InflowAISign in

Privacy

This notice explains how InflowAI handles account, knowledge, chat, and connected-service data. Updated September 12, 2026.

Contact InflowAI

For privacy questions or a data request, contact inflowai.org@gmail.com. If you use an assistant on someone else’s website, that assistant’s operator also receives your conversation and controls its knowledge and follow-ups.

What we collect and why

  • Google account identity, including your account identifier, name and email, to sign you in and keep workspaces separate.
  • Assistant settings, uploaded materials, imported website content and selected connected sources, to index knowledge and answer questions.
  • Chat messages and supplied attachments, and contact details or meeting purposes you provide, to answer questions, retain conversation history, arrange meetings and handle requested follow-ups.
  • Connection credentials and identifiers, to keep authorized integrations working until disconnected or revoked.
  • Session cookies and operational request information, including IP addresses in hosting logs, to maintain sessions, limit abuse and diagnose failures.

Google Drive and Calendar

Connecting Drive authorizes file discovery and reading. The current connection requests broad read access, but you select the sources to index. Inbox follow-ups are stored in InflowAI and are not copied to Drive. Previously linked InflowAI-created follow-up files are no longer updated; you can delete these older copies through their inbox controls. File-management permission is requested only when the assistant already has such a linked file; new connections otherwise request read-only Drive access. Selected file text and metadata are copied into the assistant’s knowledge store.

Connecting Calendar lets InflowAI read availability and manage events on the connected calendar for visitor-confirmed meetings. Booking records include the time, attendee details and provider event identifiers. Google handles calendar invitations.

These connections are optional. Google account sign-in alone does not connect Drive or Calendar. You can disconnect within the app or revoke access in your Google Account.

AI processing and sharing

To generate an answer, we send relevant knowledge excerpts, conversation context and submitted attachments needed for the request to third-party AI service providers. These providers process the requests to generate your assistant’s responses, subject to their applicable data-handling terms.

Hosting and storage run on Railway. Google, Microsoft and Notion process data when you use their corresponding connections. Assistant operators can read retained chats and follow-ups. Content selected as assistant knowledge can be reflected in answers to visitors, so only publish materials those visitors may access.

InflowAI uses connected Google data to provide the features you request. We do not sell Google user data, use it for advertising, or train our own general-purpose AI models with it. Contact InflowAI for information about the service providers that process your data.

Storage and retention

We retain account and assistant data while it is needed to operate your workspace, until you remove it through the applicable controls or request deletion. Conversations do not currently have an automatic expiry setting. The application encrypts connection credentials and queued email payloads. Other assistant data is protected by storage and account access controls; sessions use protected cookies. No system can guarantee absolute security.

Operational logs and infrastructure backups may outlast deletion from active application storage. Contact us for a specific retention or removal request; we do not promise an unverified backup-erasure deadline.

Your controls

Remove indexed sources to stop using their saved content. Disconnecting a provider prevents further authorized access but does not, by itself, erase content already imported or events already created. Delete an assistant or your account using the management controls; account deletion can remain pending while cleanup finishes.

Where email alerts are available, you can opt in separately to confirmed-booking and human-help notifications in your account settings. You may use your verified account email or verify a different notification address through a single-use link. We send verification emails to addresses you request; your existing recipient remains active until you confirm the replacement. Our email delivery service receives the chosen address and a brief alert linking to your private inbox. These alerts do not include visitor contact details, chat content or imported documents. We retain alert preferences, encrypted queued messages and delivery records with your account. Turning an alert off cancels pending messages; a message already being sent may still arrive. Account deletion removes these records from active application storage.

Deleting an inbox record can also delete its linked InflowAI-created Drive file, as stated in its confirmation. Original source files and existing calendar events are managed separately in their source services. Revoking a connection does not send a deletion request to those services.

For access, correction or deletion requests that the interface does not cover, contact us from the account concerned. We may need to verify ownership before acting. Visitors can contact the assistant operator or us with enough information to locate their conversation.

Changes

We will update this page when our data practices change. The date above identifies the current notice.