This Privacy Policy explains how Flow Forge Inc., doing business as SynthralOS AI (“SynthralOS,” “we,” “us,” or “our”), collects, uses, discloses, stores, and protects information when you use our websites, applications, APIs, workflow builder, AI agents, integrations, automations, research tools, document-processing tools, browser automation tools, consulting services, and related products and services (collectively, the “Services”).
For Canadian operations, grants, local expenses, or Canada-specific services, SynthralOS Inc. may act as an affiliated service provider, operating entity, or support entity. Unless a contract, order form, invoice, or product notice states otherwise, the contracting entity for the Services is Flow Forge Inc.
This Privacy Policy is designed for business users and organizations. By using the Services, you acknowledge this Privacy Policy.
1. Summary
SynthralOS AI helps users build, operate, and manage AI-powered workflows, agents, research systems, integrations, automations, knowledgebases, and business processes.
Because of that, we may process:
- account and billing information;
- workspace and team information;
- business contact information;
- customer-provided content, files, records, messages, prompts, documents, datasets, URLs, outputs, workflows, and automation instructions;
- connected-app information from third-party integrations;
- logs, technical usage data, and security data;
- AI prompts, generated outputs, tool calls, and workflow execution traces;
- credentials, tokens, or secrets you choose to connect, subject to security controls;
- information collected or generated through web research, enrichment, scraping, monitoring, browser automation, OCR, or document processing features.
We use this information to provide, secure, improve, support, and operate the Services; process payments; communicate with users; comply with law; prevent abuse; and fulfill customer instructions.
We do not sell your Customer Content. We do not use your private Customer Content to train public foundation models unless you authorize it or your agreement specifically permits it.
2. Scope
This Privacy Policy applies to information processed through:
- SynthralOS AI website and landing pages;
- SynthralOS AI application and workspace;
- AI agents, agent teams, workflow builder, and workflow execution runtime;
- browser automation, website navigation, scraping, monitoring, and research tools;
- document scanners, OCR, RAG, knowledgebase, vault, and data extraction tools;
- integrations, OAuth connections, API-key connectors, and third-party app actions;
- subscription services, free trials, beta features, demos, DFY deployments, consulting, and support.
This Privacy Policy does not apply to third-party websites, applications, platforms, or services that we do not control.
3. Roles: Controller, Processor, and Service Provider
Depending on the context, SynthralOS may act as either:
3.1 Controller / Business
We act as a controller or business when we decide why and how personal information is processed, such as for:
- account creation;
- billing;
- security monitoring;
- product analytics;
- marketing communications;
- customer support;
- legal compliance;
- business administration.
3.2 Processor / Service Provider
We act as a processor or service provider when we process Customer Content on behalf of a customer according to the customer’s instructions, including when we:
- run workflows;
- process files or records;
- execute AI prompts;
- retrieve information from connected apps;
- automate tasks;
- enrich records;
- create reports;
- process knowledgebase documents;
- scan or extract information from websites or files.
Where required, our processing of Customer Content may be governed by a Data Processing Addendum (“DPA”) or other written agreement.
4. Information We Collect
4.1 Account Information
We may collect:
- name;
- email address;
- phone number;
- company name;
- job title;
- username;
- password or authentication information;
- workspace name;
- team membership;
- profile settings;
- communication preferences.
4.2 Billing and Transaction Information
We may collect or receive:
- billing name;
- billing email;
- billing address;
- subscription plan;
- invoices;
- payment status;
- tax information;
- transaction metadata.
Payment card details may be processed by third-party payment processors such as Stripe or other providers. We generally do not store full payment card numbers on our own systems.
4.3 Customer Content
“Customer Content” means information that you or your authorized users submit, upload, connect, import, instruct us to process, or generate through the Services.
Customer Content may include:
- prompts and instructions;
- AI agent tasks;
- workflow steps and outputs;
- documents, PDFs, spreadsheets, images, screenshots, and files;
- CRM records;
- lead lists;
- customer records;
- sales and marketing data;
- emails, messages, notes, and transcripts;
- business databases;
- scraped or researched web data;
- enrichment results;
- browser automation traces;
- OCR results;
- knowledgebase documents;
- API responses;
- connected-app content;
- logs, outputs, reports, and generated artifacts.
You are responsible for ensuring that you have the right to submit Customer Content to the Services and instruct us to process it.
4.4 Connected-App and Integration Data
If you connect third-party applications through OAuth, API keys, tokens, webhooks, or other integrations, we may process information from those connected services based on your configuration and permissions.
This may include:
- account identifiers;
- workspace identifiers;
- files;
- folders;
- messages;
- emails;
- calendar events;
- CRM records;
- tickets;
- tasks;
- contacts;
- sheets;
- databases;
- project records;
- metadata;
- permissions;
- API responses;
- action results.
Examples may include Gmail, Google Calendar, Google Drive, Slack, HubSpot, Salesforce, Notion, Airtable, GitHub, and other business tools.
We only request and use integration permissions that are reasonably needed to provide the connected functionality you enable, unless otherwise disclosed.
4.5 Credentials, Tokens, and Secrets
When you connect tools, APIs, accounts, or automation systems, we may store or process credentials, OAuth tokens, API keys, webhook secrets, or other authentication materials.
We use these only to provide the Services, execute your instructions, maintain integrations, secure accounts, and prevent unauthorized access.
You should not provide credentials unless necessary. You are responsible for managing access rights in the third-party services you connect.
4.6 AI Prompts, Outputs, and Execution Logs
We may process:
- prompts;
- system instructions;
- agent plans;
- tool calls;
- intermediate reasoning traces where stored by the system;
- generated outputs;
- workflow execution logs;
- retries;
- errors;
- approval history;
- version history;
- audit trails;
- human-in-the-loop decisions.
We use this information to operate, debug, secure, improve, and audit the Services.
4.7 Web Research, Scraping, Monitoring, and Browser Automation Data
When you use research, scraping, monitoring, enrichment, or browser automation features, we may process:
- URLs;
- webpages;
- page titles;
- HTML;
- screenshots;
- rendered page content;
- search queries;
- search results;
- extracted entities;
- structured data;
- public business information;
- browser actions;
- cookies or session data where you provide or authorize them;
- evidence logs;
- source metadata;
- “not found” or error records.
You are responsible for ensuring that your use of these features complies with applicable law, website terms, platform policies, robots.txt where applicable, intellectual property rights, privacy rights, anti-spam rules, and data protection obligations.
4.8 Device, Usage, and Technical Information
We may collect:
- IP address;
- browser type;
- device type;
- operating system;
- referring URL;
- pages viewed;
- features used;
- session events;
- timestamps;
- approximate location based on IP;
- log files;
- error reports;
- performance data;
- diagnostics;
- security events.
4.9 Cookies and Similar Technologies
We may use cookies, pixels, local storage, SDKs, and similar technologies to:
- keep you logged in;
- remember preferences;
- secure sessions;
- analyze usage;
- improve performance;
- measure marketing effectiveness;
- prevent abuse.
You can control cookies through your browser settings. Some features may not work properly without certain cookies.
4.10 Communications
If you contact us, we may collect:
- name;
- email address;
- phone number;
- company information;
- message content;
- support tickets;
- call notes;
- chat messages;
- feedback;
- attachments.
4.11 Marketing and Sales Information
We may collect business contact information from you, public sources, referrals, events, partners, or third-party data providers, such as:
- name;
- work email;
- company;
- role;
- business website;
- LinkedIn profile;
- business phone number;
- industry;
- company size;
- lead source;
- sales notes.
We use this information for B2B marketing, sales, account management, and customer relationship management, subject to applicable law.
5. Sensitive Information
The Services are not designed for unnecessary processing of highly sensitive personal information.
You should not submit sensitive information unless it is necessary for your authorized use case and you have the right to do so. Sensitive information may include:
- government identification numbers;
- financial account numbers;
- health information;
- biometric information;
- precise geolocation;
- children’s information;
- racial or ethnic origin;
- religious or philosophical beliefs;
- political opinions;
- union membership;
- sex life or sexual orientation;
- criminal history.
If your use case requires sensitive data processing, you are responsible for ensuring appropriate consent, legal basis, safeguards, and contractual terms are in place.
6. Children
The Services are intended for business users and are not directed to children. We do not knowingly collect personal information from children under 13 or the equivalent minimum age under applicable law.
If you believe a child has provided personal information to us, contact us and we will take appropriate steps to delete it.
7. How We Use Information
We may use information to:
- provide, operate, maintain, and improve the Services;
- create and manage accounts;
- authenticate users;
- process subscriptions and payments;
- run workflows, agents, automations, research tasks, OCR jobs, browser actions, and integrations;
- generate outputs, reports, structured data, artifacts, workflows, knowledge objects, and other results;
- provide customer support;
- debug, monitor, and improve performance;
- detect, prevent, and respond to fraud, abuse, security incidents, and misuse;
- maintain audit logs and compliance records;
- communicate product updates, administrative messages, and support notices;
- send marketing communications where permitted;
- personalize product experiences;
- conduct analytics and product research;
- enforce agreements and policies;
- comply with legal obligations;
- protect the rights, safety, and property of SynthralOS, our users, and others.
8. AI Systems and Model Providers
SynthralOS may use proprietary models, third-party AI models, open-source models, hosted model providers, embedding providers, vector databases, OCR tools, web research systems, browser automation engines, and related infrastructure to provide the Services.
When Customer Content is sent to a model provider or processing vendor, we use it to fulfill your instructions and provide the Services.
Unless your agreement states otherwise, we do not authorize third-party model providers to use your private Customer Content to train their public foundation models.
You acknowledge that AI outputs may be inaccurate, incomplete, outdated, biased, or unsuitable for your specific purpose. You are responsible for reviewing outputs before relying on them.
9. Legal Bases for Processing
Where required by law, we rely on one or more legal bases, including:
- performance of a contract;
- consent;
- legitimate interests;
- compliance with legal obligations;
- protection of rights and security;
- your instructions as a customer or administrator;
- another lawful basis available under applicable law.
Our legitimate interests may include providing and improving the Services, securing the platform, preventing abuse, conducting B2B marketing, supporting customers, and operating our business.
10. How We Share Information
We may share information with:
10.1 Service Providers and Subprocessors
We may share information with vendors that help us provide the Services, such as:
- cloud hosting providers;
- database providers;
- AI model providers;
- payment processors;
- analytics providers;
- email and communication providers;
- error monitoring providers;
- customer support tools;
- security tools;
- authentication providers;
- integration providers;
- workflow infrastructure providers;
- data processing vendors.
These vendors are authorized to process information only as needed to provide services to us, unless otherwise permitted by law or your agreement.
10.2 Third-Party Integrations You Enable
If you connect a third-party application, we may send, receive, modify, retrieve, or delete information from that application according to your settings, permissions, and workflow instructions.
Third-party integrations are governed by their own terms and privacy policies.
10.3 Workspace Administrators
If you use the Services as part of an organization, workspace administrators may access information about your account, usage, workflows, Customer Content, logs, permissions, and outputs.
10.4 Affiliates
We may share information with affiliates, including SynthralOS Inc., for business operations, support, Canadian operations, grant administration, accounting, customer support, or service delivery.
10.5 Business Transfers
We may disclose information in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, due diligence process, or similar transaction.
10.6 Legal and Safety Reasons
We may disclose information if we believe it is necessary to:
- comply with law;
- respond to legal process;
- protect rights, safety, or property;
- enforce agreements;
- prevent fraud, abuse, or security incidents;
- investigate misuse;
- protect users or the public.
10.7 With Your Consent or Instructions
We may share information when you direct us to do so or otherwise consent.
11. Data Sales and Targeted Advertising
We do not sell Customer Content.
We do not use Customer Content for cross-context behavioral advertising.
We may use limited website cookies or marketing tools to understand website traffic and improve marketing. Where required, we will provide appropriate choices or consent mechanisms.
12. Data Retention
We retain information for as long as reasonably necessary to:
- provide the Services;
- maintain your account;
- fulfill the purposes described in this Privacy Policy;
- comply with legal, tax, accounting, and contractual obligations;
- resolve disputes;
- enforce agreements;
- maintain security and audit records;
- improve and debug the Services.
Customer Content retention may depend on your plan, workspace settings, deletion requests, backup cycles, legal holds, and contractual terms.
We may retain logs, metadata, backups, and security records for a limited period after deletion where necessary for security, continuity, compliance, or fraud prevention.
13. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, loss, misuse, or destruction.
Safeguards may include:
- access controls;
- authentication;
- encryption in transit;
- encryption at rest where appropriate;
- permission management;
- logging and audit trails;
- monitoring;
- vulnerability management;
- secure development practices;
- vendor review;
- separation of environments;
- least-privilege access principles.
No system is perfectly secure. You are responsible for maintaining the confidentiality of your login credentials, API keys, OAuth connections, connected accounts, and workspace permissions.
14. International Transfers
We may process and store information in Canada, the United States, and other jurisdictions where we or our service providers operate.
These jurisdictions may have data protection laws different from those in your location. Where required, we use appropriate safeguards for international transfers, such as contractual protections, data processing agreements, standard contractual clauses, or other lawful mechanisms.
15. Your Privacy Choices and Rights
Depending on your location and applicable law, you may have rights to:
- access personal information;
- correct inaccurate information;
- delete personal information;
- restrict or object to processing;
- withdraw consent;
- request portability;
- opt out of certain marketing communications;
- opt out of certain sale, sharing, or targeted advertising activities where applicable;
- file a complaint with a privacy regulator.
To exercise rights, contact us using the details below. We may need to verify your identity and authority before responding.
If your information is contained in Customer Content controlled by one of our customers, we may direct you to that customer.
16. Canadian Privacy Rights
If you are in Canada, you may request access to personal information we hold about you and request corrections where appropriate.
You may also contact us with questions about our privacy practices or challenge our compliance with this Privacy Policy.
We will respond in accordance with applicable Canadian privacy laws.
17. European, UK, and Similar Privacy Rights
If you are in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with similar rights, you may have additional rights under applicable data protection laws, including rights to access, correction, deletion, objection, restriction, portability, and complaint to a supervisory authority.
Where we rely on consent, you may withdraw consent at any time, without affecting processing that occurred before withdrawal.
Where we process personal data on behalf of a customer, that customer may be the controller and we may act as processor.
18. California and U.S. State Privacy Rights
If applicable state privacy laws apply to us, residents of those states may have rights to:
- know what personal information we collect, use, disclose, or share;
- access personal information;
- correct inaccurate personal information;
- delete personal information;
- opt out of sale or sharing of personal information;
- limit certain uses of sensitive personal information;
- not be discriminated against for exercising privacy rights.
We do not sell Customer Content. We do not knowingly sell or share personal information of children under 16.
To exercise privacy rights, contact us using the details below.
19. Marketing Communications
You may unsubscribe from marketing emails by using the unsubscribe link or contacting us. We may still send transactional or administrative messages, such as billing, security, account, and service notices.
20. Third-Party Services
The Services may link to or integrate with third-party services. We are not responsible for the privacy practices, security, content, or policies of third-party services.
Your use of third-party services is governed by their terms and privacy policies.
21. Customer Responsibilities
Customers are responsible for:
- obtaining necessary rights, notices, and consents for Customer Content;
- configuring permissions appropriately;
- managing users and workspace access;
- ensuring connected apps are authorized;
- complying with applicable privacy, data protection, anti-spam, intellectual property, scraping, employment, consumer protection, and sector-specific laws;
- reviewing AI outputs before use;
- avoiding submission of unnecessary sensitive information;
- honoring individual rights requests relating to Customer Content.
22. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Services, by email, or by other reasonable means.
The “Last updated” date indicates when this Privacy Policy was last revised.
23. Contact Us
For privacy questions, requests, or complaints, contact:
Flow Forge Inc. d/b/a SynthralOS AI
1111B S Governors Ave #42731
Dover, DE 19904
United States
Email: legal@synthralos.ai
Privacy contact
Flow Forge Inc. d/b/a SynthralOS AI
1111B S Governors Ave #42731
Dover, DE 19904
United States