flo.space
Security & privacy

The stance, written down

Read only to start, a human approval before anything acts, and a record of everything after. This page is the whole position, numbered so you can hold us to it.

01

The model

flo.space is built so the dangerous step cannot happen on its own. Connections begin with read only scopes. Before anything can act, two separate things must be true: you granted the connection permission to write, and a person approved that specific action. There is no autopilot mode to switch on, and nothing sends itself.

  • Read only to start
  • Human approval on every action
  • Full audit trail
02

What flo.space reads and keeps

flo.space reads the tools you connect in place: the threads, sheets, and files where your work already lives. What it keeps is the working context needed to prepare actions. The queue proposes from live activity rather than history, so connecting does not trigger a scrape of your archives, and a quiet inbox produces a quiet queue.

03

How AI processing works

Drafting and reasoning run on Google's Gemini API. Data sent for processing is handled under Google's API Services User Data Policy, including its Limited Use requirements. The privacy policy describes this processing in the binding language.

04

Encryption, plainly

Data moving between your browser, flo.space, and your connected tools is encrypted in transit. Where a stronger claim is not written on this page, we have not made it: security promises here are ones we can stand behind today, and the list will grow the honest way.

05

Access and roles

Access follows roles. The Owner manages connections, seats, approval rules, and billing. Managers review and approve for their own team. Reps prepare and submit, and approve within the limits set for them. Seats can be scoped per tool, so a bookkeeper's seat can see finance actions without reading sales threads. Deactivating a seat revokes its access in one click and reassigns its pending work.

06

Disconnecting and deletion

Revocation works from either side, instantly: disconnect a tool in flo.space settings, or remove flo.space from the provider's own security page. Reading stops immediately, and pending actions that depended on the tool are cancelled rather than silently executed.

Working context from a disconnected tool is deleted within 30 days, as the privacy policy sets out. The audit trail keeps its historical record of actions that actually executed, because an audit trail that forgets is not one.

07

The audit trail

Every action is logged with its full life: the sources read, the draft, the reasoning and risk level, every edit, the human decision with who and when, and the exact result the target tool returned. Declined actions are kept too. Nothing that executed can be deleted from the record, and the workspace owner can read and export all of it.

08

Questions and the binding documents

This page is the readable version. The binding versions are the privacy policy, the terms of service, and the early access terms. If something here is unclear, or you need an answer in writing before connecting anything, email hello@flo.space and a person will reply.