Legal

Privacy

Last updated September 2026

What this covers

This describes what FloForge stores when you use the product, who can reach it, and what you can do about it. It is written against how the software actually works rather than as a general statement of intent.

What we store

The account itself: the email address you sign up with, and a password held only as a hash, or a Google sign-in if you use one. We never see your Google password.

The records you put in: contacts, companies, leads, deals, tasks, meetings, notes and the activity trail generated as those change. This includes anything you import from a CSV or bring in from a connected service.

Operational records: import batches, automation runs and their outcomes, enrichment runs, and the event log that drives automations.

Who can see it

Your records are scoped to your account in the database itself, by row level security, not by filtering in the browser. Another customer cannot read your rows even if they know their identifiers.

FloForge staff can reach the Personal Butler conversation you start, in order to answer it, and can see automation run outcomes across accounts in order to diagnose failures. Staff tooling does not read the configuration of your integrations, which is where API keys live.

Credentials for connected services

An API key or OAuth token you give FloForge for HubSpot, Make.com, Apollo, Apify or Firecrawl is encrypted before storage and is not readable afterwards through the application by anyone, including you. Disconnecting a service deletes the stored credential.

Those keys belong to your own accounts with those providers. FloForge does not use one shared account across customers.

Third parties that process data

Supabase hosts the database and authentication. Vercel serves the application. Stripe handles payment — card details go to Stripe directly and FloForge never receives them.

Services you connect yourself receive only what the feature you used sends them: a website address you asked Firecrawl to read, a search you asked Apollo to run, a record you asked an automation to push to HubSpot.

Getting your data out, and deleting it

Contacts, companies, leads and deals export to CSV from the Data page. An import can be undone from the import history.

Settings has a control that permanently deletes every record in your account. It asks first, tells you how many records will go, and cannot be undone afterwards.

To delete the account itself, message us through the Personal Butler.

Contact

Questions about any of this can go through the Personal Butler inside the product.

A postal address and registered business name still need to be added here before launch. FloForge has not invented one.