Privacy Policy
Introduction
This privacy policy explains how Floot, a product of Floot, Inc ("we," or "us") collects, uses, and protects your information when you use our website (floot.com) and services. This policy applies to all users of our platform and services and should be read in conjunction with our Terms of service ("Terms"), which contain additional important information about how we handle your data and content.
Data Collection and Use
Information We Collect
Account Information
- Email address
- Name
- Account preferences and settings For detailed information about account management and your responsibilities regarding account information, please see the "User accounts and content" section of our Terms.
Service Usage Data
- Generated code and prompts
- Platform interaction data
- Feature usage statistics
- Error logs and debugging information The ownership and usage rights of generated code and content are detailed in the "Intellectual property rights" section of our Terms.
Automatically Collected Information
- IP addresses
- Browser type and version
- Device information
- Operating system
- Access times and dates
- Pages visited
Analytics and Tracking
We use Amplitude and PostHog for analytics and tracking.
For details about Amplitude and PostHog's data handling, please see their Privacy policy
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to:
- Maintain your session
- Remember your preferences
- Analyze platform usage
- Improve our services You can control cookie preferences through your browser settings.
How We Use Your Information
We use collected information as detailed in our Terms of service (see "Data usage, training, and learning" and "Service improvements and training" sections) for the following purposes:
- Provide and improve our services, including:
- Platform functionality improvements
- AI model training
- Service quality enhancements
- Support and operations:
- Provide customer support
- Process payments
- Send service updates
- Security and maintenance:
- Maintain platform security
- Analyze usage patterns
- Debug technical issues
- Prevent abuse and fraud
Data Sharing and Processing
Third-party Service Providers
We share data with trusted service providers only as needed to operate the platform. The categories of recipients are:
- AI model providers — when you use AI features (generating or editing code, chat, planning, image generation), your prompts, relevant project files, and related context are sent to the AI providers that power those features, including Anthropic, OpenAI, Google, Mistral, Groq, Cerebras, and Amazon Bedrock. These providers process the data to generate responses on our behalf.
- Cloud infrastructure and hosting — Amazon Web Services (compute, storage, content delivery) and our managed database provider host your account data and project content.
- Analytics — Amplitude and PostHog receive usage events (feature usage, page views, tool-call metadata) associated with your account identifier.
- Payments — Stripe processes payments. We do not store your full card details.
- Email delivery — Resend delivers transactional emails (sign-in links, notifications) to your email address.
- Security — Cloudflare Turnstile is used for bot protection on some requests.
For specific information about:
- Data processing practices
- Service provider requirements
- Custom handling agreements
Please see the "Data usage and learning" section of our Terms.
Data Retention
- Account information is retained while your account is active and deleted or anonymized after account deletion, except where we must retain it to comply with legal obligations.
- Project content (code, prompts, chat history, uploaded assets) is retained until you delete the project or your account.
- MCP tool-call operation logs (see "AI Assistant Connections (MCP)" below) are automatically deleted 3 days after their last update.
- Error logs and debugging information are retained for a limited operational window and then expire.
- Analytics data is retained per our analytics providers' configured retention periods.
- Payment records are retained as required by tax and accounting law.
To request deletion of specific data, contact feedback@floot.com.
Your Rights
You have the right to:
- Access your personal data
- Request data correction
- Request data deletion
- Export your data
- Opt out of certain processing
- Withdraw consent
Contact feedback@floot.com to exercise these rights.
Security Measures
We implement industry-standard security measures:
- Encrypted data transmission
- Secure data storage
- Access controls
- Regular security audits
- Employee training
Service Improvements and AI Training
As detailed in the "Data usage, training, and learning" section of our Terms, we may use certain data to improve our services and train our AI systems. Important exceptions and limitations apply.
Please refer to our Terms for complete information about:
- Types of data used for training
- Data handling practices
- Your rights regarding data usage
Data Protection and Security
Our security measures and data protection practices complement the warranty disclaimers and liability limitations detailed in our Terms. For specific information about:
- Platform security
- Data handling
- Risk allocation
- Liability limitations
Please see the "Disclaimer of warranties" and "Limitation of liability" sections in our Terms.
User Content Visibility
The content and code you generate using our services, including prompts and project files, are private and only accessible to you and Floot, Inc's authorized employees, contractors, and partners as necessary to provide support and maintain platform functionality.
If your project is set to "public," then the prompts and code can be visible to other users. Your public project can also be remixed and used as a starting point for other projects. Private projects are not remixable, and their code and prompts are not visible to other users.
Other users cannot view your private content and projects unless you choose to make them publicly available through our platform's sharing and collaboration features.
Liability Protections
Our platform includes technical measures to protect the privacy and security of user content. However, we cannot be held liable for any issues that may arise from users deliberately circumventing our platform limitations or protections to access private content.
Users are responsible for maintaining the confidentiality of their account information and for any activities that occur under their account, whether or not authorized by the user. We disclaim all liability for any damages, loss of profits, or other harm resulting from unauthorized access to user content.
Our warranty disclaimers and liability limitations, as detailed in our Terms of Service, apply to all aspects of our platform and services, including the security and privacy of user data.
Children's Privacy
Our services are not intended for users under 18. We do not knowingly collect data from children.
International Data Transfers
We may transfer data internationally within our service provider network. We ensure appropriate safeguards are in place for these transfers.
Legal Framework
This privacy policy is part of and subject to our Terms. In case of any conflict between this privacy policy and our Terms, the Terms shall prevail.
Changes to This Policy
We may update this policy periodically. Changes will be handled in accordance with the process outlined in our Terms regarding policy updates.
Contact Details
General Contact Information
- Website: https://floot.com
Contact Us For
- Privacy questions: feedback@floot.com
- DMCA and legal issues: feedback@floot.com
- General feedback: feedback@floot.com
Response Times
- We aim to respond to privacy-related inquiries within 7 business days
Additional Resources
- Terms of service: https://floot.com/terms
For the fastest response, please use the appropriate email address for your inquiry and include relevant account information when contacting us.
Browser Extensions
We may offer companion browser extensions (such as Floot Infinity) for Chrome, Firefox, Safari, and other browsers to enhance your experience with the Floot web app. All Floot browser extensions are governed by this privacy policy.
What the Extensions Do
Our browser extensions provide features that require browser-level access, such as capturing screenshots, reading or interacting with web page content, and performing actions in the browser on your behalf. This section describes the types of data our extensions may access.
Data the Extensions Access
Website Content
When you use an extension feature, it may access:
- Text, images, and other visible content on web pages
- The structure and styling of web pages
- Screenshots of web pages or portions of web pages
This data is sent to the Floot web app and may be processed by our AI service providers as part of your workflow.
Sensitive Values
During certain tasks, the extension may read sensitive information displayed on web pages, such as API keys shown on a dashboard. These values are:
- Held temporarily in memory for the duration of the active session
- Passed back to the Floot web app so they can be saved to your project
- Cleared from memory when the session ends
- Never sent to any third party directly by the extension
When the Extensions Access Data
Our extensions only access web page data based on your actions or with your permission. The extensions do not:
- Collect data in the background or without your knowledge
- Track your browsing history or activity
- Permanently store any web page content, screenshots, or sensitive values
How Extension Data Is Used
When our extensions capture data from a web page, that data is sent to the Floot web app and handled in accordance with this privacy policy. Where applicable, it may be shared with AI service providers to process your request. The extensions themselves do not send data to any third party.
Access to Websites
Some extension features, such as browser automation, may need to interact with websites of your choosing. The extensions only access websites that you direct them to or that you have granted permission for.
AI Assistant Connections (MCP)
Floot provides a Model Context Protocol ("MCP") server that lets you connect third-party AI assistants — such as ChatGPT, Claude, and AI coding agents — to your Floot account so they can build and manage Floot projects on your behalf. This section describes exactly what data flows through that connection.
How the Connection Is Authorized
You connect an AI assistant to Floot through an OAuth authorization flow (you approve the connection while signed in to your Floot account) or, for some developer tools, through an API key you create. The assistant then acts with the permissions of your Floot account.
Data We Receive (Tool Inputs)
When your AI assistant calls a Floot tool, we receive:
- Your account identity — the Floot account the connection was authorized for.
- Tool call details — the name of the tool invoked and its arguments. Depending on the tool, arguments may include: project file contents and edits (create, edit, rename, delete, patch operations), code to execute for testing and debugging, SQL queries to run against your project's database, image-generation prompts, search queries over your projects and code, project names and metadata (including app-store permission strings and publishing settings), uploaded asset files (file name, content type, and file content), and annotations or screenshots you share from the Floot preview.
- Client metadata — the name and version of the AI assistant application making the call (from its user-agent and client identification), used for compatibility, analytics, and abuse prevention.
We do not receive your conversation with your AI assistant. Your chats with ChatGPT, Claude, or any other assistant stay with that provider; Floot only receives the individual tool calls the assistant makes to our server.
Data We Send Back (Tool Outputs)
In response to tool calls, we return data from your account to your AI assistant, which may include: project file contents and file listings, results of database queries and your database schema, application logs and error output, type-check and test results, screenshots of your app preview, preview and published app URLs (which may include access tokens scoped to the project), generated images, resource and job status information, and summaries of operations performed.
Anything returned to your AI assistant becomes part of your conversation with that assistant and is thereafter handled under that provider's privacy policy (for example, OpenAI's policy for ChatGPT or Anthropic's policy for Claude). Please review your assistant provider's policy for how they store and use conversation data.
How We Use MCP Data
- To perform the requested operations — tool inputs are processed to carry out the action (editing files, running code, querying your database, publishing your app, etc.), the same way as if you performed it in the Floot web app.
- Project history — successful operations that modify your project are summarized into your project's chat history (e.g., "edited file X", "published the app") so you and your collaborators can see what the assistant changed. These records persist as part of the project.
- Operational logging — each tool call is recorded in a short-lived operation log (tool name, a summary of arguments, project, account, client application, status, result or error text, and timing) used to report job status back to your assistant and to debug failures.
- Analytics — we send an event per completed tool call to our analytics provider (PostHog) containing the tool name, success/failure status, duration, client application name, and project identifier — not the full tool arguments or file contents.
- Security, abuse prevention, and billing — we enforce daily usage limits on MCP tool calls, and image generation via MCP consumes Floot credits under your plan.
Recipients of MCP Data
MCP data is shared only with the service providers listed in "Third-party Service Providers" above (infrastructure, analytics, and — for image generation — AI model providers), and, by design, with the AI assistant provider you connected, which receives all tool outputs.
Retention of MCP Data
- Per-call operation logs are automatically deleted 3 days after their last update.
- Changes made to your projects, uploaded assets, and the project chat history entries describing them persist as part of your project until you delete them or the project.
- Analytics events are retained per the "Data Retention" section above.
Your Controls
- You can disconnect the Floot connector from within your AI assistant at any time, which stops it from making further calls to your account.
- You can revoke API keys and request server-side revocation of an assistant's access tokens by contacting feedback@floot.com.
- You can delete projects, files, and assets created through MCP the same way as any other project content.
- All rights described in the "Your Rights" section above apply equally to data collected through MCP connections.