Privacy Policy
Effective date: June 26, 2026 ยท Last updated: July 8, 2026
FloresAI (“we,” “us,” “FloresAI”), operated by Danian Flores as a sole proprietor, provides a security-first AI service that helps businesses capture and respond to inbound leads. This policy explains what data we handle, why, and your choices.
Our role
- For visitors to our website and people who contact us directly, we are a data controller.
- For mailbox or WhatsApp message data we process on behalf of a client business, we act as a data processor following the client's instructions. The client is the data controller. A Data Processing Agreement (DPA), where applicable, governs that relationship.
Information we process
From a client's connected mailbox or WhatsApp Business number (as processor):
- Inbound email or WhatsApp message content, sender details (email address or phone number), subject/timestamps, attachments, and message/thread identifiers needed to classify leads and generate responses.
- Metadata about automated processing, including intent, confidence scores, workflow decisions, model version, actions taken, and reviewer information where applicable.
From our website or direct communications (as controller):
- Information you voluntarily provide, such as your name, email address, and message.
- Basic website analytics and essential cookies, where enabled.
We do not sell personal information or customer mailbox data, and we do not use customer mailbox data for advertising.
How we use information
- To classify inbound messages and generate AI-assisted draft responses.
- To send responses only when a client has explicitly enabled automated sending.
- To maintain audit logs for security, troubleshooting, accountability, and explaining automated decisions.
- To operate, secure, maintain, and improve the service.
- To improve prompts, SOPs, workflow templates, automation logic, and other product features. We do not use customer mailbox data to train our own machine learning models.
Google user data — Limited Use
Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. We access only the Google API data reasonably necessary to provide the features a client enables. We do not sell Google user data or use it for advertising. Human access to mailbox content occurs only when authorized by the client or when reasonably necessary for customer support, security, abuse prevention, or legal compliance.
WhatsApp / Meta Platform data
Our use of the WhatsApp Business Platform complies with Meta’s WhatsApp Business Messaging Policy. We only access WhatsApp message data needed to provide the lead-response feature for a client that has connected a WhatsApp Business number, and every reply is a draft requiring human review before it sends unless a client has explicitly enabled automated sending for that message type.
Sub-processors
- Google LLC — Gmail API, for clients using the email channel.
- Meta Platforms, Inc. — WhatsApp Business Platform, for clients using the WhatsApp channel.
- Anthropic, PBC — Claude API for AI inference and response generation.
- Microsoft Azure — application hosting, Azure Key Vault, logging, and secure data storage.
Where data is processed
Our primary infrastructure operates within Microsoft Azure in the United States. Google, Meta, and Anthropic may process information as necessary to provide their services under their respective terms and privacy commitments.
Security
We use technical and organizational safeguards designed to protect customer information, including TLS encryption in transit, logical tenant isolation, least-privilege access controls, secure secret management using Azure Key Vault, audit logging, and dependency and security scanning.
Retention
- Audit records: retained for up to 18 months.
- Tamper-evident audit copy: alongside the audit records above, we maintain a separate, tamper-evident copy of the same events for each client, retained for the same 18 months. We may, at our discretion and on a per-client basis, lock this copy against early deletion; where a client's copy is locked, it cannot be deleted early โ including by us โ until the 18-month period naturally expires, even if a deletion request is made in the meantime.
- Processing-state records: retained for up to 90 days.
- WhatsApp draft/review records: once a draft reaches a final state (approved, rejected, sent, or expired), retained for up to 90 days.
- Gmail draft replies (temporary): when the AI drafts a reply for an email client, we retain a short-lived copy of that draft so that, if a human edits it before sending, we can identify the type of edit made. This copy is deleted as soon as that comparison occurs, and in any case no later than 14 days after the draft was created.
- Customer data: deleted within 30 days after a client's deletion request or account termination unless a longer retention period is required by law or contract.
Your choices
If applicable law provides you with privacy rights regarding information we process as a data controller, you may contact us to request access, correction, or deletion of your information. For mailbox data processed on behalf of a client, requests should generally be directed to the applicable client, who acts as the data controller.
Security incidents
If we become aware of a security incident affecting customer information, we will notify affected clients as appropriate and consistent with our contractual obligations and applicable law.
Children
FloresAI is intended for business use and is not directed toward children under 16 years of age.
Changes
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page.
Contact
FloresAI — Danian Flores
Email: danian.flores@floresai.io
Governing law: State of Texas, United States