Workflow AI app icon

Privacy Policy

Workflow AI

Mobile automation · Android · com.greenleaf.workflow_ai

Last updated: 28 July 2026 · Application: Workflow AI – Mobile Automation (Android package com.greenleaf.workflow_ai) · Developer: Pragat Inc · Contact: pragat.apps@gmail.com

Summary

Workflow AI is a privacy-first mobile automation platform. Your workflows, triggers and automations are created and executed locally on your Android device. We do not collect personal data, we do not sell or share it, and we operate no servers that receive your workflow content.

The app requests a number of powerful permissions — including notification access — because automation requires them. Each is used only for the workflows you build, and each is explained in section 4. Data leaves your device only when you deliberately configure a workflow that calls an external service, such as an AI provider or a webhook.

Data Why it is handled Leaves your device
Workflow and automation configurations To store and run the automations you build, in local JSON databases. No
Notification content Read on-device to fire the notification triggers you have configured. No
Installed application list So you can pick apps to launch or target in a workflow. No
Location Required by Android for certain Wi-Fi and Bluetooth operations. Not tracked or stored. No
Data you send to an external service Only what a workflow you built sends to an AI provider, webhook or API you configured. Yes — to the provider you chose
Advertising and profiling identifiers Not collected. The app contains no advertising SDK and does no profiling. Not collected

1. Who we are and what this policy covers

Workflow AI is published by Pragat Inc ("we", "us", "our"), an independent software studio. For the purposes of the GDPR we are the data controller for this app, and under India's Digital Personal Data Protection Act, 2023 we are the data fiduciary.

This policy covers the Workflow AI Android application distributed through Google Play under the package identifier com.greenleaf.workflow_ai. It does not cover any third-party service you choose to connect a workflow to — those are governed by their own policies.

By installing and using the app you accept this policy. If you do not agree with it, please uninstall the app.

2. Information we collect

We collect no personal data. The app is designed to work on-device. We operate no servers that receive your workflows, your notifications or your messages. Specifically, we do not:

  • sell user data;
  • track your personal activity;
  • upload your private notifications;
  • store your messages on our servers;
  • share data with advertisers;
  • use analytics for personal profiling.

Any data the app processes stays on your device unless you choose to connect an external service, as described in section 7.

If you submit feedback through the app, we receive the message you write and any contact address you choose to include, so that we can reply.

3. How we use information

Because we receive no personal data, we do not profile, analyse, disclose, sell or share information about you.

The data held on your device is used solely to run the automations you have built: evaluating triggers, executing actions, and showing you the results. Feedback you send us is used only to answer you and to fix the problem you reported.

4. Permissions

Automation requires broad device access, so the app requests the permissions below. Each is used only for workflows you create and control, and Android lets you revoke any of them at any time — workflows depending on a revoked permission will simply stop working.

Permission Why it is needed
INTERNET Only for API requests, AI integrations and webhook calls you configure, and for submitting feedback. Not used to collect or sell your data.
POST_NOTIFICATIONS To show you local notifications for workflow results, alerts, automation status and reminders.
BIND_NOTIFICATION_LISTENER_SERVICE To let workflows react to notifications from apps you select, such as a messaging, banking or email alert. See section 6.
ACCESS_WIFI_STATE, CHANGE_WIFI_STATE To let workflows monitor Wi-Fi status and switch Wi-Fi on or off — for example, enabling Wi-Fi when you arrive home.
ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION Required by Android before an app may perform certain Wi-Fi and Bluetooth scanning operations. The app does not track, log or store your location.
BLUETOOTH, BLUETOOTH_ADMIN, BLUETOOTH_CONNECT For workflows involving Bluetooth control, device connectivity and smart accessory automation — for example, enabling Bluetooth for your headphones.
CAMERA Used only to control the flashlight/torch. The app does not capture photos, record video, or access your camera media.
QUERY_ALL_PACKAGES So you can see your installed apps, select them for workflows, and launch them from a workflow. The list is not collected or transmitted.

5. Third-party services and processors

The app contains no advertising SDK and no profiling analytics. It interacts with third-party services only when you explicitly configure it to. No third-party integration is enabled automatically. Those integrations may include:

  • webhooks you point a workflow at;
  • external REST APIs you call from a workflow;
  • AI services such as OpenAI, Google Gemini or Anthropic Claude;
  • other cloud integrations you set up.

Your download and installation of the app is a transaction with Google Play, governed by Google's Privacy Policy and outside our control and visibility.

6. Notification access

Notification listener access is a sensitive permission, so it deserves a plain explanation. Granting it allows the app to read notifications posted on your device, which is what makes notification-triggered automation possible — for example parsing a bank alert or reacting to a message.

How notification access is used

Notifications are read and processed locally on your device. Workflow AI does not store notification content beyond what a running workflow needs, and does not transmit it to us or to any server we control. You choose which workflows use notification access, and you can revoke the permission in Android settings at any time.

If you build a workflow that deliberately forwards notification content to an external service — a webhook, an API or an AI provider — then that content leaves your device because your workflow instructed it to. Please design such workflows with care.

7. AI features and your API keys

The app lets you connect external AI services such as OpenAI, Google Gemini or Anthropic Claude. These features are optional and off until you configure them.

  • You supply your own API keys where applicable. Keys are stored on your device for the app to use and are not transmitted to us.
  • Anything a workflow sends to an AI provider — prompts, and any device or notification data your workflow includes — is transmitted to that provider and processed under their privacy policy and retention terms.
  • We are not responsible for third-party API processing. Please read the policy of any provider you connect before sending it sensitive information.

8. Local data storage and your control

Workflow AI may store the following locally on your device:

  • workflow configurations;
  • automation settings;
  • local JSON databases;
  • cached workflow data.

This data stays under your control and is not uploaded to servers we operate. At any time you may:

  • revoke any permission from Android settings;
  • delete individual workflows;
  • clear the app's local data;
  • uninstall the application completely.

9. Data retention and deletion

  • On your device — workflows and cached data persist until you delete them. Uninstalling the app removes them permanently.
  • Held by us — nothing, other than feedback messages you send us, which we keep only as long as needed to resolve your enquiry.
  • Held by services you connected — governed by that provider's retention policy. To have it deleted, contact the provider directly.

10. Security

Workflow AI is built with a privacy-first architecture:

  • local-first processing, so data need not leave the device;
  • minimal data collection;
  • app-private storage other apps cannot read;
  • user-controlled permissions, revocable at any time.

No security measure is absolute. A rooted or compromised device, or malware with elevated privileges, can undermine these protections, and we recommend keeping your device's screen lock and system updates enabled. Treat your API keys as secrets and revoke any key you believe has been exposed.

11. Children's privacy

Workflow AI is a technical automation tool and is not directed at children under 13. We do not knowingly collect personal information from children. If you are a parent or guardian and believe a child has provided us with personal information, contact us at the address in section 14 and we will act promptly.

12. Your rights

Privacy laws including the EU and UK GDPR, the California CCPA/CPRA, and India's Digital Personal Data Protection Act, 2023 give you rights to access, correct, export and delete personal data an organisation holds about you, and to know whether it is sold or shared.

We hold no personal data about you and we do not sell or share personal information. In practice:

  • Access and portability — your workflows are already on your device, under your control.
  • Correction and erasure — edit or delete any workflow, clear local data, or uninstall the app to erase everything.
  • No sale or sharing — there is nothing to opt out of, because we transmit nothing.
  • Data held by connected providers — exercise those rights with the provider directly.
  • Complaints — you may raise a concern with us at any time, and you retain the right to complain to your local supervisory authority.

13. Changes to this policy

This policy may be updated periodically to reflect new features, Android policy changes or security improvements. When it changes, the revised policy will be posted on this page and the "Last updated" date above will change, and the Play Store listing's Data Safety section will be updated to match. Please review this page periodically.

14. Contact

For support, feedback, or privacy-related questions:

Pragat Inc — Privacy enquiries
pragat.apps@gmail.com

We aim to respond to privacy enquiries within 30 days.