Who we are
Fomio is a service operated by FLOW SOFTWARE L.P., registered in Greece as GEORGANTZELIS ANDREAS KAI SIA L.P., company no. 184467906000, VAT EL802877827, at Leoforos Dimokratias 1, Oraiokastro, 57013 Thessaloniki, Greece. We are the data controller for everything described here — meaning we are the ones who decide what gets collected, and the ones you complain to when you think we got it wrong.
Write to hello@fomio.ai about anything on this page.
What we collect, and why
Your account
Your email address, and your name if you signed in with Google and Google told us. That is the whole account. There is no password, because signing in works by a link sent to your inbox — so there is no password for us to store or lose.
We need this to give you an account and to send alerts to it, which is the product. In legal terms that is performance of a contract.
The apps you ask us to watch
The address you paste, a name for it, and the pages we find on it. To find those pages we load your site once and read the links on it, the same way a browser would.
What happened when we checked
Every check records whether the page answered, how long it took, the response code it gave, and a short snippet of what came back. That snippet is what lets us tell “the page is fine” from “the page loaded an error message”. If your pages show personal data to a logged-out visitor, that data could appear in a snippet — we only ever fetch pages as an anonymous visitor, so we see exactly what a stranger with the link would see, and nothing behind your login.
Raw check results are deleted automatically after 48 hours. What survives is the summary: that something was down between one time and another. That is what your history is made of, and it contains no response content.
Error reports from your app’s visitors
If you paste our snippet into your own app, it tells us when a page there breaks for one of your visitors. This is the one place Fomio touches somebody else’s users, so it is worth being exact about what it sends:
- The page it happened on, with the identifiers stripped out —
/orders/:id, never/orders/8471. No id out of one of your URLs is ever written down. - Whether it was a failed request or the page itself crashing.
- The response code and a truncated error message, so we can explain what broke.
- A random id that exists for the length of one browser tab and is thrown away when it closes. It is not a cookie, it is never stored in the visitor’s browser, and it identifies nobody. It exists so we can tell “one person clicked a broken button four times” apart from “four people hit the same wall”.
No IP address, no cookie, no name, no email, no page content. These reports are deleted after 7 days.
For this data, you are the controller and we act on your instructions — so telling your own visitors that you use us is your responsibility, and the Terms say so.
Payments
Handled entirely by Stripe. No card number ever reaches us — not the number, not the security code, not the billing address. We keep the identifier Stripe gives us for your subscription, which plan it is, and whether it is active. Stripe keeps the rest and has its own privacy policy.
Measurement, and how to switch it off
We use three things to understand how people find Fomio and where they get stuck. They run unless you turn them off, using the banner you see on your first visit or the link at the bottom of this section. Turning them off costs you nothing — the product works identically either way.
- Meta pixel— records that a page was viewed, and sets Meta’s own cookies. It never runs on your dashboard or on a status page.
- Meta Conversions API — the same reporting, sent from our server rather than your browser, because signing up and paying both finish somewhere a script cannot see. It sends Meta a one-way scrambled version of your email address, which Meta uses to match you to an advert you saw. This is the one worth reading twice, because an ad blocker cannot stop it and you cannot see it happening — which is exactly why it is behind the same consent.
- Microsoft Clarity — records a replay of how the page was used, including on the dashboard. Your app names, addresses and email address are masked out of those recordings in our code, so they are not in the replay to begin with.
The legal basis for all three is our legitimate interest in understanding how people find and use the product, balanced against an unconditional right to refuse: press Turn it offon the banner and none of them load again. If you have already dismissed it, clearing this site’s cookies brings it back, or email us and we will confirm it for you.
Cookies
Four kinds. Only the first two remain if you turn measurement off:
- Signing in. Set when you log in, so the next page knows it’s you. Without it there is no way to be logged in at all.
- Your answer to the banner. One cookie storing “yes” or “no” for six months, so we stop asking. Storing a refusal is the only way to honour it.
- Meta’s (
_fbp,_fbc) — not set if you have turned measurement off. - Clarity’s — likewise.
Who else sees your data
We use other companies to run Fomio. Each one only gets what it needs for its job, and none of them may use it for anything else.
- Supabase — the database and the sign-in system. Holds your account and everything about your apps.
- Vercel — hosting. Sees requests to the site, including IP addresses, in ordinary server logs.
- Resend — sends every email we send you, so it sees your address and the contents of the alert.
- Stripe — payments, as above.
- Google — only if you choose to sign in with it, and only then to confirm the address is yours.
- Anthropic— we send the page paths and link labels we found on your site to an AI model, which groups them into sensible names for the dashboard (“Blog posts”, “Country pages”). Your email address is never part of that, and the model provider does not train on it.
- Meta and Microsoft — only with your consent, as described above.
Some of these are in the United States. Where that is the case, the transfer relies on the European Commission’s standard contractual clauses or an adequacy decision covering that company.
We do not sell your data, and we do not share it with anyone not on this list.
How long we keep it
- Raw check results — 48 hours, then deleted automatically.
- Error reports — 7 days, then deleted automatically.
- Your history of outages — for as long as your account exists. How far back you can see it depends on your plan; how long we hold it does not.
- Your account and apps — until you delete them.
- Payment records — as long as tax law requires, which is normally several years, and is not something we can shorten on request.
Your rights
If you are in the UK or the EU you have the right to get a copy of what we hold about you, to have it corrected, to have it deleted, to object to how we use it, and to take it elsewhere. You can withdraw consent for the measurement tools at any time without giving a reason.
Email hello@fomio.ai and we will do it within a month. There is no form and no fee.
If you think we have handled your data badly you can complain to your national data-protection authority — in our case, the one in Greece. We would rather you told us first, but you do not have to.
Security
Everything travels over an encrypted connection. Your data is separated from every other customer’s at the database level, so one account’s query cannot reach another account’s rows. Sign-in is by emailed link, which means there is no password to be reused or stolen from us.
We are a small team and we will not pretend otherwise: if something happens that affects your data, we will tell you what happened and when, in plain language, within 72 hours of finding out.
Children
Fomio is not for under-16s and we do not knowingly collect anything about them.
If this page changes
The date at the top moves and, if the change actually affects you, we email you before it takes effect. We will not quietly widen what we collect and let you find out later.
