Privacy Policy
Last updated 26 July 2026
Operator details — to be confirmed before publication
- Legal entity name: to be confirmed
- Registered address: to be confirmed
- Company / registration number: to be confirmed
- Contact email for legal and privacy requests: to be confirmed
- Governing law and jurisdiction: to be confirmed
These pages describe how the product actually works today. They are a starting point drafted from the implementation, not legal advice, and should be reviewed by a qualified adviser for your jurisdiction before you rely on them.
This policy explains what Cybex Flow collects, why, and what happens to it. It covers two groups of people: the businesses who use the service, and their customers, whose messages pass through it.
1. Information we collect from businesses
- Account details — name, email address, and login credentials handled by our authentication provider.
- Business profile — business name, description, industry, contact details, opening hours, services, and FAQs you enter or that we read from a website address you give us.
- Content you create — anything you teach your assistant, plus leads, customers, appointments, quotes, and invoices you record.
- Connection details — the accounts and numbers you connect. Access tokens are encrypted before storage.
- Usage and diagnostics — feature usage counts, error reports, and technical logs used to run and debug the service.
2. Information we process on your behalf
When your customers message you on a connected channel, we process what is needed to deliver and answer that conversation: their message content, the identifier the channel gives us (such as a phone number, social handle, or chat session), any name the channel provides, and details they choose to share — for example when asking for a quote or booking.
For phone calls we process call metadata, and where your provider supplies them, recordings and transcripts. You are the controller of this information; we process it to provide the service to you.
3. Why we process it
- To operate the service — delivering messages, generating replies, and keeping records.
- To provide the AI assistant, which requires sending conversation content and your business information to the AI providers listed below.
- To secure the service — abuse prevention, rate limiting, and audit trails.
- To support you when you contact us.
- To bill you, if you are on a paid plan.
We do not sell personal information, and we do not use your customers’ conversations to advertise to them.
4. Service providers we share with
We use a small number of processors, each for a specific purpose:
- Hosting, database, and file storage — to run the application and store your data.
- AI providers — to generate assistant replies and summaries. Conversation content and relevant business information are sent for this purpose.
- Messaging and telephony providers — to deliver messages and calls on the channels you connect.
- Email delivery — for transactional email such as invitations and notifications.
- Payment processing — for paid plans. Card details are handled by the payment processor; we never see or store full card numbers.
- Error monitoring — to detect and diagnose faults.
5. Retention
We keep your account and business data for as long as your account is active. Conversations, calls, and records are retained so you can refer back to them. If you ask us to delete your data, contact us at the address above — we will confirm what can be removed and what we must keep for legal or accounting reasons.
Being straight with you: there is no self-service “delete my account” button in the product yet. Deletion is handled manually on request today. We are building the self-service version.
6. Your choices
- You can view and edit your business information at any time in the app.
- You can pause the assistant, or take over any conversation, at any time.
- You can disconnect any channel, which stops us sending or receiving on it.
- You can request a copy or deletion of your data by contacting us.
If your customers ask you to delete their information, you can remove their records in the app, or contact us for help.
7. Security
Access to your data is restricted to your business by database-level access rules. Access tokens for connected accounts are encrypted before storage. Uploaded files are held in private storage and served through short-lived links. Webhook traffic from external providers is signature-verified before it is accepted. No system is perfectly secure, and we do not claim otherwise.
8. Calls, recordings, and consent
Where you enable phone answering, calls may be recorded and transcribed by your telephony provider. Recording and consent laws vary by country and region, and you are responsible for making any disclosure the law requires.
9. Where data is processed
Our providers may process data in countries other than yours, including the United States. Confirm the specific regions with us if that matters for your business.
10. What we do not claim
We make no certification claims. In particular, the service is not offered as a HIPAA-compliant service, we do not sign business associate agreements, and we hold no SOC 2 or ISO certification. Do not use Cybex Flow to process protected health information or other specially regulated data.
11. Children
The service is for businesses and is not directed at children.
12. Changes
We may update this policy. If a change is material we will give notice in the service or by email.
13. Contact
Privacy questions and data requests go to the contact address above. See also our Terms of Service.