Floot procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Your account data, project content, uploaded files, and the databases of apps built on Floot are stored in the United States (Amazon Web Services and Neon, us-east-1 region). Some processing may occur outside the United States: content delivery network edge caches serve cached copies of published apps and public files from locations worldwide, and AI providers may process requests in other regions. We ensure appropriate safeguards are in place for these transfers.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Permanently store any web page content, screenshots, or sensitive values” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Inactive free accounts. If an account has never had a paid plan and has had no activity for 12 months — no sign-in, no use of the Floot builder, and no use through a connected AI assistant — we may delete it, together with its projects, their databases and uploaded files. Before doing so we email the account's address twice, 30 days and 7 days before the deletion date. Signing in at any point before that date keeps the account. Accounts that have ever had a paid plan, and accounts with a published app that is still receiving visitors, are not deleted for inactivity. Deletion follows the same process as closing your account yourself.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Analytics data — PostHog events are retained per PostHog's configured retention period; published-app visitor analytics (Tinybird) are retained for 12 months.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Changes made to your projects, uploaded assets, and the project chat history entries describing them persist as part of your project until you delete them or the project.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Project history — successful operations that modify your project are summarized into your project's chat history (e.g., "edited file X", "published the app") so you and your collaborators can see what the assistant changed. These records persist as part of the project.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Operational logging — each tool call is recorded in a short-lived operation log (tool name, a summary of arguments, project, account, client application, status, result or error text, and timing) used to report job status back to your assistant and to debug failures.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ To request deletion of any Google user data, contact us at the addresses listed in the Contact section; we respond within 7 business days.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ When you disconnect a Google account from an app, its stored tokens are deleted and the app can no longer access your Google data. Deleting your Floot account removes all stored tokens.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Account information is retained while your account is active and deleted or anonymized after account deletion, except where we must retain it to comply with legal obligations.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Upon any termination, discontinuation, or cancellation of Services or your Floot, Inc account, the following provisions of these Terms will survive: Service Terms, Charges and Payment (to the extent you owe any fees at the time of termination); Confidentiality; provisions related to permissions to access Customer Data (to the extent applicable); Warranties and Disclaimers; Indemnity; Limitations of Liability; Termination; and the Miscellaneous provisions. Furthermore, we may remove or delete your Customer Data within a reasonable period of time after the termination or cancellation of Services or your Floot, Inc account.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Floot stores only the OAuth tokens needed to keep your Google connection active, encrypted at rest. Your Google content (emails, calendar events, Drive files) is processed transiently to serve each request and is not copied to Floot's own storage.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ In the event of any loss or corruption of any data associated with a Subscription, Floot, Inc will use commercially reasonable efforts to restore the lost or corrupted data from the latest relevant backup maintained by Floot, Inc. EXCEPT FOR THE FOREGOING, FLOOT, INC WILL NOT BE RESPONSIBLE FOR ANY LOSS, DESTRUCTION, ALTERATION, UNAUTHORIZED DISCLOSURE OR CORRUPTION OF ANY DATA.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ Per-call operation logs are automatically deleted 3 days after their last update.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ You may cease use of the Services at any time. If you are paying for a Subscription, you may cancel your Subscription through the process detailed earlier. You may also request to delete your Floot, Inc account at any time by sending an email to feedback@floot.com . Upon cancellation or termination of your account, all unused credits are forfeited.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Application and platform logs are retained for 90 days (published-app backend logs and Floot platform logs) and 30 days (CDN edge logs); preview-environment request captures used by the assistant's debugging view expire after 1 hour. Log records cannot be selectively deleted before they expire.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ MCP tool-call operation logs (see "AI Assistant Connections (MCP)" below) are automatically deleted 3 days after their last update.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Payment records are retained as required by tax and accounting law.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Analytics events are retained per the "Data Retention" section above.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Project content (code, prompts, chat history, uploaded assets) is retained until you delete the project or your account, or until the account is deleted for inactivity as described below.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ You connect an AI assistant to Floot through an OAuth authorization flow (you approve the connection while signed in to your Floot account) or, for some developer tools, through an API key you create. The assistant then acts with the permissions of your Floot account.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ For the avoidance of doubt, Floot, Inc may engage third parties as service providers to the Services (for example, Floot, Inc may use third party data hosting providers).” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Email delivery — Amazon SES (Amazon Web Services) delivers our emails (sign-in links, notifications, product updates) to your email address.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Floot provides a Model Context Protocol ("MCP") server that lets you connect third-party AI assistants — such as ChatGPT, Claude, and AI coding agents — to your Floot account so they can build and manage Floot projects on your behalf. This section describes exactly what data flows through that connection.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Security and fraud prevention — Cloudflare Turnstile is used for bot protection on some requests. Fingerprint generates a device identifier for signed-in accounts, used only to detect duplicate accounts and abuse of free credits and referral rewards.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We share data with trusted service providers only as needed to operate the platform. The categories of recipients are:” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Some of the models we use (such as GLM and Kimi) are open weight models operated for us by independent inference infrastructure providers (currently Fireworks AI and Baseten) within their isolated serving infrastructure. Your data is processed there solely to generate the response and is never transmitted to the model developers (such as Z.ai or Moonshot AI) for training or any other secondary purpose.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Document and image understanding features may use Google's Gemini API, and apps configured with their own AI resources may use the Anthropic or OpenAI APIs, in all cases via commercial API terms that exclude training on your data.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Payments — Stripe processes payments. We do not store your full card details.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ We do not transfer or disclose Google user data to third parties for purposes other than the ones described in this section. The only transfers are: (a) to the data processors named in "AI Processing of Google User Data" below, strictly to deliver the app feature you invoked; (b) where necessary for security purposes, such as investigating abuse; (c) to comply with applicable law or a legal process; or (d) as part of a merger, acquisition, or sale of assets, in which case you will receive prior notice of any change in how your Google user data is handled.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ When our extensions capture data from a web page, that data is sent to the Floot web app and handled in accordance with this privacy policy. Where applicable, it may be shared with AI service providers to process your request. The extensions themselves do not send data to any third party.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Analytics — we send an event per completed tool call to our analytics provider (PostHog) containing the tool name, success/failure status, duration, client application name, and project identifier — not the full tool arguments or file contents.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ AI model providers — when you use AI features (generating or editing code, chat, planning, image generation), your prompts, relevant project files, and related context are sent to the AI providers that power those features, including Anthropic, OpenAI, Google, Cerebras, Amazon Bedrock, Fireworks AI, Baseten, and Fal. These providers process the data to generate responses on our behalf. Google user data is sent to an AI provider only when you invoke an app feature that operates on that data, solely to generate the response you requested (see "AI Processing of Google User Data" below).” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Cloud infrastructure and hosting — Amazon Web Services (compute, storage, content delivery) hosts project files, uploaded assets, and published apps. Neon hosts the databases of apps built on Floot. Render hosts Floot's own platform database (account and project metadata, builder chat history).” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ The Services may contain features designed to interoperate with your, or a third party's, web-based, mobile, or other software application that is made available by you or your Authorized Users (" Connected Applications") . To use such features, your or your Authorized Users may be required to obtain access to such Connected Applications from their providers, and grant Floot, Inc access to you or your Authorized Users' account(s) on such Connected Applications. If you use a Connected Application with the Services, you grant Floot, Inc permission to allow the Connected Application and its provider to access Customer Data solely as required for the interoperation of that Connected Application with the Services. Any acquisition by you of Connected Applications, and any exchange of Customer Data between you and any Connected Application provider, product or service, is solely between you and the applicable Connected Application provider. Floot, Inc does not warrant or support Connected Applications. Floot, Inc is not responsible for any disclosure, modification or deletion of Customer Data resulting from access by any Connected Application or its provider. You are solely responsible for ensuring that it has all necessary licenses and rights to use the Connected Application for the purposes contemplated herein.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Logging and monitoring — Datadog receives Floot's platform logs (error and operational logs from Floot's own services), retained for 90 days. Logs from apps built on Floot stay in Amazon CloudWatch for 90 days and are not sent to Datadog; they contain what your app's code writes to its logs plus the request method and path, and do not include request or response bodies, headers, cookies, or IP addresses. Amazon CloudFront edge logs for published apps record only a tenant identifier, response size, status, and cache result — no IP address, cookie, user-agent, or query string — and are retained for 30 days for bandwidth billing.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ MCP data is shared only with the service providers listed in "Third-party Service Providers" above (infrastructure, analytics, and — for image generation — AI model providers), and, by design, with the AI assistant provider you connected, which receives all tool outputs.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Advertising and affiliate measurement — to learn which campaigns bring people to Floot, we share sign-up, checkout and purchase events with Google Ads and Meta, both from your browser (their cookies and pixels) and from our servers. These events can include a hashed version of your email address, your IP address and browser user-agent, the advertising click identifier you arrived with, and the value of a purchase; Google and Meta also use them to build advertising audiences. FirstPromoter, our affiliate platform, receives the email address of a sign-up and purchase amounts when you arrived through an affiliate's link, so the affiliate can be credited. Stape hosts the tagging server (sumo.floot.com) these events pass through, as a processor on our behalf. For visitors in the European Economic Area, the United Kingdom and Switzerland, none of this happens unless you accept marketing cookies; elsewhere you can opt out by contacting feedback@floot.com. Google user data obtained through Floot's Google integrations is never shared with advertising partners.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ In response to tool calls, we return data from your account to your AI assistant, which may include: project file contents and file listings, results of database queries and your database schema, application logs and error output, type-check and test results, screenshots of your app preview, preview and published app URLs (which may include access tokens scoped to the project), generated images, resource and job status information, and summaries of operations performed.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Analytics — PostHog receives usage events (feature usage, page views, tool-call metadata) associated with your account identifier, and session recordings. Google Analytics receives page views and site events from floot.com. Tinybird receives visitor analytics from apps published on Floot (see "Analytics and Tracking" above), associated with your published app's domain; these events never include IP addresses. Google user data is never included in analytics events.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Apps published on Floot include built-in visitor analytics (the Analytics tab in your project), processed by Tinybird. For each page view of your published app it records a random session identifier (by default kept in the browser's localStorage on your app's domain with a 30-minute sliding expiry; it does not use cookies), the page path, the referring page, the browser's user-agent and language, and a country derived from the browser's timezone. It does not record IP addresses or the query string of the URL. This data is retained for 12 months. If your app serves users in jurisdictions that require consent for analytics storage, you are responsible for obtaining it; the tracker provides a consent API (window.flootAnalytics.setMode) for your app's banner, and the project can be set to keep the identifier in memory only (nothing stored on the device) or to disable the analytics entirely.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Google user data is never sold, and is never transferred to advertisers, data brokers, or information resellers.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ This data is sent to the Floot web app and may be processed by our AI service providers as part of your workflow.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We use PostHog for product analytics on floot.com and in the Floot builder, including session recordings that replay how pages and the builder are used (password fields are never recorded). We also use Google Analytics to measure site traffic. Where analytics cookies are off (see "Cookies and Tracking Technologies" below), PostHog still counts visits but stores nothing on your device and records no sessions.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Requests are routed through Floot's own AI gateway to inference providers acting as our data processors, solely to generate the response you requested.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Anything returned to your AI assistant becomes part of your conversation with that assistant and is thereafter handled under that provider's privacy policy (for example, OpenAI's policy for ChatGPT or Anthropic's policy for Claude). Please review your assistant provider's policy for how they store and use conversation data.” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ Active Subscription Required to Purchase. Purchasing additional hosting credits (including via auto-reload) and receiving any monthly hosting allowance included with your subscription require an active paid subscription. Hosting credits already on your account — including any complimentary lifetime credit granted on signup and any credits you previously purchased — remain available to consume even without a paid subscription, subject to the expiration date that applied when they were granted or purchased.” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ Certain Services are offered under different pricing plans, the limits and features of which are available at floot.com/pricing. Your rights and obligations with respect to certain Services will be based in part on the pricing plan you choose.” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ You may choose to use Beta Services in its sole discretion. Notwithstanding anything to the contrary in these Terms or otherwise: (a) Beta Services may not be supported and may be changed or terminated at any time without notice; (b) Beta Services may not be as reliable or available as the Services; (c) Beta Services have not been subjected to the same security requirements, measures, and auditing as the Services; (d) Beta Services constitute Floot, Inc’s Confidential Information; and (e) BETA SERVICES ARE PROVIDED “AS IS” WITHOUT ANY WARRANTY, INDEMNITY OR SUPPORT AND FLOOT, INC’S LIABILITY FOR BETA SERVICES WILL NOT EXCEED FIFTY DOLLARS (US $50). For purposes of these Terms, “Beta Services” means services or features identified as “alpha,” “beta,” “preview,” “early access,” or “evaluation,” or words or phrases with similar meanings.” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ To cancel, you can either (i) initiate a cancellation through your Floot, Inc account settings within the Services or (ii) email us at feedback@floot.com with your cancellation request. You will be responsible for all Subscription Fees incurred for the then-current Subscription period. Canceling your Subscription will not terminate your Floot, Inc account. See Termination below for information on terminating your Floot, Inc account.” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ To upgrade or downgrade your Subscription to a different product plan, you can either (i) initiate the upgrade or downgrade through your Floot, Inc account settings within the Services or (ii) email us at feedback@floot.com with your request. Floot, Inc reserves the right to automatically downgrade your Subscription to a free user plan if you have any unpaid Subscription Fees. ” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ We may terminate your access to and use of the Services, at our sole discretion, at any time and without notice or liability to you, provided that if Floot, Inc freezes your account or cancels your Subscription and the termination is not due to your breach of these Terms, Floot, Inc will provide you a pro rata refund of pre-paid unused Subscription fees unless, in our reasonable estimation, we are not legally permitted to do so (in which case any refund rights are null and void). Notwithstanding the foregoing, all unused credits are immediately forfeited upon termination and no refund or credit will be provided for unused credits.” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ You may cancel your Subscription at any time but please note that such cancellation will only be effective at the end of the then-current Subscription period. Unless required by law, YOU WILL NOT RECEIVE A REFUND OF ANY PORTION OF THE SUBSCRIPTION FEE PAID FOR THE THEN-CURRENT SUBSCRIPTION PERIOD AT THE TIME OF CANCELLATION.” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.