Privacy Policy

Last updated: 2026-07-22

1. Who we are

This Privacy Policy describes how Flowly AI, operated by TOO Kenguru group (Кенгуру групп), registered at Zhibek Zholy 135, block 3, office 3101/2, 10th floor, Almaty, Kazakhstan ("we", "us", or "Flowly"), collects and processes personal data.

Data Protection Officer contact: flowlyaialmaty@gmail.com.

2. Data we collect

Account data: email address, password hash, name, billing information.

Instagram channel data (when you connect an Instagram Business Account via Meta Login):

Other channels (Telegram, WhatsApp): chat content, sender name and handle, media URLs, timestamps.

Usage data: request logs, IP addresses (for rate limiting), feature usage analytics.

3. Legal basis (GDPR Art. 6 / ZRK-152 RK)

4. Third parties with whom we share data

To operate the service, we transmit message content and related metadata to the following processors:

We do not sell personal data to third parties.

5. Cross-border data transfer

Flowly AI uses split hosting. The main public app, core API, authentication, billing, payment, and the databases used by those main services are hosted outside the Republic of Kazakhstan by DigitalOcean in Frankfurt am Main, Germany. Analytics, notifications, parser, WhatsApp, and Telegram-user services, including their service data stores, are hosted on a public GPU/application host in Almaty, Kazakhstan. For personal data transferred to infrastructure or processors outside Kazakhstan, including the DigitalOcean-hosted main services and the AI providers listed above, we obtain your explicit consent at registration in accordance with Law of the Republic of Kazakhstan No. 94-V "On Personal Data and Their Protection" (ZRK-152).

6. Retention

Chat history and other end-client data are retained for the period determined by the business user that controls the connected channel and are deleted or returned upon that user's request or when service provision ends. Account data is retained while your account is active and is deleted or anonymized within a technically reasonable period after account closure, unless retention is required by law. Audit records for data-deletion requests are retained indefinitely, as required under GDPR Article 5(2) accountability.

7. Your rights

Under GDPR and ZRK-152 RK, you have the right to:

To exercise any right, contact flowlyaialmaty@gmail.com.

8. Security

Passwords are stored hashed (Argon2 primary, bcrypt fallback). OAuth tokens are encrypted at rest. All network traffic uses HTTPS/TLS.

9. Cookies and similar technologies

The Service uses cookies and similar technologies to authenticate users, maintain sessions, remember preferences, ensure security, and collect anonymized usage statistics. Essential cookies are required for the Service to work. Non-essential cookies, if introduced, are used only with your consent through the cookie banner. You can manage cookies through your browser settings; disabling some cookies may limit Service functionality.

10. Changes to this policy

Material changes will be communicated by email to account holders. The "Last updated" date at the top of this page reflects the latest revision.

11. Contact

Questions or complaints: flowlyaialmaty@gmail.com.