Floom Cloud Privacy
Last updated 2026-07-01.
This policy applies to Floom Cloud, including the hosted web app, CLI authentication, MCP server, connected accounts, and hosted worker runtime. If you self-host Floom, your deployment operator controls where that data is stored and processed.
Information we store
- Account and workspace data - account identity, workspace membership, settings, CLI/MCP tokens, and audit-relevant product events.
- Library folders and uploaded files - files and notes added to workspace context, file inputs, generated outputs, downloadable artifacts, and version history where enabled.
- Workers and runs - worker definitions, run inputs, step logs, tool calls, outputs, errors, schedules, approvals, artifacts, and cost or usage metadata.
- Conversations and Library folders - workspace agent chat history, instructions, resolved prompts, conversations, channel wiring, and tool configuration.
- Connections and secrets - OAuth connection metadata, MCP server configuration, secret names, and encrypted secret values. Secret values are write-only through the browser.
- Workspace agent data - instructions, resolved prompts, conversations, channel wiring, and tool configuration.
- Product telemetry - page views, safe UI interaction events, error events, and coarse environment details such as viewport size and timezone. Telemetry is sanitized server-side: token-shaped strings, email addresses, and sensitive property keys are redacted before storage.
Where data is stored
Cloud workspace records are stored in Floom Cloud systems with workspace/user access controls. Workers execute in isolated sandbox environments. Connected-tool actions may be brokered through Composio or MCP servers configured by the workspace.
Connected accounts
Floom uses connected accounts only to perform requested worker actions and workspace-agent tasks. A worker must declare the connection it needs before it can use that account. For Gmail or other inbox data, prefer read-only workers and approval gates unless you intentionally want the worker to send, delete, or modify data.
Third parties
Floom can send data to providers selected for a workspace, including model providers, E2B, Composio, OAuth providers such as Google or Slack, MCP servers, and transactional email providers when email is enabled. Those providers process data under their own terms.
Controls
- Telemetry preferences, export, and deletion are available through the telemetry API.
- Workspace API tokens are scoped to one workspace and can be revoked.
- CLI and MCP clients use tokens that can be revoked or disconnected.
- Secrets can be deleted or rotated by the workspace owner.
- Workers, runs, approvals, and Library files can be deleted from the app where those controls are available.
- Disconnect integrations you no longer want workers to access.
Retention
Floom keeps workspace data while it is needed to provide the product, preserve run history, support debugging, prevent abuse, or meet legal obligations. Deleting a workspace object removes it from ordinary product use, though backups, security logs, and provider-side records may persist for a limited operational period.
See also the Floom Cloud Terms.