Privacy policy

flottra stores the details of the X accounts you connect, so this policy matters more than most. It says what we collect, what we do with it, where it lives, who else touches it, and how to get it deleted. Short version: we keep what the service needs to run, encrypted, and nothing is sold or shared for advertising.

Last updated DUCK DIGITAL LTD, company no. 16726307

1. Who is responsible

The data controller is DUCK DIGITAL LTD (company number 16726307, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom). For anything about your data, write to hello@flottra.com.

2. What we collect

Your flottra account. Your name, email address and a hashed password, plus the session cookie that keeps you signed in and a cookie that remembers your theme choice. We do not run advertising trackers or third-party analytics on flottra.com.

The X accounts you connect. Usernames, passwords, two-factor secrets, session cookies and profile details of the X accounts you add. Passwords and secrets are encrypted before they are stored and are only decrypted to be sent to your own computer. They are never displayed in the panel.

Proxies. The addresses and credentials of the proxies you supply, stored encrypted, so that your computer can use them.

What the app does. Schedules, personas, drafts, posts and a log of each task the app ran, with its result. The app also sends us short diagnostic log lines (errors, timings, version) so that failures can be found and fixed. Where a task fails, the app may keep a screenshot or page extract of the X page it was on; that capture stays on your computer unless you choose to send it to us.

Devices. A name and key pair for each computer you pair with the panel, and when it was last seen.

Billing. Your plan, invoices and payment history. Card details are entered with, and held by, our payment provider; we never see or store a full card number.

Support. Anything you send us by email.

3. Why we use it

  • To provide the service you signed up for: storing your accounts and schedules and delivering them to your computer. Legal basis: performance of our contract with you.
  • To bill you and keep the records the law requires us to keep. Legal basis: contract and legal obligation.
  • To keep the service secure, find and fix failures, and stop abuse. Legal basis: our legitimate interest in running a working, safe service.
  • To answer you when you write to us. Legal basis: legitimate interest, or contract where your question is about your subscription.

We do not sell personal data, and we do not use it for advertising or profiling. We send no marketing email unless you ask for it.

4. AI-drafted text

When you ask flottra to draft posts or replies, the persona and topics you configured and the text being replied to are sent to a third-party language-model provider (currently Anthropic or OpenAI, depending on the feature) to generate the draft. We send only what the draft needs; we do not send account passwords or proxy details, and we do not use these providers’ services for anything other than generating your drafts.

5. Who else processes data

We use a small number of providers to run the service, each only for the purpose named:

  • Hetzner Online GmbH (Germany): the servers and database that run the panel.
  • Cloudflare (US/EU): DNS and email routing for our domain.
  • Payment providers such as Stripe or Creem: taking payment, issuing invoices and, where they act as seller of record, collecting tax. Their own privacy notices apply to the details you enter at checkout.
  • Language-model providers (Anthropic, OpenAI): drafting text, as described above.

We may also disclose data where the law requires it, or to protect the rights and safety of our customers or ourselves. Otherwise it stays with us.

6. Where it is stored, and transfers

The panel and its database are hosted in Germany. Some providers above are based in the United States; where personal data reaches them we rely on the UK and EU standard contractual clauses and the safeguards those providers offer. Your own computer holds the browser profiles and sessions of the accounts it runs; that data is on your machine, not ours.

7. How long we keep it

  • Account, X account, proxy and schedule data: for as long as your workspace exists. When the workspace is deleted they go with it, including the saved logins.
  • Diagnostic logs sent by the app: 30 days, then deleted automatically.
  • Invoices and payment records: six years after the end of the year they relate to, which is what UK tax law requires.
  • Support email: three years after the conversation ends.

8. Your rights

Under the UK GDPR and, where it applies to you, the EU GDPR, you can ask us for a copy of your personal data, ask us to correct or delete it, restrict or object to how we use it, and receive it in a portable form. To exercise any of these, including deleting your workspace and everything in it, email hello@flottra.com from the address on the workspace; we answer within one month and confirm when a deletion is done.

If you are unhappy with how we handle your data you can complain to the UK Information Commissioner’s Office (ico.org.uk) or to the data-protection authority of the country you live in.

9. Security

Credentials are encrypted at rest and only decrypted to be delivered to a computer you have paired, over an authenticated, encrypted connection. Access to production systems is limited to the people who run them. No system is perfectly secure; if we learn of a breach that affects your data we will tell you and the relevant authority as the law requires.

10. Children

flottra is for adults. We do not knowingly collect data from anyone under 18.

11. Changes

The date at the top says when this policy last changed. For changes that reduce your rights or expand what we collect we will email you before they take effect.

Privacy policy · flottra