Last updated: July 2026
Raflo Labs (“Raflo”, “we”, “us”) provides a platform for building and deploying custom AI agents over your business data. This policy explains what personal data we collect, how we use it, and your rights. Questions? Email team@raflolabs.com.
Raflo Labs is the data controller for your account and website data. For the documents and content you upload to train your agents, you are the controller and Raflo acts as a processor on your behalf.
We process personal data to perform our contract with you, for our legitimate interests (security, abuse prevention, product improvement), with your consent (non-essential cookies/analytics, withdrawable any time), and to meet legal obligations.
To generate responses, your agents’ prompts and retrieved context may be sent to third-party large-language-model providers (such as OpenAI, Anthropic, and Google) or to a self-hosted “Sovereign” endpoint you configure. We offer a PII-redaction option that scrubs personal data before external LLM calls. Other sub-processors include our cloud hosting (Railway), email delivery, and error monitoring (Sentry). All are bound to process data only as instructed.
This section applies only if you connect a Google Calendar to Raflo’s AI scheduling agent. In line with the Google API Services User Data Policy, it explains exactly what Google user data we access and how we handle it.
Data accessed. When you connect your Google Calendar, Raflo accesses only: (a) free/busy time ranges on calendars you have access to, to check availability (Google “calendar.events.freebusy” scope); and (b) event details — creating, reading, updating, and deleting events — but only on calendars you own (Google “calendar.events.owned” scope). Raflo does not access, share, or delete other Google Calendars, does not change any calendar’s sharing permissions, and does not access your Gmail, Contacts, Drive, or any other Google data.
Data use. Google Calendar data is used exclusively to power Raflo’s AI scheduling agent — checking your availability and creating, rescheduling, or cancelling calendar events on your behalf, at your direction. It is not used for any other purpose, for advertising, or to train generalized AI/ML models.
Data sharing. We do not sell your Google Calendar data or share it with third parties, except: with the sub-processors necessary to run this feature — the same large-language-model providers and infrastructure listed in Section 5 (OpenAI, Anthropic, and Google to generate a scheduling response, and Railway for hosting), and only when actually used to process a scheduling request you initiate; when required by law; or to protect rights, property, or safety. See Section 5 (AI providers & sub-processors) above.
Data protection. Your Google Calendar OAuth tokens are encrypted at rest and transmitted only over encrypted connections (HTTPS/TLS). Access is scoped to the authenticated user who granted it. You can revoke Raflo’s access at any time from your Google Account permissions page (myaccount.google.com/permissions) or by disconnecting the integration inside Raflo.
Data retention & deletion. Raflo does not keep a copy of your calendar. Free/busy and event data are requested from Google in real time to complete a scheduling action and are not cached beyond the specific booking records Raflo creates at your direction. Your OAuth tokens are retained only while the integration remains connected. Disconnecting Google Calendar in Raflo, or deleting your Raflo account, immediately revokes and permanently deletes the stored tokens and the associated calendar/booking data — there is no separate retention period.
Raflo Labs’ use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell your personal data. We share it only with the sub-processors above, when required by law, or to protect rights and safety.
Your data may be processed in countries outside your own (including the United States). Where required, such transfers rely on appropriate safeguards, such as Standard Contractual Clauses.
We keep account data while your account is active and as needed to provide the service. Conversations, logs, and other records are retained for limited periods and then deleted or anonymized. You can export your data and permanently delete your account from your profile, which removes your agents, files, and associated data.
Data is encrypted in transit (HTTPS), and secrets and tokens are encrypted at rest. Access is restricted to the authenticated owner, and each agent’s documents are isolated. No system is 100% secure, but we apply industry-standard safeguards.
Depending on your location (GDPR / UK GDPR / CCPA), you may have the right to access, correct, delete, port, or restrict/object to processing of your personal data, and to withdraw consent. California residents may request disclosure of the data collected and its deletion; we do not sell personal information. To exercise any of these, email team@raflolabs.com or use the export and delete tools in your account. You may also lodge a complaint with your local data-protection authority.
We use strictly necessary cookies for authentication and, with your consent, limited analytics. You can manage non-essential cookies via the cookie banner.
The service is not directed to children under 16, and we do not knowingly collect their personal data.
We may update this policy from time to time. Material changes will be posted here with a new “Last updated” date.
Raflo Labs — team@raflolabs.com