FlowraLab
Privacy PolicyTerms of Service

FlowraLab public policies

Privacy Policy

How FlowraLab collects, uses, protects, and gives you control over information used to provide the service.

Effective
August 23, 2026
Contact
support@flowralab.com

Overview

This Privacy Policy explains how FlowraLab processes information when you use our SEO operations platform, create an account, add websites, run audits, or connect third-party services. We process data to provide the features you ask for, keep the service secure, and operate FlowraLab. We do not sell personal information or Google user data.

Information FlowraLab processes

Depending on how you use FlowraLab, we may process:

  • Account and organization data: email address, display name, account security state, organization memberships, roles, workspaces, and permissions.
  • Site and SEO data: projects, website hostnames, sitemap URLs, URL records, technical audit results, findings, index observations, and audit history.
  • Integration data: connection status, provider identifiers, selected properties or models, encrypted credentials, synchronization state, and provider error categories.
  • Content data: WordPress post and page metadata, content made available for an authorized feature, generated or suggested content, review history, and publication records.
  • Usage and operational data: feature usage, job status, quota observations, security and audit events, request identifiers, timestamps, and technical diagnostics needed to operate and protect the service.

Google user data

FlowraLab connects to Google Search Console only after an authorized user chooses to connect a Google account and completes Google's OAuth consent flow. FlowraLab requests the read-only Search Console scope:

https://www.googleapis.com/auth/webmasters.readonly

Data accessed

With that permission, FlowraLab may access the Search Console properties the user can view, URL Inspection data, Search Analytics data, search queries, clicks, impressions, click-through rate, average position, and related SEO observations needed for the requested FlowraLab features. The scope does not give FlowraLab permission to modify Search Console properties.

How Google data is used

Google data is used to display Search Console observations, connect those observations to the correct FlowraLab Site and URL record, monitor indexing, identify content opportunities, and provide user-requested SEO workflows. When an authorized user explicitly runs an AI feature, limited relevant SEO context may be included with the request sent to the Organization's configured AI provider to produce that visible feature result. FlowraLab does not use Google user data for advertising, ad targeting, credit decisions, or data brokerage.

Storage, protection, and sharing

OAuth access and refresh tokens are encrypted at rest, access-controlled, and never displayed publicly or returned to users after storage. FlowraLab limits access and transfers to what is needed to provide the user-facing feature, protect the service, comply with law, or use service providers acting on our behalf under appropriate obligations. FlowraLab's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Read the Google API Services User Data Policy.

User control

Users can disconnect Google Search Console from FlowraLab. Disconnecting stops new access and removes locally stored OAuth credentials through the integration workflow. Previously created audit history or derived observations may remain for the retention periods described below unless deletion is requested or required by law. Users can also revoke FlowraLab's access from their Google Account permissions.

WordPress data and credentials

Customers may provide a WordPress site URL, username, and Application Password. FlowraLab encrypts the Application Password and does not redisplay it after storage. When authorized, FlowraLab may read posts, pages, metadata, permalinks, and content to synchronize the URL Library or support content workflows. FlowraLab modifies existing WordPress content, creates a draft, or publishes a post only after an authorized user takes the corresponding action. Users can replace credentials or disconnect WordPress.

OpenRouter and AI features

OpenRouter is bring-your-own-key: each Organization supplies its own API key and selects the model it wants to use. FlowraLab encrypts the key and never redisplays it after storage. When an authorized user explicitly runs an AI feature, FlowraLab may send the website or article content, instructions, relevant SEO context, and selected reference material needed for that request to the configured AI provider. FlowraLab does not send one tenant's content in another tenant's request. OpenRouter's handling of data is governed by the customer's relationship with OpenRouter and the selected model provider.

How information is used

  • Provide, maintain, and improve requested FlowraLab features.
  • Authenticate users and enforce tenant, role, and capability boundaries.
  • Run durable audits, synchronizations, inspections, and content jobs.
  • Measure usage, manage quotas, diagnose failures, and prevent abuse.
  • Maintain audit trails and communicate important service information.
  • Meet legal obligations and protect users, FlowraLab, and third parties.

Disclosure and service providers

FlowraLab may use infrastructure, database, security, and other service providers to operate the service. They may process information only as needed to perform services for FlowraLab and subject to applicable contractual and security controls. Information may also be disclosed when required by law, to protect rights or safety, or in connection with a business transaction subject to appropriate protections. FlowraLab does not sell user data.

Retention and deletion

FlowraLab keeps information for as long as reasonably needed to provide the service, maintain security and audit history, resolve disputes, and meet legal obligations. Retention can vary by data type and account state. Integration credentials are deleted or invalidated when the integration is disconnected. Some information may remain temporarily in protected backups or where retention is required for security, integrity, or legal reasons.

Users may request account or data deletion by emailing support@flowralab.com. We may need to verify the requester's identity and authority over the relevant account or Organization before acting on a request.

Security

FlowraLab uses administrative, technical, and organizational safeguards appropriate to the nature of the data, including encrypted credential storage, access controls, tenant isolation, and protected transport. No system can guarantee absolute security, and users are responsible for protecting their account credentials and promptly reporting suspected misuse.

Your choices and rights

Users can review and update account information, disconnect integrations, limit data sent to providers by choosing which features to run, and request access, correction, export, or deletion where applicable. Available rights depend on the user's location and applicable law. Requests may be sent to support@flowralab.com.

Changes to this policy

FlowraLab may update this policy as the service, providers, or legal requirements change. We will update the effective date and provide additional notice when a change materially affects how user data is handled or requires renewed consent.

Contact

Questions, privacy requests, and account or data deletion requests can be sent to support@flowralab.com.

FlowraLab
Privacy PolicyTerms of Service