Privacy Policy
Flossi India Private Limited ("Flossi," "we," "us," or "our") operates the Flossi platform — a brand deal CRM, invoicing, and financial management tool for content creators — available at flossi.app (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information.
By using the Service, you agree to the collection and use of information as described in this policy.
1. Information We Collect
1.1 Information You Provide
- Account information: name, email address, profile photo
- Deal and contract data: brand names, deal values, payment terms, deliverables, dates, and any notes you enter
- Income data: income amounts, platform sources, and payment dates you record
- Media kit content: bio, audience statistics, photos, and other content you upload
- Support communications: messages you send us
1.2 Gmail Data (When You Connect Your Inbox)
When you connect your Gmail account, Flossi accesses your inbox using Google's OAuth 2.0 protocol. We request two permissions: gmail.readonly and gmail.send. Our use of Gmail data is limited strictly to the purposes described below.
Flossi's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Read access (gmail.readonly): We scan your inbox solely to identify incoming brand collaboration emails and extract structured deal terms — such as brand name, rate, deliverables, and payment schedule — for display in your dashboard. We do not read personal emails, newsletters, or other non-business correspondence. We do not store raw email content. Only extracted structured fields (e.g., "Brand: Nike, Rate: $5,000, Due: June 30") are stored in your account.
Send access (gmail.send): We send invoices and follow-up emails to brand partners on your behalf, using your Gmail address as the sender. You review and approve the content of every email before it is sent. We never send emails automatically without your explicit approval for each message.
Strict Access Restrictions: Flossi does not build or provide internal tools or admin interfaces for employees or contractors to browse or read your emails. Access to your inbox is strictly programmatic and automated. Our team will only inspect system records if explicitly requested and authorized by you to diagnose a specific technical issue.
No AI Model Training: Flossi never uses your Gmail data, emails, attachments, or private communications to train, retrain, or improve generalized or public artificial intelligence / machine learning models.
You can revoke Gmail access at any time from Settings → Connections within the app, or from your Google Account settings at myaccount.google.com. Revoking access immediately stops all Gmail-related features and deletes active access tokens.
Flossi does not use Gmail data to serve advertising. We do not share Gmail data with third parties except as described in Section 4 (Service Providers and Sub-processors).
1.3 Instagram Data (When You Connect Your Instagram Account)
When you connect your Instagram Professional or Creator account, Flossi accesses your account using Meta's Graph API. We request permissions necessary to read your direct messages and profile data.
Message access: We scan your Instagram direct messages (DMs) solely to identify incoming brand collaboration inquiries and extract structured deal terms for your dashboard. We do not read personal messages, and we do not store raw message content. Only extracted structured fields are stored in your account.
You can revoke Instagram access at any time from Settings → Connections within the app, or from your Facebook/Meta account settings. Revoking access immediately stops all Instagram-related features.
Flossi does not use Instagram data to serve advertising and does not share it with third parties except as described in Section 4 (Service Providers and Sub-processors).
1.4 Usage and Analytics Data
We collect information about how you use the Service — including pages visited, features used, clicks, and session duration — via PostHog analytics. This data is used to improve the product and understand feature usage. It does not include the content of your deals or emails.
1.5 Payment Data
When you subscribe to a paid plan, payment is processed by Stripe, Inc. Flossi does not store your credit card number or payment credentials. Stripe's Privacy Policy governs the handling of your payment information.
1.6 Device and Technical Data
We may collect standard technical data such as browser type, operating system, IP address, and referring URL to operate and secure the Service.
2. How We Use Your Information
- To provide, operate, and improve the Service
- To detect brand collaboration emails and extract deal terms (with your Gmail permission)
- To detect brand collaboration messages and extract deal terms (with your Instagram permission)
- To send invoices and professional communications on your behalf (with your explicit approval)
- To generate financial summaries and tax estimates for your personal planning use
- To send transactional emails, onboarding communications, and product updates
- To respond to your support requests
- To detect and prevent fraud, abuse, or security incidents
- To comply with applicable legal obligations
3. AI Processing & Privacy Guarantees
Flossi uses Anthropic's Claude AI models to:
- Classify incoming emails as brand-collaboration-related or not
- Extract deal terms from email content (rate, deliverables, payment schedule, exclusivity)
- Draft professional reply emails and invoice follow-ups for your review
- Generate deal analysis and scoring
Email content processed by AI is sent securely to Anthropic's API solely for real-time inference and is subject to Anthropic's Privacy Policy. Neither Flossi nor Anthropic uses your private emails, messages, or deal data to train AI models. AI-extracted data may contain errors — all extracted information is presented for your review and can be corrected before being saved.
4. How We Share Your Information
We do not sell your personal information. We share data only with the following service providers, each bound by data processing agreements to use your data solely to provide services to Flossi:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage |
| Anthropic | AI processing — email classification, term extraction, email drafting |
| Stripe | Subscription payment processing |
| Resend | Transactional email delivery |
| Inngest | Background job and workflow processing |
| PostHog | Product analytics |
| Vercel | Application hosting |
| Cloudflare | Website hosting and CDN |
| Formspree | Waitlist email collection |
We may also disclose your information if required by law, court order, or to protect the rights, property, or safety of Flossi, our users, or the public.
5. Data Retention
- Account data: retained while your account is active and deleted within 30 days of a verified deletion request
- Deal and financial data: retained for 7 years from the date of creation to comply with standard financial record-keeping requirements; you may request deletion subject to legal retention obligations
- Raw email content: not stored — only extracted structured fields are retained
- Gmail access tokens: immediately revoked when you disconnect Gmail from Settings → Connections
- Analytics data: retained for 24 months
6. Your Rights
California Residents (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect about you and how it is used and shared
- Delete personal information we hold about you, subject to certain legal exceptions
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information (we do not sell or share your data for advertising)
- Non-discrimination for exercising any of these rights
To exercise your rights, contact us at hello@flossi.app. We will respond within 45 days.
All Users
Regardless of location, you may at any time: access your data from within the app, correct inaccurate data, disconnect Gmail, or request account deletion by contacting us.
7. Data Security
We implement industry-standard security measures including TLS encryption in transit, encryption at rest, and row-level database security ensuring users can only access their own data. However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
8. Beta Services Notice
The Service is currently in beta. Security, availability, and data integrity may not meet the standards of a fully production-hardened service. We recommend maintaining your own records of critical financial and deal information during the beta period.
9. Children's Privacy
The Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice on the Service. The updated policy will be effective upon posting. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Flossi India Private Limited
Email: hello@flossi.app
