics and ad-measurement data is held by Google and — if you allowed ad measurement specifically — by Meta, not on our server, so none of it is among the records a request to us deletes; there is nothing of it here to remove. What reaches each of them is described in Privacy Policy Section 8. Stop it at source in Settings → Privacy, which ends all future sending to both, and clear the on-device identifiers with Settings → Privacy → Delete analytics data. If you allowed only product analytics and never ad measurement, Meta received nothing at all and only the Google half applies. If you never allowed either choice, none of this applies: nothing was collected.
What we can have deleted, and what we cannot. For the Google half, write to support@flowroid.com — we will ask on your behalf, because Google holds it as our processor in a property we control, and Google expires it after 2 months in any case.
We cannot delete Meta’s copy for you
Meta acts as an independent controller under the Meta Business Tools Terms: what it receives becomes Meta’s, held under Meta’s own retention rules and its own privacy policy. We can stop sending to Meta at any time, and we can clear what is stored on your phone, but we cannot delete Meta’s copy on your behalf. There is no request we can make on your behalf and no instruction we can give, so we would rather say so than let this page imply a completeness it does not have. To have it deleted, ask Meta directly — through the controls in your Meta account, or the routes set out in the Meta Privacy Policy.
The data on your phone
Your flows, variables, execution logs and crash reports are yours outright, and no request to us is needed or possible: we have no copy and no way to reach them. Delete them with Settings → Reset App Data, or by uninstalling the app. Privacy Policy Section 14 lists the individual controls.
How long we take
We confirm within 30 days of receiving a complete request, the period GDPR Article 12 allows. A request is complete once it carries a device key we can find. If the key does not match a record we will tell you so rather than guess: deleting the wrong row would reset a stranger’s trial and detach their unlock.
Withdrawing consent is not a request and needs no reply. Analytics and ad measurement are the only things Flowroid does on the basis of your consent, and you take it back yourself in Settings → Privacy — immediately, with no form, no account to verify and no waiting period. Withdrawal does not affect the lawfulness of what was collected beforehand, and it changes nothing else about the app.
Erasure is one of several rights you hold over these records. For access, rectification, restriction, objection or portability, write to the same address: support@flowroid.com. Privacy Policy Section 17 sets them out, and you can complain to your national data protection authority if you think we have handled your data unlawfully.