FlowRMM legal

Privacy Policy

Effective date and version: September 5, 2026 (2026-09-05)

Who we are and the scope of this notice

FlowDevs LLC, 612 Gumtree St NE, Saint Joseph, MN 56374, provides FlowRMM. Contact clientsupport@flowdevs.io for privacy, access, correction, or deletion requests. This notice covers our website, Flow Personal, and information FlowDevs receives in providing Business services. Our services are currently available only in the United States to eligible adults or organizations, as described in the Terms of Service. U.S.-only availability does not mean every third-party provider processes data exclusively in the United States.

We do not train on your data

FlowDevs does not use your data to train or fine-tune AI models. We do not sell your personal information or share it for cross-context behavioral advertising.

If you choose to connect an independent AI service or agent, that service can receive the information its authorized tools return, including computer details, screenshots, commands, and results. Its own terms, retention rules, and account settings govern its use of that information; our commitment does not change another provider's policies. Review those settings before connecting a service. Automated processing needed to deliver a feature is different from training a model.

Information we process

Website and inquiries. Information you provide in an application, demo, or support request can include your name, contact details, company, role, endpoint range, and message. Earlier Personal beta requests may include a Discord handle and stated use case. Discord is not required for public Personal signup. Hosting and security systems may process IP addresses, browser details, request times, and error logs.

Personal accounts. We store a random account identifier, name, optional unverified email label, passkey public keys and credential identifiers, authentication metadata, account creation time, and the policy versions and U.S./adult eligibility attestation accepted at signup. We do not receive your passkey's private key, fingerprint, face scan, or device unlock PIN.

Remote management. We process computer ownership and enrollment records, device identifiers and fingerprints, hostnames, operating system and software information, health and connection status, session and approval metadata, commands, reported results, and activity/audit records. Depending on the feature you use or authorize, data can include screen images, remote keyboard/mouse input, clipboard content, files, and command output. Such content may contain personal or confidential information visible on the managed computer. Do not assume everything on a remote screen is invisible to the service or to an authorized connected tool.

Plans and payments. We process plan status and billing identifiers needed to manage an optional paid subscription. Payment providers process payment details under their own notices; FlowRMM does not require payment for creating a Free account.

Why we use information and when people may access it

We use information to authenticate you, connect your computers, carry out authorized work, enforce ownership and approval boundaries, provide support, administer plans, diagnose failures, maintain security, prevent abuse, and meet legal obligations. Routine service operation involves automated processing. We do not browse customers' screens, files, or command content out of curiosity or for advertising.

Authorized personnel may access the information reasonably necessary to provide support you request or authorize, operate and repair the service, investigate abuse or security incidents, protect people or the service, or comply with law. Access should be limited to the purpose and personnel who need it. Technical administrative access can exist; we do not claim that encryption makes all customer content inaccessible to us.

We may disclose information when legally required by a valid subpoena, court order, or other compulsory legal process, or when disclosure is otherwise permitted by law and reasonably necessary to address an emergency involving serious harm or protect legal rights. An informal government request does not automatically entitle the requester to customer data. We assess requests and limit disclosure to what is legally required or justified. Where legally permitted and appropriate, we will notify affected users.

Personal hosting, Business hosting, and service providers

Flow Personal is hosted by FlowDevs. We administer its application and storage, so we process the account and operational information described above. For customer-deployed Business, the customer administers its Azure tenant and determines the use, access, and retention of data in that deployment. FlowDevs does not receive blanket tenant access just because the customer installs FlowRMM. Customer-authorized support access and configured integrations can still disclose data to us or other providers.

Customer-deployed Business is not a promise that no information ever leaves the tenant. Licensing, release/update checks, support, billing, and explicitly connected tools can exchange the information needed for those functions. The customer should review integration permissions and its own privacy obligations to employees and other endpoint users. Direct a request about a Business-managed computer to that organization's administrator first; we can help identify the appropriate contact where possible.

We use providers for hosting, storage, security, email/support, billing, and requested integrations. The marketing site is hosted through Lovable; configured inquiry routing and scheduling may use Microsoft Power Automate and Microsoft Bookings. Optional paid Personal billing uses Stripe. Providers acting on our behalf may process information necessary for their service. Independently selected AI services and customer-configured integrations are also subject to their own policies. We may disclose necessary records to professional advisers or in a corporate transaction, subject to applicable confidentiality and legal obligations.

Cookies, storage, and retention

We use authentication cookies and browser storage for sign-in, security, preferences, and interface behavior. Hosting and security providers may use technical cookies or logs needed to deliver their services. We do not use customer management content for advertising profiles.

Account and ownership records remain while needed to provide your account and protect device ownership. Operational, support, security, audit, and billing records are retained as needed for their purpose, configured retention, dispute resolution, and legal obligations. Retention varies by record type and by Business deployment; we do not promise a universal deletion deadline. Backups, fraud-prevention records, legal holds, and immutable audit records may persist after an account deletion request. Such retained information remains subject to this notice and applicable law.

Your choices and requests

You can stop using the service, revoke connected tools, remove enrolled computers, and request access to, correction of, or deletion of your personal information by emailing clientsupport@flowdevs.io. Identify the account or issue without sending passkeys, pairing codes, passwords, or full sensitive command output. We verify identity and authority before releasing data, changing ownership, or deleting records; an email label alone is not enough. We respond within the time required by applicable law and explain any lawful exception or inability to verify a request. We do not discriminate against you for exercising an applicable privacy right.

Account deletion does not itself uninstall the agent from your computers or delete copies held by independent third-party services. Remove or uninstall those connections separately. Personal does not intentionally offer accounts to people under 18. Contact us if you believe a child has provided information so we can investigate and take appropriate action.

Security and changes to this notice

We use safeguards designed to protect information, including passkey authentication and ownership and access controls. No service can guarantee absolute security. Customer-deployed Business security is shared among the customer, Microsoft, and FlowDevs according to what each controls; see the Terms of Service.

We will date changes to this notice and give appropriate notice of material changes. We will not silently repurpose previously collected data in a way that conflicts with the commitments under which it was collected. Where consent is required, we will obtain it before making that change.