Last updated August 9, 2026
Privacy Policy
This policy explains how Flowour, operated by Nimiti LLC, a Pennsylvania limited liability company based in Plymouth, Pennsylvania (“Flowour,” “we,” or “us”), handles information when you use flowour.ai and the Flowour app.
Information we collect
We collect account details you provide or receive from Firebase Authentication, such as your name, email address, linked sign-in provider, and account identifier. Anonymous use remains available for Sandbox work until you choose to link an account.
We store the product and brand context you enter, uploaded images or videos, ad plans and creative, approval and rejection history, Flow settings, budgets and targets, Campaign Kit settings, support messages, preferences, and security or audit records.
When you import results or later connect an advertising provider, we process the selected provider account and campaign identifiers, currency and time-zone context, reporting bindings, daily spend and performance metrics, source and completeness evidence, measurement checks, and reconciliation history. Flowour records deterministic analysis, recommendations, policy versions, decisions, actions, and receipts so that you can see why a change was proposed or made.
How we use information
We use information to operate and secure Flowour; create plans and ad assets; enforce quotas and approval gates; prepare Campaign Kits; import, reconcile, monitor, and report results; produce evidence-backed recommendations; provide support; prevent abuse; and improve reliability.
Product and brand context may be sent to paid-tier Google Gemini services to generate plans, copy, images, policy checks, or summaries. Flowour does not intentionally send provider credentials, invite codes, or payment secrets to Gemini. AI output does not approve an ad or authorize a provider action.
Advertising providers and delegated actions
Self-launch ads remain in your own provider account, and Flowour cannot publish, pause, end, or otherwise change them. Reporting-only connections sync results but do not grant Flowour publishing authority.
If the app later shows verified publishing or Autopilot authority for an exact channel, Flowour may perform only the action you requested or the narrow routine actions you explicitly armed within versioned limits. It never automatically approves creative, launches or resumes delivery, increases spend or a spending ceiling, changes your objective or measurement, or activates a replacement. Provider reporting and action confirmation may be delayed, so an external ad may continue delivering briefly. Emergency Off prevents the next ordinary automatic action; revoking a connection begins a reconciled unlink process.
Service providers and sharing
We use Firebase and Google Cloud for authentication, database, storage, hosting, server functions, security, and AI processing. Advertising providers receive information only when you launch there or authorize an applicable connection. A future payment provider receives billing information only when paid billing is enabled. We may disclose information to comply with law, protect users or the service, or complete a business transfer with appropriate safeguards.
We do not sell personal information or share it for cross-context behavioral advertising.
Security, retention, and deletion
Access is restricted by account ownership and server-enforced rules. Provider credentials, future billing controls, invite hashes, and internal operation records are not client-readable. No internet service is completely secure, so keep your linked account and provider accounts protected.
We retain data while your account is active and as needed for service, security, audit, dispute, and legal obligations. Account deletion first fences new writes, reconciles any Flowour-controlled external work, asks you to acknowledge Self-launch ads that only you can stop, and then purges account data to a fixed point. Minimal security tombstones and legally required transaction records may remain for a limited period. Deleting Flowour data does not stop a Self-launch ad in your provider account.
Your choices
You can remain anonymous for Sandbox use, link or unlink supported identities and providers, change notification preferences, export safe owner-visible data when available, use Emergency Off where available, and request account deletion. Email alerts require a verified email address.
Children, international use, and changes
Flowour is intended for businesses and people old enough to enter a binding contract, not children under 13. Information may be processed in the United States. We will post material policy changes here and update the date above.
Contact
Questions or privacy requests: support@flowour.ai.