Legal

Privacy Policy

Last updated: 2026-06-23

1. Who we are

42flows is an autonomous AI service that researches a customer's business, publishes SEO-optimized content to the customer's website, optimizes existing pages for search and AI answer engines, and tracks performance. Service is operated by:

  • For customers in India: Goforce Pvt Ltd., India.
  • For customers outside India: Goforce Inc., Wyoming, USA.

Contact for privacy questions: [email protected].

2. What data we collect

2.1 Account data

When you sign up, we collect your name, company name, email address, billing country, selected launch plan, payment-provider route, and legal acceptance versions. We use email verification codes; we do not store passwords.

2.2 Business profile data

We crawl your public website and store a structured profile of your business (products, services, audience, brand voice) inside a per-customer "living business profile." This is derived from your own public content.

2.3 Google Search Console data

If you connect Google Search Console, we request the https://www.googleapis.com/auth/webmasters.readonly scope and pull your search performance daily: clicks, impressions, click-through rate, position, query, page, device, and country dimensions. We also use Google Search Console's URL Inspection API to monitor whether new pages we publish on your behalf are indexed by Google.

We do not write to Google Search Console. We do not request access to the Google Indexing API. We do not access any Google account data beyond the Google Search Console properties you explicitly grant. Data is stored encrypted at rest. You can disconnect at any time from the dashboard, which immediately revokes our OAuth token and triggers deletion of stored Google Search Console data within 24 hours.

2.4 Instagram and Meta data

If you connect your Instagram Business or Creator account, we use the Instagram Graph API (operated by Meta) to read account-level performance daily: reach, impressions, profile views, follower count, audience-by-city, audience-by-country, audience-by-age, audience-by-gender. We also read per-post insights (impressions, reach, engagement, saves, likes, comments, video plays).

We request the following Meta permissions: instagram_basic, instagram_manage_insights, pages_show_list, pages_read_engagement, business_management. We do not post on your behalf. We do not message followers. We do not download user-generated content from third parties. Data is stored encrypted at rest. You can disconnect from our dashboard or revoke the app from your Instagram settings; either action immediately revokes the token and triggers deletion of stored Instagram and Meta data within 24 hours.

For details on requesting deletion of Instagram data we hold, see our Data Deletion page.

2.5 Google Business Profile data

If you authorize us to manage your Google Business Profile, we request the https://www.googleapis.com/auth/business.manage scope and act only on the profiles you explicitly grant. We use the My Business Business Information API to read and update your listing's business information (primary and additional categories, services, business description, opening hours, and attributes) to keep it accurate and complete, the My Business Account Management API to resolve your account and location hierarchy so we operate on the correct location, and the Google My Business v4 API to read your reviews and post responses on your behalf after your authorization.

We add ourselves as a Manager of your profile, never an owner; we do not transfer ownership and we never act on a profile you have not authorized. Google Business Profile data obtained through the API is cached temporarily for no more than 30 calendar days, then refreshed or deleted, and is stored encrypted at rest. We do not aggregate, resell, or use it to train external models. If you end your relationship with us, we provide the ability to disassociate your profile from our platform within 7 business days. You can disconnect at any time from the dashboard, which immediately revokes our OAuth token and triggers deletion of stored Google Business Profile data within 24 hours.

2.6 Payment data

Stripe is the active launch payment route for customers outside India. Indian customers are routed by billing country to Razorpay once Razorpay setup is complete. These payment processors handle card and bank details directly; 42flows stores only billing country, provider route, plan ID, invoice IDs, amounts, currencies, payment statuses, cancellation status, and tax records required to operate the subscription. We never store card numbers, CVVs, or full bank account details.

2.7 Operational data

We maintain an activity log of every meaningful action our agents take on your behalf (content generated, pages optimized, articles delivered, errors encountered) so you can audit what the service is doing. This log is visible to you in the dashboard.

2.8 Site analytics

We use a self-hosted privacy-preserving analytics tool (Umami) on 42flows.com to understand how visitors find and use the site. We do not use Google Analytics, Facebook Pixel, or other third-party trackers. We do not set advertising cookies.

3. How we use your data

We use your data only to:

  • Operate the service you signed up for (research, content generation, publishing, optimization, performance tracking).
  • Improve the quality of agent outputs (a fleet-level oversight layer of SEO professionals reviews outcomes across customers and improves the underlying skills).
  • Communicate with you about the service (transactional emails, support replies).
  • Comply with legal obligations.

We do not sell your data. We do not share your data with third parties for marketing or analytics purposes. We do not use your data to train external machine-learning models.

4. Who can access your data

Inside 42flows, access is limited to: the founder, the fleet-level SEO oversight team (humans who review outcomes and adjust skills, never operating any individual customer), and infrastructure providers strictly required to run the service (database hosting, content delivery, payment processing). Every individual with access is bound by confidentiality.

Infrastructure providers we use: Hetzner (server hosting, Germany), Cloudflare (CDN and DNS), Resend (transactional email), Stripe (active launch payments outside India), Razorpay (planned India payments), OpenRouter / Anthropic / Google / DataForSEO / fal.ai (AI model and SEO data providers, called server-side from our infrastructure).

5. How long we keep your data

While your subscription is active: we keep all data necessary to operate the service.

When you disconnect a single integration (e.g., Google Search Console or Instagram): we delete all data tied to that integration within 24 hours and revoke the OAuth token immediately.

When you cancel your account: we delete all customer-identifying data and OAuth tokens within 30 days. Anonymized operational metrics (aggregate cost-to-serve, success rates) may be retained for service quality analysis.

We may keep certain records longer where law requires (e.g., tax records for invoiced amounts).

6. Your rights

You have the right to access, correct, export, or delete your data. Until every control is self-service from the dashboard, email [email protected] for privacy requests and we will respond within 30 days.

Customers in India have rights under the Digital Personal Data Protection Act, 2023 (DPDP Act). Customers in the EU and UK have rights under the GDPR and UK GDPR. Customers in California have rights under the CCPA / CPRA. Specifically:

  • Right to access: request a copy of the data we hold about you.
  • Right to correct: ask us to fix inaccurate data.
  • Right to delete: ask us to delete your data (subject to legal retention).
  • Right to port: receive your data in a structured, machine-readable format.
  • Right to object: object to particular processing activities.
  • Right to withdraw consent: revoke any consent you previously gave.

7. Children

42flows is a business-to-business service. We do not knowingly collect data from anyone under 18.

8. International data transfers

Our infrastructure is primarily located in Germany (Hetzner). Some AI providers we call (OpenRouter, Anthropic, Google, DataForSEO, fal.ai) operate in the United States and other regions. Data sent to these providers is governed by their respective data-protection terms.

If you are in India, your data is processed under the Digital Personal Data Protection Act, 2023. If you are in the EU or UK, transfers outside your jurisdiction rely on Standard Contractual Clauses or equivalent safeguards with the relevant processors.

9. Security

All data is transmitted over HTTPS. OAuth tokens and other sensitive credentials are encrypted at rest. We maintain isolated per-customer data boundaries: one customer's content, profile, and analytics are never visible to another customer or accessible from another customer's session.

10. Changes to this policy

When we make material changes to this policy we will notify active customers by email and post a banner on the dashboard. Smaller clarifications may be made without notice; the "Last updated" date at the top of this page always reflects the most recent change.

11. Contact

Privacy and data-protection questions: [email protected].

Instagram and Meta data deletion requests: [email protected], or see the Data Deletion page.