Privacy policy
Last updated: October 1, 2026
InvokeFlow Inc. makes software that lets humans, automations, and AI agents operate the applications you already own: InvokeFlow Composer (desktops), InvokeFlow Aria (displays) and InvokeFlow Conductor (the control console). This policy explains what data our website and our products collect, how it is used, and what control you have.
Who we are
InvokeFlow products are developed by InvokeFlow Inc. (“we”, “us”, “our”), a Delaware corporation based in Austin, Texas. For privacy questions, contact us at privacy@invokeflow.ai.
Our website
Analytics and cookies
We use HubSpot to understand how visitors use invokeflow.ai. When you visit, HubSpot’s tracking code may set cookies (including __hstc, hubspotutk, __hssc and __hssrc) that record the pages you view, when you visit, the site that referred you, your browser and device type, and an approximate location derived from your IP address. We use this to see which pages are useful and to improve the site.
Where the law requires it, we ask for your consent before these cookies are set, using the banner on our site. You can change your choice at any time:
You can also block or delete cookies in your browser. HubSpot processes this data for us under its own privacy policy. If you share your contact details with us, for example in a form, HubSpot may connect them to your earlier visits.
Hosting
Our website is hosted on Google Firebase Hosting. To deliver pages and protect the service, Google processes your IP address and basic request details, such as the page requested and your browser type.
Fonts
Our pages load fonts from Google Fonts, so your browser sends your IP address to Google when it fetches them.
If you email us, we use your message and address to reply and to follow up on your inquiry.
Data our products collect
Information you provide
- Device name — A name you choose for your display or desktop agent during setup. Stored locally on your device.
- MQTT broker credentials — The server address, username, and password for your MQTT broker. Stored in encrypted local storage on your device. We never see or store these credentials.
- API keys — If you use optional features like weather or AI services, any API keys you enter are stored in encrypted local storage. We do not have access to them.
Camera and microphone (Aria)
InvokeFlow Aria can use your device’s camera and microphone for the following features, all of which are optional and disabled by default:
- Camera — Presence detection, face detection, object detection, facial recognition, intercom and video calling, motion detection, and camera snapshots.
- Microphone — Speech-to-text, intercom and video calling, and audio streaming.
All camera and microphone processing happens on your device. Images, video, and audio are not sent to our servers. If you configure integrations (such as an MQTT broker, Home Assistant, or a Feature Server), media may be transmitted to the services you choose to connect to — but only to those services and only when the relevant feature is active.
AI assistant and generative AI
Aria’s machine-learning features — face, human, and motion detection, speech-to-text, and text-to-speech — run locally: on your device, or on your own self-hosted Feature Server. They do not use a third-party AI service, and the images, video, audio, and text they process are not sent to us or to any third party.
Aria also offers an optional AI assistant that you enable and configure. You choose where it runs:
- Local or self-hosted — a local Ollama model or your own self-hosted Feature Server. Your input stays on your own devices and is not shared with any third party.
- A third-party cloud AI provider — OpenAI, Anthropic, Google (Gemini), Mistral AI, or Together AI, using an API key you provide. If you select a cloud provider, the messages and content you send to the assistant are transmitted to that provider to generate responses, and are processed under that provider’s privacy policy (and may be stored by them).
Before any cloud AI provider is enabled, the app shows an in-app notice that names the specific provider and explains that your input will be sent to that third-party service, and asks for your explicit consent. No data is sent to a cloud AI provider unless you enable the assistant, select that provider, and agree. The connection is directly between your device and the provider using your own API key — we are not involved in that exchange.
Facial recognition data (Aria)
If you use the facial recognition feature, face training data (mathematical representations of facial features, not photographs) is stored locally on your device. This data is never uploaded to our servers or shared with third parties. You can delete all stored face data at any time through the app’s settings.
Desktop orchestration and audit logs (Composer)
InvokeFlow Composer is a native agent that manages real application windows on a desktop you control. It can capture screenshots and publishes window and process telemetry to the MQTT broker you configure. Composer maintains a tamper-evident audit log of the commands it handles; this log is stored locally on the device and is not transmitted to us. Composer runs non-elevated and only manages windows on the machine where you install it.
Device telemetry
InvokeFlow products collect basic device information locally, including battery level, CPU and memory usage, platform type, brightness, and volume. This information is used for on-screen status displays and performance optimization. It is only transmitted to your own MQTT broker if you have configured one — it is never sent to us or to any third-party service.
If you enable the optional location feature, latitude and longitude may also be published to your MQTT broker. Location data is never sent to our servers.
Crash reports and diagnostics
InvokeFlow apps can send anonymous crash reports and diagnostic data to help us improve the product. This feature is off by default. If you choose to turn it on in Settings, the following data may be sent when an error occurs:
- Error messages and stack traces
- Device platform and OS version
- App environment (development or production)
Before transmission, the app automatically strips API keys, tokens, passwords, and other sensitive values from reports. No personally identifiable information is included. You can turn this on or off at any time in Settings > General > Crash Reports & Diagnostics.
Weather data
If you use the weather widget, your location (latitude and longitude) and your OpenWeatherMap API key are sent to the OpenWeatherMap service to retrieve weather data. This is a direct connection between your device and OpenWeatherMap — we are not involved in that exchange. OpenWeatherMap’s own privacy policy governs their handling of that data.
Payments
All purchases are processed by Paddle.com Market Limited (“Paddle”), our Merchant of Record. When you purchase a license, Paddle collects your name, email address, and payment information directly. We do not see or store your payment details. Paddle’s privacy policy governs how they handle your billing information.
Data our products do not collect
- Outside the design-partner pilot, we do not collect or store your MQTT messages or communication data.
- We do not collect camera images, video, or audio.
- We do not collect facial recognition data.
- We do not collect your location.
- We do not sell or rent personal data, and we share it only with the service providers named in this policy.
- Our products do not include advertising SDKs or ad tracking.
MQTT communications
All MQTT communication occurs between your devices and the broker you configure. Except in the design-partner pilot described below, we do not operate, intercept, or have access to your MQTT broker or the messages sent through it. If you connect to a public MQTT broker, be aware that any data you publish will be sent to that server.
Design-partner pilot
If your company is a design partner using our hosted pilot at partners.invokeflow.ai, we run the MQTT broker and the Conductor console for your company on our servers. Commands and device telemetry for your company’s machines pass through that broker, and Conductor stores your users’ sign-in details (such as name, email address and role), an identity for each enrolled machine, and a record of which user made each request. We use this data only to run the pilot for your company. To have it deleted, contact privacy@invokeflow.ai.
Third-party services
InvokeFlow products may connect to the following third-party services depending on which features you enable. Each is optional and configured by you:
- Your MQTT broker — For remote control and telemetry
- Home Assistant — For smart home integration and auto-discovery
- OpenWeatherMap — For weather widget data
- Cloud AI providers (OpenAI, Anthropic, Google Gemini, Mistral AI, Together AI) — Optional, and only if you enable the AI assistant and select a cloud provider, using API keys you provide and with your explicit consent. Local options (Ollama) and your self-hosted Feature Server keep AI processing off third-party services.
- Paddle — For payment processing
- Feature Server (InvokeFlow Core) — Your self-hosted backend for WebRTC, remote browser, and TTS
Our website uses these services:
- HubSpot — Website analytics and cookies
- Google Firebase Hosting — Hosting for invokeflow.ai
- Google Fonts — Fonts for invokeflow.ai
We are not responsible for the privacy practices of these third-party services. Their use is governed by their respective privacy policies.
Data storage and security
- Sensitive data (MQTT credentials and API keys) is stored using encrypted local storage on your device.
- Outside the design-partner pilot, our products store no user data on our servers. All app data lives on your device.
- Website analytics are stored by HubSpot on our behalf.
- MQTT command signing (HMAC-SHA256) is available for verifying the authenticity of commands sent to your device.
Data retention and deletion
All InvokeFlow product data is stored locally on your device. You can delete it at any time by:
- Clearing individual settings through the app
- Deleting stored face data through the app’s settings
- Uninstalling the app, which removes all local data
Outside the design-partner pilot, we do not retain any product data on our servers, so there is nothing for us to delete on our end. For Paddle billing records, contact Paddle directly. Website analytics are kept in HubSpot; to have analytics data about you deleted, contact privacy@invokeflow.ai.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, or delete personal data. Our products store data locally on your device, so you already have full control of it. For website data held in HubSpot, or any other request, contact us at privacy@invokeflow.ai. You can change your cookie choice at any time with the Cookie settings button above.
Children’s privacy
Our website and products are not directed to children under 13, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. Changes will be communicated through the app or on our website. Continued use of our website or InvokeFlow products after changes constitutes acceptance of the updated policy.
Contact
For questions about this privacy policy, contact privacy@invokeflow.ai.