ByteFlow Privacy Policy
Last updated: 15 July 2026
Effective date: 15 July 2026
1. Introduction
ByteFlow ("ByteFlow", "we", "us", or "our"), operated by DifferentByte, provides a no-code visual workflow automation platform that lets users build and run automated workflows connecting Google Workspace services and other third-party applications (the "Service"). This Privacy Policy explains what information we collect, how we use it, how we protect it, how long we keep it, and how you can delete it or revoke our access.
This Privacy Policy applies to https://byteflow.bot, https://flow.byteflow.bot, and all related ByteFlow applications and services. By using the Service, you agree to the collection and use of information in accordance with this policy.
Contact / Data Controller:
DifferentByte
9th Floor Bhageeraths, Bhageeratha Square, Kacheripady, Kochi, Ernakulam, Kerala 682018, India
Email: info@differentbyte.in
Phone: +91 70213 87737
2. Information We Collect
2.1 Information you provide directly
- Account information: name, email address, phone number.
- Account credentials: password (stored only as a salted hash) or third-party sign-in identity.
- Payment information: billing details, processed by our payment processor (Razorpay). We do not store full card numbers.
- Communication preferences and any content you submit through support or contact forms.
- Workflow configuration: the workflows, prompts, node settings, and automation logic you create.
2.2 Information from connected Google accounts
When you connect a Google account to a ByteFlow workflow, you grant ByteFlow access to specific Google data through Google's OAuth consent screen. We access only the scopes you approve, and only to perform the actions your workflow defines. See Section 4 (Google User Data) for a scope-by-scope breakdown.
2.3 Information collected automatically
- Usage and log data: IP address, browser type, device information, pages viewed, and timestamps.
- Cookies and similar technologies: used to keep you signed in and to analyze and improve the Service (see Section 11).
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service and run the workflows you build;
- Authenticate you and keep your account and connected integrations secure;
- Execute automated actions on the third-party services (including Google) that you connect;
- Process transactions and send you related information;
- Respond to your requests, questions, and support enquiries;
- Send you technical notices, security alerts, and administrative messages;
- Detect, prevent, and address fraud, abuse, security, and technical issues;
- Comply with legal obligations.
We do not use your information for advertising, and we do not sell your information. See Section 6 for how this applies specifically to Google user data.
4. Google User Data
This section describes exactly what Google account data ByteFlow accesses, why, and how each requested OAuth scope is used. ByteFlow requests the minimum scopes necessary to provide the automation features you choose to use.
4.1 Google sign-in / identity
| Scope | Data accessed | How ByteFlow uses it |
|---|---|---|
| openid, userinfo.email, userinfo.profile | Your primary Google email address and basic profile (name, profile picture) | To create and identify your ByteFlow account and to label which Google account a workflow is connected to. |
4.2 Workspace automation scopes
ByteFlow only requests the scopes that correspond to the Google connectors you add to a workflow. If you never add a given connector, that action is never performed on your data.
| Scope | Google service | What ByteFlow does with it |
|---|---|---|
| gmail.send | Gmail | Send email notifications and reports on your behalf. ByteFlow never reads, searches, or modifies your inbox — gmail.send grants send-only access. |
| calendar.events | Google Calendar | Create, read, update, and delete calendar events, and schedule Google Meet video calls, as defined by your workflows. This scope does not grant access to your calendar sharing settings or the ability to delete entire calendars. |
| spreadsheets | Google Sheets | Read from and write to spreadsheets your workflow references by ID/URL (for example, reading sheet data as workflow input and writing processed results back). Required because automated, scheduled workflows operate on spreadsheets you specify without an interactive file picker. |
| documents | Google Docs | Create Google Docs, and read and update documents your workflow references by ID (for example, generating a report or appending workflow output to an existing document). |
| contacts | Google Contacts (People API) | Create and update contact records — for example, saving a new lead captured by a workflow into Google Contacts. |
| contacts.other.readonly | Google Contacts — "Other contacts" | Read the "Other contacts" list (addresses auto-saved from your email interactions), which is a separate resource not covered by the contacts scope, so workflows can look up known contacts. |
| forms.responses.readonly | Google Forms | Read the responses submitted to Google Forms that ByteFlow created for your workflow. |
| drive.file | Google Drive / Docs / Sheets / Forms | Create and manage only the files ByteFlow itself creates (for example, output documents, spreadsheets, and Google Forms). ByteFlow cannot see or touch any other file in your Drive with this scope. |
Note on Forms: ByteFlow creates and edits Google Forms that it creates, authorized through the non-sensitive drive.file scope. It requests forms.responses.readonly only so your workflow can read the responses to those forms. ByteFlow does not request broad access to your other, pre-existing Forms.
4.3 What ByteFlow does NOT do
- We do not read your Gmail inbox.
- We do not access files in your Google Drive that ByteFlow did not create (drive.file is app-created-files only).
- We do not use Google user data for advertising, resale, or to train AI/ML models (see Sections 7 and 8).
5. How Long We Keep Data (Data Retention)
We retain data only for as long as necessary for the purposes described in this policy.
| Data type | Retention |
|---|---|
| Google OAuth tokens (access and refresh tokens) | Stored encrypted at rest and retained only while you keep the integration connected, so that scheduled and recurring workflows can run. Deleted immediately when you disconnect the integration, delete the workflow that uses it, or delete your account. |
| Google user content accessed during a workflow run (e.g., spreadsheet rows read, calendar events, contact records) | Processed transiently in memory to complete the requested action. It is not used to build a persistent copy of your Google data. |
| Workflow execution results / run logs | Retained for up to 30 days so you can review the output of a run, then automatically deleted. You can delete a run's results sooner from the app. |
| Account information and workflow configurations | Retained for the life of your account and deleted within 30 days of account deletion. |
| Billing records | Retained as required by applicable tax and accounting law. |
When a retention period expires for a given type of data, we delete or irreversibly anonymize it.
6. Deleting Your Data and Revoking Access
You are always in control of ByteFlow's access to your Google data. You can:
- Disconnect a Google account in ByteFlow — go to Integrations / Connected Accounts in the app and choose Disconnect. This immediately deletes the stored OAuth tokens for that account.
- Revoke access from your Google Account — visit myaccount.google.com/permissions and remove ByteFlow. This revokes all tokens Google issued to us.
- Delete your ByteFlow account — from Settings → Account, or by emailing us at info@differentbyte.in. We will delete your account data, connected-integration tokens, and workflow configurations within 30 days, except where we are required by law to retain certain records.
- Request deletion of specific data — email info@differentbyte.in at any time and we will action verified requests within 30 days.
7. Limited Use of Google User Data
ByteFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide and improve the user-facing automation features you have chosen to use in ByteFlow.
- We do not transfer or sell Google user data to third parties, data brokers, or information resellers.
- We do not use Google user data for serving advertisements, including personalized, retargeted, or interest-based advertising.
- We do not allow humans to read Google user data unless (a) you have given us explicit consent to read specific data, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.
8. AI, Machine Learning, and Google Workspace Data
ByteFlow is an AI-assisted automation platform. Where a workflow uses an AI feature, your data may be sent to a third-party AI model provider (such as Anthropic, OpenAI, or Google) solely to produce the output of that specific workflow run, at your direction.
We affirm that:
- ByteFlow does not retain, and does not use, data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.
- Google Workspace API data is used only to deliver the specific, user-facing feature you requested within your workflow.
- Our AI-model providers are contractually bound not to train their models on data we submit through their business/API tiers.
9. How We Share Information
We do not sell your personal information. We share information only in these limited cases:
- With your direction: when your workflow sends data to a service you connected (this is the core function of the Service).
- With service providers (sub-processors) who help us operate the Service under confidentiality obligations — for example: hosting and database (Supabase / cloud infrastructure), payment processing (Razorpay), and AI model providers (Anthropic, OpenAI, Google) used only to execute AI workflow steps you configure.
- For legal reasons: to comply with law, regulation, legal process, or enforceable governmental request, or to protect the rights, safety, and property of ByteFlow, our users, or the public.
- In a business transfer: in connection with a merger, acquisition, or sale of assets, subject to this Privacy Policy.
Google user data is never shared for any purpose prohibited by the Limited Use requirements in Section 7.
10. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption in transit (TLS/HTTPS) for all data exchanged with the Service and with Google APIs.
- Encryption at rest for stored OAuth tokens and other sensitive credentials.
- Access controls limiting employee access to production data on a need-to-know basis.
- Data isolation so that one user's connected accounts and data are not accessible to another user.
No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard practices.
11. Cookies and Tracking Technologies
ByteFlow uses cookies and similar technologies to keep you signed in, remember your preferences, and analyze and improve performance. You can control cookies through your browser settings; disabling some cookies may affect functionality.
12. International Data Transfers
We are based in India and may process and store information in India and in other countries where we or our service providers operate. Where required, we implement appropriate safeguards for cross-border transfers in compliance with applicable data protection laws.
13. Your Data Protection Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data (rectification);
- Delete your data (erasure);
- Restrict or object to certain processing;
- Data portability;
- Withdraw consent at any time.
To exercise any of these rights, contact us at info@differentbyte.in. We respond to verified requests within 30 days.
14. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email, and the "Last updated" date above will be revised. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
16. Contact Us
If you have questions or concerns about this Privacy Policy or how your data is handled, contact us:
DifferentByte — ByteFlow
Email: info@differentbyte.in
Phone: +91 80692 56212, +91 70213 87737
Address: 9th Floor Bhageeraths, Bhageeratha Square, Kacheripady, Kochi, Ernakulam, Kerala 682018, India
