1. Introduction
Welcome to dotflow.bot ("we", "our", or "us"). We are a technology integration and automation service. We are committed to protecting our interests and defining how we collect, use, and process your data. By using our website and our AI voice agent and workflow automation services, you consent to the data practices described in this Privacy Policy.
2. Information We Collect
We collect information to operate our business effectively and provide you with the best possible service. This includes:
- Information You Provide: Name, email address, phone number, company details, payment information, and any data submitted via forms or during consultations.
- AI Interaction Data (voice agents and workflow automation only): Transcripts, recordings, and metadata from interactions with our AI Voice Agents and automated workflows. You acknowledge that AI interactions are processed and stored by third-party infrastructure providers (such as AI modeling and telephony platforms) for quality, model-improvement, and operational purposes. This bullet does not apply to Local Prospect Hunter, which collects no voice or workflow interaction data and is governed exclusively by Section 5 below; no data received from Google APIs is ever sent to any AI service.
- Automatically Collected Information: IP addresses, browser types, device identifiers, and browsing behavior on our website. We use cookies and third-party analytics tools — including Google Analytics and Google Tag Manager — as well as Microsoft Clarity, which captures session recordings and heatmaps (mouse movement, clicks, and scrolling) to help us understand and improve how visitors use our site.
3. Use of Information
We use your information strictly at our discretion to: provide, maintain, and improve our services; process transactions; send administrative messages, marketing, and promotional materials; and detect, investigate, and prevent fraudulent transactions and other illegal activities to protect the rights and property of dotflow.bot.
4. Data Sharing and Subprocessors
We share your data with trusted infrastructure providers necessary for our service delivery, including but not limited to AI voice and language-model platforms, telephony and messaging APIs, automation and workflow tools, scheduling software, CRM systems, and hosting platforms. As an integrator, dotflow.bot configures these systems but does not maintain own-hosted data storage for AI interactions. We explicitly disclaim any liability for data breaches, leaks, or mishandling caused by these third-party subprocessors. Local Prospect Hunter is the exception to this general description: its subprocessors are named individually in Section 5, and data it receives from Google APIs is shared with none of them.
5. Google User Data — Local Prospect Hunter
This section applies exclusively to Local Prospect Hunter (hunter.dotflow.bot), an invitation-only B2B prospecting application operated by dotflow.bot. Local Prospect Hunter lets a signed-in user connect their own Google account in order to send outreach emails from it. It requests three OAuth scopes: openid and email, used only to display which Google account is connected, and gmail.send, used to send email on the user's behalf.
- What we use it for: the gmail.send permission is used exclusively to send individual outreach emails that the signed-in user has reviewed and explicitly approved, one message at a time. There is no bulk, scheduled, or automated sending.
- Recipient consent:sending through the connected Google account is limited to recipients who have consented to receive commercial email from the user — either by replying to the user's earlier correspondence or by giving express consent, which the user records in the application together with supporting evidence before the send is allowed. This limit is enforced server-side on every send. Every non-reply message must contain a visible opt-out, every message carries a List-Unsubscribeheader, and recipients on the user's suppression list are never emailed.
- What we cannot and do not do: the application requests only the narrow gmail.sendscope, so it cannot read, modify, or delete any mailbox content. Google user data is never used for advertising, profiling, or credit decisions; it is never sold; it is not used to develop or train generalized artificial-intelligence or machine-learning models; and no human reads it, except with the user's explicit consent for support or where required by law and security investigations.
- Storage and security:the Google OAuth refresh token is stored encrypted at rest (AES-256-GCM) and is used only to obtain a short-lived access token at the moment the user sends an approved message. Message content is composed by the user in the application and transmitted to Google's Gmail API solely for delivery of that message.
- Artificial intelligence, and what is never sent to it:the application has exactly one AI feature — scoring a prospect business for relevance. What it sends to the model is the user's own business description typed in Settings, public business-directory fields (name, category, address, website) and text collected from the prospect company's own public website. No data received from any Google API is ever sent to an AI service — not the connected account's address, and not the content of any message. The requests are served by OpenAI's gpt-5-minithrough the Vercel AI Gateway, and every one of them carries the gateway's disallow prompt training instruction, which routes the request only to providers that do not use prompt data to train their models. The gateway deletes prompts and responses once the request completes.
- Revoking access:the user can disconnect the Google account at any time in the application's Settings, which deletes the stored token and revokes it with Google, or directly at myaccount.google.com/permissions.
Local Prospect Hunter's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Limitation of Liability
To the maximum extent permitted by law, dotflow.bot shall not be held liable for any unauthorized access to, alteration of, or the disclosure of your data. While we implement reasonable security measures, no digital system is entirely secure. You provide your data at your own risk.
7. Data Retention
We retain your data for as long as necessary to provide our services, comply with our legal obligations, or until you request its deletion. We reserve the right to delete data that is no longer required for operational purposes at our discretion.
8. Your Rights (GDPR / CCPA / LGPD)
Depending on your location, you may have rights regarding your personal data, including:
- Information access and data portability.
- Correction of inaccurate or incomplete data.
- Deletion ("Right to be Forgotten") of your personal information.
- Objection to processing for marketing purposes.
To exercise these rights, please contact us at the email below.
9. Contact Us
If you have any questions about this Privacy Policy, please contact us at: contact@dotflow.bot.