Privacy Policy
Flownomic LLC · Effective July 16, 2026
Who we are
Flownomic (“Flownomic,” “we,” “us”) is a marketing analytics platform operated by Flownomic LLC. We connect, on your instruction, to marketing data sources you own — Google Business Profile, Google Search Console, Google Analytics, Google Ads, and Meta (Facebook/Instagram) Ads — and present that data back to you in dashboards, reports, and through your private AI connector. Questions: brenden@flownomic.ai.
Information we collect
- Account information — your name, business name, website domain, email address, and password (stored hashed) when you create an account.
- Billing information — handled by Stripe, our payment processor. We never see or store your full card number; we store your subscription status and plan.
- Connected marketing data — described in detail below, accessed only after you explicitly connect an account via OAuth.
- Usage data — logs of product activity (e.g., which reports and connector tools are used) to operate, secure, and improve the service.
Google user data — what we access and why
When you click “Connect Google,” Google shows you exactly which permissions you are granting. We request the following scopes, and use each one only as described:
- Search Console (
webmasters) — we read your site's search performance (queries, clicks, impressions, indexing status) to power your rankings and traffic dashboards, and — only when you use those features — submit sitemaps or request indexing on your behalf. - Google Analytics (
analytics.readonly) — we read your GA4 property's traffic and conversion reports to power your analytics dashboards. Read-only. - Business Profile (
business.manage) — we read your locations, reviews, posts, photos, and performance to power your Business Profile dashboards; and — only when you or your plan's services use those features — publish posts, reply to reviews, or update profile fields you approve. - Google Ads (
adwords) — we read your campaigns, ad groups, ads, and performance metrics to power your advertising dashboards; and — only if you explicitly enable campaign management for your account — create or edit campaigns, ad groups, ads, and budgets at your direction. Management is off by default, every change you initiate is confirmed with you before it is applied, and every change is logged in your dashboard.
Your connected data appears in your dashboards, in scheduled summaries, and through your private AI connector (below). It is never shown to other Flownomic customers, never sold, and never used for advertising.
Limited Use disclosure: Flownomic's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine-learning models.
Meta (Facebook/Instagram) data
If you connect Meta Ads, we read your ad accounts, campaigns, and performance metrics via the Meta Marketing API to power your advertising dashboards. If — and only if — you explicitly enable campaign management for your account, we also create or edit campaigns, ad sets, and ads at your direction; management is off by default, every change you initiate is confirmed with you before it is applied, and every change is logged in your dashboard. We do not access your personal profile, friends, or content beyond the ad account you select. Our use complies with the Meta Platform Terms and Developer Policies.
Your AI connector
Each client gets a private, revocable connector (an MCP endpoint) that lets AI assistants you choose — such as Claude or ChatGPT — query your own connected marketing data. The connector is scoped to your business only, rate-limited, audit-logged, and can be regenerated or revoked by you at any time in Settings. Whatever an assistant does with data you give it is governed by that assistant's own terms.
How data is stored and protected
- OAuth tokens are encrypted at rest (AES-256-GCM) and used only server-side.
- All data is transmitted over TLS.
- Mirrored marketing data (e.g., daily metrics) is stored per-client with tenant isolation enforced in the application and database.
- Data is retained while your account is active. Disconnecting a source stops new collection; deleting your account removes your data within 30 days, except records we must keep for legal or billing purposes.
Service providers (sub-processors)
We use a small set of vendors to run Flownomic:
- Supabase — database and authentication hosting.
- Railway — application hosting.
- Stripe — payments and subscription billing.
- Resend — transactional email (invites, sign-in, notifications).
- Anthropic / OpenAI — AI processing for features you invoke (e.g., generating your growth roadmap or summaries). Inputs are limited to what the feature needs.
- DataForSEO — third-party search-ranking data (keyword positions); we send keywords and locations, never your Google account data.
Each processes data only to provide their service to us. We do not sell personal information.
Your rights and choices
- Disconnect any source at any time in Settings → Connections; you can also revoke Flownomic's access from your Google Account permissions page.
- Revoke your AI connector at any time in Settings.
- Access, export, correct, or delete your data — email brenden@flownomic.ai and we'll respond within 30 days.
- Cancel your subscription at any time from Settings → Plan; cancellation takes effect at the end of the billing period.
Children
Flownomic is a business tool and is not directed to children under 13.
Changes
We'll post any material changes to this policy here and update the effective date. Continued use after changes means you accept the updated policy.
Contact
Flownomic LLC · brenden@flownomic.ai
See also our Terms of Service.