Service provider: Flowtropolis AB
Privacy and deletion contact: support@flowtropolis.com
Data Controller
Flowtropolis AB, at Bällstavägen 66, 186 50 Vallentuna, Sweden, is the data controller for account administration, service security, our own product analytics, and our direct customer relationships. When an organisation uses Flowtropolis to manage its own projects and participants, we may process personal data in its content on that organisation's behalf under a data processing agreement. In that case, the organisation determines the purposes of that processing and its privacy notice also applies. You can contact us for help identifying the relevant organisation.
1. Who we are and what this policy covers
This policy explains how Flowtropolis AB ("Flowtropolis", "we", "us") processes personal data when you use our hosted Flowtropolis service. It covers the Flowtropolis web editor, the Flowtropolis XR application for Meta Quest, related Unity desktop and viewer clients where offered, and the backend services supporting them.
An independently operated or self-hosted deployment may have a different operator and privacy policy. Meta's processing for its accounts, devices, operating system, and store is covered by Meta's own privacy notices.
2. Information we process
The information depends on the features you use. We receive it from you, your device, your organisation or collaborators, and any sign-in provider you choose.
| Information | Examples and purpose |
|---|---|
| Account and sign-in information | Email address, display name, account identifier, profile image, authentication credentials and session tokens; phone number or sign-in provider identifiers where those sign-in methods are offered. Used to create and secure your account, sign you in, and recover access. |
| Organisation and service records | Organisation and workspace membership, roles, invitations, licence information, credit balances and usage transactions. Used to administer access and the features available to you. |
| Guest access | A generated guest identifier and display name, session credentials, room participation, and any content or activity associated with the guest account. Guest access does not mean that no data is stored. |
| Content you create or provide | Scenes, 3D models, images, textures, video and other uploaded files, file names and metadata, annotations, and shared presentations. Used to store, process, display, and share your projects. Content can contain personal data about you or other people. |
| AI feature inputs and results | Prompts, conversation history, selected images or models, scene context, generated assets, and processing results. Used when you request AI-assisted creation or editing. |
| Collaboration and XR information | Display name, avatar selection, session and room identifiers, presence, voice audio, and headset, controller, and hand movement. Used to operate shared experiences; see section 3. |
| Camera and spatial information | Images you take with the in-app camera, QR-code payloads, spatial-anchor identifiers and spatial information used for supported mixed-reality features; see section 3. |
| Technical and security information | IP address, browser or client information, request details, timestamps, errors, performance information, and security or administrative events. Used to operate, protect, and troubleshoot the service. |
| Usage information | Session timing, features used, scenes opened, assets uploaded or placed, application version, and associated organisation or content identifiers. Used to understand and improve the service. |
| Communications | Information you send when requesting support or exercising your rights, plus account and service emails and their delivery records. Used to respond and communicate with you. |
An organisation administrator may provide your email address and role when inviting you. A collaborator may include your personal data in shared content. Required account and technical information is necessary for the associated service to work; you can choose whether to use optional features such as voice, camera capture, and AI tools.
3. Meta Quest, voice, movement, and mixed reality
Movement and avatars. The Quest application processes headset and controller position and orientation and, when hand tracking is used, hand pose and joint information. This enables interaction and avatar animation. In a multiplayer session, relevant movement and avatar state are transmitted through realtime networking and made available to other participants so that they can see and interact with you. Hiding an avatar or hand visual does not necessarily stop the underlying movement synchronisation.
Voice. If you grant microphone access, the application processes audio for voice communication and related avatar lip movement. When you are unmuted, your voice is transmitted in realtime to other participants in the session. Muting stops voice transmission; it does not necessarily stop local microphone capture. Revoke microphone permission in your device settings to prevent the application from accessing the microphone. Flowtropolis does not store realtime communication or voice content long-term. Live movement and communication data are processed to support the session; technical and security records are covered separately in section 8.
Passthrough and photographs. Passthrough lets you see your physical surroundings in a mixed-reality experience. On supported headsets, the in-app camera can also request access to camera images to create a mixed-reality photograph. When you take a photograph with this tool, the image is uploaded to Flowtropolis storage in the current organisation/workspace and displayed as shared session content. It can include people, objects, documents, and other details in your surroundings. Taking a picture with this tool is therefore not a local-only action. Access to saved images follows the relevant file and workspace permissions.
Spatial features and QR codes. Supported features process spatial-anchor and colocation information to align the experience between headsets. Anchors can be saved on the device and shared using Meta's spatial-anchor services. QR scanning processes detected code contents and their spatial references to open or join the corresponding Flowtropolis experience. Flowtropolis retains photographs and images from these features as user content, but does not keep a separate permanent store of spatial-anchor or room-mapping data in its backend. Spatial anchors and their lifecycle are managed through Meta's SDK and services; anchor data and references may persist on the device or with Meta. The Flowtropolis application does not explicitly delete saved anchors.
Your controls. You can choose whether to use optional features and manage available permissions in your headset settings. Refusing a permission can prevent the related feature from working. Changing permissions does not delete previously uploaded photographs or other stored data. See section 9 to request deletion. Other participants may also take screenshots or recordings using their own devices or platform features.
4. Why we use information and our legal bases
Where the EU/EEA GDPR applies, our processing relies on the following bases. For data processed on an organisation's behalf, that organisation is responsible for establishing its legal basis.
| Purpose | Legal basis |
|---|---|
| Provide the account, editor, storage, collaboration, and features you request | Performance of our contract with you. Where the contract is with your organisation, our legitimate interest in providing its authorised users with the agreed service. |
| Protect accounts, prevent misuse, maintain reliability, and investigate errors | Our legitimate interests in operating a secure and reliable service. |
| Answer support requests and send necessary service messages | Performance of our contract, or our legitimate interest in supporting users and administering customer relationships. |
| Meet applicable recordkeeping requirements and respond to valid legal requests | Compliance with legal obligations. |
We collect product usage data to improve our services, based on our legitimate interest in improving Flowtropolis. You can opt out in your account settings.
We do not sell personal data or use it for advertising. We do not use personal data to train our own AI models.
A device permission is a technical access control; it does not by itself establish the legal basis for every use of the resulting data. Where we rely on consent, you can withdraw it without affecting processing already lawfully carried out.
5. Cookies, local storage, analytics, and diagnostics
The editor uses cookies and browser storage for sign-in, security, and preferences. The Unity application stores information such as a refresh token, display preferences, avatar choices, and spatial-anchor references on the device to support continued use. Clearing browser or application data can sign you out and remove local settings; it does not delete your server-side account or content.
See our Cookie Notice for details about browser storage and your choices.
Our product analytics use a random identifier linked to your account through a separate mapping. Event records can also contain organisation, scene, asset, or room identifiers. These records are pseudonymous, not anonymous.
You can turn off future first-party product-analytics collection for your account in the editor's settings using the usage-analytics toggle, currently labelled "Share anonymous usage analytics". This setting does not delete existing records and does not control security logs, service communications, or diagnostics.
We process diagnostic information, such as error reports and performance information, to investigate problems and improve reliability.
6. Who receives information
Other users and your organisation. Participants receive the information needed for a shared experience, including your display name, avatar, relevant movement, and transmitted voice. Organisation members and administrators can access information and content according to their roles. If you enable a public presentation or distribute a share link, people with that access can view the content made available through it.
Service providers. We use providers to host and deliver the service, authenticate users, send emails, diagnose problems, and provide multiplayer and AI functionality. The provider and data involved depend on the feature:
| Entity Name | Flowtropolis Service | Location of Processing | Purpose of Processing |
|---|---|---|---|
| Amazon Web Services (AWS) | Platform backend, storage, and content delivery | Ireland for hosting and storage; content delivery may use regional edge locations | Host the backend; store and deliver files; process operational records and analytics archives. |
| MongoDB Atlas | Platform database | Ireland | Store account, organisation, workspace, content, and service records. |
| SuperTokens | Managed account authentication | Ireland | Manage sign-in, credentials, authentication records, and sessions. |
| Sentry | Diagnostics | EU | Process error reports and performance information to troubleshoot the service. |
| Photon | Realtime collaboration and voice | Amsterdam, Netherlands | Connect participants and transmit session, avatar, movement, and voice data. |
| fal.ai | AI-assisted content generation and editing | Provider-selected regions; varies by service and request; not restricted to the EU/EEA | Process selected prompts, images, models, and results for the AI feature requested. |
| OpenRouter and routed model providers | AI-assisted planning and generation | United States for OpenRouter's standard infrastructure; model processing locations vary by routed provider | Route and process prompts, context, selected content, and model responses. |
| Vercel | Web editor and website hosting | Stockholm, Sweden; static files are served from locations closest to the user | Host and deliver web interfaces and process related requests and connection information. |
| Resend | Account and service emails | Ireland for email sending; the United States for stored message content, delivery logs, and account records. | Deliver messages and process recipient details, message content, and delivery records. |
| Google Workspace | Support and privacy-request email | Google's global infrastructure and subprocessors; processing is not limited to the EU/EEA | Receive, store, and send support correspondence, attachments, and privacy requests. |
| Meta | Flowtropolis XR platform and spatial features | On the local headset and through Meta Platform Services associated with the Meta account used on that device. Meta determines its cloud processing locations. | Support headset functionality and manage shared spatial anchors. |
The locations above describe the main service arrangements. Provider support, subprocessors, content delivery, and routed AI models can involve additional countries. Our use of an EU hosting region does not mean that all processing takes place within the EU/EEA. See section 7 for international transfers. Meta separately determines its processing for Meta accounts, devices, and platform services under its own privacy notices.
When you use an AI tool, we send the selected inputs and necessary context to the relevant external provider for processing. We opt out of the use of inputs and outputs for model training through the AI APIs we use. We otherwise use the providers' standard service terms and default routing and retention settings. These settings do not restrict processing to the EU/EEA and do not guarantee zero data retention by every provider. Providers may also process technical and usage records to operate, secure, and bill for their services and meet legal obligations. See section 8 for AI retention.
We may disclose information where necessary to comply with applicable law, protect legal rights, or address fraud or security incidents. Any transfer of personal data as part of a business reorganisation must remain subject to applicable data-protection requirements.
7. International transfers
Some providers and their subprocessors process information outside the EEA, including in the United States. AI processing destinations also depend on the model and provider used. We use our providers' standard data processing agreements. Where a transfer is not covered by an applicable European Commission adequacy decision, these agreements provide for the European Commission's Standard Contractual Clauses and applicable safeguards. You can contact support@flowtropolis.com for information about a transfer affecting your data and a copy of the relevant safeguards.
8. How long information is kept
We keep personal data for the purposes described in this policy and delete it when it is no longer needed, subject to applicable legal obligations and valid deletion requests. Retention depends on the category:
| Category | Retention |
|---|---|
| Accounts | Accounts are deleted after 2 years without authenticated use of Flowtropolis. Signing in or using the service while authenticated, including on a headset, counts as activity. This applies to registered and guest accounts, including users belonging to active paid organisations. You can request earlier deletion as described in section 9. |
| Shared organisation content | Shared content remains with the organisation when an individual account is removed. When the organisation's last user is removed after 2 years of inactivity, we also delete its remaining stored data. Backup copies follow the separate retention period below. Earlier personal-data deletion requests are handled under section 9. |
| Private AI conversation history | Deleted when the individual account is deleted. Shared organisation content remains subject to the rule above. Backup copies follow the separate retention period below. |
| First-party usage events in the live analytics database | Scheduled to expire after 30 days. |
| First-party usage-event archives | Retained for 2 years after archival. When an account is deleted, we remove the mapping between that account and its analytics identifier. |
| Security audit and processing-event records in the application database | Scheduled to expire after 90 days. This does not specify provider or infrastructure log retention. |
| Service-email records in the application database | Scheduled to expire after 365 days. Provider-held copies may have a different period. |
| Live room-presence records | Expire shortly after room-activity updates stop; the current expiry is approximately one minute, followed by database cleanup. |
| Realtime communications, voice, and live movement | Used to support the live session. Flowtropolis does not store this content long-term. Technical and security records follow their separately stated retention periods. |
| Spatial anchors and local anchor references | Managed through Meta's SDK and services; may remain on the device or with Meta. The Flowtropolis application does not explicitly delete saved anchors. |
| Diagnostics and ordinary infrastructure logs controlled by Flowtropolis | Retained for up to 90 days, unless specific records are needed for an ongoing security investigation or a legal obligation. |
| Backups | Retained for 2 years. |
| Support and privacy-request correspondence | Kept while the request is open and for up to 2 years after it is resolved, then deleted. We retain only specific information for longer where necessary to meet a legal obligation or establish, exercise, or defend a legal claim. |
Copies held by AI providers. These are separate from private AI conversation history stored by Flowtropolis. Under fal's default settings, request inputs and outputs in its request history are retained for 30 days. Uploaded and generated media files are also retained for 30 days under our account's media-expiry settings. See fal's retention documentation.
OpenRouter normally deletes prompt and response content after completing the request under its default settings, subject to its exceptions for malicious use and legal requirements. The model provider receiving a routed request may retain it under its own rules; we do not restrict routing to providers offering zero retention. The applicable period depends on the provider and model used, including any abuse-monitoring requirements. See OpenRouter's provider data policies. For information about a particular AI request or to request deletion, contact us under section 9.
Providers may keep their own operational, security, and billing records under their service agreements, separately from the Flowtropolis-controlled logs listed above. Deletion of provider-held copies may take additional time under their deletion and backup processes. We include relevant providers when handling a valid deletion request.
Removing the account-to-analytics mapping removes the direct account link. Archived events can still contain organisation, scene, asset, or room identifiers, so removing that mapping does not by itself make every archived record anonymous. Requests to erase personal data in these records are handled under section 9.
Automatic database and storage cleanup is asynchronous. A scheduled expiry does not mean all copies disappear at that exact instant. Where a legal obligation or a specific dispute requires longer retention, we limit the retained information to what is necessary for that purpose.
9. Requesting account or data deletion
To request deletion of your Flowtropolis account or personal data, email support@flowtropolis.com. We suggest the subject "Flowtropolis data deletion" so we can identify your request. This deletion-request process is available to all users, regardless of country or region, free of charge.
Your request must include either:
- The email address you use to sign in to Flowtropolis, if you have a registered account; or
- Your guest account ID, if you use anonymous guest access. You can find this ID in the application's App Menu. To open the App Menu, press the menu button on your left Meta Quest (Oculus) controller while using the application.
You can also specify whether you want to delete your entire account or particular data, such as uploaded photographs, an AI conversation, or analytics records. Do not send passwords or session tokens. We may ask for proportionate information to verify your identity and locate the data.
Our support team handles deletion requests through a documented manual process. We assess the request, delete personal data that must be erased, and involve relevant service providers. If we must retain specific information, we will explain the reason and applicable retention. If the relevant organisation is the controller, we will help route the request to it and assist with its response. Leaving an organisation does not automatically delete all shared project content; personal data within that content remains subject to applicable rights.
Deleting content in the application, signing out, uninstalling the Quest application, or deleting your Meta account does not by itself request deletion of all information held by Flowtropolis. A Flowtropolis deletion request does not delete your Meta account. Saved or shared spatial data and copies held by other participants may require separate handling; we will explain the actions available for your request.
10. Your rights
Depending on applicable law, you may request access, correction, erasure, restriction, or portability of your personal data, object to processing based on legitimate interests, and withdraw consent. Contact the privacy address above. Where the GDPR applies, we normally respond within one month; if a permitted extension is necessary, we will explain it within that month.
You may complain to your local data-protection authority. As Flowtropolis AB is established in Sweden, you can contact Integritetsskyddsmyndigheten (IMY).
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you.
11. Security
We use authentication, access permissions, organisation/workspace access controls, and restricted access to stored files to protect information. Access is limited according to the service's roles and operational needs. Contact us if you believe your account or personal data has been compromised.
12. Age eligibility
Flowtropolis is intended for professional and organisational use. Users must be at least 13 years old. Users under 18 may participate only through an organisation that authorises their use, with any parental or guardian permission required by applicable law. Any higher minimum age required by local law or the relevant device or platform also applies.
The service is not intended for children under 13. If we learn that a child under 13 is using Flowtropolis, we will take steps to end that use and delete personal data collected through it, unless retention is required by law. Contact support@flowtropolis.com if you believe this has happened.
13. Changes to this policy
We will update the "Updated" date at the top of this policy when it changes. For material changes, we will provide an appropriate notice through the service or another suitable channel. Where a change requires consent, we will obtain it before carrying out that processing.