Flomatic AI
Privacy Policy
Effective Date: May 2, 2026 •
Last Updated: May 2, 2026
Application: AI Meeting Tracker (iOS and Android)
Operator: ALL ROYAL LLC, doing business as Flomatic AI
This Privacy Policy explains how ALL ROYAL LLC ("Flomatic AI," "we," "our," or "us") collects,
uses, discloses, and protects information when you use the AI Meeting Tracker mobile application
(the "App"). The App is an enterprise business tool distributed exclusively to authorized users
of organizations that have contracted with Flomatic AI. It is not available to the general public.
1. Who This Policy Applies To
This Policy applies to all users of the AI Meeting Tracker App. Access to the App is granted
exclusively by invitation through an enterprise or organizational account. If you are using the
App, your organization has entered into a separate agreement with Flomatic AI that may supplement
or supersede certain provisions of this Policy. Please review any agreement your organization
has signed with us.
The App is intended for use by individuals who are at least 18 years of age or the applicable
age of majority in their jurisdiction. We do not knowingly collect personal information from
anyone under 18. If we learn that we have collected personal information from a minor, we will
promptly delete it.
2. Information We Collect
2.1 Information You Provide Directly
- Account credentials: Username and password created or assigned by your organization's administrator.
- Business card data: Contact names, job titles, company names, email addresses, phone numbers, physical addresses, websites, and other information extracted from photographed business cards.
- Meeting notes: Text notes you type manually within the App.
- Meeting metadata: Lead classification (hot, warm, cold), priority level, follow-up flags, event names, associated distributors, and product information you assign to a lead.
- Email drafts: AI-generated and manually edited follow-up email drafts you create or approve within the App.
- Company profile information: Your organization's name, logo, and profile data entered in the settings.
2.2 Information Collected Automatically Through the App
- Audio recordings: Meeting conversation recordings captured through your device microphone when you explicitly initiate a recording session.
- Audio transcripts: Text transcripts generated from your audio recordings.
- Business card images: Photographs of business cards taken with your device camera or selected from your photo library.
- Contact photographs: Photos you take or select to associate with a contact record.
- Device contacts (optional): If you grant contacts permission, the App may read or write contact information to your device's address book when you explicitly save a business card contact.
2.3 Information Collected Automatically by Our Systems
- Usage data: Actions performed in the App (e.g., leads created, recordings started, emails sent), timestamps, and feature usage patterns for the purpose of service improvement and support.
- Device information: Device operating system and version, App version, and general device type, collected for compatibility and bug resolution purposes.
- Authentication tokens: Session tokens stored securely on your device using the platform's secure enclave (iOS Keychain / Android Keystore) to maintain your logged-in state.
2.4 Permissions Requested
| Permission |
Purpose |
Required |
| Camera |
Photograph business cards for AI extraction and capture contact photos |
Required for card scanning features |
| Microphone |
Record meeting conversations for AI transcription |
Required for recording features |
| Photo Library |
Select existing business card images or contact photos from your library |
Optional |
| Contacts |
Save extracted business card contacts to your device address book |
Optional |
You may deny any optional permission. Denying camera or microphone will disable the scanning
and recording features respectively, but the App remains functional for manual data entry and
reviewing existing records.
3. How We Use Your Information
- Service delivery: To operate the App, store your lead and meeting data, generate AI-assisted transcripts and email drafts, and enable follow-up workflows.
- AI processing: To transcribe audio recordings, extract contact data from business card images, generate follow-up email drafts, and classify or summarize meeting content using third-party AI models (see Section 5).
- CRM synchronization: To sync approved contact and lead data to your organization's Odoo CRM instance when you or your administrator enable this integration.
- Follow-up communication: To facilitate sending follow-up emails via Gmail or follow-up messages via WhatsApp Business when you explicitly initiate a send action.
- Service support: To diagnose technical issues and respond to support requests.
- Service improvement: To understand how features are used and improve the App's functionality. We do not use your individual meeting content or contact data to train third-party AI models without your explicit consent.
- Legal compliance: To comply with applicable laws, regulations, and legal process.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, we process
your personal data under the following legal bases:
- Contract performance: Processing necessary to provide the App and services under the enterprise agreement with your organization.
- Legitimate interests: Service improvement, security monitoring, and support operations, balanced against your privacy interests.
- Legal obligation: Compliance with applicable law.
- Consent: Where we rely on consent (e.g., optional device permissions), you may withdraw consent at any time by revoking permissions in your device settings, though this may affect certain App features.
5. Third-Party Service Providers
We share data with the following categories of third-party processors to operate the App. All
third-party processors are contractually bound to protect your data and may only process it as
directed by us.
5.1 Supabase
We use Supabase as our database and file storage provider. All lead data, contact records, meeting
notes, transcripts, audio recordings, and business card images are stored on Supabase-managed
infrastructure. Supabase is hosted on AWS infrastructure, predominantly in the United States.
See Supabase's privacy policy at supabase.com/privacy.
5.2 OpenAI
We use OpenAI's APIs for two purposes: (a) audio transcription of meeting recordings using
OpenAI Whisper, and (b) AI-assisted generation of follow-up email drafts and meeting summaries
using OpenAI GPT models. Audio data and text data submitted to OpenAI are subject to OpenAI's
API data usage policies. As of the effective date of this Policy, OpenAI does not use API
inputs to train its models. See openai.com/policies/privacy-policy.
5.3 Google AI (Gemini / Vision)
We use Google AI services to perform optical character recognition (OCR) on business card images
and to assist with contact data extraction. Business card images may be transmitted to Google's
APIs for processing. See policies.google.com/privacy.
5.4 Odoo CRM
If your organization has configured the Odoo integration, approved lead and contact data (name,
company, email, phone, notes) is synchronized to your organization's Odoo CRM instance. The
Odoo instance is operated by or on behalf of your organization. Data transmitted to Odoo is
governed by your organization's agreement with Odoo and their privacy terms.
5.5 WhatsApp Business API
When you explicitly send a follow-up message via WhatsApp, the recipient's phone number and
your composed message are transmitted through the WhatsApp Business API (operated by Meta
Platforms, Inc.). This transmission occurs only upon your deliberate action. Meta's data
practices are governed by their
WhatsApp Privacy Policy.
5.6 Gmail API
When you send a follow-up email through the App, we use the Gmail API to send the email on your
behalf using your authenticated Google account. We access only the send-email scope. We do not
read, store, or process the contents of your Gmail inbox. Your use of the Gmail integration is
subject to Google's
Privacy Policy.
6. Data Retention
We retain your personal data for as long as your organizational account is active or as needed
to provide the services. Specifically:
- Lead and contact records: Retained until you or your administrator deletes them, or until your organizational account is terminated.
- Audio recordings: Retained as stored files until deleted by you or your administrator. We recommend deleting recordings once transcription is confirmed.
- Transcripts and notes: Retained as part of the lead record until deleted.
- Account data: Retained for up to 30 days after account deletion to allow for recovery, then permanently deleted.
- Usage logs: Retained for up to 90 days for debugging and service monitoring.
- Legal hold: Data may be retained longer if required by law or active legal proceedings.
7. Data Security
We implement technical and organizational measures appropriate to the sensitivity of the data
we process, including:
- Encrypted data transmission over HTTPS/TLS for all App-server communications.
- Encrypted file storage for audio recordings and images at rest within Supabase.
- Authentication tokens stored using platform secure storage (iOS Keychain / Android Keystore).
- Role-based access controls limiting data access to authorized personnel only.
- Organizational accounts are isolated - one organization's data is not accessible to another.
No security system is impenetrable. In the event of a data breach that affects your personal
data, we will notify affected users and relevant authorities as required by applicable law.
8. International Data Transfers
ALL ROYAL LLC is incorporated in the United States. Your data may be processed and stored in
the United States and other countries where our third-party processors operate. If you are
located in the EEA or UK, transfers of your personal data outside of those regions are made
under appropriate safeguards, including Standard Contractual Clauses (SCCs) as approved by
the European Commission, or equivalent mechanisms where applicable.
9. Your Privacy Rights
9.1 For All Users
- Access and correction: You may view and edit your contact and meeting data directly within the App at any time.
- Account deletion: You may delete your account and all associated data from within the App's settings. See our Data Deletion Policy for full details on what is removed and the timeline.
- Permission revocation: You may revoke camera, microphone, photo library, or contacts permissions at any time through your device's system settings.
9.2 For EEA and UK Residents (GDPR / UK GDPR)
In addition to the rights above, if you are located in the EEA or UK, you have the right to:
- Data portability: Request a copy of your personal data in a structured, machine-readable format.
- Erasure ("right to be forgotten"): Request deletion of your personal data, subject to legal retention obligations.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests.
- Automated decision-making: Object to solely automated decisions that produce legal or similarly significant effects. Note that AI-generated content in this App (transcripts, email drafts) is always reviewed and approved by a human user before any action is taken.
- Lodge a complaint: You have the right to lodge a complaint with your local data protection authority.
To exercise these rights, contact us at info@flomatic.io.
9.3 For California Residents (CCPA / CPRA)
California residents have the right to know what personal information we collect, to request
deletion, to opt out of the "sale" of personal information (we do not sell personal information),
and to non-discrimination for exercising these rights. To make a verifiable consumer request,
contact us at info@flomatic.io.
10. Children's Privacy
The App is designed for use by business professionals and is not directed at children under
the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not
knowingly collect personal information from children. If you believe a child has provided
us with personal information, please contact us at info@flomatic.io
and we will promptly delete such information.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will
update the "Last Updated" date at the top of this page and, where feasible, provide notice
through the App or by email to your registered address. Your continued use of the App after
the effective date of a revised Policy constitutes your acceptance of the revised terms.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices,
please contact us:
ALL ROYAL LLC (d/b/a Flomatic AI)
Email: info@flomatic.io
Application: AI Meeting Tracker
For EEA/UK inquiries related to GDPR rights, please include "GDPR Request" in the subject line.
We will respond within 30 days.