Skip to content
FlowroidHelp & Docs

Privacy Policy

Effective
September 25, 2026
Last updated
September 25, 2026
Application
com.flowroid

The short version

  • Your automations run on your device. Flows, variables, execution logs and crash reports stay there, and we have no way to read them.
  • In the app: analytics and ad measurement are off until you turn them on. Flowroid asks on first run with everything switched off, the two choices are independent, and you can change them at any time in Settings → Privacy (Section 8). Allowing ad measurement is the one choice that discloses to a second company, Meta; refuse it and Meta receives nothing. No ads are shown in the app and there is no third-party crash reporting.
  • On this website: anonymous, cookieless page counts — no account, no identifier that survives the day, nothing you typed. Do Not Track and Global Privacy Control are honoured, and there is a one-click switch to turn it off entirely (Section 12).
  • One routine call goes to a server we operate whatever you choose: an anonymous licence check that proves this install’s trial and purchase status. It carries a one-way hash, never your raw device identifier and never any automation content.
  • Two optional features send your content off the device. The first is the AI assistant: your message, the conversation so far, and the tools it may use go to our AI proxy and on to Google’s Gemini API to be answered. Analytics, if you allow it, carries no content at all.
  • The second is AI steps in your flows: each time a flow runs one, the step’s prompt — including any values the flow puts in it, such as a notification’s text — takes the same route. We do not store or log any of it, and it is not used to train models. Use neither and nothing you type or automate reaches our servers — your flows keep running either way (Section 7).
  • Apart from analytics you have allowed, everything else that leaves your phone is traffic you create: an HTTP Request action you configure, or a purchase handled by Google Play.
  • Secret variables are encrypted at rest with AES-256 in the Android Keystore.
  • Settings → Reset App Data and uninstalling both clear your device. Your licence record is separate and is kept until you ask us to delete it: request deletion.
On this page
  1. 01Introduction
  2. 02Data controller
  3. 03Permissions & data
  4. 04Background location
  5. 05Data storage
  6. 06Licence verification
  7. 07AI assistant & steps
  8. 08Analytics & ads
  9. 09Embedded HTTP server
  10. 10HTTP Request action
  11. 11Third-party services
  12. 12This website
  13. 13Data sharing
  14. 14Retention & deletion
  15. 15Security
  16. 16Children
  17. 17Your rights
  18. 18Policy changes
  19. 19Contact

Contents

  1. 01Introduction
  2. 02Data controller
  3. 03Permissions & data
  4. 04Background location
  5. 05Data storage
  6. 06Licence verification
  7. 07AI assistant & steps
  8. 08Analytics & ads
  9. 09Embedded HTTP server
  10. 10HTTP Request action
  11. 11Third-party services
  12. 12This website
  13. 13Data sharing
  14. 14Retention & deletion
  15. 15Security
  16. 16Children
  17. 17Your rights
  18. 18Policy changes
  19. 19Contact

01Introduction

Flowroid (“we”, “our”, or “the app”) is an Android automation platform. This Privacy Policy explains what data Flowroid accesses, how it is used, where it is stored, and your rights with respect to that data.

Core principle: your automation content stays on your device unless you put a step in a flow that sends it. Flows, variables, execution history and crash reports are never uploaded, and we have no ability to read them. Every permission the app asks you for is used solely to power automations you configure; the one set it does not ask for — the advertising-identifier permissions the measurement libraries declare — is used only if you allow ad measurement, and is listed in Section 3 alongside the rest.

Flowroid contacts a server of ours for three things, and this policy is precise about the difference between them.

  • The licence check — to confirm whether this install is in its trial or carries an active entitlement. It carries a one-way hash, no personal data, no automation content, and never your raw device identifier. Section 6 sets out exactly what is sent and why.
  • The AI assistant — if you choose to use it, what you type is sent to our AI proxy and on to Google’s Gemini API to be answered. This is real content leaving your device, and Section 7 states plainly what is sent, where it goes, and what happens to it.
  • AI steps in your flows — if you put one in a flow, it sends its prompt, including any values the flow puts in it, to the same AI proxy each time the flow runs it, with no assistant open. This is content leaving your device too, and the same section sets it out.

A fourth path exists only if you switch it on: analytics and ad measurement, which Flowroid asks about on first run with everything switched off and which carry no content you created. Section 8 sets out what they collect, who receives it, and how to withdraw.

Your automations do not depend on any of them: flows, triggers and actions run on the device, and keep running with no connection and no AI. A flow sends something to our AI service only through an AI step you placed in it, and only that step’s prompt; a user who uses neither the assistant nor an AI step transmits no content.

02Data Controller

Flowroid is published by an individual developer, not a registered company, based in the Arab Republic of Egypt. For the records described in Section 5, and for the assistant and AI-step content described in Section 7, that developer is the data controller within the meaning of the General Data Protection Regulation (GDPR). Google acts as our processor in both cases.

  • Contact e-mail: support@flowroid.com
  • Data deletion requests: flowroid.com/data-deletion

We do not have a data protection officer, and we are not required to appoint one: the server-side records are limited to the fields listed in Section 5, assistant and AI-step content is not retained at all, and neither is used for profiling or monitoring.

03Permissions and Data We Access

The following table lists every Android permission Flowroid may request or declare, why it is needed, and where the resulting data goes. Each On device? answer describes only what that permission does — none of them covers the AI assistant or AI steps, whose own data flow is set out in Section 7.

Every row except the last is a permission Flowroid asks for to power an automation you configure. The last row is not: the advertising-identifier permissions are declared by the measurement libraries Flowroid links, are never prompted for by Android, and are used only while you allow ad measurement (Section 8). We list them rather than let the manifest say more than this page does.

PermissionPurposeOn device?
ACCESS_FINE_LOCATIONACCESS_COARSE_LOCATIONACCESS_BACKGROUND_LOCATIONGeofence triggers — detect when you enter or leave locations you define. Background location is required so geofences fire when the app is not in the foreground.Yes — coordinates are processed by Google Play Services on-device. Flowroid does not transmit your location.
BIND_NOTIFICATION_LISTENER_SERVICENotification triggers (a notification arrives or is removed), and the Reply to Notification, Press Notification Button, List Notifications and Dismiss Notifications steps.Yes. Title and text are evaluated in memory and never written to Flowroid’s logs or run history. They leave the device only if you put them into an AI step, an HTTP request, or an assistant conversation.
READ_PHONE_STATEPhone-call trigger — detect incoming and outgoing call state (idle / ringing / active). Flowroid does not read the phone number.Yes
READ_CONTACTSCondition evaluation — optionally match a caller against your contacts (e.g., “run only if caller is in Contacts”). Contact data is evaluated locally and is never uploaded.Yes
READ_CALENDARCalendar event trigger — start an automation when a calendar event begins or ends.Yes — event data is evaluated locally and never transmitted.
INTERNETSix uses: (a) user-created HTTP Request actions send data to endpoints you configure; (b) Google Play Billing for the one-time unlock, the Flowroid AI subscription and credit top-ups; (c) licence and purchase verification with our server (Section 6); (d) the optional AI assistant, which sends what you type to our AI proxy (Section 7); (e) AI steps you put in a flow, which send their prompt to the same proxy each time the flow runs one (Section 7); (f) analytics and ad measurement, only if you have allowed them, to Google and — for ad measurement alone — to Meta (Section 8).No for these six paths, and only these six: what you configure an HTTP Request action to send, the anonymous licence check, — if you open the assistant — your message and its context, — if a flow has an AI step — that step’s prompt, and — if you allowed it — the analytics described in Section 8, which carries nothing you created. Everything else the app does, including running your flows, stays on the device. Billing is handled by Google.
com.google.android.gms.permission.AD_IDandroid.permission.ACCESS_ADSERVICES_AD_IDandroid.permission.ACCESS_ADSERVICES_ATTRIBUTIONAd measurement, and only while you allow it (Section 8). These are declared by the two measurement libraries — Google’s and Meta’s — rather than requested by Flowroid: Android never prompts for them, which is why they are listed here. The first reads the resettable Advertising ID; the other two are the Privacy Sandbox routes to the same measurement on newer Android versions. Decline or withdraw ad measurement and none of them is used. Meta’s library would add two more — ACCESS_ADSERVICES_CUSTOM_AUDIENCE and ACCESS_ADSERVICES_TOPICS — and Flowroid removes both from the manifest it ships, so it cannot take part in remarketing or interest-based advertising even in principle.No while you allow ad measurement — the Advertising ID is sent to Google with the conversion. Yes otherwise: nothing is read.
ACCESS_WIFI_STATECHANGE_WIFI_STATEWi-Fi triggers (connect/disconnect) and Wi-Fi toggle action.Yes
BLUETOOTH_CONNECTBluetooth device trigger and Bluetooth toggle action.Yes
NFCNFC tag trigger — detect NFC tags to start automations.Yes
ACCESS_NOTIFICATION_POLICYDo Not Disturb control action.Yes
MODIFY_AUDIO_SETTINGSVolume and ringer-mode actions.Yes
WRITE_SETTINGSSystem settings actions (screen brightness, screen timeout, auto-rotate).Yes
CALL_PHONEPhone-call action — opens the system dialer with a number pre-filled. Flowroid does not make calls directly; the user confirms in the system dialer.Yes
SCHEDULE_EXACT_ALARMScheduled (time-based) triggers using exact alarm delivery.Yes — scheduling only; nothing about your schedules is transmitted.
RECEIVE_BOOT_COMPLETEDRestart the automation service after device reboot.Yes
FOREGROUND_SERVICEFOREGROUND_SERVICE_DATA_SYNCFOREGROUND_SERVICE_SPECIAL_USEFOREGROUND_SERVICE_LOCATIONKeep the automation service running reliably in the foreground.Yes — service metadata only.
POST_NOTIFICATIONSShow the persistent foreground-service notification and the notifications your flows post — including buttons on them that run other flows, and progress bars.Yes
WAKE_LOCKPrevent the CPU from sleeping while time-sensitive actions execute.Yes
VIBRATEVibration action.Yes
RECORD_AUDIOSpeaking to the AI assistant. Requested the first time you tap the microphone, and never otherwise. There is no wake word and no always-on listening: the microphone is live only while you hold the assistant open and have started it yourself.Speech is turned into text by your device’s own recogniser where one is installed. Flowroid never records or stores your audio. If your device has no offline speech pack, Android may route the recognition through its system provider (typically Google) — that is the platform, not Flowroid, and the in-app permission screen says so. The resulting text is then handled exactly like a typed message (Section 7).
BIND_DEVICE_ADMINDevice-admin actions (lock screen). The app requests Device Administrator status only if you enable a lock-screen automation.Yes
ACTIVITY_RECOGNITIONStep Counter trigger — fire a flow when your step count reaches a threshold you set (e.g., “at 10,000 steps”). The device’s hardware step-counter sensor is read only when you create such a flow.Yes — step counts are read from the on-device sensor and evaluated locally. Flowroid never stores, uploads, or shares step or other fitness data.
PACKAGE_USAGE_STATSApp-foreground trigger — start a flow when you open a specific app. Requires the “Usage access” special permission you grant in system settings.Yes — the currently-foreground package is evaluated locally and never transmitted.
QUERY_ALL_PACKAGESApp pickers — let you choose any installed app as the subject of a trigger (notification, app-open) or action (launch, stop). Used to populate the in-app app list.Yes — the installed-app list is shown only in the picker UI on your device and is never transmitted.
SYSTEM_ALERT_WINDOWDisplay-over-other-apps — used by actions that need to show content above other apps.Yes
KILL_BACKGROUND_PROCESSES“Stop app” action — ask Android to stop a background app you select.Yes

Text shared to Flowroid needs no permission. When you share text from another app to Flowroid through Android’s share sheet, it starts the flow you chose. The shared text is capped at 20,000 characters, is never written to a log, and is used as a plain value — it is never evaluated as a {{…}} expression. It leaves the device only if that flow sends it, for example in an AI step.

04Background Location

Why we need background location

Flowroid’s geofence feature detects when you enter or leave areas you define on a map. Geofences must be monitored continuously — including when the app is not on screen — to fire reliably. This requires the ACCESS_BACKGROUND_LOCATION permission.

Background location is used exclusively to evaluate geofence boundary crossings via the Google Play Services Geofencing API. Flowroid does not log, store, or upload your GPS coordinates. Location data is processed entirely on-device by Google Play Services; Flowroid only receives a binary “entered” or “exited” event per geofence.

If you do not create any geofence triggers, you can decline this permission and the rest of the app will work normally.

05Data Storage

Local database

All flows, variables, execution history, and app settings are stored in a Room (SQLite) database on your device’s internal storage. This data never leaves the device except when you use the export feature, configure an HTTP Request action to send it, or put it into an AI step’s prompt.

Secret variables

Variables you mark as “Secret” (e.g., API keys, passwords) are encrypted at rest using the Android Keystore (AES-256). Secret values are never displayed in logs or the execution history UI.

Crash reports

If Flowroid crashes, a local crash report is saved to files/crashes/ on your device. These reports contain the stack trace, app version, Android OS version, and device manufacturer/model. They do not contain notification content, location data, contact data, or any other personal information. Reports are capped at 10 files (oldest deleted automatically). Crash reports are never uploaded; you can view or delete them from the app’s log viewer.

Flow execution logs

When a flow runs, Flowroid writes a log entry that includes the flow name, trigger type, action results, and any error messages. Notification titles and bodies, and text shared to Flowroid, are deliberately excluded from log entries. Logs are stored locally and you can clear them at any time in Settings → Logs. A flow you build can still write a notification’s text to a file of your own (the “Receipts into a Spreadsheet” template does), and then it is in that file.

What we store on our servers

The table below is the complete list of what our server holds. None of these records contains your name, e-mail address, automation content, or any raw device identifier: the hashes below are computed on your device before anything is sent. Two of them exist only because Flowroid AI, the trial and earlier purchases include an AI allowance — they count what you have spent, never what you said (Section 7).

RecordWhat it holdsHow long we keep it
Device recordA one-way SHA-256 hash of an Android device identifier combined with a secret salt, computed on your device; the date your trial started; integrity flags returned by Google Play Integrity; the date this install first ran a real automation; and the app version it first registered with and first ran an automation on. The version is a release number shared by every install of that release, not an identifier.Kept for the life of the product, and deleted on request. This record is what makes the trial one per device.
Purchase recordA one-way SHA-256 hash of the Google Play purchase token, the obfuscated account identifier Google Play supplies, the device keys the purchase is linked to (at most 10), which product it is, its state and renewal date, and whether it has been revoked. This covers the one-time unlock, a Flowroid AI subscription, an unlock bought before 17 August 2026, and a legacy Flowroid Pro subscription.Kept while the entitlement is active, then for 90 days.
AI usage meterA running tally of the AI credits spent in the current billing period, keyed by an anonymous metering id and the calendar month. The metering id is a hash of your purchase once you own Flowroid, and of the device key during the trial. It counts usage. It holds nothing you asked, and nothing that was answered.12 months, then deleted automatically.
AI credits (balance and ledger)A running balance of the AI credits you have bought, and an append-only ledger with one row per top-up bought and per AI request paid from purchased credits: the same anonymous metering id, the number of credits added or spent, and — for a top-up — a hash of that purchase’s Play token so the same purchase can never be redeemed twice. It belongs to your purchase, and is shared by every device the purchase is restored on.Kept while the credits are yours to spend — purchased credits do not expire. Deleted on request when the device asking is the last one linked to the purchase.
Redeemed credit-pack recordA one-way hash of each credit-pack purchase, with its product and date. Once your AI credits are erased it has no link to you, your device or your purchase.Kept permanently, so the same pack purchase can never be redeemed twice. Not deletable on request, because it identifies no one.
Request logsThe HTTP method, route, response status, and latency of each call to our server, plus a truncated or hashed IP address. Request and response bodies are never logged — including the assistant’s and every AI step’s.30 days, then deleted automatically.

Our server also keeps a single fleet-wide daily counter of AI spend, which exists to cap our own costs. It holds a date and a number, and no identifier of any kind — yours or anyone else’s.

These records are stored on Google Cloud infrastructure in the europe-west1 region (Belgium). See Section 11 for the processors involved and Section 14 for how to have them deleted.

06Licence and Purchase Verification

Flowroid is a paid app with a 14-day trial. The trial and every kind of purchase — the one-time unlock, a Flowroid AI subscription, a one-time unlock bought before 17 August 2026, and a legacy Flowroid Pro subscription — are verified with a licence server we operate. This section describes that exchange in full.

What the app sends

  • A device key. Your device’s ANDROID_ID combined with a secret salt and hashed with SHA-256 on your device. Only the resulting hash is transmitted. The hash cannot be reversed, and the raw ANDROID_ID never leaves your phone.
  • A hashed purchase token, once you buy Flowroid, subscribe to Flowroid AI or buy a credit pack, so that Google Play’s record of the purchase can be matched to your entitlement without us storing the token itself. The purchase record also stores which product it is, so the server knows what it unlocks.
  • A Google Play Integrity verdict, which tells us whether the request came from a genuine, unmodified copy of Flowroid. It describes the app and the device, not you.

What the app receives

A short-lived signed licence stating whether this install is in its trial or entitled, and — if you are entitled to AI — an anonymous metering id and your credit allowance. The metering id is derived by hashing: from your unlock purchase once you own Flowroid, and from the device key during the trial. It is what the AI usage meter and AI credits in Section 5 are keyed by, which is why every device you restore the purchase on shares one balance, and it identifies an entitlement, not a person.

What the app never sends

No flows, flow names, variables, secrets, execution logs, crash reports, notification content, location, contacts, or calendar data. The licence request has no field capable of carrying them. The device record does hold the date this install first ran a real automation, and the app version it registered and first ran one with (Section 5); those are a date and a release number, not anything from the automation.

Why we do it

  • Entitlement. Your unlock — or a Flowroid AI or legacy Flowroid Pro subscription — must keep working across reinstalls and on any device signed into the same Google account, up to the device limit. Verifying it against a record is what makes that possible.
  • Metering the AI allowance. Cloud inference costs us money per request, so the credits included with Flowroid AI, the trial or an earlier purchase are counted server-side against the metering id above. Only the amount is recorded, never the content.
  • One trial per device. The trial needs no payment method, so nothing else stops it from being restarted indefinitely by reinstalling the app. The device record deliberately survives an uninstall, a clear-data, and Settings → Reset App Data. That persistence is the anti-abuse mechanism, and we would rather state it plainly than have you discover it.

If the server is unreachable

A successful check is recorded on your device as a signed licence. Flowroid keeps working on that licence until it expires, and renews it automatically once connectivity returns. Losing your connection does not lock the app.

Legal basis (GDPR Article 6)

Why we are allowed to process this

Performance of a contract (Article 6(1)(b)) for the purchase, metering and credit records: verifying your entitlement and counting the allowance it includes is how we deliver what you paid for.

Legitimate interests (Article 6(1)(f)) for the device key and the integrity verdict: preventing repeated trials and fraudulent entitlements on a paid app. We balanced that interest against your privacy by hashing the identifier on the device, storing no contact details, and keeping no request bodies. You can object to this processing under Section 17.

07The AI Assistant and AI Steps

Flowroid offers AI in two optional forms. These are the only parts of Flowroid that send your content to our servers — the analytics in Section 8 carries none — so this section is deliberately specific.

  • The AI assistant: a chat surface where you describe what you want in plain language and it runs Flowroid’s own actions and your flows.
  • AI steps you place in a flow, which send their prompt each time the flow runs them (below).

Automation is not affected by any of this

Your flows, triggers, conditions and actions keep running without AI, with or without a connection, whatever your credit balance is. A flow runs on the device. It sends something to our AI service only through an AI step you placed in it, and only that step’s prompt.

What the assistant sends, when you use it

When you send a message to the assistant, the following leaves your device over an encrypted, certificate-pinned connection:

  • Your message — what you typed, or what your device’s speech recogniser turned your speech into.
  • The conversation so far — the earlier messages in that session, because a reply that ignores them would be useless.
  • The tool definitions — the list of Flowroid actions and flows the assistant is allowed to use, including your flow names, so it can pick the right one.
  • Tool arguments and results — what it decided to run and what came back, so it can carry on from there: for example, the titles and text of notifications, if you ask the assistant about your notifications. Notification keys are replaced with opaque references first.
  • Your signed licence, carrying the anonymous metering id from Section 6. There is no account, no e-mail address and no name attached to the request.

Anything you put into a message is part of that message. If you paste a password, an address or someone else’s details into the assistant, they are sent with it — the same as with any chat assistant. Your secret variables are never included: the assistant cannot read them, and they are not sent.

Where it goes

Your message, and every AI step’s prompt, goes to Flowroid’s AI proxy, which we operate on Google Cloud in europe-west1 (Belgium), and from there to Google’s Gemini API, which generates the reply. The proxy exists so that AI works without you having to sign up with an AI provider, and so the included allowance can be metered.

What happens to it

  • We do not store it. Your message or prompt and the reply pass through our proxy in memory for the length of the request and are never written to a database or a file.
  • We do not log it. Our request logs record the method, route, status and latency of a call — never its body. There is no debugging log of prompts, and a test in our build fails if one is ever added.
  • It is not used to train models. We do not train anything on it, and Flowroid uses Google’s paid Gemini API tier, whose terms state that Google does not use prompts or responses submitted through it to improve its products.
  • Google logs it briefly for abuse detection. Under those same terms Google retains prompts and responses for a limited period, solely to detect and prevent abuse of its API. That is Google’s processing, on its own retention schedule, and we state it here rather than claim a zero-retention pipeline we do not control.
  • What we do count is the cost. Every request adds a number to the AI usage meter in Section 5 — how many credits it consumed, against an anonymous metering id. That meter is how a monthly allowance can exist at all. It holds no content.

AI steps in your flows

Ask AI, Classify with AI, Extract with AI, Summarize with AI and Translate with AI are steps you can place in a flow, from the Intelligence section of the palette. They produce text or data for the next step. They never act on another app, read your screen, or run an action by themselves.

  • When they send. Every time the flow runs one, triggered by whatever starts the flow — a notification, a schedule, a webhook, a share. No assistant has to be open. Setting Flowroid up also runs one AI step, once.
  • What is sent. Only the step’s resolved prompt and system instruction. That can include whatever values the flow fills in, which means any of these kinds of data: messages — the title and text of a notification from a chat, email or SMS app (Flowroid has no SMS permission and never reads your messages store; only the notification text you chose to send); a calendar event’s title and notes; a file’s contents; and other text you create or receive — the clipboard, text you shared to Flowroid, a webhook body, an HTTP response, or the prompt you wrote. It takes the assistant’s route and pipeline: the same pinned connection, the same personal-data filter (Settings → AI → Privacy), to our AI proxy and on to Google’s Gemini API. Not stored, not logged, not used for training. Prompts are clipped at 8,000 characters, and shared text at 20,000.
  • What is never sent. Secret variables. A step that references one cannot be saved. And nothing is sent from a flow that has no AI step.
  • Your own model. If you point AI at your own endpoint (Settings → AI → Advanced), the prompt is sent there as it is instead, and to nobody else.
  • Before you install a template. Every Intelligence template’s detail screen says what text it sends — for example, “Sends the notification title and text to your AI provider” — before you install it.
  • Cost and limits. Each run spends credits like an assistant message. By default a flow may make 30 AI calls an hour and 200 a day. Running a flow with AI steps by hand asks first, and offers to run it with the AI skipped.
  • Without AI. A step with fallback text uses it and the flow carries on. Automation is never gated by AI credits.

Running your own model instead

If you would rather nothing reached our servers, point Flowroid at a model you host yourself — Ollama, LM Studio, or any OpenAI-compatible server — under Settings → AI → Advanced. Assistant messages and AI-step prompts then go to the address you entered and nowhere else: not to our proxy, not to Google, and they do not touch your allowance. Flowroid does not offer to send your content to a cloud AI provider under an API key of your own; that route was removed.

Speaking to it

The microphone is used only while you have the assistant open and have started it yourself — there is no wake word and no background listening. Flowroid never records or stores your audio. Speech is converted to text by your device’s recogniser, which on a device without an offline speech pack may be Android’s system provider (typically Google). The text is then treated exactly like a typed message.

What stays on the device

Two assistant features never involve a server at all: the learned shortcuts that let repeated commands run instantly, and the automation suggestions Flowroid draws from your own usage. Both are computed on the phone, are stored only there, and are never uploaded. Reports you file about a bad assistant reply are also stored on the device.

Legal basis (GDPR Article 6)

Performance of a contract (Article 6(1)(b)). Sending your message, or an AI step’s prompt, to be answered is the feature you asked for; we cannot deliver it without transmitting it. You choose whether to use the assistant and whether to put an AI step in a flow, and the rest of Flowroid is unaffected if you never do.

08Analytics and Advertising

Flowroid asks, the first time you open it, whether it may collect anything for analytics and advertising. If you installed Flowroid before it asked, it asks once, the same way, the next time you open it after updating. Everything in this section happens only if you said yes, and only for the purposes you said yes to. If you have not answered, or you answered no, nothing described here is collected — not reduced, not anonymised: not collected. Flowroid works exactly the same either way.

What is collected

  • A short, fixed list of steps you take in the app, as bare counts with no detail attached: you finished setup, you saved a flow, you ran a flow successfully for the first time, the first-run step started waiting for your first flow to run, or you skipped it, the unlock screen was shown to you, and the AI step in setup produced a result. Each SDK additionally records its own standard events — Google’s, your first open of the app and how long a session lasted; Meta’s, that the app was opened. Meta receives these steps only if you allowed ad measurement; if you allowed product analytics alone, Meta receives nothing.
  • Purchases. After a purchase our server has verified, one more event is counted — you unlocked Flowroid, you subscribed to Flowroid AI, or you bought AI credits. Like every other event it carries no detail: no price, no product and no order number. Purchase events go to Google Analytics only and are never sent to Meta.
  • Identifiers. A Firebase “app instance ID” — an identifier for this installation, not for you — and, only while you allow ad measurement, the Android Advertising ID. The Advertising ID is a resettable identifier you control in your Android settings. Meta receives the Advertising ID and an installation identifier of its own, again only while you allow ad measurement. We do not use Meta’s “Advanced Matching”, so no e-mail address, phone number or name is ever sent to Meta — Flowroid has none of those to send.
  • An approximate location, meaning the city Google or Meta infers from the IP address the data arrives on. Flowroid never sends your actual location: geofence triggers and the map picker work on the device (Section 4), and no flow, event or licence check carries coordinates.
  • Basic technical facts about the device the SDK reports by itself: model, Android version, app version, language, country.

What is never collected

No content, ever. Not the names of your flows, not the contents of a variable, not a notification, not a message you typed to the assistant, not an address you geofenced. The set of events Flowroid can raise is fixed in its source code and none of them carries any attached detail — there is no field to put your data in. Flow runs, execution logs and trigger history stay on the device exactly as described in Section 5.

The two choices, and what each one permits

They are independent. Allowing one never turns on the other.

ChoiceWhat it permitsGoogle Consent Mode signal
Product analyticsCounting a short, fixed list of steps — you finished setup, you saved a flow, you ran a flow successfully for the first time, the first-run step started waiting for your first flow to run, or you skipped it, the unlock screen was shown to you, and the AI step in setup produced a result — and a verified purchase, so we can see where Flowroid gets in the way. Google receives these; Meta does not receive anything under this choice.analytics_storage
Ad measurementTelling us that an advertisement brought you to Flowroid and that you got set up, so we know which campaigns are worth running. This is the only choice that discloses anything to Meta: allowing it sends to Google and to Meta, and refusing it means Meta receives nothing at all, whatever you chose above.ad_storagead_user_data

There is no third choice

Flowroid does not ask for ad personalization, and never turns it on: Google’s ad_personalization signal is set to denied for every user, whatever they choose, so nothing Flowroid sends is used to choose the advertisements you see elsewhere or to build a remarketing list.

For Meta we do the same thing by a different mechanism. Every event sent to Meta carries Meta’s Limited Data Use flag, for every user in every country, which asks Meta to use the data for measurement and attribution rather than for ad targeting or profile building. We do not use Meta’s Advanced Matching, so no e-mail address, phone number or name is ever sent — Flowroid has none to send — and the app removes the Android permissions that would let either SDK take part in remarketing or interest-based advertising.

Flowroid shows no advertisements and contains no ad-serving or ad-mediation SDK — nothing in the app can display an advertisement to you. The two SDKs it does contain, Google Analytics for Firebase and Meta (Facebook) App Events, are measurement SDKs: they report on advertising we bought elsewhere and show you nothing. What is measured is an advertisement we bought elsewhere, not one shown to you inside Flowroid.

Who receives it, and on what basis

Google receives it. Google Analytics for Firebase processes it on our instructions, in a property we control, as our processor. If you allow ad measurement, Google also reports the resulting conversions to Google Ads, the advertising platform we use to promote Flowroid, marked as not to be used for personalised advertising. Google’s own handling is described in the Google Privacy Policy, and its row is in Section 11.

Meta receives it too, but only if you allow ad measurement, and the difference between the two recipients matters enough that we would rather state it plainly than let it read as a footnote. Google acts as our processor: the data sits in a property we control and Google deletes it when we say so. Meta acts as an independent controller under the Meta Business Tools Terms: what it receives becomes Meta’s, held under Meta’s own retention rules and its own privacy policy. We can stop sending to Meta at any time, and we can clear what is stored on your phone, but we cannot delete Meta’s copy on your behalf. To ask Meta directly, use the controls in your Meta account or the routes in the Meta Privacy Policy. Meta receives the same product steps as Google — never the purchase events — your advertising identifier, and the coarse region derived from your IP address, and nothing else. Its row is in Section 11.

Refuse ad measurement and Meta receives nothing

If you allow product analytics but not ad measurement, Meta receives nothing at all — not a reduced event, not an anonymised one: nothing is sent to Meta. The two choices are genuinely independent, and ad measurement is the only one that reaches Meta.

Legal basis (GDPR Article 6)

Your consent (Article 6(1)(a), and the equivalent provisions in the UK, Switzerland and Quebec), asked for before any collection and withdrawable at any moment. It is the only thing in this policy that runs on consent: the licence check runs on the contract between us (Section 6), and turning analytics off does not affect it.

Turning it off, and deleting what is on your device

  • Settings → Privacy, at any time, in no more taps than it took to allow. Each choice has its own switch and a change applies immediately.
  • Turning a choice off also deletes the analytics identifiers stored on your device — Google’s and, if you turn off ad measurement, Meta’s — so nothing collected afterwards can be joined to anything collected before.
  • Settings → Privacy → Delete analytics data does that on its own, without changing your choices.
  • Neither can reach data Google or Meta have already received, and the two halves have different answers. For the Google side, write to support@flowroid.com and we will action it, because Google holds it as our processor; we answer within 30 days. For the Meta side we can stop sending but cannot delete on your behalf, because Meta holds it as its own controller — ask Meta directly through your Meta account or the routes in the Meta Privacy Policy.

How long it is kept

Google expires the user- and event-level analytics data after 2 months, the shortest retention Google Analytics offers; aggregated reports outlive it and contain nothing that identifies a device. Our own licence records are separate, are not analytics, and are covered by Section 14.

Meta’s retention is Meta’s, not ours. We do not set it and cannot shorten it; it is governed by the Meta Privacy Policy. This is the practical consequence of Meta being an independent controller rather than our processor. It is the main reason the two recipients are described separately above rather than lumped together.

Your US state privacy rights

If you live in California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana or another US state with a comprehensive privacy law, this subsection is for you.

We do not sell personal information for money, and we never have. We do not use your data for targeted advertising either: Flowroid does not ask for ad personalization, and tells Google, for every user, not to use what it receives for personalised ads. If you allow ad measurement, Google Ads and Meta each learn that one of our advertisements brought you to Flowroid, and we use that only to measure and bid on our own campaigns. Those laws define a “sale” and a “share” broadly, and we would rather tell you exactly what happens than argue whether measuring our own ads falls inside “sharing for cross-context behavioural advertising”.

Because Meta receives it as its own controller rather than as our processor, we treat that disclosure as a “share” and give you the opt-out those laws require. Two things follow. First, the opt-out is the Ad measurement switch described below, and it starts off. Second, for every event we send — from every device, in every country, not only in the United States — we set Meta’s Limited Data Use flag, which asks Meta to use the data for measurement and attribution rather than for ad targeting or building a profile of you. We apply it everywhere rather than only where the law demands it, because deciding which users are American means guessing at their location, and we would rather not guess.

Your opt-out is the same switch as everyone else’s

And it is off until you turn it on. Flowroid asks before collecting anything, with every choice switched off; you can turn Ad measurement, or both choices, off at any time in Settings → Privacy. There is no form to fill in, no account to verify, and no waiting period. On this website, the Global Privacy Control signal is honoured (Section 12).

You also have the right to know what we hold about you, to have it deleted, to have it corrected, and not to be discriminated against for exercising any of those rights — Flowroid is identical in every feature and price whatever you choose here. Because there are no accounts, the identifier we hold is the device key shown at Settings → About → Device key; quote it when you write to support@flowroid.com. We do not use or disclose sensitive personal information for inferring characteristics, and we do not knowingly process the data of anyone under 18 — Flowroid is an adults-only app.

09Embedded HTTP Server

Flowroid includes an optional local HTTP server (off by default) that allows external systems to trigger flows via REST API. By default, the server binds to 127.0.0.1 (loopback only) and is not reachable from other devices on the network. An explicit “Enable LAN access” setting expands the bind address to 0.0.0.0.

When the server is enabled, any HTTP requests received are processed locally. You are responsible for securing access (API key, network configuration). We recommend not enabling LAN access on untrusted networks.

10User-Configured HTTP Requests

The HTTP Request action lets you send data to any URL you configure. You are fully in control of what data is sent and to which endpoint. Flowroid does not inspect, log, or intercept the content of these requests beyond what is necessary to execute them. You are responsible for the privacy implications of the endpoints you call.

11Third-Party Services

ServicePurpose in FlowroidPrivacy policy
Google Play BillingThe one-time unlock, the Flowroid AI subscription and the optional AI credit top-ups. Google handles payment processing; Flowroid receives a purchase token and the purchase state, never your payment details.Google Privacy Policy
Google — Gemini APIAnswers the AI assistant and your flows’ AI steps. When — and only when — you use the assistant or a flow runs an AI step, your message and its conversation context, or the step’s prompt, are forwarded by our proxy to Google’s Gemini API, which acts as our sub-processor for that request. Google’s terms for paid API use state that this content is not used to improve or train its models; Google does log it for a limited period to detect abuse of its API.Gemini API Additional Terms
Google Analytics for Firebase / Google AdsCounts a short, fixed list of product steps and verified purchases, and measures which advertising campaign brought a user to Flowroid. Collected only with that user’s consent, per purpose, and never containing any content they created. Google processes it as our processor in a property we control; with ad measurement allowed it also reports the resulting conversions to Google Ads, marked as not for personalised advertising. See Section 8.Google Privacy Policy
Meta (Facebook) App EventsMeasures which Meta advertising campaign brought a user to Flowroid. Receives the same product steps as Google — never the purchase events — and only if that user allowed ad measurement specifically; product analytics alone sends Meta nothing. Flowroid has no Facebook login, no sharing to Facebook, and shows no ads. Unlike every other row in this table, Meta is an independent controller of what it receives rather than our processor: we can stop sending, but we cannot delete Meta’s copy on your behalf. See Section 8.Meta Privacy Policy
Google Play IntegrityConfirms that a licence request comes from a genuine, unmodified Flowroid install before a trial or an entitlement is granted. Returns a verdict about the app and device, not about you.Google Privacy Policy
Google Cloud Platform (Cloud Run, Cloud SQL)Hosts Flowroid’s licence server, its AI proxy, and their database in the europe-west1 region (Belgium). Google acts as our processor: it stores the records in Section 5 on our instructions and does not use them for its own purposes.Google Cloud Privacy Notice
Google Play Services — LocationGeofencing API for location-based triggers.Google Privacy Policy
Google Maps SDKMap picker for setting up geofence locations. Map tiles are loaded from Google’s servers; your precise location is not sent unless you explicitly search for it.Google Privacy Policy

Flowroid shows no advertisements, and it uses no third-party crash reporting — crash reports are written on your device and stay there. It does integrate two measurement SDKs, Google Analytics for Firebase and Meta (Facebook) App Events; both are used to understand which of our own advertising campaigns work, neither shows you anything, and neither collects anything at all until you allow it — Meta’s not even then, unless the choice you allowed was ad measurement. Both are covered in full in Section 8. Beyond that, the app calls a server of ours for the licence check in Section 6, and — only if you use them — the AI assistant and AI steps in Section 7.

One row in that table is not like the others. Every service above acts as our processor — it handles the data on our instructions and deletes it when we say so — except Meta (Facebook) App Events, which receives what we send as an independent controller. That distinction decides what we can promise you about deletion, and it is set out in Section 8.

This table is about the app, which is what everything above it describes. The website you are reading is a separate thing with separate answers — a different measurement tool, cookieless and with no advertising use — and it gets its own section rather than a footnote: Section 12.

12This Website

Everything above describes the Android app, whose own measurement — consent-gated, per purpose, and carrying nothing you created — is in Section 8. This section is about this website, which is a different collector with a different recipient and a different lawful basis: cookieless page counts, no advertising use, no identifier that survives the day. It says exactly what is counted — including how to switch it off, at the bottom.

What is counted

  • Page views — the page’s address, the page that linked to it, and the campaign parameters on the link if it carried any. Every other query parameter is stripped in your browser before anything is sent.
  • Your browser’s own headline facts — browser, operating system, device type, screen size, language, and the country your network resolves to. Not your IP address: it is used to work out the country and is never stored.
  • A short list of interactions — which call to action was pressed, which help question was opened, which table-of-contents entry was followed, how far down a page was read, and which address produced a 404.

What is not

No cookies are set and no identifier is stored in your browser. A visit is recognised only by a one-way hash of your network address and browser, salted with a value that is rotated daily — which means the same person on the same browser is not recognisable across days and is never recognisable across sites. There is no advertising network, no data broker, no cross-site profile, and nothing is sold or shared.

Nothing you type is measured. The support composer and the deletion request on this site assemble a draft in your browser and send nothing anywhere; what is counted is that a draft was opened and which topic it used, never a word of what it says.

Where it goes

To https://umami.pharadev.com/api/send, our account with Umami — an open-source, cookieless analytics engine, hosted here by its maker, which processes these events on our instructions as our processor and for no purpose of its own.

The rows are kept while the site is measured. There is no request to make about them and none we could act on: they carry no name, no address, no account and no identifier of yours, so there is nothing in them to look up, export or erase. The deletion route in Section 14 is about the app’s licence records, which are a different thing entirely.

Legal basis (GDPR Article 6)

Legitimate interests (Article 6(1)(f)): knowing which pages are read and which of them fail is how this site gets better. We balanced that against your privacy by choosing a measurement tool that sets no cookie, stores no identifier and keeps no IP address — which is also why you were not made to dismiss a consent banner to read a privacy policy. Nothing is read from or written to your device unless you press the button below, and the one thing it writes is your refusal.

Turning it off

Three ways, any of which is enough. Your browser’s Do Not Track setting and the Global Privacy Control signal are both honoured, and neither needs anything from us. Or switch it off for this browser here — the setting is kept in this browser only, so it does not follow you to another one:

A content blocker also works, and nothing on this site breaks when the tracker is blocked: it is loaded after the page is usable and nothing waits on it.

13Data Sharing and Disclosure

We do not sell your personal data for money and we never have. US state privacy laws define “sell” and “share” more broadly than that, and Section 8 explains exactly what allowing ad measurement sends to Google Ads and to Meta, and how to opt out. Beyond that, your data is disclosed only as follows:

  • Google Play Billing — the one-time unlock, Flowroid AI subscriptions and top-ups are handled by Google. We receive a purchase token and the purchase state, not your payment details.
  • Google (Gemini API) — answers the AI assistant and your flows’ AI steps. If you use the assistant, your message and its conversation context, and if a flow runs an AI step, that step’s prompt, are shared with Google as our sub-processor, for the sole purpose of generating that reply. Nothing is shared unless you use the assistant or a flow runs an AI step. See Section 7.
  • Google (Analytics for Firebase, and Google Ads) — only if you allowed it, and only for the choices you allowed. Nothing is shared if you declined or have not answered, and nothing shared this way contains anything you created. Google receives it as our processor. See Section 8.
  • Meta (Facebook) App Events — only if you allowed ad measurement, which is off until you turn it on. Meta receives it as an independent controller, under Limited Data Use, and nothing shared this way contains anything you created. Nothing at all is shared if you declined, have not answered, or allowed only product analytics. See Section 8.
  • Our hosting provider — the records in Section 5 are stored on Google Cloud infrastructure in europe-west1 (Belgium) under a data-processing agreement. Google processes them on our instructions only.
  • Our website analytics provider — the anonymous page counts described in Section 12 are processed on our instructions by the host of our Umami instance. They concern this website, not the app, and contain no identifier of yours.
  • Legal obligations — if required by law, court order, or to protect the safety of any person.
  • User-initiated HTTP requests — data you send via the HTTP Request action goes to the endpoints you configure. This is entirely under your control.

14Data Retention and Deletion

On your device

Everything Flowroid creates while automating (flows, variables, execution logs, crash reports) lives on your device, and you can delete it at any time:

  • Flows and variables: delete individually within the app, or use Settings → Reset App Data to wipe everything.
  • Execution logs: Settings → Logs → Clear Logs.
  • Crash reports: Settings → Logs → Clear Crash Reports.
  • All app data: uninstalling Flowroid removes every locally stored file from your device.

On our server

Resetting the app is not deletion

Settings → Reset App Data, clearing the app’s storage, and uninstalling Flowroid all clear your device. None of them deletes your licence record. That record is deliberately kept across a wipe, a reinstall and a clear-data, because it is what keeps the trial to one per device (Section 6).

The retention period for each record is listed in Section 5: request logs are deleted after 30 days, a purchase record 90 days after the entitlement stops being active, the AI usage meter after 12 months, and the device record is kept for the life of the product unless you ask us to delete it. Your AI credits (balance and ledger) belong to your purchase, not to one device, and are kept while they are yours to spend, because purchased credits do not expire. A deletion request erases them when the device asking is the last one linked to the purchase. A one-way hash of each credit pack you bought is kept, unlinked from you, so the same purchase cannot be redeemed twice.

Nothing you asked the assistant, and no AI step’s prompt, is retained by us at any point (Section 7), so there is no conversation history on our side to delete or export.

Analytics data is not ours to keep or delete. If you allowed it, Google holds it and expires the user- and event-level rows after 2 months — the shortest retention Google Analytics offers. If you allowed ad measurement specifically, Meta holds a copy too, and Meta’s retention is Meta’s, not ours. We do not set it and cannot shorten it; it is governed by the Meta Privacy Policy. This is the practical consequence of Meta being an independent controller rather than our processor. Turning a choice off in Settings → Privacy stops collection and deletes the identifiers on your device, but it cannot reach what either has already received. For the Google half, write to us and we will ask on your behalf; for the Meta half we can stop sending but cannot delete on your behalf, so the route is Meta’s own (Section 8).

To have your device, purchase and AI records deleted, follow the request route at flowroid.com/data-deletion. It explains what is removed, what to include so we can find your record, and the two consequences worth knowing in advance: deletion resets the trial for that device, and your unlock and any Flowroid AI subscription have to be re-linked with Restore purchase. We cannot delete your Google Play order record; that is Google’s, and you can manage it in your Google account.

15Security

We apply the following security measures to protect your data:

  • Secret variables are encrypted using AES-256 via the Android Keystore. If Keystore initialisation fails, the app refuses to store secrets rather than falling back to plaintext.
  • All traffic between the app and our server — licence checks, assistant requests and AI steps alike — is encrypted in transit with TLS 1.2 or higher, against a certificate pinned in the app.
  • The records in Section 5 are encrypted at rest. Assistant and AI-step content is never at rest on our side to begin with.
  • The licence database has no public IP address. It is reachable only from the licence service over a private network path, never from the open internet.
  • The API server requires an API key by default.
  • The HTTP Request action maintains a blocklist against Server-Side Request Forgery (SSRF) attacks targeting loopback, link-local, and RFC 1918 private addresses.
  • Boot receivers and background services are not exported and cannot be invoked by third-party apps.

16Children's Privacy

Flowroid is not directed at children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided personal data through the app, please contact us at the address below so we can take appropriate action.

17Your Rights

There are two sets of data and two routes to them — plus the analytics you may have allowed, which has a third route and is covered at the end of this section.

Data on your device

You hold this outright. No request to us is needed, and none is possible: we cannot reach it.

  • Access — view all flows, variables, and logs within the app.
  • Correction — edit or delete any flow or variable at any time.
  • Deletion — Settings → Reset App Data, or uninstall the app.
  • Portability — export your flows as JSON files via the import/export feature.

The records on our server

For the records in Section 5 you have the rights of access, rectification, erasure, restriction of processing, objection, and data portability under the GDPR, and comparable rights under other applicable privacy laws. There is no assistant history among them: we keep none.

How to identify your record

These records hold no name, e-mail address, or account, so we cannot look yours up from the address you write to us from. They are keyed by the device key, which the app displays for you to copy. Quote it in your request; without it we have nothing to search on. Submit the request at flowroid.com/data-deletion or by e-mail to support@flowroid.com. We respond within 30 days.

Erasing your device record resets the 14-day trial for that device, and erasing your purchase record detaches your unlock and any Flowroid AI subscription from it. If it is the only device on your purchase, the purchase’s AI meter and any unspent purchased credits are erased too — only a one-way hash of each credit pack, unlinked from you, stays so it cannot be redeemed twice; if other devices still use it, they keep the purchase, its meter and its credits. If you have paid for Flowroid and then ask us to erase these records, use Restore purchase afterwards: your entitlement lives with your Google account, not with the record we deleted.

Analytics and ad measurement

These run on your consent (GDPR Article 6(1)(a)) and on nothing else, which gives you a right the rest of this policy does not: you can withdraw it at any moment, with no reason and no request to us. Each choice has its own switch in Settings → Privacy, a change applies immediately, and turning a choice off also deletes the analytics identifier stored on your device. Withdrawal does not affect the lawfulness of anything collected beforehand, and it changes nothing else about Flowroid — same features, same price. Section 8 has the detail, including what neither switch can reach. One limit is worth stating here rather than only there: withdrawal stops all future sending, but the copy Meta already holds is Meta’s own, not ours, and we cannot delete it for you — ask Meta through your Meta account or the routes in the Meta Privacy Policy. Data Google holds as our processor we can and will have deleted on request.

If you are in the United States, your state may give you additional rights over advertising data specifically — those are set out in the same section.

You may object at any time to the processing we carry out on the basis of legitimate interests (Section 6). If you believe we have handled your data unlawfully, you can also complain to your national data protection supervisory authority.

Your Google Play order record is held by Google as its own controller. To exercise rights over it, contact Google directly.

18Changes to This Policy

We may update this Privacy Policy when the app’s data practices change. We will update the “Last updated” date at the top of this page. For significant changes, we will provide notice within the app. Your continued use of Flowroid after an update constitutes acceptance of the revised policy.

19Contact

For privacy-related questions or requests, please contact:

  • E-mail: support@flowroid.com

Back to top


Flowroid© 2026. Automation that runs on your device.

AutomationsPrivacyData deletionTermsSupportHelp