Privacy Policy
Last updated: April 2026
1. Overview
Flino ("we", "our", "us") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our service at flino.com and flino.io.
Controller: Emad Ette, Berlin, Germany — support@flino.com
2. Data We Collect
We collect the following categories of personal data:
- Account data: Name, email address, and password when you register
- Usage data: Log data, IP addresses, browser type, pages visited, and actions within the app
- Email integration data: OAuth tokens for Gmail connection; we do not store the content of your emails on our servers beyond what is necessary for the service
- Billing data: Payment information processed by our payment provider (Stripe); we do not store full card details
- Customer data you upload: Offer information and contact details you enter into Flino
3. Legal Basis for Processing
We process your data on the following legal bases under GDPR Art. 6:
- Contract performance (Art. 6(1)(b)): To provide our services to you
- Legitimate interests (Art. 6(1)(f)): For security, fraud prevention, and service improvement
- Legal obligation (Art. 6(1)(c)): For tax and accounting requirements
- Consent (Art. 6(1)(a)): For optional analytics cookies (where applicable)
4. How We Use Your Data
- To create and manage your account
- To send automated follow-up emails through your connected Gmail account
- To provide AI-powered text suggestions and sequence management
- To process payments and manage subscriptions
- To communicate with you about your account and our services
- To improve and develop our service
- To comply with legal obligations
5. Gmail Integration
Flino connects to your Gmail account via Google OAuth to send follow-up emails on your behalf. Specifically:
- We request only the minimum necessary Gmail permissions (send emails)
- Emails are sent from your own Gmail address — Flino does not appear as the sender
- We do not read, store, or analyze the content of your existing emails
- You can revoke our Gmail access at any time through your Google account settings
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Data Sharing
We do not sell your personal data. We share data only with:
- Infrastructure providers: Cloudflare (hosting, CDN), located in the EU/EEA where possible
- Payment processors: Stripe (billing) — see Stripe Privacy Policy
- Analytics: Only privacy-friendly, cookie-less analytics tools (if used)
- Legal authorities: Where required by law
Fonts / Schriftarten: Alle auf dieser Website verwendeten Schriftarten (Inter) werden ausschließlich lokal von unseren eigenen Servern ausgeliefert. Es wird keine Verbindung zu Google Fonts (fonts.googleapis.com, fonts.gstatic.com) oder anderen Drittanbieter-Font-Servern hergestellt. Beim Besuch dieser Website werden daher keine IP-Adressen oder weiteren personenbezogenen Daten an Google übermittelt.
7. Data Retention
We retain your data for as long as your account is active. After account deletion:
- Account data is deleted within 30 days
- Billing records are retained for 10 years (legal requirement under German tax law)
- Anonymized usage statistics may be retained indefinitely
8. Your Rights
Under GDPR, you have the following rights:
- Right of access (Art. 15): Request a copy of your personal data
- Right to rectification (Art. 16): Correct inaccurate data
- Right to erasure (Art. 17): Request deletion of your data
- Right to restriction (Art. 18): Limit how we process your data
- Right to data portability (Art. 20): Receive your data in a machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests
- Right to withdraw consent: Where processing is based on consent
To exercise any of these rights, contact us at support@flino.com.
9. Cookies
We use cookies and similar technologies. For details, see our Cookie Policy. You can manage your cookie preferences at any time.
10. Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and regular security reviews.
11. Children's Privacy
Flino is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the app. Continued use of our services after changes constitutes acceptance of the updated policy.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. In Germany, this is the relevant state data protection authority (Landesdatenschutzbehörde).