Floot

Privacy Policy

Introduction

This privacy policy explains how Floot, a product of Floot, Inc ("we," or "us") collects, uses, and protects your information when you use our website (floot.com) and services. This policy applies to all users of our platform and services and should be read in conjunction with our Terms of service ("Terms"), which contain additional important information about how we handle your data and content.

Data Collection and Use

Information We Collect

Account Information

  • Email address
  • Name
  • Account preferences and settings For detailed information about account management and your responsibilities regarding account information, please see the "User accounts and content" section of our Terms.

Service Usage Data

  • Generated code and prompts
  • Platform interaction data
  • Feature usage statistics
  • Error logs and debugging information The ownership and usage rights of generated code and content are detailed in the "Intellectual property rights" section of our Terms.

Automatically Collected Information

  • IP addresses
  • Browser type and version
  • Device information
  • Operating system
  • Access times and dates
  • Pages visited

Analytics and Tracking

We use PostHog for analytics and tracking on floot.com and in the Floot builder.

For details about PostHog's data handling, please see their Privacy policy

Apps published on Floot include built-in visitor analytics (the Analytics tab in your project), processed by Tinybird. For each page view of your published app it records a random session identifier (stored in a first-party "session-id" cookie on your app's domain with a 30-minute sliding expiry), the page path, the referring page, the browser's user-agent and language, and a country derived from the browser's timezone. It does not record IP addresses or the query string of the URL. This data is retained for 12 months. If your app serves users in jurisdictions that require consent for analytics cookies, you are responsible for obtaining it.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Maintain your session
  • Remember your preferences
  • Analyze platform usage
  • Improve our services You can control cookie preferences through your browser settings.

How We Use Your Information

We use collected information only for the following purposes:

  • Provide and improve our services, including:
    • Platform functionality improvements
    • AI model training, using only your chat history with the Floot AI builder (see "AI Training" below)
    • Service quality enhancements
  • Support and operations:
    • Provide customer support
    • Process payments
    • Send service updates
  • Security and maintenance:
    • Maintain platform security
    • Analyze usage patterns
    • Debug technical issues
    • Prevent abuse and fraud

Only your chat history with the Floot AI builder may be used for AI training. No other data is used for training. See "AI Training" below.

The purposes above apply to data you provide directly to Floot. They do not apply to Google user data obtained through Google APIs. Google user data is used solely to provide or improve the user-facing features of the app you connected it to, and for no other purpose, as described in the "Google User Data and AI/ML Features (Limited Use)" section below.

Data Sharing and Processing

Third-party Service Providers

We share data with trusted service providers only as needed to operate the platform. The categories of recipients are:

  • AI model providers — when you use AI features (generating or editing code, chat, planning, image generation), your prompts, relevant project files, and related context are sent to the AI providers that power those features, including Anthropic, OpenAI, Google, Cerebras, Amazon Bedrock, Fireworks AI, Baseten, Fal, and DeepSeek. These providers process the data to generate responses on our behalf. Google user data is sent to an AI provider only when you invoke an app feature that operates on that data, solely to generate the response you requested (see "AI Processing of Google User Data" below).
  • Cloud infrastructure and hosting — Amazon Web Services (compute, storage, content delivery) hosts project files, uploaded assets, and published apps. Neon hosts the databases of apps built on Floot. Render hosts Floot's own platform database (account and project metadata, builder chat history).
  • Analytics — PostHog receives usage events (feature usage, page views, tool-call metadata) associated with your account identifier. Tinybird receives visitor analytics from apps published on Floot (see "Analytics and Tracking" above), associated with your published app's domain; these events never include IP addresses. Google user data is never included in analytics events.
  • Payments — Stripe processes payments. We do not store your full card details.
  • Email delivery — Resend delivers transactional emails (sign-in links, notifications) to your email address.
  • Security — Cloudflare Turnstile is used for bot protection on some requests.
  • Logging and monitoring — Datadog receives Floot's platform logs (error and operational logs from Floot's own services), retained for 90 days. Logs from apps built on Floot stay in Amazon CloudWatch for 90 days and are not sent to Datadog; they contain what your app's code writes to its logs plus the request method and path, and do not include request or response bodies, headers, cookies, or IP addresses. Amazon CloudFront edge logs for published apps record only a tenant identifier, response size, status, and cache result — no IP address, cookie, user-agent, or query string — and are retained for 30 days for bandwidth billing.

Every AI provider that can receive data from apps built on Floot or Google user data (Anthropic, OpenAI, Google, Fireworks AI, and Baseten) is used under commercial API terms that prohibit training on customer data, and processes that data solely to generate the response you requested. Cerebras, Amazon Bedrock, Fal, and DeepSeek are used only by the Floot builder for developer prompts and image generation and never receive data from apps built on Floot or Google user data.

Data Retention

  • Account information is retained while your account is active and deleted or anonymized after account deletion, except where we must retain it to comply with legal obligations.
  • Project content (code, prompts, chat history, uploaded assets) is retained until you delete the project or your account.
  • MCP tool-call operation logs (see "AI Assistant Connections (MCP)" below) are automatically deleted 3 days after their last update.
  • Application and platform logs are retained for 90 days (published-app backend logs and Floot platform logs) and 30 days (CDN edge logs); preview-environment request captures used by the assistant's debugging view expire after 1 hour. Log records cannot be selectively deleted before they expire.
  • Analytics data — PostHog events are retained per PostHog's configured retention period; published-app visitor analytics (Tinybird) are retained for 12 months.
  • Payment records are retained as required by tax and accounting law.

To request deletion of specific data, contact feedback@floot.com.

Your Rights

You have the right to:

  • Access your personal data
  • Request data correction
  • Request data deletion
  • Export your data
  • Opt out of certain processing
  • Withdraw consent

Contact feedback@floot.com to exercise these rights.

Security Measures

We implement industry-standard security measures:

  • Encrypted data transmission
  • Secure data storage
  • Access controls
  • Regular security audits
  • Employee training

AI Training

Our use of data for AI training is limited to one category, and everything else is excluded.

Builder chat history (may be used). Your conversations with the Floot AI builder in the Floot editor, meaning the prompts you send and the responses the builder returns while building a project, may be used by Floot to improve our services and to train and improve our own AI systems. This is the only data we use for AI training. Google user data and data from apps built on Floot are excluded even where they appear in builder chat history.

Data in the apps you build (never used). Data belonging to you or to the end users of apps built on Floot is never used for AI training of any kind and is never transferred to any third party for training. This includes app databases, end-user accounts and content, files uploaded to apps, and any data those apps receive from connected services. Apps built on Floot may send this data to an AI provider only to generate a response an end user requested, and every provider is used under commercial API terms that prohibit training on that data.

Google user data (never stored, never used). Data obtained through Google APIs, such as Gmail messages, Google Calendar events, and Google Drive files, is not stored by Floot and is never used to train, fine-tune, or improve any AI or machine learning model, whether Floot's or a third party's. This applies whether the data is raw, aggregated, anonymized, or derived, and it applies equally to Google user data accessed by Floot itself and to Google user data accessed by any app built on Floot. Apps built on Floot may access Google user data only with the end user's consent, may use it only to provide or improve that app's own features, and may not use it for AI training or transfer it to any third party for training. Floot retains only the encrypted OAuth tokens needed to keep the connection active, and Google content is processed transiently to serve each request. Google user data is never used to improve Floot's platform or for any purpose other than providing or improving the user-facing features of the app you connected it to.

Data Protection and Security

Our security measures and data protection practices complement the warranty disclaimers and liability limitations detailed in our Terms. For specific information about:

  • Platform security
  • Data handling
  • Risk allocation
  • Liability limitations

Please see the "Disclaimer of warranties" and "Limitation of liability" sections in our Terms.

User Content Visibility

The content and code you generate using our services, including prompts and project files, are private and only accessible to you and Floot, Inc's authorized employees, contractors, and partners as necessary to provide support and maintain platform functionality.

If your project is set to "public," then the prompts and code can be visible to other users. Your public project can also be remixed and used as a starting point for other projects. Private projects are not remixable, and their code and prompts are not visible to other users.

Other users cannot view your private content and projects unless you choose to make them publicly available through our platform's sharing and collaboration features.

Liability Protections

Our platform includes technical measures to protect the privacy and security of user content. However, we cannot be held liable for any issues that may arise from users deliberately circumventing our platform limitations or protections to access private content.

Users are responsible for maintaining the confidentiality of their account information and for any activities that occur under their account, whether or not authorized by the user. We disclaim all liability for any damages, loss of profits, or other harm resulting from unauthorized access to user content.

Our warranty disclaimers and liability limitations, as detailed in our Terms of Service, apply to all aspects of our platform and services, including the security and privacy of user data.

Children's Privacy

Our services are not intended for users under 18. We do not knowingly collect data from children.

Data Location and International Data Transfers

Your account data, project content, uploaded files, and the databases of apps built on Floot are stored in the United States (Amazon Web Services and Neon, us-east-1 region). Some processing may occur outside the United States: content delivery network edge caches serve cached copies of published apps and public files from locations worldwide, and AI providers may process requests in other regions. We ensure appropriate safeguards are in place for these transfers.

Legal Framework

This privacy policy is part of and subject to our Terms. In case of any conflict between this privacy policy and our Terms, the Terms shall prevail.

Changes to This Policy

We may update this policy periodically. Changes will be handled in accordance with the process outlined in our Terms regarding policy updates.

Contact Details

General Contact Information

  • Website: https://floot.com

Contact Us For

  • Privacy questions: feedback@floot.com
  • DMCA and legal issues: feedback@floot.com
  • General feedback: feedback@floot.com

Response Times

  • We aim to respond to privacy-related inquiries within 7 business days

Additional Resources

  • Terms of service: https://floot.com/terms

For the fastest response, please use the appropriate email address for your inquiry and include relevant account information when contacting us.

Google User Data and AI/ML Features (Limited Use)

Apps built on Floot can optionally connect to Google services such as Gmail, Google Calendar, and Google Drive through Google APIs, only with your explicit consent granted via Google's OAuth flow.

Limited Use Statement

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Floot's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What Google User Data Is Accessed

Depending on the Google scopes you grant to a specific app, the app may access your Google account email address and profile name, your Gmail messages, your Google Calendar events, and your Google Drive files. Only the scopes you explicitly approve on Google's consent screen are requested, and each app requests only the scopes needed for its features.

How Google User Data Is Used

  • Google user data is used solely to provide or improve the user-facing features of the app you connected it to (for example, displaying your emails, calendar events, or files, or performing an action you requested on them). Any improvement is limited to the specific features of that app that you use.
  • Google user data is not used for any other purpose. In particular, it is never used for advertising or targeted advertising, marketing, analytics, market research, profiling, credit or lending decisions, or to improve Floot's own platform or any other product.
  • Google user data, whether raw, aggregated, anonymized, or derived, is never used to develop, train, or improve generalized, non-personalized, or foundational AI/ML models, neither by Floot nor by any third party.

How Google User Data Is Shared or Transferred

  • Google user data is never sold, and is never transferred to advertisers, data brokers, or information resellers.
  • We do not transfer or disclose Google user data to third parties for purposes other than the ones described in this section. The only transfers are: (a) to the data processors named in "AI Processing of Google User Data" below, strictly to deliver the app feature you invoked; (b) where necessary for security purposes, such as investigating abuse; (c) to comply with applicable law or a legal process; or (d) as part of a merger, acquisition, or sale of assets, in which case you will receive prior notice of any change in how your Google user data is handled.
  • Humans do not read Google user data except with your explicit consent (for example, when you ask us for support on a specific item), where necessary for security purposes, or to comply with applicable law.

AI Processing of Google User Data

Google user data is sent to an AI model only when you explicitly invoke an AI feature that operates on that data (for example, asking an app's assistant to summarize your inbox). When that happens:

  • Requests are routed through Floot's own AI gateway to inference providers acting as our data processors, solely to generate the response you requested.
  • Every provider is used under API or service terms that prohibit the use of your data to train their models. Google user data is never used to create, train, or improve any foundational or generalized AI/ML model.
  • Some of the models we use (such as GLM and Kimi) are open weight models operated for us by independent inference infrastructure providers (currently Fireworks AI and Baseten) within their isolated serving infrastructure. Your data is processed there solely to generate the response and is never transmitted to the model developers (such as Z.ai or Moonshot AI) for training or any other secondary purpose.
  • Document and image understanding features may use Google's Gemini API, and apps configured with their own AI resources may use the Anthropic or OpenAI APIs, in all cases via commercial API terms that exclude training on your data.

Storage, Retention, and Deletion of Google User Data

  • Floot stores only the OAuth tokens needed to keep your Google connection active, encrypted at rest. Your Google content (emails, calendar events, Drive files) is processed transiently to serve each request and is not copied to Floot's own storage.
  • When you disconnect a Google account from an app, its stored tokens are deleted and the app can no longer access your Google data. Deleting your Floot account removes all stored tokens.
  • You can also revoke Floot's access at any time from your Google Account security settings at https://myaccount.google.com/permissions.
  • To request deletion of any Google user data, contact us at the addresses listed in the Contact section; we respond within 7 business days.

Browser Extensions

We may offer companion browser extensions (such as Floot Infinity) for Chrome, Firefox, Safari, and other browsers to enhance your experience with the Floot web app. All Floot browser extensions are governed by this privacy policy.

What the Extensions Do

Our browser extensions provide features that require browser-level access, such as capturing screenshots, reading or interacting with web page content, and performing actions in the browser on your behalf. This section describes the types of data our extensions may access.

Data the Extensions Access

Website Content

When you use an extension feature, it may access:

  • Text, images, and other visible content on web pages
  • The structure and styling of web pages
  • Screenshots of web pages or portions of web pages

This data is sent to the Floot web app and may be processed by our AI service providers as part of your workflow.

Sensitive Values

During certain tasks, the extension may read sensitive information displayed on web pages, such as API keys shown on a dashboard. These values are:

  • Held temporarily in memory for the duration of the active session
  • Passed back to the Floot web app so they can be saved to your project
  • Cleared from memory when the session ends
  • Never sent to any third party directly by the extension

When the Extensions Access Data

Our extensions only access web page data based on your actions or with your permission. The extensions do not:

  • Collect data in the background or without your knowledge
  • Track your browsing history or activity
  • Permanently store any web page content, screenshots, or sensitive values

How Extension Data Is Used

When our extensions capture data from a web page, that data is sent to the Floot web app and handled in accordance with this privacy policy. Where applicable, it may be shared with AI service providers to process your request. The extensions themselves do not send data to any third party.

Access to Websites

Some extension features, such as browser automation, may need to interact with websites of your choosing. The extensions only access websites that you direct them to or that you have granted permission for.

AI Assistant Connections (MCP)

Floot provides a Model Context Protocol ("MCP") server that lets you connect third-party AI assistants — such as ChatGPT, Claude, and AI coding agents — to your Floot account so they can build and manage Floot projects on your behalf. This section describes exactly what data flows through that connection.

How the Connection Is Authorized

You connect an AI assistant to Floot through an OAuth authorization flow (you approve the connection while signed in to your Floot account) or, for some developer tools, through an API key you create. The assistant then acts with the permissions of your Floot account.

Data We Receive (Tool Inputs)

When your AI assistant calls a Floot tool, we receive:

  • Your account identity — the Floot account the connection was authorized for.
  • Tool call details — the name of the tool invoked and its arguments. Depending on the tool, arguments may include: project file contents and edits (create, edit, rename, delete, patch operations), code to execute for testing and debugging, SQL queries to run against your project's database, image-generation prompts, search queries over your projects and code, project names and metadata (including app-store permission strings and publishing settings), uploaded asset files (file name, content type, and file content), and annotations or screenshots you share from the Floot preview.
  • Client metadata — the name and version of the AI assistant application making the call (from its user-agent and client identification), used for compatibility, analytics, and abuse prevention.

We do not receive your conversation with your AI assistant. Your chats with ChatGPT, Claude, or any other assistant stay with that provider; Floot only receives the individual tool calls the assistant makes to our server.

Data We Send Back (Tool Outputs)

In response to tool calls, we return data from your account to your AI assistant, which may include: project file contents and file listings, results of database queries and your database schema, application logs and error output, type-check and test results, screenshots of your app preview, preview and published app URLs (which may include access tokens scoped to the project), generated images, resource and job status information, and summaries of operations performed.

Anything returned to your AI assistant becomes part of your conversation with that assistant and is thereafter handled under that provider's privacy policy (for example, OpenAI's policy for ChatGPT or Anthropic's policy for Claude). Please review your assistant provider's policy for how they store and use conversation data.

How We Use MCP Data

  • To perform the requested operations — tool inputs are processed to carry out the action (editing files, running code, querying your database, publishing your app, etc.), the same way as if you performed it in the Floot web app.
  • Project history — successful operations that modify your project are summarized into your project's chat history (e.g., "edited file X", "published the app") so you and your collaborators can see what the assistant changed. These records persist as part of the project.
  • Operational logging — each tool call is recorded in a short-lived operation log (tool name, a summary of arguments, project, account, client application, status, result or error text, and timing) used to report job status back to your assistant and to debug failures.
  • Analytics — we send an event per completed tool call to our analytics provider (PostHog) containing the tool name, success/failure status, duration, client application name, and project identifier — not the full tool arguments or file contents.
  • Security, abuse prevention, and billing — we enforce daily usage limits on MCP tool calls, and image generation via MCP consumes Floot credits under your plan.

Recipients of MCP Data

MCP data is shared only with the service providers listed in "Third-party Service Providers" above (infrastructure, analytics, and — for image generation — AI model providers), and, by design, with the AI assistant provider you connected, which receives all tool outputs.

MCP tools do not access Google APIs, and Google user data is not stored in your project or database, so Google user data is not returned as tool output.

Retention of MCP Data

  • Per-call operation logs are automatically deleted 3 days after their last update.
  • Changes made to your projects, uploaded assets, and the project chat history entries describing them persist as part of your project until you delete them or the project.
  • Analytics events are retained per the "Data Retention" section above.

Your Controls

  • You can disconnect the Floot connector from within your AI assistant at any time, which stops it from making further calls to your account.
  • You can revoke API keys and request server-side revocation of an assistant's access tokens by contacting feedback@floot.com.
  • You can delete projects, files, and assets created through MCP the same way as any other project content.
  • All rights described in the "Your Rights" section above apply equally to data collected through MCP connections.