Flourisha

Privacy Policy

Version 1.2 · Effective August 28, 2026


What this policy is, in plain words. Flourisha reads your documents to help you organize and understand them. To do that, she sends the text of those documents to outside AI providers for processing. That means your document content does not stay only on Flourisha's own servers. This policy tells you what she collects, who she sends it to, how long it is kept, that it is not used to train AI models, and the choices and rights you have, including specific rights for California residents whose documents contain health or financial information.


1. Who We Are

Flourisha (the "Service") is operated by Harmony Group, Inc. ("Harmony Group," "we," "us," or "our"), a Florida corporation located at 2637 East Atlantic Blvd, #1321, Pompano Beach, FL 33062.

Flourisha is a personal AI operating system that helps you capture, organize, understand, and act on your documents and information. This Privacy Policy applies to your use of the Flourisha web application, browser extension, and mobile app (together, the "Service").

2. Information We Collect

Account information. When you create an account, we collect your name, email address, and authentication details.

Documents and content you provide. Flourisha is built to work with your documents. This may include highly sensitive material, for example tax letters, financial statements, bank records, health documents, legal contracts, and scanned physical mail. We collect the documents you upload, the text and data extracted from them, the notes you write, and the messages you send when you chat with Flourisha about your documents. Because you decide what to upload, the content you give us may include categories of sensitive personal information described in Section 8.

Billing information. If you are on a paid plan, our payment processor, Stripe, collects your billing address and payment-card details directly from you and processes the payment. We receive only what we need to run your account, for example your billing contact details, the plan you are on, and whether a payment succeeded. We never receive or store your full card number.

Connected accounts. If you connect a third-party service (for example, Google Drive), we access only the specific files or folders you authorize through that service's consent screen. We index those files to make them searchable and usable in Flourisha. We do not copy your entire drive.

Usage information. We collect technical information about how you use the Service, such as log data, device and browser information, and feature usage, to operate and improve the Service.

3. How We Use Your Information

We use your information to:

  • Provide the Service, meaning to store, organize, classify, search, and let you chat with your documents.
  • Generate AI-powered responses when you ask Flourisha questions about your documents.
  • Maintain, secure, and improve the Service.
  • Communicate with you about your account and the Service.

We use the content of your documents only to provide these functions to you. We do not use your document content to build profiles about you for our own purposes, and we do not use it to train any AI model, ours or a provider's.

4. AI Processing and the Providers We Use (please read this section carefully)

Flourisha uses third-party artificial-intelligence providers to make sense of your documents. This means that when you use certain features, the text of your documents is transmitted to these providers for processing. Your documents do not stay solely on Flourisha's own servers during these operations. We use these providers under their commercial and API terms, which do not permit them to train their models on your content by default.

We currently use the following AI providers:

Anthropic (Claude API). Flourisha uses Anthropic's Claude API for several features. When you upload a document, Flourisha sends it to Claude to classify it and pull out key fields. That upload request travels through OpenRouter, an AI gateway service that passes the request on to Anthropic for us. We configure OpenRouter to route these requests only to Anthropic and to no other provider. If the gateway is unavailable, Flourisha sends that request straight to Anthropic instead. A number of other Flourisha features send text straight to Anthropic's Claude API by design, for example summarizing meetings and transcripts, pulling details out of your documents, and organizing your records. Whether a request goes through OpenRouter or directly, it runs under Anthropic's Commercial Terms of Service, and under those terms Anthropic does not train its models on your content. Anthropic keeps API data only for a limited period (up to 30 days) for operations and abuse prevention, and may keep content longer only if a specific request is flagged for a safety review. Content kept for safety review is still never used to train models.

Google (Gemini API). When you chat with a document, Flourisha sends the relevant document text to Google's Gemini API (a paid Google Cloud service) to generate the response you see. Under Google's terms for paid Gemini API use, Google does not use your prompts or responses to improve its products or to train its models. Google logs this content only for a limited period (currently up to 55 days) to detect and prevent policy violations, and does not use it for model training.

OpenAI (Embeddings API). To make your documents searchable, Flourisha sends document text to OpenAI's embeddings API, which converts the text into a numerical representation used for search. Under OpenAI's API terms, data sent to the OpenAI API is not used to train or improve OpenAI's models by default. OpenAI retains API content for up to 30 days for abuse-monitoring purposes and then deletes it, unless a longer period is legally required.

What this means for you in plain language: To answer your questions and organize your files, Flourisha sends your document content to the AI providers above. None of the AI model providers above use your content to train their AI models under the terms we use. We do not sell your documents, and we do not use your documents to train any AI model ourselves. Beyond the AI providers named here, a small number of service providers help us run the Service, for example the hosting provider that stores your data, the gateway that passes AI requests on for us, the payment processor that handles your billing, and the service that receives documents you email to your Flourisha address. They are listed in Section 5, and we do not authorize any of them to use your content to train AI models.

5. Other Service Providers (Subprocessors)

In addition to the AI providers above, we use the following service providers to operate Flourisha. They process data on our behalf under written contracts that require them to protect it and to use it only to provide services to us.

ProviderPurposeData involved
AnthropicAI document classification and field extractionDocument content
Google (Gemini API)AI chat responses and entity extractionDocument content during chat and extraction
OpenAIText embeddings for searchDocument text
OpenRouterAI gateway. Passes our document-classification requests on to Anthropic (see Section 4). It is a routing service, not an AI model providerDocument content, including the uploaded file itself, in transit to Anthropic
DeepgramAudio and meeting transcriptionAudio you record, if you use voice or meeting features
ContaboServer hosting and backups. Flourisha's database, file storage, and search run as self-hosted software on Contabo's serversAll of your processed data at rest, including documents, extracted data, and embeddings
CloudflareReceiving documents you email to your Flourisha address, and content delivery / DNSEmails and attachments you send in; general web traffic to the Service
NangoSecure OAuth connection to your linked accounts (e.g., Google Drive)Authorization tokens only (no document content)
Google (Drive API)Access to the files/folders you connectThe specific files you authorize
Google (Gmail)Sending you notification and account emailYour email address and the notice we send (no document content)
StripePayment processing, subscriptions, and billing, if you are on a paid planYour name, email address, billing address, and payment-card details, which you give to Stripe and which Stripe holds. We never receive or store your full card number. No document content

Flourisha's database, file storage, search index, and application run as open-source software that we operate ourselves on Contabo's servers. The software projects behind that stack (for example, the open-source Supabase project) do not receive your data; only our hosting provider, Contabo, holds it at rest, which is why they appear as a single entry above rather than as separate companies.

We keep this list current and will update it as our providers change. If we add or change a subprocessor that handles your document content, we will update this list and, for material changes, note it in the "Last updated" date.

6. How We Share Your Information

We share your information only as described in this policy:

  • With the AI providers and subprocessors listed above, to operate the Service.
  • If required by law, legal process, or to protect rights, safety, and security.
  • In connection with a merger, acquisition, or sale of assets, in which case we will notify you.

We do not sell your personal information, we do not "share" it for cross-context behavioral advertising, and we do not use your documents to train AI models.

7. Data Retention

We keep your account information and documents for as long as your account is active.

When you delete a document. Deleting a document removes it from your library right away, so it no longer appears in Flourisha or in your search results, and it removes the document file and its record from our systems. Some data we derived from the document to power search and organization, such as its search index entries, can remain for a period afterward. We are rolling out an automated process that erases this derived data as well. Until that process is fully in place, you can email privacy@flourisha.ai, where a member of our team receives your request, erases the derived data by hand, and confirms to you when it is done.

Documents you email in. Documents that reach Flourisha through your personal Flourisha email address first arrive in a capture inbox. When you delete a document from that inbox, it is not erased right away. It moves into a holding area, where our design keeps it for up to 30 days. Automatic removal from that holding area is still being built. Until it is in place, email privacy@flourisha.ai and a member of our team will erase the document for you and confirm when it is done.

When you close your account. You can ask us to close your account at any time by emailing privacy@flourisha.ai. We do not close or deactivate accounts automatically. When you make the request, a member of our team deactivates your account and removes your data, and confirms to you when it is done. We are building an automated process to carry this out in full; until it is in place, we handle account-closure requests by hand.

Deletion is always subject to legal retention requirements and to our standard backup cycles, and copies may remain in our backups until those backups age out on their normal retention schedule. AI providers keep transmitted content only for the limited periods described in Section 4.

8. Your Privacy Rights and Choices

Depending on where you live, you may have rights over your personal information. To exercise any right below, contact us at privacy@flourisha.ai or at the mailing address in Section 1. You can also disconnect any linked account at any time from the Integrations page in Flourisha.

8.1 Rights available to everyone

  • Access. Ask what personal information we hold about you.
  • Correct. Ask us to fix inaccurate personal information.
  • Delete. Ask us to delete your documents and personal information. See Section 7 for how deletion works today and how to reach us. Deletion is subject to legal retention requirements and standard backup cycles.
  • Export. Ask for a copy of the content you provided, in a portable form.

8.2 California residents (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know / access the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third parties to whom it is disclosed.
  • Delete personal information we collected from you, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Opt out of the "sale" or "sharing" of personal information. We do not sell your personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of, but you retain the right.
  • Limit the use and disclosure of your sensitive personal information (see Section 8.3).
  • Non-discrimination. We will not deny you service, charge you a different price, or give you a lesser quality of service for exercising your rights.

Categories of personal information we collect are described in Section 2 (account information, billing information, document content, connected-account data, and usage information). We do not sell or share personal information. Under California law, our transmission of your document content to the AI providers and subprocessors in Sections 4 and 5 is a disclosure to service providers that process the content only to provide the Service to us. It is not a "sale" (which requires that we receive money or other valuable consideration for the disclosure, Cal. Civ. Code § 1798.140(ad)) and it is not a "share" (which requires disclosure for cross-context behavioral advertising, Cal. Civ. Code § 1798.140(ah)). We pay these providers to process data for us; we are not paid for your data.

To exercise a California right, email privacy@flourisha.ai. We will verify your request against the information in your account before acting on it. You may use an authorized agent to submit a request; we may ask the agent for proof of authorization. If we decline a request, you may ask us to reconsider.

8.3 Sensitive personal information (health and financial documents)

Because you decide what to upload, the documents you give Flourisha may contain sensitive personal information as defined in Cal. Civ. Code § 1798.140(ae), including, depending on what you upload, information about your health, financial account numbers together with an access or security code, government identifiers found in tax and legal documents, and the contents of your mail or messages.

We use this sensitive personal information for one purpose only: to provide the Service you asked for, meaning to store, organize, classify, search, and answer your questions about your own documents. We do not use it to infer characteristics about you for our own purposes, we do not sell or share it, and we do not use it to train any AI model.

Because we use your sensitive personal information only to provide the Service you requested, and not to infer characteristics about you or for any other purpose, we are not required to offer a separate "Limit the Use of My Sensitive Personal Information" control. If our use of sensitive personal information ever changes, we will provide that control and tell you.

8.4 EU / UK residents

The Service is directed to users in the United States and is not marketed to residents of the European Union, the European Economic Area, or the United Kingdom. If Flourisha begins serving EU/UK users, we will add GDPR / UK-GDPR rights and the processor safeguards those laws require before that launch.

9. Security

We use technical and organizational measures to protect your information. We encrypt data in transit, and we control and limit access to it and to the systems that hold it. No system is perfectly secure, but we work to protect your data and to limit who can reach it.

10. Children's Privacy

The Service is intended for adults. You must be at least 18 years old to use Flourisha (see the Terms of Service). We do not direct the Service to children and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from someone under 18, we will delete it.

11. Changes to This Policy

We may update this policy from time to time. Each published version carries a version identifier and an effective date. If we make material changes, we will update the "Last updated" date and notify you, and, where required or appropriate, ask you to review and accept the updated policy the next time you sign in.

12. Contact Us

If you have questions about this policy or your data, contact us at privacy@flourisha.ai or at Harmony Group, Inc., 2637 East Atlantic Blvd, #1321, Pompano Beach, FL 33062.


*Flourisha is a service of Harmony Group, Inc. © 2026 Harmony Group, Inc. All rights reserved.*

See also our Terms of Service. Questions about your data? Email privacy@flourisha.ai.