Privacy Policy
Last updated: July 26, 2026
1. Scope
This Privacy Policy describes how Jade’s Gems & SOULutions LLC, doing business as DivineX (“DivineX,” “we,” “us,” or “our”) collects, uses, and protects information in connection with Flow, our hosted Growth Operations Platform, and our marketing website.
Flow is a hosted service: we host your workspace and your data on infrastructure we operate (through the subprocessors listed in Section 8). If you are a business using Flow to manage your own customers or leads, you (or your organization) are generally the data controller for that customer/lead data, and DivineX acts as a data processor on your behalf for that data — while we are the controller for your own account information (Section 2 below).
2. Information We Collect
2.1 Account information
When you create an account, we collect your name, email address, and (through our payment processor) billing information. Firebase Authentication is used to manage sign-in; we do not store your password directly — Firebase handles credential storage.
2.2 Customer/contact data you store in Flow
Flow lets you store and manage data about your own leads and customers — names, emails, phone numbers, notes, deal/pipeline information, calendar events, form submissions, and similar business records you or your team enter or import. This data is yours; we process it to provide the Service.
2.3 Communications sent and received through Flow
If you use Flow’s email, SMS, WhatsApp, voice, or web chat features, we store the content of those messages/calls (and metadata such as timestamps and delivery status) so you can see your own conversation history. This includes:
- AI conversation content — if you enable an AI Agent (web chat, SMS, WhatsApp, voice) or use the in-app AI assistant, the messages exchanged are stored in our database, and the message content is sent to our AI model provider (OpenRouter) to generate a reply. Voice calls are additionally processed by our voice AI provider (Vapi), which converts speech to text and back and provides call summaries/transcripts that we store. See our Responsible AI Policy for more on how these features work.
- Web chat sessions are tied to a session identifier stored in the visitor’s browser (see Section 4) rather than to a login, until/unless the visitor provides their name, email, or phone during the conversation.
2.4 Files you upload
Most of Flow does not involve file uploads. Where it does — currently, profile/cover images for the Community feature (group and course cover images, member avatars) — uploaded files are stored via Firebase Storage.
2.5 Location information
When someone submits a public hosted form, we derive an approximate location (city-level, from IP address via a third-party lookup service) and, as a fallback, a country-level location from the phone number’s country code, to power features like the leads map. This is best-effort and may be null.
2.6 Website usage
When you visit our marketing site or use the app, we may collect basic technical information (IP address, browser type, pages viewed) through standard server logs.
3. How We Use Information
We use the information above to: provide and operate the Service; process your subscription and payments; deliver the messages/calls/automations you configure; generate AI responses where you’ve enabled AI features; provide customer support; maintain security and prevent abuse; and communicate with you about the Service. We do not sell your personal information.
4. Cookies
Flow uses a small number of functional cookies, all necessary for the Service to work — we do not use advertising or cross-site tracking cookies:
| Cookie | Purpose | Duration |
|---|---|---|
__session | Signed-in session (Firebase auth) | ~12 days |
| Community member session | Signed-in session for the Community feature | ~30 days |
| SSO handoff cookies | Short-lived, used only during the Ascend→Flow sign-in handoff | Seconds to 30 seconds, then cleared |
We also use localStorage (not a cookie, but similar in effect) for a few non-sensitive purposes: remembering an anonymous web-chat visitor’s session ID, whether you’ve dismissed certain in-app banners, and your conversation-view theme preference.
5. Analytics & Tracking
We do not currently use any analytics, advertising, or tracking technology on Flow. No analytics SDK, advertising pixel, session-replay tool, or error-monitoring service is active in production today. The platform has the underlying capability to optionally enable Meta (Facebook) Pixel, Google Tag Manager, and live chat in the future; if any of these are switched on, we will update this Privacy Policy first to describe what they collect before they go live.
6. Payment Processing
Flow’s own subscription billing (what you pay DivineX to use the Service) is processed by Stripe; we do not store your full card number ourselves.
Separately, Flow lets you (as a subscriber) invoice and collect payment from your own customers, using either your PayPal.me link or a Stripe payment option tied to this deployment’s Stripe account. DivineX is not a party to those downstream payments between you and your customers, and is not responsible for disputes arising from them — but because card payments there run through the same shared Stripe account, that transaction data is processed by Stripe on our behalf as well.
7. Data Storage & Security
Your data is stored using Firebase/Firestore and Firebase Storage (Google Cloud infrastructure), secured with authentication, per-workspace access rules, and encryption in transit (HTTPS) and at rest (as provided by Google Cloud). Workspace isolation is enforced at the data layer, not just the UI — one workspace’s data is never readable by another workspace’s users. Sensitive tokens (API keys, webhook secrets) are hashed or encrypted before storage. No security measure is perfect, and we cannot guarantee absolute security.
8. Third-Party Processors
Depending on which features you use, the following third parties may process data on our behalf:
| Service | Purpose | Data involved |
|---|---|---|
| Firebase / Google Cloud | Database, authentication, file storage | All account and customer data |
| Render | Application hosting | All data that passes through the application at runtime |
| Stripe | Payment processing | Billing/payment details |
| Twilio | SMS, WhatsApp, and voice number provisioning | Phone numbers, message/call content |
| Resend | Transactional and bulk email delivery | Email addresses, message content |
| OpenRouter | AI model inference (text) | AI conversation content |
| Vapi | AI voice call handling | Call audio, transcripts |
| Deepgram | Speech-to-text for AI voice calls, via Vapi | Call audio (voice channel only) |
| ElevenLabs | Text-to-speech for AI voice calls, via Vapi | AI-generated call audio (voice channel only) |
| Firecrawl | Optional website content scraping (AI knowledge base) | Public website content you point it at |
| Meta (Facebook/Instagram) | Optional inbox + social posting integration | Message content, connected Page data |
| Mapbox | Map rendering (leads map, booking) | Approximate location data |
| ipapi.co | IP-based geolocation on form submissions | IP address |
| Web push provider (VAPID) | Optional browser push notifications | Push subscription endpoint |
Deepgram and ElevenLabs are Vapi’s own default providers for the voice channel (speech-to-text and text-to-speech, respectively) — we don’t connect to them directly, but voice call audio passes through them as part of how Vapi delivers the feature. Each provider processes only what’s needed for the feature it powers, and features requiring a given provider are unavailable if it isn’t configured.
9. Data Retention
We retain your account and customer data for as long as your account is active. If you cancel or your account is terminated, we retain Your Data for 30 days to allow for export or reactivation. After that period, Your Data is deleted from our production systems as part of our standard account-closure process.
10. Data Deletion & Your Rights
You can delete individual contact records yourself from within the app at any time. Full account or workspace deletion is handled by support request — contact us to request deletion of your account or data, and we will act on verified requests. Depending on your location, you may have rights to access, correct, or delete your personal information, or to receive a copy of it, under applicable law (for example, GDPR or CCPA where they apply). Contact us to exercise these rights.
11. Children’s Privacy
Flow is a business tool and is not directed at, or intended for use by, children. We do not knowingly collect personal information from children under 13 (or the relevant minimum age in your jurisdiction). If you believe a child has provided us with personal information, contact us and we will delete it.
12. Related Documents
This Privacy Policy should be read together with our Terms of Service and Responsible AI Policy.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a new “Last updated” date and, for material changes — including turning on any new tracking technology (Section 5) — provide reasonable notice before the change takes effect.
14. Governing Law
This Policy is governed by the laws of the State of Texas, United States, without regard to conflict-of-laws principles.
15. Contact
For questions about this Privacy Policy or to exercise your data rights, email hello@divinex.io, or write to us at:
Jade’s Gems & SOULutions LLC
440 Louisiana St
Houston, TX 77002
United States