FloQ

Privacy policy

Last updated: 26 September 2026 · Versione italiana

1. Who we are

FloQ is a service of LOGIN SRL (“SoftwareX”), Via Legnano 26, 63821 Porto Sant'Elpidio (FM), VAT IT02573380447. Privacy questions: privacy@software-x.it.

This policy (Articles 13 and 14 of the EU General Data Protection Regulation, “GDPR”) covers:

2. What we process, why and for how long

DataPurposeLegal basisRetention
Name, email, password (stored only as a hash), optional profile pictureCreate and run your accountContract (Art. 6.1.b)While the account exists, then 30 days
Connected devices, date and time of sign-ins (IP addresses are used in memory only, to limit attempts)Account security, new sign-in alertsLegitimate interest in security (Art. 6.1.f)12 months
Verification codes sent by emailAddress confirmation, two-step sign-in, password resetContract15 minutes
Identifier of the Microsoft or Google account used to sign inSign in with Microsoft or GoogleContractWhile linked to the account
Push notification tokensSend the notifications you choseContractWhile the device stays connected
Team activity logSecurity and accountability within the teamLegitimate interest24 months
Connected AI assistants (app, team, permissions, last use) and the log of what they read (tool used and target, never the content)Running the connection, showing it to you and to the team’s ownersContract and legitimate interest in securityConnection: until you revoke it or it goes unused for 60 days; log: 90 days

For team content FloQ stores: email metadata (sender, recipients, subject, date, folder, status and a 200-character preview), chat messages and attachments, mailbox credentials and 2FA secrets (encrypted). Full email bodies and email attachments are never written to our disks: they are read from the mail provider when someone opens the message and kept in memory for at most 15 minutes.

3. Google and Microsoft mailboxes and sign-in

You can connect a Gmail or Google Workspace mailbox, or a Microsoft 365 / Outlook mailbox, by signing in with that account instead of typing its password. You can also sign in to FloQ with your Google or Microsoft account.

What FloQ accesses.

How FloQ uses it. Only to provide the features you see in the app: showing folders and messages to you and to the team members you chose to share the mailbox with, searching, sending the emails you write, carrying out your actions (mark as read, move, archive, delete) and notifying you of new messages. A personal mailbox is visible only to you.

What FloQ does not do. It does not sell this data, use it for advertising, profiling or market research, use it to train artificial intelligence or machine learning models, or share it with anyone other than the technical providers listed below as needed to run the service, or as required by law. No one at SoftwareX reads your email, except with your explicit consent for a problem you ask us to solve, for security reasons, or to comply with the law.

Protection and retention. The token issued by Google or Microsoft is encrypted (AES-256-GCM) with a key of its own for each team. Message metadata is kept while the mailbox is connected; full bodies are never stored on disk. When you disconnect the mailbox from FloQ, its token and all its data are deleted from the database immediately and from backups within 30 days. You can also revoke access at any time at myaccount.google.com/permissions or myapps.microsoft.com.

Limited Use. FloQ’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. AI assistants

You can connect FloQ to an AI assistant of your choice (for example Claude or ChatGPT) through the MCP protocol, if your team’s owners allow it. The assistant has access, in one team, to what you see: the mail of the mailboxes you can access and the channels and direct messages you can read. It is read-only by default; only if the team’s owners allow it and you agree, can it also answer mail, send mail and write in the chat on your behalf. It cannot see 2FA codes. How it works.

When the assistant reads a mail or a message, that content is sent, at your request, to the service you connected. From then on that provider handles it under its own terms and privacy policy, which SoftwareX does not control: check your assistant’s settings, including whether conversations are used to train models. The assistant’s provider is not one of our providers: you choose it.

Gmail mailboxes connected with Google are never available to assistants: data received from Google APIs is not transferred to third-party artificial intelligence services. You get an email at every new connection; you can revoke it at any time from Profile → AI assistants, and the team’s owners can switch assistants off for everyone.

5. Recipients

Data is stored on servers in the European Union. These providers process it only as needed to run the service:

ProviderServiceData
OVH SAS (France)Server: database, sync, backupsAll service data
Cloudflare, Inc. (USA)Network to the server; storage of chat attachments and encrypted backup copiesTraffic in transit, chat attachments, encrypted backups
Resend, Inc. (USA)System emails (codes, invitations, alerts)Name, email and content of the system email
Apple Inc. (USA)Push notifications on iPhone, iPad and MacDevice token, notification title and preview
Google LLC (USA)Push notifications on Android (Firebase Cloud Messaging)Device token, notification title and preview

Transfers to US providers rely on the EU-US Data Privacy Framework or Standard Contractual Clauses. As mail providers, Google, Microsoft and the others are not our providers: you or your team choose them, and FloQ connects to them on your behalf. FloQ uses no third-party analytics or tracking.

6. Security

Encrypted connections; argon2 password hashing; mailbox credentials, tokens and 2FA secrets encrypted with a per-team key; two-step sign-in by email code; alerts on every new sign-in; sessions revocable per device; encrypted nightly backups; an updated, automatically monitored server.

7. Your rights

You can ask to access, correct, delete, restrict or port your data, and object to processing (Articles 15–22 GDPR), by writing to privacy@software-x.it. You can delete your account at any time from the app or on the Delete your account page. For a team’s content, also contact the company that runs it; SoftwareX helps it respond. You can lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or your local authority.

8. Changes

We announce important changes in the app or by email before they apply. The date at the top shows the latest version.