VoiceFlowgent. Last updated: 31 August 2026
VoiceFlowgent builds and operates business automation systems for its clients. Our software connects to accounts and tools that the client already owns, and runs workflows on infrastructure the client owns and controls.
This policy explains three things: what our software can touch, what we do and do not do with it, and how access is removed.
The principle everything else follows from
The client owns their accounts, their data, and the server the automation runs on. We build the system that moves data between them. We are not a destination for that data.
Read every section below through that principle and it will make sense.
Whose data this covers
Client data. Information inside a client's own connected systems that an automation reads, writes or moves.
Website visitor data. Information collected when someone browses voiceflowgent.com. Covered separately at the end.
What our software can access
An automation only ever connects to systems the client explicitly authorises, and only to the extent the commissioned work requires. Depending on what the client asks us to build, that may include:
Email and calendar. Reading messages, attachments and calendar entries in a connected mailbox, and sending mail or notifications from it. Providers include Google Gmail, Microsoft Outlook and Microsoft 365.
Files, documents and spreadsheets. Reading and writing files in a connected storage account. Providers include Google Sheets, Google Drive, Microsoft Excel and OneDrive.
Databases and business records. Reading and writing records in a connected database or CRM. Providers include Airtable, Supabase, PostgreSQL, HubSpot, Salesforce and Zoho.
Messaging channels. Reading and sending messages on channels the client connects, such as WhatsApp, Telegram and Slack.
Calls, meetings and transcripts. Where a client commissions call or meeting automation, recordings and transcripts they already hold or generate, through their own telephony and meeting tools.
AI and processing services. Where a workflow needs a document read, text understood or audio transcribed, the relevant content is sent to an AI provider such as OpenAI, Anthropic or Deepgram.
The list names providers as examples of each category, not as a fixed set. A client using a different tool in the same category is covered by the same terms.
How access is granted and removed
Access is granted by the account owner, through that provider's own consent screen or by issuing a key. It is never obtained any other way.
Access can be withdrawn by the account owner at any time, without asking us. For Google accounts that is myaccount.google.com/permissions. Other providers have an equivalent screen. Clients can also ask us to disconnect and we will do so.
Withdrawing access stops the automation. It does not delete anything the client owns.
What we do with the data
Data is processed only to deliver the automation the client commissioned. For example, extracting order details out of incoming email and into the client's own spreadsheet.
Data stays inside the client's own connected accounts and on the client's own server. It is not copied onto VoiceFlowgent's systems as a matter of course, not retained by us, not sold, not shared with anyone outside the flow the client asked for, and not used for advertising.
We do not build profiles, do not aggregate one client's data with another's, and do not reuse client data to develop products for anyone else.
AI processing and model training
Where an automation uses an AI model, the content sent to that model is sent under the client's own API account with that provider, governed by that provider's terms.
Content sent through those API accounts is not used to train models. This is the standard commercial API position of the providers we work with. We do not train any model of our own on client data.
Google API Services: Limited Use disclosure
VoiceFlowgent's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy
Specifically, data obtained through Google APIs is:
used only to provide or improve the user-facing features of the automation the account owner authorised
not transferred to third parties except as necessary to provide those features, or where required by law
not used for advertising, and not sold
not read by humans, except with the account owner's explicit consent, for security purposes such as investigating abuse or a fault, or to comply with applicable law
Other providers
Where an automation connects to Microsoft, or to any other provider, we apply the same standard: least access necessary, use limited to the commissioned automation, no onward transfer, no advertising use, no human reading without consent.
Access by our people
Our staff do not routinely read client data. A person may see it only in three situations: the client asks us to look at something, a fault or security incident has to be investigated, or the law requires it. Access is limited to what the situation needs.
Sub-processors
Delivering an automation may involve infrastructure and service providers, such as the hosting platform the automation runs on and the AI providers named above. Where a client's data reaches such a provider, it does so as part of the workflow the client authorised, under that provider's own terms, and usually under the client's own account.
Retention and deletion
We do not retain copies of client data as part of normal operation. Where a build or support task requires temporary working copies, they are deleted when that task is finished.
Deletion is therefore mostly in the client's hands: revoke the connection at the provider, delete the records inside their own systems, and the data is gone. If a client asks us to disconnect and delete anything we hold, we do it and confirm.
Security
Automations run on infrastructure the client owns and controls. Credentials are stored in the automation platform's encrypted credential store, never in workflow code, never in plain text, and never in shared documents. Connections use the provider's own authorised methods.
Visitors to this website
voiceflowgent.com is a brochure website. Browsing it does not connect you to any automation.
The site is hosted on a third-party website platform, which may set cookies necessary to serve the site and may collect standard technical logs such as IP address, browser type and pages viewed.
If you contact us through a form or by email, we use what you send only to reply and to discuss the work.
We do not sell website visitor data.
You can block or clear cookies in your browser at any time.
Children
Our services are sold to businesses. The website and our services are not directed at children, and we do not knowingly collect data about them.
Your rights
If you are a client or a website visitor, you can ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted. Write to the address below and we will respond.
Changes to this policy
If this policy changes, the updated version is posted on this page with a new last updated date. Material changes affecting an active client will also be raised with that client directly.
Contact
Questions about this policy, or any request under it: sheikh.abdullah@voiceflowgent.com.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.