Privacy Policy
Last updated: March 2026
1. Introduction
Axioma Studios ("we", "our", "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information when you use FlowBot, our no-code chatbot and social media management platform.
2. Data We Collect
Account Data
- Name, email address, and profile photo (provided via Google authentication)
- Subscription and payment history (processed by Stripe — we do not store credit card numbers)
Platform Usage Data
- Chatbot flows, templates, and automation rules you create
- Messages sent and received through connected channels
- Contact information of your customers (as managed by you)
- AI usage metrics and credit consumption
- Analytics data (message counts, response times, engagement metrics)
Third-Party Account Data
When you connect social media accounts (WhatsApp, Instagram, TikTok, LinkedIn, YouTube), we collect:
- Account identifiers (user ID, display name, profile picture)
- Access tokens (encrypted, used to communicate with the platform on your behalf)
- Business account information (phone numbers, verified names, page details)
3. How We Use Your Data
- To provide and operate the FlowBot platform
- To send and receive messages on your behalf through connected channels
- To upload and publish content to your connected social media accounts
- To process payments and manage subscriptions
- To provide AI-powered chatbot responses
- To generate analytics and performance reports
- To improve our services through anonymized, aggregated usage analysis
- To send service-related notifications (account updates, billing, security alerts)
4. Data Storage and Security
Your data is stored securely using industry-standard infrastructure:
- Cloud hosting on Google Cloud Platform (Firebase) and Supabase
- All data is encrypted in transit (TLS/SSL) and at rest
- Access tokens for third-party services are encrypted and stored securely
- Regular security audits and monitoring
- Row Level Security (RLS) enabled on all database tables
5. Data Sharing
We do not sell your personal data. We may share data only in the following circumstances:
- Service providers: Stripe (payments), Google Cloud (hosting), Supabase (database), OpenAI (AI processing)
- Third-party platforms: Messages and content are transmitted to the platforms you connect (Meta, TikTok, etc.) as required for the service to function
- Legal requirements: When required by law, regulation, or legal process
6. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Disconnect: Remove any connected third-party account at any time
- Export: Request an export of your data in a portable format
- Cancel: Cancel your subscription and close your account at any time
7. Data Retention
We retain your data for as long as your account is active. Upon account deletion:
- Personal data is deleted within 30 days
- Message history and conversation logs are permanently removed
- Third-party access tokens are immediately revoked and deleted
- Anonymized analytics data may be retained for service improvement
8. Cookies and Tracking
FlowBot uses essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising trackers. Analytics data is collected server-side without personal identifiers.
9. Children's Privacy
FlowBot is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
10. International Data Transfers
Your data may be processed in servers located outside your country of residence, including the United States and Brazil. We ensure appropriate safeguards are in place for international data transfers in compliance with applicable data protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes via email or in-app notification. The "Last updated" date at the top of this page indicates when the policy was last revised.
12. Contact Us
If you have questions or concerns about this Privacy Policy or your data, please contact us at:
Axioma Studios
Email: contato@axiomastudio.com.br
Website: axiomastudio.com.br
13. Compliance
This Privacy Policy is designed to comply with applicable data protection regulations, including the Brazilian General Data Protection Law (LGPD — Lei Geral de Proteção de Dados) and, where applicable, the European General Data Protection Regulation (GDPR).
FlowBot