Skip to main content
Legal

The fine print, in plain sight.

How we collect, use, and protect your data - and your participants’.

Privacy Policy

1. Introduction

Welcome to the Privacy Policy of Flob Inc. ("Company," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our reOS platform ("Research Operating System") and related services (collectively, the "Service").

This Privacy Policy covers both the personal data of our customers and website visitors, for which Flob Inc. is the data controller, and the personal data of Research Participants — the people our customers invite to studies, interviews, and calls through the Service — which we process on behalf of our customers as a data processor. If you are a Research Participant, Sections 2 and 3 explain who is responsible for your data and how to exercise your rights.

We are committed to protecting your privacy and ensuring you understand how your personal data is processed. Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.


2. Who Is Responsible for Your Data: Our Two Roles

We process personal data in two distinct roles, and your rights and the party responsible depend on which role applies:

(a) Flob Inc. as data controller. For personal data relating to our customers and website visitors — account information, billing information, usage data, and marketing data — Flob Inc. is the data controller (or "business" under the California Consumer Privacy Act) and this Privacy Policy describes that processing in full.

(b) Flob Inc. as data processor (Research Participants). Our customers use reOS to conduct research with their own users, customers, and other individuals ("Research Participants"). When you receive a study invitation through reOS, complete a form or survey, book a session, or join a live or AI-conducted interview or call, the organization that invited you (our customer, the "Research Organizer") decides why and how your data is used. The Research Organizer is the data controller of that data, and Flob Inc. processes it only on the Research Organizer's instructions as a data processor (or "service provider"). Section 3 describes this processing in more detail.

Contact details of the controller (where Flob Inc. is the controller):

Flob Inc. 1111B S Governors Ave STE 49827 Dover, DE 19904 United States

Data Protection Contact: support [at] reos [dot] ai

Privacy Lead (data protection inquiries): Rob Manzano Email: rob [at] reos [dot] ai

For European Union residents, where Flob Inc. acts as the data controller under the General Data Protection Regulation (GDPR), our privacy lead oversees compliance with data protection requirements and can be contacted directly for any GDPR-related inquiries.


3. Research Participants: Data We Process on Behalf of Research Organizers

This section is written for Research Participants — the people our customers invite into their research — as well as for our customers.

3.1 What We Collect About Research Participants

Depending on how the Research Organizer configures their study, the Service may process the following about you as a Research Participant:

  • Contact and profile information: Name, email address, and other details provided by you or by the Research Organizer (for example, when they import a participant list or connect a recruitment platform such as Prolific)
  • Communications: Study invitations, scheduling emails, reminders, and other messages sent to you through the Service at the Research Organizer's direction, and related delivery metadata (such as whether an email bounced)
  • Form and survey responses: Answers you submit through forms, surveys, and screeners hosted by the Service
  • Scheduling information: Session bookings, RSVP responses, and availability you provide
  • Consent records: Records of the consents you grant (including their version, date, and time)
  • Session recordings and transcripts: Audio and video of live research sessions, calls, and interviews — including sessions conducted by an AI interviewer — together with automatically generated transcripts, captions, and speaker attributions
  • AI-generated analysis: Observations, insights, summaries, and other analyses derived from your contributions
  • Incentive information: If the Research Organizer offers you a reward, the details needed to deliver it (such as your name, email address, and reward amount) are shared with the incentive provider the Research Organizer has connected for that purpose
  • Technical data: IP address, browser and device information, and usage data collected when you use participant-facing pages of the Service

3.2 How This Data Is Used

We process Research Participant data solely to provide the Service to the Research Organizer and on their documented instructions — for example, to send the invitations they compose, host their forms, run and record their sessions, transcribe recordings, and generate the analyses they request. We do not use Research Participant data for our own marketing, we do not sell it, and we do not use it to train AI models (see Section 7.1).

3.3 AI Interviews and AI Processing

Some sessions are conducted or assisted by an AI interviewer, and research content is analyzed by third-party AI providers listed in Section 7. The Service presents notices when you are interacting with an AI system, and Research Organizers are contractually required to inform you when AI conducts or analyzes your session and to obtain any legally required consents (including recording consents) before the session begins.

3.4 Your Rights as a Research Participant

Because the Research Organizer is the data controller of your data, requests to access, correct, delete, or object to the processing of your research data should be directed to the organization that invited you to the study. Their contact details are typically included in the study invitation or consent form.

If you contact us directly, we will refer your request to the relevant Research Organizer and notify them, and we will provide reasonable assistance so they can respond. Where we are legally required to act on your request directly, we will do so. You can reach us at support [at] reos [dot] ai. You can opt out of further emails sent through the Service at any time using the unsubscribe link included in those emails.

3.5 Retention of Research Participant Data

We retain Research Participant data for as long as the Research Organizer instructs us to (typically for the duration of their account and their research projects), after which it is deleted in accordance with Section 9. Research Organizers can delete participant data at any time using the Service's deletion tools.


4. Information We Collect

We collect information in several ways when you use our Service:

4.1 Information You Provide to Us

Account Information:

  • Email address
  • Full name
  • Profile picture/avatar
  • Password (stored in encrypted/hashed form)
  • Two-factor authentication settings and backup codes
  • Passkey/WebAuthn credentials for passwordless authentication

Organization Information:

  • Organization name
  • Organization logo
  • Member roles and permissions

Billing Information:

  • Billing name (individual or company)
  • Billing email address
  • Billing address (street, city, state/province, postal code, country)
  • Tax identification number (VAT ID, if applicable)

Note: Payment card information is collected and processed directly by our payment processor (Stripe) and is not stored on our servers.

Research Content:

  • Video and audio interview files
  • Documents and transcripts
  • Notes and annotations
  • Observations and insights
  • Personas and customer profiles
  • Reports and summaries
  • Any other content you upload or create through the Service

Communications:

  • Support requests and correspondence
  • Feedback and suggestions
  • Survey responses

4.2 Information Collected Automatically

Device and Technical Information:

  • IP address
  • Browser type and version
  • Operating system
  • Device identifiers
  • Screen resolution and device capabilities

Session Information:

  • Session tokens
  • Login timestamps
  • User agent strings
  • Referring URLs

Usage Information:

  • Features accessed and actions taken within the Service
  • AI model usage (models used, processing volume)
  • Units consumed and the activities that consumed them
  • Time spent on pages
  • Click patterns and navigation paths
  • Search queries within the Service

Log Data:

  • Server logs recording requests to our Service
  • Error logs and diagnostic data
  • Performance metrics

4.3 Information from Third Parties

OAuth Providers: If you choose to sign in using third-party authentication providers, we may receive:

  • Basic profile information (name, email, profile picture)
  • OAuth tokens for authentication purposes

Payment Processor: Our payment processor (Stripe) may share:

  • Transaction status and confirmation
  • Subscription status
  • Customer identifiers

4.4 Research Data Processing

When you use our AI-powered analysis features, the following data may be processed:

  • Transcripts of uploaded audio/video content
  • Text content from documents
  • User-generated prompts and queries
  • AI-generated outputs (observations, insights, summaries)

This data is processed by our third-party AI providers as described in Section 7.


5. How We Use Your Information

We use the information we collect for the following purposes:

5.1 Providing and Maintaining the Service

  • Creating and managing your account
  • Authenticating your identity and securing your account
  • Processing your research content through AI analysis
  • Generating insights, observations, and reports
  • Enabling collaboration features
  • Processing payments and managing subscriptions

5.2 Improving and Developing the Service

  • Analyzing usage patterns to improve features
  • Developing new features and functionality
  • Debugging and fixing errors
  • Conducting research and analysis
  • Testing new features

5.3 Communications

  • Sending service-related notifications (account verification, security alerts, billing)
  • Responding to your inquiries and support requests
  • Sending product updates and announcements (with your consent where required)

5.4 Security and Fraud Prevention

  • Detecting and preventing fraud, abuse, and security threats
  • Monitoring for suspicious activity
  • Enforcing our Terms of Service
  • Protecting our rights and property

5.5 Legal Compliance

  • Complying with applicable laws and regulations
  • Responding to legal requests and court orders
  • Establishing, exercising, or defending legal claims

5.6 Advertising and Marketing (Consent-Based)

We do not currently use third-party advertising networks, tracking pixels, or targeted advertising on the Service.

If we introduce targeted advertising in the future, all such activities for EEA, UK, and Swiss users will be based solely on your prior consent (Article 6(1)(a) GDPR), obtained through our cookie consent manager before any advertising technology is activated. You would be able to withdraw that consent at any time, and such withdrawal would not affect the lawfulness of processing based on consent before its withdrawal. Without your consent, we will not process your personal data for advertising purposes.

We may send you product updates and marketing emails about our own services, with your consent where required; you can unsubscribe at any time.


6. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds under Article 6 of the GDPR:

6.1 Contract Performance (Article 6(1)(b))

Processing necessary for the performance of our contract with you, including:

  • Account creation and authentication
  • Providing the core Service features
  • Processing payments

6.2 Legitimate Interests (Article 6(1)(f))

Processing necessary for our legitimate interests, including:

  • Improving and developing the Service
  • Ensuring security and preventing fraud
  • Analyzing usage and performance

We have conducted balancing tests for each legitimate interest processing activity. In each case, we have determined that: (a) the processing is necessary to achieve our legitimate interest; (b) the processing does not override your fundamental rights and freedoms; and (c) you would reasonably expect such processing given your relationship with us. For service improvement and security purposes, we process only aggregated or pseudonymized data where possible, minimizing any impact on your privacy. You have the right to object to processing based on legitimate interests at any time by contacting our privacy lead (see Section 2).

6.3 Consent (Article 6(1)(a))

Where you have given consent, including:

  • Marketing communications (where consent is required)
  • Analytics cookies and advertising cookies
  • Certain data sharing with third parties

You may withdraw consent at any time.

6.4 Legal Obligation (Article 6(1)(c))

Processing necessary to comply with legal obligations, including:

  • Tax and accounting requirements
  • Responding to lawful government requests

7. Data Sharing and Third Parties

We may share your information with the following categories of third parties:

7.1 AI Service Providers

To provide AI-powered analysis features, we transmit your research content to the following third-party AI providers:

AI service providers, what each one receives, and where it is processed
ProviderPurposeData SharedLocation
AnthropicAI analysis, content generationPrompts, transcripts, documentsUnited States
OpenAIAI analysis, content generation, transcriptionPrompts, transcripts, documents, audioUnited States
Google (Gemini / Vertex AI)AI analysis, content generationPrompts, transcripts, documentsUnited States
Amazon Web Services (Bedrock)AI analysis, content generationPrompts, transcripts, documentsEU (eu-central-1) or US (us-east-1), matching your data region
Cloudflare Workers AIAI analysis, embeddings, speech synthesisPrompts, transcripts, documentsGlobal (Cloudflare network)
Fireworks AIOpen-model inference, reached through Cloudflare AI GatewayPrompts, transcripts, documentsUnited States
Together AIOpen-model inference, reached through Cloudflare AI GatewayPrompts, transcripts, documentsUnited States
CerebrasLow-latency open-model inferencePrompts, transcripts, documentsUnited States
OpenRouterAI model routing (fallback)Prompts, transcripts, documentsUnited States (routes to upstream providers)
AssemblyAIAudio/video transcriptionAudio/video filesEuropean Union (Dublin, Ireland)
CartesiaSpeech synthesis for AI interviewsAI-generated response textUnited States

These providers process your data according to their respective privacy policies and data processing agreements. If your organization brings its own API keys for a provider ("BYOK"), that provider processes your data under your organization's own agreement with the provider.

AI Model Training Policy

We have selected AI providers that commit to not using your data for model training. We do not and will never explicitly opt-in to allow any provider to use your data for training purposes. Below are the specific commitments from each provider:

Model training policy by provider
ProviderTraining PolicySourceAccessed
Anthropic"Anthropic may not train models on Customer Content from Services."Commercial TermsJanuary 2026
OpenAI"Data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in)."API Data UsageJanuary 2026
Google (Vertex AI)"Google won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction."Vertex AI Data GovernanceJanuary 2026
Cloudflare Workers AI"Cloudflare does not use your Customer Content to (1) train any AI models made available on Workers AI or (2) improve any Cloudflare or third-party services."Workers AI Data UsageJanuary 2026
AssemblyAI"We will not use files you submit for model training if you [...] are utilizing our European servers." We use exclusively EU servers.Model Training FAQJanuary 2026

For providers not listed in the table above (including Amazon Bedrock, Fireworks AI, Together AI, Cerebras, OpenRouter, and Cartesia), our data processing agreements with those providers prohibit the use of customer data for model training, and several additionally commit to deleting data after processing.

Important Disclaimer: While we have taken reasonable steps to select providers that commit to not using customer data for training and we do not explicitly authorize such use, we cannot guarantee that providers will not violate their stated commitments. We are not responsible for any unauthorized use of data by third-party providers that occurs in violation of their stated policies; if we become aware of such a violation, we will notify affected customers and take reasonable steps to enforce our agreements.

Automated Decision-Making and AI Processing (Article 22 GDPR)

Our AI-powered features assist you in analyzing research content, generating insights, and creating summaries. We want to be transparent about how this processing works:

Nature of AI Processing: The AI analysis features are tools that support your research workflow. They generate suggestions, summaries, and observations based on content you provide. These outputs are intended to assist your work, not to make autonomous decisions about you or produce legal or similarly significant effects on you.

Human Oversight: All AI-generated outputs are presented to you for review. You retain full control over whether to accept, modify, or reject any AI-generated content. No decisions affecting your rights or access to the Service are made solely by automated means.

7.2 Infrastructure Providers

Infrastructure providers, what each one receives, and where it is processed
ProviderPurposeData SharedLocation
CloudflareHosting, CDN, security, file storage (R2), AI Gateway, real-time calls, video transcodingAll Service data, uploaded filesUS-based company; file storage and workers are regionalized to your selected data region (EU by default)
PlanetScaleDatabase hostingAll structured dataEU (Frankfurt, eu-central-1) by default; US (us-east-1) for organizations that select US data residency
TurbopufferVector search indices for semantic searchEmbeddings derived from research contentEU (eu-central-1) or US (us-east-1), matching your data region
Amazon Web ServicesGeneral cloud hosting and compute, email delivery (SES), media processing, backup storage (S3)Email addresses and names; uploaded media files; backup copies of Service dataEU (eu-central-1) or US (us-east-2), matching your data region

Data residency: Customer research data at rest (database records, uploaded files, vector indices) is stored in the customer's selected region — EU (Frankfurt) by default, or the United States for customers who choose US residency. Account, authentication, and organization registry data is stored in the EU (Frankfurt). Transient AI processing may occur outside your region as described in Sections 7.1 and 8.

7.3 Analytics and Monitoring Providers

Analytics and monitoring providers, what each one receives, and where it is processed
ProviderPurposeData SharedLocation
SentryError tracking, performance monitoring, session replay on errorsError logs, stack traces, device info, IP addressUnited States
CloudflareFirst-party, aggregated usage analyticsAggregated usage metricsGlobal (Cloudflare network)

Sentry Error Tracking and Session Replay: When errors occur in the Service, we automatically collect diagnostic information including:

  • Error messages and stack traces
  • Browser and device information
  • User actions leading to the error (session replay; text inputs and sensitive fields are masked, and we apply automated PII scrubbing before transmission)
  • Performance metrics

This data helps us identify and fix bugs to improve the Service. You can control analytics collection through our cookie consent manager.

We do not currently use third-party product analytics or web analytics services (such as Google Analytics or PostHog). If we introduce such a service in the future, we will update this Privacy Policy and, where required, request your consent through our cookie consent manager first.

7.4 Payment Processing

Payment processing providers, and what each one receives
ProviderPurposeData Shared
StripeSubscription and payment processingBilling information, transaction data

7.5 Email Services

Email service providers, and what each one receives
ProviderPurposeData Shared
Amazon Web Services (AWS SES)Transactional emails, notifications, participant communicationsEmail addresses, names
CloudflareEmail deliveryEmail addresses, names

7.5a Meeting Recording Services

Meeting recording services, what each one receives, and where it is processed
ProviderPurposeData SharedLocation
Recall.aiMeeting bot for recording video conferences (Zoom, Google Meet, Microsoft Teams)Meeting audio/video, participant informationUnited States

7.5b Integrations and Connected Accounts

The Service lets our customers connect their own accounts with third-party services and platforms. When a customer connects such an integration, personal data may be exchanged between the Service and that provider at the customer's direction and under the customer's own agreement with that provider. We are not the controller of the data you hold in those third-party services, and their handling of your data is governed by their own terms and privacy policies. Examples of integrations a customer may connect include:

  • Participant recruitment platforms (such as Prolific), used to source Research Participants
  • Incentive and reward payout providers, used to send rewards to Research Participants
  • Calendar and scheduling (such as Google Calendar)
  • Storage and productivity tools (such as Google Drive, Microsoft Teams, GitHub, Linear, and Jira/Atlassian), used to import research material or export results

Data flows through these integrations only when a customer connects and configures them.

7.6 Advertising Partners

We do not currently share personal data with advertising partners, and no third-party advertising cookies or tracking pixels are placed by the Service.

If we introduce advertising partners in the future, no advertising cookies will be placed and no data will be shared with such partners until you actively consent through our cookie consent manager (for EEA, UK, and Swiss users, consent is the sole legal basis for such sharing). You would be able to withdraw your consent at any time, and we would cease sharing your data with advertising partners immediately.

7.7 Other Disclosures

We may also share your information:

  • With your consent: When you direct us to share information with third parties
  • For legal reasons: To comply with laws, legal processes, or government requests
  • For safety and security: To protect the rights, property, or safety of Flob Inc., our users, or others
  • In business transfers: In connection with a merger, acquisition, bankruptcy, or sale of assets
  • With service providers: Contractors and agents who perform services on our behalf, bound by confidentiality obligations

8. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws than your home country.

8.1 Data Residency

Customer research data at rest is stored in the customer's selected region — EU (Frankfurt) by default, or the United States for customers who choose US data residency. Account, authentication, and organization data is stored in the EU (Frankfurt). However, to provide AI analysis and related features, research content is transmitted to third-party providers for transient processing, several of which are US-based companies; this processing is covered by the transfer mechanisms below.

8.2 Transfer Mechanisms

For transfers from the EEA, UK, or Switzerland to the United States and other countries without an adequacy decision, we rely on:

  • Standard Contractual Clauses (SCCs): EU Commission-approved contractual terms, executed with all subprocessors that receive such transfers
  • EU-US Data Privacy Framework (DPF): For transfers to DPF-certified US companies
  • Your consent: Where appropriate and where you have provided explicit consent

We maintain a Transfer Impact Assessment covering these transfers, following the European Data Protection Board's recommendations, and re-evaluate it at least every six months.

8.3 Safeguards

We implement appropriate safeguards to protect your data during international transfers, including:

  • Encryption in transit and at rest
  • Zero- or minimal-retention processing by AI providers (data is processed and discarded, not stored)
  • Access controls and authentication
  • Contractual protections with service providers, including prohibitions on model training and data-deletion obligations

9. Data Retention

We retain your personal data for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

9.1 Retention Periods

Retention period by data category
Data CategoryRetention Period
Account dataDuration of account + 30 days after deletion request
Research contentDuration of account + 30 days after deletion
Research Participant dataPer the Research Organizer's instructions; deleted with the associated research content
Billing records7 years (legal requirement)
Usage logs90 days
Support communications3 years
Marketing consent recordsDuration of consent + 3 years

9.2 Deletion

When you delete your account or request data deletion:

  • Your personal data will be deleted or anonymized within 30 days
  • Backup copies may be retained for up to 90 days
  • We may retain certain data as required by law or for legitimate business purposes

10. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data.

Research Participants: if your data was collected as part of a study run by one of our customers, the Research Organizer is the data controller — please direct your request to them as described in Section 3.4. We will assist them in fulfilling it. The rights below apply where Flob Inc. is the data controller.

10.1 Rights Under GDPR (European Union, EEA, UK)

If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights under the General Data Protection Regulation:

Right of Access (Article 15): You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data.

Right to Rectification (Article 16): You have the right to correct inaccurate personal data and to complete incomplete data.

Right to Erasure ("Right to be Forgotten") (Article 17): You have the right to request deletion of your personal data in certain circumstances.

Right to Restriction of Processing (Article 18): You have the right to request that we restrict processing of your personal data in certain circumstances.

Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

Right to Object (Article 21): You have the right to object to processing based on legitimate interests, including profiling and direct marketing.

Rights Related to Automated Decision-Making (Article 22): You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.

Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

Response Time: We will respond to your requests within 30 days, which may be extended by two further months where necessary.

10.2 Rights Under CCPA (California)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the purposes of collection, and the categories of third parties with whom we share your information.

Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.

Right to Correct: You have the right to request correction of inaccurate personal information.

Right to Opt-Out of Sale/Sharing: You have the right to opt out of the "sale" of your personal information and the "sharing" of your personal information for cross-context behavioral advertising.

Right to Limit Use of Sensitive Personal Information: You have the right to limit the use and disclosure of sensitive personal information.

Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

Categories of Personal Information Collected: In the past 12 months, we have collected the following categories of personal information: identifiers, commercial information, internet activity, geolocation data, professional information, and inferences.

"Sale" and "Sharing" of Personal Information: We do not "sell" personal information, and we do not currently "share" personal information for cross-context behavioral advertising. If that changes, we will update this notice and provide the required opt-out mechanisms before any sale or sharing occurs.

10.3 Rights Under LGPD (Brazil)

If you are located in Brazil, you have the following rights under the Lei Geral de Proteção de Dados:

  • Confirmation of the existence of processing
  • Access to personal data
  • Correction of incomplete, inaccurate, or outdated data
  • Anonymization, blocking, or deletion of unnecessary or excessive data
  • Data portability
  • Deletion of data processed with consent
  • Information about sharing with third parties
  • Information about the possibility of denying consent
  • Revocation of consent

10.4 Rights Under Other Jurisdictions

Canada (PIPEDA): Canadian residents have rights to access and correct personal information, and to withdraw consent subject to legal restrictions.

Australia (Privacy Act): Australian residents have rights to access and correct personal information under the Privacy Act 1988.

10.5 Exercising Your Rights

To exercise any of your privacy rights, please contact us at:

Email: support [at] reos [dot] ai

Mail: Flob Inc. Attn: Privacy Request 1111B S Governors Ave STE 49827 Dover, DE 19904 United States

We may need to verify your identity before processing your request. We will respond to verified requests within the timeframes required by applicable law.


11. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage.

11.1 Security Measures

  • Encryption: Data is encrypted in transit (TLS 1.3/HTTPS) and at rest (AES-256)
  • Access Controls: Role-based access controls, two-factor authentication (TOTP and passkeys), and configurable MFA enforcement
  • Infrastructure Security: Secure cloud infrastructure with Cloudflare WAF, DDoS protection, and rate limiting
  • Credential Protection: API keys and sensitive credentials are encrypted at the application level before storage
  • Monitoring: Security monitoring, audit logging, and alerting for suspicious activity
  • Vendor Security: Third-party vendors are evaluated for security certifications and practices, with data processing agreements in place

11.2 Certifications and Independent Audits

Flob Inc. maintains:

  • SOC 2 Type II attestation (independent audit of our security, availability, and confidentiality controls over time)
  • ISO/IEC 27001 certification (information security management system)
  • ISO/IEC 42001 certification (AI management system, covering the responsible development and operation of our AI features)
  • A GDPR compliance program, including records of processing activities, transfer impact assessments, and data protection reviews

Audit reports and certificates are available to customers on request, subject to confidentiality obligations.

While we maintain these certifications and safeguards, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11.3 Your Responsibilities

You are responsible for:

  • Maintaining the security of your account credentials
  • Using strong, unique passwords
  • Enabling two-factor authentication
  • Notifying us promptly of any unauthorized access

11.4 Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities as required by applicable law.


12. Children's Privacy

The Service is not intended for use by individuals under the age of 18, and we do not knowingly collect personal information directly from children under 18 as account holders. If we become aware that we have collected such information, we will take steps to delete it promptly.

Research Organizers may only involve minors as Research Participants where they have obtained verifiable parental or guardian consent and comply with all applicable children's privacy laws, as required by our Terms of Service; the Research Organizer is the data controller for such data.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support [at] reos [dot] ai.


13. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and track information about your use of the Service. For detailed information about our use of cookies, please see our Cookie Policy.

13.1 Types of Cookies

  • Essential Cookies: Required for the Service to function (authentication, security)
  • Functional Cookies: Remember your preferences (theme, settings)
  • Analytics Cookies: Help us understand how you use the Service (error tracking and diagnostics)
  • Advertising Cookies: Not currently used; if introduced, they will require your prior consent

13.2 Your Choices

You can manage your cookie preferences through our cookie consent banner or by adjusting your browser settings. Note that disabling certain cookies may affect the functionality of the Service.


14. Do Not Track Signals

Some browsers transmit "Do Not Track" (DNT) signals. Our Service does not currently respond to DNT signals, as there is no industry standard for handling such signals. You can manage tracking through our cookie consent manager.

Global Privacy Control (GPC): Because we do not sell personal information and do not share personal information for cross-context behavioral advertising, there is currently no sale or sharing for a GPC signal to opt you out of. If our practices change, we will honor GPC signals as required by applicable law.


15. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party websites you visit.


16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by:

  • Posting the updated Privacy Policy on the Service
  • Updating the "Last Updated" date
  • Sending you an email notification (for material changes)

Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.

We encourage you to review this Privacy Policy periodically.


17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Flob Inc. 1111B S Governors Ave STE 49827 Dover, DE 19904 United States

Email: support [at] reos [dot] ai

Data Protection Contact: For GDPR-related inquiries, you may contact our data protection point of contact at the same address.

17.1 Complaints

If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with your local data protection authority:


18. California Privacy Notice

This section provides additional information for California residents pursuant to the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).

18.1 Categories of Personal Information

In the preceding 12 months, we have collected the following categories of personal information:

Categories of personal information collected
CategoryExamplesCollected
IdentifiersName, email, IP address, account IDYes
Personal Information (Cal. Civ. Code 1798.80)Name, address, phone numberYes
Protected Classification CharacteristicsNone intentionally collectedNo
Commercial InformationPurchase history, subscription recordsYes
Biometric InformationNone collected for identification purposesNo
Internet ActivityBrowsing history, interactions with ServiceYes
Geolocation DataIP-based approximate locationYes
Sensory DataAudio/video files you uploadYes
Professional InformationJob title (if provided)Yes
Education InformationNone intentionally collectedNo
InferencesUsage patterns, preferencesYes
Sensitive Personal InformationAccount credentialsYes

18.2 Sources of Personal Information

We collect personal information from:

  • You directly (account creation, content upload)
  • Automatically (usage data, device information)
  • Third parties (OAuth providers, payment processor)

18.3 Business or Commercial Purposes

We use personal information for the purposes described in Section 5 of this Privacy Policy.

18.4 Disclosure for Business Purposes

We disclose personal information to the categories of third parties described in Section 7 of this Privacy Policy.

18.5 Sale and Sharing of Personal Information

Note for EEA/UK/Swiss Users: The terms "sale" and "sharing" used in this section are specific legal definitions under California law (CCPA/CPRA) and do not reflect how we process data for users in the EEA, UK, or Switzerland.

For California Residents: We do not "sell" personal information, and we do not currently "share" personal information with advertising partners for cross-context behavioral advertising. If our practices change, we will update this notice and provide an opt-out mechanism (including honoring Global Privacy Control signals) before any sale or sharing occurs. You may contact us about your rights at any time by emailing support [at] reos [dot] ai with the subject line "California Privacy Request."

18.6 Retention

We retain personal information as described in Section 9 of this Privacy Policy.


This Privacy Policy was last updated on August 19, 2026.