Last updated: 2026-06-16

Privacy Policy

How QualifAI collects, uses, and protects your data.

Flow-Forges (“we”, “us”, “our”) describes in this document how it collects, uses, and protects information from users of QualifAI. Using the service constitutes agreement to the practices outlined.

1. Data We Collect

  • Account information — name, email, company name, and a hashed password.
  • Client configuration — persona, qualification questions, scoring thresholds, follow-up sequences, and Twilio number settings.
  • Lead data — phone numbers, names, email addresses, budget, timeline, scores, and conversation transcripts. This belongs to you; we process it on your behalf.
  • Usage data — page views, API calls, error logs, and timestamps.
  • Billing metadata — payment references, plan tier, activation timestamps. Full card or bank details are never stored; XflowPay handles payment processing.

2. SMS Communications

  • Consent — Leads consent to receive SMS messages by initiating contact: either texting a business's Twilio number first, or submitting a web form that explicitly discloses they will receive SMS replies. We never send unsolicited text messages. Inbound consent is logged with timestamp and IP for compliance.
  • What to expect — Depending on the business's configuration, leads may receive: qualification questions (asked one at a time), booking confirmations, and appointment reminders. A typical conversation consists of 1–6 messages.
  • Opt-out — Reply STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, or QUIT at any time to immediately stop all messages. Reply HELP or INFO for support contact details. Opt-out requests are processed instantly and are permanent for that conversation.
  • Phone numbers — Phone numbers are used solely for SMS communication between the lead and the specific business they contacted. Numbers are never sold, shared across businesses, or used for third-party marketing.
  • Message and data rates — Standard message and data rates may apply per the lead's mobile carrier plan.

3. How We Store Data

Data resides in Supabase Postgres with row-level security (RLS). Encryption covers data at rest and in transit (TLS 1.2+). Backups kept for 30 days. We do not sell, rent, or share your data with third parties for marketing purposes.

4. Sub-processors

  • Twilio — SMS messaging
  • Anthropic (Claude) — qualification & scoring
  • DeepSeek — inference
  • Supabase — Database, auth, real-time
  • Ollama — Local model (self-hosted)
  • XflowPay — Bank transfer payments
  • Vercel / Hetzner — Hosting

5. Data Retention

Account and lead data is kept for the duration of an active subscription plus 90 days after cancellation, then permanently deleted — unless earlier deletion is requested or longer retention is legally required. Logs may be kept non-identifiably for up to 12 months.

6. Your Rights

  • Access — obtain a copy of your personal data
  • Rectification — correct inaccurate data
  • Deletion — request erasure of your data
  • Portability — receive data in a structured format
  • Object — object to processing for marketing
  • Withdraw consent — at any time

Send requests to privacy@flow-forges.com. We respond within 30 days.

7. GDPR & CCPA

For EEA/UK/CH users, Flow-Forges acts as a data processor for lead data and data controller for account information. Legal bases: contract performance and legitimate interests.

California residents have rights to know, delete, and opt out of sale of personal information. We do not sell personal information. Exercise rights via privacy@flow-forges.com.

8. Security & Changes

Industry-standard practices: TLS encryption, bcrypt hashed passwords, service-role isolation, RLS, least-privilege access. No system is perfectly secure — contact us if you suspect a breach.

Policy updates are notified by email at least 14 days before taking effect.

© 2026 FlowForges. All rights reserved.