Privacy Policy
This policy explains which personal data is processed when you use Flocta and which services receive it in the currently configured operating state. Services that are not configured or active are deliberately not listed.
Controller
The controller responsible for data processing under the GDPR is the operator named in the Legal notice . The contact details provided there also apply to all privacy-related enquiries.
Principles of processing
We process personal data only where necessary to provide the application (Article 6(1)(b) GDPR) or where we have a legitimate interest in secure and functional operation (Article 6(1)(f) GDPR). Content you enter is not used to train models and is not sold.
Hosting and server logs
The application is hosted by Vercel Inc. When you access it, technically necessary connection data, including IP address, time, requested resource and user agent, is processed to deliver the application and maintain its security.
Server functions are configured for Vercel's Frankfurt region (fra1). Static content continues to be delivered through the global CDN. Selecting a technical region does not replace a data processing agreement or a review of subprocessors and transfer safeguards. Vercel is a US company, so this setting alone cannot rule out access from or data transfers to the United States.
AI chat and language models
A core function of Flocta is chat with open language models. Your inputs, including chat messages, uploaded-document content where applicable, saved notes and custom instructions, are sent to the configured model provider to generate a response.
Current provider: Scaleway Generative APIs — processing in EU (France). Processing takes place within the EU.
Knowledge base and embeddings
When you upload documents to the knowledge base, their text is converted into numerical embeddings so relevant passages can be retrieved. The underlying text excerpts are sent to the embedding provider for this purpose.
Draft-status notice: Embeddings are currently generated technically through OpenRouter in the United States, which involves a data transfer to the United States. Final assignment of this flow to the EU provider is part of the ongoing migration and must be confirmed by Max.
Storage of your data
Chats, knowledge-base content, usage counters and copies of generated media are stored in a database hosted by Supabase so they remain available between sessions. Retention follows the duration of your use; you can delete your content (see Your rights).
Quick dictation in the browser
The feature labelled “Quick dictation” uses your browser's speech recognition in your selected language. Depending on the browser and operating system, audio may be processed by the browser or operating-system provider; Flocta does not control that processing path or its storage location. The same applies to “Voice conversation”, which is expressly offered as a browser feature. The Therapy recorder does not use this browser-based speech recognition. For mixed German and English speech, use “Record DE + EN” instead when the EU path described below is configured.
EU voice transcription
When you provide audio for transcription, the audio file is uploaded to the configured Scaleway endpoint in Paris and converted into text by Whisper. The raw transcript may then be sent to a separate Mistral cleanup model at the same provider; a deterministic check rejects its output if it contains impermissible word changes. The specific processing location, retention and subprocessors are governed by the operator's agreement with Scaleway. Voice recordings may contain particularly sensitive data; use this feature only for content you are authorised to transmit.
Multi-agent analysis (“Therapy session”)
When you start a Therapy session, the text you enter or transcribe and the intermediate results derived from it are sent to the current language-model provider named above for analysis. Several bounded model steps structure statements, extract evidenced problems, draft suggestions and check their traceability. This does not automatically perform external actions or deployments.
Flocta does not persist raw audio recordings. Scaleway processes them under its current default zero-retention policy; any exceptional retention and processing by the provider is governed by the operator's agreement with Scaleway. The browser stores no more than 15 sessions, including transcript, analysis and report, locally in IndexedDB for up to 90 days. You can delete individual sessions earlier in the Therapy view; “Delete account” also removes all local Therapy transcripts and reports. Without live model access, the feature accepts no input and does not run a sample analysis as a substitute.
Abuse prevention and rate limiting
We limit the number of requests to prevent abuse. Short-lived counters associated with hashed IP addresses are held in storage hosted by Upstash. Plain-text IP addresses are not stored permanently.
Sign-in and accounts
Guest access is available without sharing data with third parties. You may optionally provide an email address from which a display name is derived.
You can also sign in with GitHub and Google. When you sign in this way, the selected provider sends us the data authorised for sign-in, generally your email, name and profile image. These providers act as independent controllers and may process data in third countries.
Code execution in the browser
The code interpreter runs Python code directly in your browser using Pyodide. Core components are loaded from our server. For additional packages, your browser may load files from the public jsDelivr content-delivery network, which transmits your IP address to its operator.
Servers you connect (MCP)
You can connect external tool servers (MCP). When you invoke such a tool, the required arguments from your chat are sent to the server you selected. You are responsible for these destinations and their privacy practices.
Optional access to local files (Local Companion)
If you expressly pair and start the optional Local Companion on your device, a workflow you provide can read a UTF-8 text file configured explicitly by its relative path within a folder you select. Recursive file listings are disabled in the persistent Companion; the separate browser folder access can list visible names only locally in the browser. The Companion establishes only an outbound encrypted connection to Flocta; it does not open an externally accessible port on your device. Write access, shell commands, hidden files and symbolic links are technically blocked.
Our systems process the device name and grant alias you assign, device status and last connection, the requested relative path, task and workflow status, and the result read. The absolute local folder path remains on your device. Device tokens are stored server-side only as cryptographic hashes and are displayed once during pairing. Text results are limited to 2 MB per task.
The guided macOS setup stores the device token, selected absolute folder path, runtime files and local connection logs in the private ~/.flocta folder and can create a start-at-login entry that applies only to your user account. An installed removal launcher deletes the device-specific local credentials and start-at-login entry; server-side revocation under Integrations is also required to authoritatively block the paired device.
Processing is necessary to perform the function you configured (Article 6(1)(b) GDPR). You may revoke the device at any time under Integrations; this prevents new access and ends pending workflow tasks. Processed task results and error details are automatically removed from task records after 30 days. If the account is deleted earlier, the server-side deletion cascade removes them sooner.
Local browser storage (no tracking)
Flocta stores certain settings and your chat content locally in your browser, in localStorage and, for larger data sets, in IndexedDB. These are functional values only: your selected colour scheme, interface language, sidebar state, whether the introduction has already been viewed (flocta.intro.seen), a preferred read-aloud voice, and your settings and chat history so they persist between sessions.
This storage is strictly necessary for the operation of the application that you expressly requested. No cookies or identifiers are set for analytics, tracking or advertising, and none of this data is shared with third parties. Under Section 25(2)(2) TDDDG, no consent is therefore required; for this reason, Flocta does not display a cookie banner. You can delete this local data at any time through your browser settings.
Your rights
Subject to the statutory requirements, you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21 GDPR). To exercise these rights, contact the party named in the Legal notice .
You also have the right to lodge a complaint with a data-protection supervisory authority (Article 77 GDPR).
Changes to this policy
Because the range of functions and services may change, we update this policy where necessary. The services listed in this version reflect the current technical operating state.