Privacy Policy
Last updated 2026-08-19
In one sentence: we collect the minimum, sell nothing, train no models on your data, and you can leave with everything.
1. Who we are
Flowlexi, a Brazilian company, CNPJ 11.403.710/0001-89, is the data controller for Flowlexi Cloud (cloud.flowlexi.com). Privacy contact and data protection officer: privacy@flowlexi.com.
2. What we collect
Only what running the service needs. No ad trackers, ever.
Account data: name, e-mail, password hash, language preference. Billing data: handled by our payment providers (Stripe for USD, Asaas for BRL — Asaas requires CPF/CNPJ for Pix); we store only references and invoice status, never card numbers. Operational data: instance metrics, API request logs and audit events needed to run and secure the service. Analytics: self-hosted, cookie-light, first-party only (Umami on our own servers) — no data is shared with ad networks.
Your stored content (documents, embeddings, collections) is yours; we process it only to provide the service, as described in the Terms.
3. Legal bases
We process personal data to perform our contract with you (account, billing, support), to meet legal obligations (tax and consumer rules), and under legitimate interest for service security and product analytics — always in the least intrusive way available. Anything beyond that only happens with your consent, which you can withdraw at any time.
4. Who we share data with
Processors we need to operate — never buyers of your data.
We share data only with processors required to operate: Stripe and Asaas (payments), Fly.io (network edge for our gateway), Forward Email (transactional e-mail). Our databases and your stored content live on infrastructure we operate in Brazil. We do not sell personal data and do not use it to train models.
5. International transfers
Payment processing with Stripe and edge routing with Fly.io may transfer limited data outside Brazil. These providers operate under contractual safeguards consistent with LGPD art. 33 and GDPR requirements.
6. Retention
Kept while your account lives, plus short legal tails.
Account and content data are kept while your account is active. After a subscription ends, shared-plan data is kept 14 days and dedicated machines are deleted 7 days after the term; expired sandboxes get a 14-day upgrade window, then deletion. Billing records are retained as tax law requires. Security logs are kept for up to 12 months.
7. Your rights
Access, correct, export, delete — one e-mail away.
You may request access, correction, portability, anonymization or deletion of your personal data, information about sharing, and review of automated decisions — as provided by the LGPD (art. 18) and, where applicable, the GDPR. Write to privacy@flowlexi.com; we answer within 15 days. You may also complain to the Brazilian authority (ANPD) or your local authority.
8. Cookies
We use only essential cookies: session authentication and language preference. Our self-hosted analytics does not use cross-site tracking cookies.
9. Security and incidents
Data is encrypted in transit, access is role-restricted and logged, and API keys are stored hashed. If an incident creates relevant risk to you, we will notify you and the ANPD as the LGPD requires.
10. Changes
Material changes to this policy are announced by e-mail at least 30 days in advance. The date at the top always reflects the current version.