Effective Date
This Privacy Policy is effective as of October 1, 2026. It describes how Pure Grace AI, LLC handles personal information collected through https://www.floworah.com/.
Introduction
Pure Grace AI, LLC (“we,” “us,” or “our”) operates https://www.floworah.com/. This Privacy Policy explains what personal information we collect, how we use and disclose it, and the choices available to individuals whose personal information we process. Personal information means information that identifies, relates to, or could reasonably be linked with a particular individual or household.
Information We Collect
We collect personal information that individuals provide to us directly, and information that is collected automatically when an individual interacts with our website. The categories of personal information we collect depend on how an individual interacts with https://www.floworah.com/. We collect this information for the business purposes described in this Policy.
Personal Information of Consumers Under 16
We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.
How We Use Your Information
We use personal information to provide and maintain our services, to respond to inquiries, to secure our systems, and for other business purposes described at the point of collection. The purposes for which we process each category of personal information, and the period for which we retain it, are described in this Policy.
Sharing With Third Parties
We disclose personal information to third-party partners and vendors beyond our service providers, as described in this Policy. Where we disclose personal information to a third party that is not acting as our service provider or processor, we do so for the business purposes described at the point of collection. Individuals may exercise the choices described below regarding such disclosures.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate https://www.floworah.com/, remember preferences, and analyze usage. Some tracking technologies enable behavioral advertising. Individuals may manage cookie preferences through their browser settings or any cookie preference tools we make available. Our Cookie Policy provides further detail on the categories of cookies in use.
AI, Automated Processing, and Model Training
We use artificial intelligence and automated processing to provide certain features of our services. Where automated processing produces a legal or similarly significant effect concerning an individual, we describe that processing and the choices available. Individuals may contact us at privacy@floworah.com with questions about our use of automated processing.
We do not process sensitive data for the purpose of training, fine-tuning, or evaluating artificial-intelligence models without the individual’s consent. Where an individual has given that consent, it may be withdrawn at any time by contacting us at privacy@floworah.com; withdrawal takes effect prospectively and does not affect processing carried out before the withdrawal. [ATTORNEY REVIEW REQUIRED]
Personal Data and Large Language Model Training
We do not collect, use, or sell personal data for the purpose of training large language models. This statement covers training performed by us and training performed by a vendor acting on our behalf. If this changes, we will update this Policy and provide notice and, where applicable law calls for it, obtain consent before personal data already collected is used for that purpose.
Your Privacy Rights
This section describes the privacy choices we make available. Regardless of where an individual lives, we offer every individual the ability to ask us what personal information we hold about them, to ask us to correct it, to ask us to delete it, to ask for a copy of it, and to tell us not to sell or share it. The sections that follow describe the additional rights that particular state privacy laws give to residents of those states, the conditions attached to them, and how they are exercised. Where a state law gives a resident of that state a right that goes beyond the choices described in this section, the state section controls for that resident.
How These Choices Apply to Us
Some privacy laws apply only to organizations above a size, revenue, or data-volume threshold, and we are below those thresholds for the laws that set them. We offer the choices described in this Policy as a matter of our own policy rather than because a particular statute obliges us to, and we honor them on the terms stated here. Where a privacy law applies to us directly, we follow that law, and the state sections below describe what it provides.
California Residents — CCPA/CPRA
This section applies to California residents and supplements the rest of this Policy under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). Under the CCPA/CPRA, a California resident is a “consumer,” and the information we handle about them is “personal information.” The rights described below are available to California residents and may be exercised as described in the Submitting a Privacy Request section.
California residents have the right to know what personal information we collect, use, disclose, and sell. [ATTORNEY REVIEW REQUIRED]
California residents have the right to request deletion of their personal information, subject to certain exceptions. [ATTORNEY REVIEW REQUIRED]
California residents have the right to correct inaccurate personal information we maintain about them. [ATTORNEY REVIEW REQUIRED]
California residents have the right to opt out of the sale or sharing of their personal information. [ATTORNEY REVIEW REQUIRED]
Notice at Collection — Categories of Personal Data We Process
This section is our notice at collection. It states each category of personal information we collect, the purpose for which we collect and use that category, and the period for which we retain it, or the criteria we use to determine that period. Whether we sell or share personal information is stated separately in this Policy.
| Category of personal information | Business or commercial purpose for collection | Retention period or criteria |
| Identifiers | To create and manage user accounts, authenticate users, provide and support the service, process subscriptions, communicate with users about their accounts, and keep the service secure. | For as long as the account is active, plus the applicable statute of limitations period. |
| Commercial information | To provide the subscription plan and add-ons purchased, manage billing and usage limits, and keep transaction records. | For as long as the account is active, plus the applicable statute of limitations period. |
| Internet or other similar network activity | To operate, secure, and troubleshoot the service, detect fraud and abuse, and keep security and audit records. | For as long as the account is active, plus the applicable statute of limitations period. |
| Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) | To set up and maintain the business profile, bill subscriptions, and contact the account holder about the service. | For as long as the account is active, plus the applicable statute of limitations period. |
| Audio, electronic, visual, thermal, olfactory, or similar information | To store, edit, generate, schedule, and publish the photos, videos, and other media users upload or create with the service, at the user’s direction. | For as long as the account is active, plus the applicable statute of limitations period. |
We disclose personal data to the following categories of third parties:
- Service providers and contractors
- Internet service providers and hosting providers
- Social networks
- Payment processors
- Government entities and law-enforcement agencies (where required by law)
- Professional advisors (e.g. attorneys, auditors, insurers)
- Parties to a merger, acquisition, or other corporate transaction
Where we sell or share personal information, the notice of the right to opt out and the choices available to individuals appear in the Your Privacy Rights section of this Policy. This Policy is available at https://www.floworah.com/, and a link leading directly to this section appears at or before the point at which we collect personal information.
California Residents — Categories of Sources
We collect personal information from the following categories of sources:
- Directly from the consumer
- The consumer’s device (automatically, as the consumer interacts with our services)
- Social networks
- Our service providers and contractors
California Residents — Sensitive Personal Information
We do not collect sensitive personal information as defined by Cal. Civ. Code § 1798.140(ae).
California Residents — We Do Not Sell or Share Personal Information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. We have not sold or shared the personal information of California residents in the preceding 12 months.
Virginia Residents — VCDPA
This section applies to Virginia residents under the Virginia Consumer Data Protection Act (VCDPA). Under the VCDPA, Pure Grace AI, LLC may act as a “controller” that determines the purpose and means of processing a consumer’s personal data. Virginia consumers have the rights described below, and may appeal a refusal to act on a request as provided by the VCDPA.
Virginia consumer rights under the VCDPA include access, correction, deletion, portability, and opt-out. [ATTORNEY REVIEW REQUIRED]
Colorado Residents — CPA
This section applies to Colorado residents under the Colorado Privacy Act (CPA). Under the CPA, a Colorado consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Colorado consumers may exercise these rights as described in the Submitting a Privacy Request section, including through a recognized universal opt-out mechanism where applicable.
Connecticut Residents — CTDPA
This section applies to Connecticut residents under the Connecticut Data Privacy Act (CTDPA), as amended effective July 1, 2026 (Public Act 25-113) and October 1, 2026 (Public Act 26-64). Under the CTDPA, a Connecticut consumer has the rights to access their personal data — including inferences we have drawn from it — and to correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects, whether or not the decision is made solely by automated means. Where a consumer requests access to personal data that consists of a Social Security number, a government-issued identifier, financial-account information, or biometric or neural data, we notify the consumer that we hold that data rather than disclosing the data itself. Sensitive data under the CTDPA includes data revealing status as nonbinary or transgender, disability or medical treatment, neural data, government-issued identifiers, financial-account information, and Social Security numbers; we process sensitive data only with the consumer’s consent. This Policy states whether we process personal data for targeted advertising and whether we engage in profiling, and the AI, Automated Processing, and Model Training section states whether we collect, use, or sell personal data for the purpose of training large language models. A Connecticut consumer also has the right to obtain a list of the third parties to which we have SOLD the consumer’s personal data or, where that consumer-specific information is not available, a list of the third parties to which we have sold personal data. Connecticut consumers may exercise these rights as described in the Submitting a Privacy Request section, including through a recognized universal opt-out mechanism where applicable, and may appeal a refusal to act on a request as described in that section. We do not sell a Connecticut consumer’s precise geolocation data.
Utah Residents — UCPA
This section applies to Utah residents under the Utah Consumer Privacy Act (UCPA). Under the UCPA as amended effective July 1, 2026, a Utah consumer has the rights to access their personal data, to correct inaccuracies in their personal data taking into account the nature of the data and the purposes of the processing, to delete their personal data, to obtain a portable copy, and to opt out of targeted advertising and the sale of personal data. Utah consumers may exercise these rights as described in the Submitting a Privacy Request section.
Texas Residents — TDPSA
This section applies to Texas residents under the Texas Data Privacy and Security Act (TDPSA). Under the TDPSA, Pure Grace AI, LLC may act as a “controller” that determines the purpose and means of processing a consumer’s personal data. Texas consumers have the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Texas consumers may exercise these rights as described in the Submitting a Privacy Request section, including through a recognized universal opt-out mechanism where applicable.
Texas Residents — Sensitive Personal Data
We do not sell the sensitive personal data or the biometric personal data of Texas residents. Where we process sensitive data, we do so with the consumer’s consent as the TDPSA provides.
Montana Residents — MCDPA
This section applies to Montana residents under the Montana Consumer Data Privacy Act (MTCDPA). Under the MTCDPA, a Montana consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Montana consumers may exercise these rights as described in the Submitting a Privacy Request section, including through a recognized universal opt-out mechanism where applicable.
Delaware Residents — DPDPA
This section applies to Delaware residents under the Delaware Personal Data Privacy Act (DPDPA). Under the DPDPA, a Delaware consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. A Delaware consumer also has the right to obtain a list of the categories of third parties to which we have disclosed the consumer’s personal data. Delaware consumers may exercise these rights as described in the Submitting a Privacy Request section, including through a recognized universal opt-out mechanism where applicable, and may appeal a refusal to act on a request as described in that section.
Nebraska Residents — NDPA
This section applies to Nebraska residents under the Nebraska Data Privacy Act (NDPA). Under the NDPA, a Nebraska consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Nebraska consumers may exercise these rights as described in the Submitting a Privacy Request section, including through a recognized universal opt-out mechanism where applicable.
New Hampshire Residents — NH Privacy Act
This section applies to New Hampshire residents under the New Hampshire Privacy Act. Under that law, a New Hampshire consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. New Hampshire consumers may exercise these rights as described in the Submitting a Privacy Request section, including through a recognized universal opt-out mechanism where applicable.
New Jersey Residents — NJDPA
This section applies to New Jersey residents under the New Jersey Data Privacy Act (NJDPA). Under the NJDPA, a New Jersey consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Sensitive data under the NJDPA includes financial information, and we handle it as described in this Policy. New Jersey consumers may exercise these rights as described in the Submitting a Privacy Request section, including through a recognized universal opt-out mechanism where applicable.
Tennessee Residents — TIPA
This section applies to Tennessee residents under the Tennessee Information Protection Act (TIPA). Under the TIPA, a Tennessee consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Tennessee consumers may exercise these rights as described in the Submitting a Privacy Request section.
Indiana Residents — INCDPA
This section applies to Indiana residents under the Indiana Consumer Data Protection Act (INCDPA). Under the INCDPA, an Indiana consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Indiana consumers may exercise these rights as described in the Submitting a Privacy Request section.
Kentucky Residents — KCDPA
This section applies to Kentucky residents under the Kentucky Consumer Data Protection Act (KCDPA). Under the KCDPA, a Kentucky consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Kentucky consumers may exercise these rights as described in the Submitting a Privacy Request section.
Iowa Residents — ICDPA
This section applies to Iowa residents under the Iowa Consumer Data Protection Act (ICDPA). The ICDPA provides a narrower set of rights than several other state privacy laws. Under the ICDPA, an Iowa consumer has the rights to confirm whether we process their personal data and to access it, to delete personal data they provided, to obtain a portable copy, and to opt out of the sale of personal data. The ICDPA does not provide a right to correct personal data, and it does not provide a separate right to opt out of targeted advertising or profiling. Where we process sensitive data, we provide notice and the opportunity to opt out as described under the ICDPA. Iowa consumers may exercise these rights as described in the Submitting a Privacy Request section; we respond within the timeframe the ICDPA allows.
Oregon Residents — OCPA
This section applies to Oregon residents under the Oregon Consumer Privacy Act (OCPA). Under the OCPA, an Oregon consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. The OCPA also gives Oregon consumers the right to obtain a list of the specific third parties to which we have disclosed personal data. We do not sell the personal data of a consumer where we have actual knowledge, or willfully disregard, that the consumer is under 16 years of age; consent does not cure that prohibition. We do not sell precise geolocation data that identifies a consumer’s location within a radius of 1,750 feet. Oregon consumers may exercise these rights as described in the Submitting a Privacy Request section, including through a recognized universal opt-out mechanism where applicable, and may appeal a refusal to act on a request as described in that section.
Minnesota Residents — MCDPA
This section applies to Minnesota residents under the Minnesota Consumer Data Privacy Act (MCDPA). Under the MCDPA, a Minnesota consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Where profiling produces a decision that has a legal or similarly significant effect, a Minnesota consumer also has the rights to question the result of the profiling, to be informed of the reason the profiling was used, to review the personal data used in the profiling, and, where the decision was based on inaccurate personal data, to have that data corrected. The MCDPA also gives Minnesota consumers the right to obtain a list of the specific third parties to which we have disclosed personal data. Minnesota consumers may exercise these rights as described in the Submitting a Privacy Request section, including through a recognized universal opt-out mechanism where applicable.
Maryland Residents — MODPA
This section applies to Maryland residents under the Maryland Online Data Privacy Act (MODPA). Under the MODPA, a Maryland consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. The MODPA imposes heightened limits that we reflect in our practices: we limit our collection of personal data to what is reasonably necessary and proportionate to provide or maintain the specific product or service that the consumer has requested, we do not sell sensitive data, and we do not process for targeted advertising or sell the personal data of a consumer where we knew or should have known that the consumer is under 18 years of age. We also do not sell a Maryland consumer’s personal data where we know or should know that the purchaser seeks to use it for immigration enforcement, and we do not knowingly sell a Maryland consumer’s personal data to any federal, state or local governmental unit that has engaged in or supported civil immigration enforcement within the preceding six months.
A Maryland consumer also has the right to obtain a list of the categories of third parties to which we have disclosed that consumer’s personal data or, where we do not maintain that information in a format specific to the consumer, a list of the categories of third parties to which we have disclosed any consumer’s personal data.
Maryland consumers may exercise these rights as described in the Submitting a Privacy Request section, including through a recognized universal opt-out mechanism where applicable, and may appeal a refusal to act on a request as described in that section.
Maryland Residents — Authorized Agents
Maryland limits what an authorized agent may do. Under Maryland law, a consumer may designate an authorized agent only to opt out of the processing of their personal data. For every other Maryland privacy right — confirming and accessing personal data, correcting it, deleting it, obtaining a copy of it, and obtaining the list of categories of third parties — the Maryland consumer must submit the request themselves. A parent or legal guardian of a child, and a guardian or conservator of a consumer subject to a protective arrangement, may exercise any of these rights on that individual’s behalf.
Florida Residents — FDBR
This section applies to Florida residents. Certain requirements of the Florida Digital Bill of Rights (FDBR) apply to us regardless of our size or revenue, and we describe them here. We do not operate a voice-recognition, facial-recognition, video, or audio feature that collects personal data from a Florida consumer through the microphone or camera of their device while that feature is not in active use by the consumer, without the consumer’s consent. We do not sell the sensitive personal data of a Florida consumer without first obtaining that consumer’s consent. We maintain reasonable security measures for personal information, and we provide notice of a breach of security affecting personal information as Florida law requires, including where the information involved is biometric or geolocation data. Florida consumers may contact us at privacy@floworah.com regarding any of these matters.
Rhode Island Residents — RIDTPPA
This section applies to Rhode Island residents under the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA). Under the RIDTPPA, a Rhode Island consumer has the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Rhode Island consumers may exercise these rights as described in the Submitting a Privacy Request section, and may appeal a refusal to act on a request as described in that section.
No Retaliation for Exercising Privacy Rights
We do not discriminate or retaliate against an individual for exercising a privacy right described in this Policy. In particular, we do not deny goods or services, charge a different price or rate, including through a discount, benefit, or penalty, provide a different level or quality of goods or services, or suggest that an individual will receive a different price, rate, level, or quality, because that individual exercised a privacy right. This applies equally to an applicant to an educational program, a job applicant, a student, an employee, and an independent contractor, none of whom we retaliate against for exercising a privacy right. A difference in price or service that is reasonably related to the value provided to us by an individual’s data, and participation in a loyalty, rewards, premium-features, discount, or club-card program, are not by themselves discrimination; where we offer a financial incentive or a price or service difference of that kind, we describe its material terms and the method we used to calculate the value of the data, and we obtain the individual’s prior opt-in consent, which may be revoked at any time.
Authorized Agents
Except where a state section of this Policy provides otherwise, an individual may use an authorized agent to submit a privacy request on their behalf. Where a state section limits which requests an authorized agent may submit in that state, that limit governs for residents of that state. An authorized agent may submit a request by contacting us at privacy@floworah.com and providing proof that the individual signed a permission for the agent to act. We may also ask the individual to verify their own identity with us directly, or to confirm to us directly that they gave the agent permission. We do not require a power of attorney for an individual to use an authorized agent, and where an individual has given an agent a power of attorney under California Probate Code sections 4121 to 4130 we do not ask for the separate signed permission. We do not ask an individual to resubmit, in their own name, a request an authorized agent has already made on their behalf. We do not ask for signed permission where the request is made through an opt-out preference signal. An authorized agent may use the personal information it obtains only to submit and complete the request, to verify identity, and to prevent fraud.
How We Verify a Privacy Request
Before we act on a request to know, delete, or correct, we verify that the requester is the individual whose personal information is the subject of the request. We verify by matching the information the requester gives us against personal information we already hold. For a request for the categories of personal information we hold, we match at least two reliable data points. For a request for specific pieces of personal information, we match at least three reliable data points and ask for a signed declaration, under penalty of perjury, that the requester is the individual they claim to be; we keep those declarations as part of our records. Where an individual has an account with us, we ask them to sign in and to re-authenticate before we disclose, correct, or delete their personal information. For a request to correct, we verify using personal information that is not itself the subject of the correction. Any information we collect only to verify a request is used only to verify the request, to secure our systems, and to prevent fraud, is not used for any other purpose, and is deleted as soon as practical afterward. We charge no fee to verify a request, and we do not verify identity before acting on a request to opt out of the sale or sharing of personal information.
Submitting a Privacy Request
Individuals may submit a privacy request to exercise the choices and rights described in this Policy by contacting us at privacy@floworah.com. For requests to know, delete, or correct, we verify the requester’s identity before acting on the request, as described in the How We Verify a Privacy Request section. We do not require identity verification for a request to opt out of the sale or sharing of personal information.
We confirm receipt of a request to know, delete, or correct within 10 business days and tell the requester how we will process it. We respond to a request within 45 calendar days of receiving it, whether or not we have completed identity verification; where reasonably necessary we may extend that period once by up to 15 additional calendar days, and we notify the requester of the extension and the reason for it. We act on a request to opt out of the sale or sharing of personal information as soon as feasibly possible and no later than 15 business days after we receive it.
We do not charge a fee to act on a privacy request, and we do not require an individual to create an account in order to make one.
Appeals. If we decline to act on a privacy request, we notify the requester of our decision and of the reasons for it, and the requester may appeal that decision by contacting us at privacy@floworah.com with the word “Appeal” in the subject line. The appeal process takes no more steps and no more time than the original request did, and it is free. We respond to an appeal in writing within 45 days of receiving it, and we state the reasons supporting the response. If we deny the appeal, we give the requester a way to submit a complaint to the authority for their state:
- Colorado: the Colorado Attorney General
- Connecticut: the Connecticut Attorney General
- Delaware: the Delaware Department of Justice
- Iowa: the Iowa Attorney General
- Indiana: the Indiana Attorney General
- Kentucky: the Kentucky Attorney General
- Maryland: the Consumer Protection Division of the Office of the Maryland Attorney General
- Minnesota: the Minnesota Attorney General
- Montana: the Montana Attorney General
- Nebraska: the Nebraska Attorney General
- New Hampshire: the New Hampshire Attorney General
- New Jersey: the New Jersey Division of Consumer Affairs in the Department of Law and Public Safety
- Oregon: the Oregon Attorney General
- Rhode Island: the Rhode Island Attorney General
- Tennessee: the Tennessee Attorney General and Reporter
- Texas: the Texas Attorney General
- Virginia: the Virginia Attorney General
To submit a privacy request, contact us at privacy@floworah.com. [ATTORNEY REVIEW REQUIRED]
Nevada Residents — Opt Out of the Sale of Covered Information
Nevada law gives a consumer the right to direct an operator of a commercial website not to make any sale of the covered information the operator has collected or will collect about that consumer. Our designated request address for a verified request of that kind is privacy@floworah.com. A Nevada consumer may send a verified request to that address, and we respond within 60 days of receiving it. Where reasonably necessary we may take up to 30 additional days, and we tell the consumer when we do. Covered information under Nevada law means a first and last name, a home or physical address, an email address, a telephone number, a social security number, an identifier that allows a specific person to be contacted physically or online, and any other information collected through the website and kept together with one of those identifiers.
How We Protect Personal Information
We maintain reasonable administrative, technical, and physical security procedures and practices appropriate to the nature of the personal information we hold, designed to protect it from unauthorized access, destruction, use, modification, or disclosure. Those measures include:
role-based access controls that limit access to staff whose duties require it; multi-factor authentication on accounts that can reach personal information; encryption of personal information in transit using TLS; encryption of personal information at rest; application-level AES-256-GCM encryption of social account credentials and authentication secrets; physical and environmental security of data centers maintained by our infrastructure providers
No method of transmission or storage is completely secure, and we do not represent that our security measures are impenetrable.
Do Not Track Signals
Some browsers transmit a “Do Not Track” (DNT) signal. There is no industry or legal standard for how an operator is required to respond to a DNT signal, and we do not respond to DNT signals. We do process opt-out preference signals as described elsewhere in this Policy, and individuals may exercise the choices described in this Policy regardless of whether their browser transmits a DNT signal.
Changes to This Policy
We may update this Privacy Policy. When we do, we revise the “Last Updated” date shown in this Policy and post the updated Policy at https://www.floworah.com/. We do not separately notify individuals in advance of changes, so please review this Policy periodically. Where a material change would apply to personal information we collected before the change, we provide notice and a reasonable opportunity to withdraw consent before we process that previously-collected personal information under the changed Policy. Individuals may review the personal information we hold about them, and request changes to it, by following the process described in the Submitting a Privacy Request section.
Last Updated
This Privacy Policy was last updated on October 1, 2026.
Contact Information
Questions about this Privacy Policy or our handling of personal information may be directed to Pure Grace AI, LLC at privacy@floworah.com. Correspondence regarding privacy requests may also be sent to that address.