security & data

flo can look.
she can't touch.

you're giving an assistant the keys to your inbox and your books — you should know exactly how far those keys turn. here's the honest version.

gmail is read-only

flo's gmail scope can look at mail, and that's it. she cannot send, delete, label-spam, or reply on your behalf — the permission doesn't exist in her token.

your tokens are encrypted at rest

gmail and xero oauth tokens are stored encrypted, and never leave our servers. revoke access any time from settings — or directly from your google / xero account.

she never guesses on your books

only high-confidence invoices are filed automatically. anything uncertain — duplicates, new vendors, fuzzy totals — waits in your review queue for a human click.

minimal xero footprint

flo writes bills, attachments and the payment fixes you approve. she does not touch invoices you raise, payroll, contacts beyond vendors, or anything she wasn't asked to.

your data is not the product

no selling, no ad profiles, no training third-party models on your books. flo reads what she needs to file your invoices, and that's the whole business model.

leave cleanly

disconnect an inbox and flo stops reading it immediately. wipe your chat history with one click. everything she filed lives in your xero — it was always yours.

the practical bits

  • encrypted in transit (tls) and at rest
  • oauth only — flo never sees your passwords
  • push notifications are opt-in, per device
  • scoped api access, least-privilege by default
  • you can disconnect any integration in settings
  • report anything odd: [email protected]

the longer, legal-flavoured version lives in the privacy policy. questions we haven't answered? ask us directly.

trust is earned in the queue.

start flo on a slow week, watch what she files and what she asks about. that's the whole pitch.

hire flo — free →