Flourish AI LLC, a Florida limited liability company with its principal place of business in Bay County, Florida, doing business as Flourish (“Flourish,” “we,” “us,” or “our”), respects your privacy. This Privacy Policy explains what information we collect through flourishwithai.co (the “Site”) and in the course of delivering our AI education, leadership training, and consulting services, how we use and share it, the choices you have, and how to reach us.
By using the Site or providing us your information, you agree to this Policy. If you do not agree, please do not use the Site.
Short version: we collect what you give us and basic technical data. We use it to answer you, scope and deliver engagements, and market our own services. We do not sell your personal information, and we never share mobile phone numbers or SMS consent with anyone for their own marketing. What we learn about your organization in an engagement is confidential, and we will not name you in our marketing without asking. You can opt out of email and text messages at any time.
1.Scope of This Policy
This Policy applies to personal information we collect:
- through the Site, including any form, chat, scheduling tool, AI readiness assessment, seminar registration, or free download offered on it;
- when you email, call, or text us, or book a discovery call with us;
- when your organization engages us and we deliver an engagement (the “Services”), including sessions, workshops, seminars, assessments, and advisory work;
- when a Participant attends a session we deliver; and
- from third parties such as our payment processor, our CRM and messaging platforms, our scheduling tool, and our video conferencing provider.
This Policy does not apply to the privacy practices of any third-party AI tool, platform, social network, or other service you or your organization uses independently, including those referenced or demonstrated in a session. Section 13 explains where that line falls.
A note on roles. Where your organization gives us personal information about its own people so that we can deliver an engagement, your organization decides why that information is collected and we act on its instructions. In that situation your organization's own privacy notice governs its relationship with those individuals, and this Policy describes what we do with the information on its behalf. See Section 11.
↑ Back to top2.Information We Collect
2.1 Information you give us
| Category | Examples |
|---|---|
| Identifiers & contact information | Name, job title, organization name, work and personal email address, mobile and other telephone numbers, mailing address, time zone, and any social or professional profile you choose to share |
| Organization & qualification information | Organization type and size, sector, team or congregation size, budget range, decision-making role, current use of AI, tools already in place, objectives, timeline, and anything you tell us on a discovery call or in an intake form |
| Assessment responses | Your answers to our AI readiness assessment or any survey, questionnaire, or pre-work we send |
| Engagement & account information | Engagement dates, format, location, participant count, preferences, accessibility and dietary requirements, and credentials for any portal or resource library we give you access to |
| Billing information | Billing contact, billing address, purchase order or reference number, payment option, tax exemption status, and invoice status. Payment card and bank account numbers are collected and stored by our payment processor, not by us. We receive only limited information such as the last four digits, card brand, and expiration date |
| Participant rosters | Names, work email addresses, job titles, and any accessibility or dietary requirements your organization sends us so that we can deliver a session. See Section 11 |
| Session participation | Attendance, join and leave times, questions asked, chat messages, poll and exercise responses, and material a Participant chooses to share in the room |
| Session recordings | Where a Participant is on camera or microphone: their video, voice, display name, chat messages, and anything shared on screen. See Section 12 |
| Communications | The content of emails, text messages, form submissions, chat messages, voicemails, support requests, and notes from discovery and scoping calls |
| Consent records | Records of your email and SMS opt-in, including date, time, IP address, the form used, and the exact disclosure text shown to you at the time |
2.2 Information collected automatically
When you visit the Site, we and our providers may automatically collect: IP address; approximate location derived from IP address; browser type and version; operating system and device type; screen size; referring and exit URLs; pages viewed, time on page, and clicks; date and time of visit; and unique device or cookie identifiers. Within any portal or video conferencing platform we use, we also record login times, join and leave times, and content access events.
2.3 Information from third parties
We may receive information about you from our payment processor (transaction status, limited card details), our CRM, scheduling, email, SMS, video conferencing, and form platforms, and, where you register through one, a webinar or event platform. Where a colleague refers you or adds you to a roster, we receive your information from them rather than from you.
2.4 Sensitive information
We do not seek, and ask that you do not send us, sensitive personal information such as Social Security numbers, government identification numbers, financial account credentials, precise geolocation, health information beyond an accessibility or dietary requirement, biometric data, or information revealing racial or ethnic origin, religious beliefs, or sexual orientation. Please also do not send us, or raise in a session, personal information about a third party that you are not entitled to share, or confidential information belonging to a customer, member, patient, employer, or other party.
↑ Back to top3.Client Business Information
This section has no equivalent in a consumer privacy policy, and it is the one most relevant to a corporate, nonprofit, or ministry client. A consulting engagement means we learn things about how your organization actually works. Those things are not marketing material for us.
3.1 What we learn. In the course of scoping and delivering an engagement we typically learn non-public information about your organization — strategy, staffing, internal processes, systems and vendors, budgets, governance concerns, membership or congregational matters, and candid views expressed by your leaders in the room.
3.2 How we treat it. We treat all of it as confidential under Section 11 of our Terms of Service. We use it only to scope, deliver, and support your engagement. We do not disclose it to any third party except to our own personnel and contractors who need it to deliver the engagement and who are bound by equivalent confidentiality obligations, or where disclosure is required by law.
3.3 We will not name you without asking. We will not identify your organization, describe your engagement, quote you, or use your logo in our marketing, case studies, or client list without your prior written permission, which you may withdraw at any time as to new materials. We may describe engagements in general, anonymized, non-identifying terms — for example “a regional healthcare provider” — without permission.
3.4 What we may learn from across engagements. We may use anonymized, aggregated observations across many engagements — for example how often a category of question comes up — to improve our curriculum, provided the result does not identify you and does not reveal your confidential information.
3.5 Individuals inside your organization. Where a person's views or performance are discussed in an engagement, we do not create or keep individual assessments of your employees and do not report on named individuals to their leadership unless you have specifically engaged us to do so and told the individuals concerned.
↑ Back to top4.Cookies & Tracking Technologies
We and our providers use cookies, tags, local storage, and similar technologies to operate the Site and the platforms we deliver through, keep you signed in, remember your preferences, and keep things secure.
| Type | Purpose |
|---|---|
| Strictly necessary | Enable core functions such as page delivery, form submission, login sessions, security, and load balancing. These cannot be switched off through the Site. |
| Functional | Support features such as chat, scheduling, the AI readiness assessment, video playback position, and remembering form entries. |
| First-party platform analytics | Our website, funnel, and CRM platform records page views, referring source and campaign parameters, form submissions, and which page a contact came from, so that we can see which of our own pages work. This processing is carried out by that platform on our instructions and for us alone; the data is not combined with data from other websites and is not made available to any advertiser. |
We do not run third-party advertising or cross-site tracking. As of the Last Updated date above, the Site does not use the Meta Pixel, Meta's Conversions API, Google Analytics, LinkedIn Insight Tag, or any other third-party advertising, retargeting, or cross-context behavioural tracking technology. The only measurement in use is the first-party platform analytics described in the table above. If that changes, we will update this Section and the Last Updated date before or at the time the technology goes live, and we will describe the opt-out mechanisms available to you.
Your choices. Most browsers let you refuse or delete cookies through their settings. Blocking cookies may cause parts of the Site or the platforms we deliver through to stop working, including login.
↑ Back to top5.How We Use Your Information
We use personal information to:
- respond to your inquiry, schedule and conduct discovery and scoping calls, and answer questions about our programs;
- prepare proposals, quotations, and Engagement Confirmations, and confirm dates and formats;
- deliver engagements, including sessions, workshops, seminars, assessments, and advisory work, and tailor content to your organization's objectives;
- administer participant rosters, joining links, pre-work, materials, and accessibility arrangements;
- score and return AI readiness assessments and provide the resulting recommendations;
- process payments, issue invoices and receipts, and collect amounts owed;
- send transactional and service communications such as session links, reminders, schedule changes, and billing notices;
- send marketing communications by email and, where you have opted in, by text message;
- improve the Site, our curriculum, and our programs, including by reviewing anonymised, aggregated participation and feedback data;
- maintain records of consent and preferences;
- protect the security and integrity of the Site and our platforms, detect and prevent fraud and unauthorised access, prevent unauthorised distribution of our program materials, and enforce our Terms of Service; and
- comply with legal obligations and establish, exercise, or defend legal claims.
6.Email Communications & Opt-In
6.1 Consent. When you submit your email address through a form on the Site, book a discovery call, register for a seminar, download a free resource, or otherwise provide it to us for that purpose, you consent to receive marketing and promotional emails from Flourish — including educational content, case studies, program announcements, offers, and reminders.
6.2 Transactional email. If your organization has engaged us, we will also send email that is necessary to deliver the engagement, such as scheduling confirmations, session links and reminders, pre-work and materials, schedule changes, and billing notices. These are not marketing messages and continue for as long as the engagement is live.
6.3 Participants are not added to marketing lists. We do not add a Participant to our marketing email list on the strength of a roster their employer sends us. A Participant receives marketing email from us only if they opt in themselves.
6.4 How to opt out. Every marketing email includes an unsubscribe link in the footer. You may also email [email protected] with the subject line “Unsubscribe.” We honor opt-out requests promptly, and in all cases within ten (10) business days, as required by the CAN-SPAM Act. Opting out of marketing email does not stop transactional email.
6.5 Our commitments. Our marketing emails identify Flourish as the sender, use accurate subject lines and header information, are identified as advertising where required, and include our valid physical mailing address.
↑ Back to top7.SMS / Text Messaging & Opt-In
No mobile information will be sold or shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are never shared with any third party, and are excluded from all information sharing described elsewhere in this Policy. Mobile numbers are disclosed only to the vendors that transmit messages on our behalf, and those vendors are contractually prohibited from using the information for any purpose other than delivering our messages.
Consent to receive text messages is not a condition of engaging our Services or of purchasing any product or service.
7.1 How you opt in. You give prior express written consent by taking a clear affirmative action, such as checking an unchecked consent box on one of our forms that appears next to the disclosure describing this program, replying with a requested keyword to a message you asked to receive, or submitting your mobile number in a field expressly labeled for text messaging. We keep a record of the date, time, IP address, form, and disclosure language associated with your consent.
7.2 Program description. Once you opt in, you may receive recurring automated marketing and informational text messages from Flourish — including messages sent using an automatic telephone dialing system — relating to discovery call scheduling and reminders, proposal follow-up, session reminders, pre-work nudges, program announcements, account and service updates, and promotional offers.
| Program name | Flourish AI Alerts |
|---|---|
| Message frequency | Recurring. Frequency varies based on your interaction with us and on your engagement schedule. |
| Message & data rates | Message and data rates may apply. Your mobile carrier's standard charges apply to every message sent and received. Flourish is not responsible for these charges. |
| To opt out | Reply STOP to any message at any time. You will receive one final confirmation message, after which no further marketing text messages will be sent to that number. |
| For help | Reply HELP to any message, or email [email protected] |
| Carrier liability | Mobile carriers are not liable for delayed or undelivered messages. |
| Eligibility | You must be at least 18 years old and be the subscriber of, or have authority over, the mobile number you provide. |
| Availability | Supported carriers may change without notice. Message delivery is not guaranteed in all areas or on all carriers. |
7.3 Only your own number. Consent must come from the person who holds the number. We do not accept a mobile number submitted on someone else's behalf, and we do not text a Participant because their employer listed a mobile number on a roster.
7.4 Withdrawing consent. Replying STOP withdraws your consent immediately for the number from which you reply. You may also email [email protected] to be removed. Opting out of text messages does not remove you from email, and does not stop transactional communications necessary to deliver a live engagement.
7.5 Changing your number. Please tell us if you stop using a mobile number you have given us, so that we do not message a person who has not consented.
↑ Back to top8.Telephone Calls
If you provide a telephone number and request contact, you consent to receive calls from Flourish at that number regarding your inquiry, your proposal, and your engagement. You may ask us to stop calling at any time by telling us during a call or by emailing [email protected], and we will add you to our internal do-not-call list. We may record or take notes of discovery and scoping calls for quality and training purposes where permitted by law; where consent is required, we will tell you at the start of the call and you may decline.
↑ Back to top9.How We Share Information
We share personal information only as described below. Mobile telephone numbers and SMS consent are excluded from all sharing except with the messaging vendors identified below as Service Providers.
| Recipient | Purpose |
|---|---|
| Service providers — CRM and marketing automation, website and funnel hosting, email delivery, SMS delivery, scheduling, video conferencing, form and survey tools, workflow automation, cloud storage | To operate the Site and deliver the Services. Providers may process personal information only on our instructions and are contractually restricted from using it for their own purposes. |
| Payment processor | To process payments and issue invoices. The processor collects and stores payment credentials directly under its own privacy policy. |
| Facilitators & contractors | Where an engagement is delivered or supported by an associate facilitator or contractor, they receive only what they need to deliver it and are bound by confidentiality obligations equivalent to ours. |
| Your own organization | Where you attend as a Participant, your employer or the organization that engaged us may receive attendance information and general feedback about the session. We do not report individual performance to your leadership. See Section 3.5. |
| Other Participants in your session | Questions you ask, material you share, and comments you make in a session are visible to the other people in the room. See Section 12. |
| Professional advisors — attorneys, accountants, insurers | To obtain professional advice and manage risk, under duties of confidentiality. |
| Legal & safety | Where we believe disclosure is required by law, subpoena, or legal process, or is reasonably necessary to protect the rights, property, or safety of Flourish, our clients, or the public, to investigate fraud or unauthorised distribution of our program materials, or to enforce our Terms. |
| Business transfer | In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to the acquirer honoring this Policy. Mobile opt-in data will not be transferred for the acquirer's own marketing without new consent. |
| With your direction | Any other sharing you specifically request or authorize, including permission to name your organization or feature your results in our marketing. |
10.We Do Not Sell Your Information
Flourish does not sell personal information for money, and does not share personal information for cross-context behavioral advertising by third parties, as those terms are defined under state privacy laws. We do not rent, trade, or license personal information to data brokers, lead aggregators, list sellers, or other advertisers, and we have not done so in the twelve (12) months preceding the Last Updated date above.
Some state privacy laws define “sale” or “sharing” broadly enough to capture the use of advertising cookies and pixels. As described in Section 4, we do not currently use any, and our first-party platform analytics are not shared with advertisers or combined across other websites. If we adopt advertising technology in future, we will update Section 4 and this Section and will provide the opt-out mechanisms those laws require. You can contact us at [email protected] at any time with questions.
↑ Back to top11.Participant Rosters & Attendee Data
11.1 Where roster data comes from. To deliver a session we usually need a participant roster from the organization that engaged us — typically names, work email addresses, job titles, and any accessibility or dietary requirements. That information comes from your employer or the organization that booked the session, not from you.
11.2 The organization is responsible for notifying its people. Under Section 15 of our Terms of Service, the organization that provides a roster confirms that it has the authority to do so and has given its people whatever notice its own privacy policy and applicable law require. If you are a Participant and were not told your details were shared with us, please raise it with your employer first — and you can also contact us at [email protected].
11.3 What we do with it. We use roster data only to deliver the engagement: to send joining links, reminders, pre-work, and materials, to arrange accessibility requirements, and to record attendance. We do not use it to build marketing lists (see Section 6.3) or to send text messages (see Section 7.3).
11.4 What we ask organizations not to send. Please send only what we need. Do not send Social Security numbers, government identification numbers, financial account details, health information beyond an accessibility or dietary requirement, performance reviews, disciplinary records, or other sensitive personnel information.
11.5 Return and deletion. On written request from the organization after an engagement ends, we will delete or return roster data, except for records we must retain for accounting, tax, or legal defense purposes and copies held in routine backups until they expire.
11.6 Individual requests. A Participant may exercise the rights in Section 16 directly with us. Where the request concerns information the organization provided or controls, we will tell the Participant and, where appropriate, refer the request to that organization.
↑ Back to top12.Session Recordings
12.1 Sessions are recorded. Sessions are recorded so that people who could not attend can catch up and so the material stays available to the organization for its access period. A recording may capture your video, voice, display name, chat messages, questions, and anything you share on screen.
12.2 The organization tells its people. The organization that engages us is responsible for informing Participants in advance that sessions are recorded and for obtaining any consent required by law or by its own policies. Several states require the consent of all parties to record a conversation.
12.3 You control how much of you is captured. Participation on camera is optional. You may keep your camera off, stay muted, use a first name or display name rather than your full name, and ask questions in writing. If you would prefer your contribution not be retained, tell us during or promptly after the session and we will edit it out of the retained copy where technically practicable.
12.4 Who can see recordings. Recordings are made available to the organization that engaged us, for the access period agreed with it. We may retain a copy for our own records. Where a recording segment contains no client confidential information and no identifiable Participant, we may reuse it as general instructional material.
12.5 Marketing use requires permission. We will not use a recording, image, name, voice, or quotation that identifies your organization or you personally in our public advertising or marketing without asking separately and obtaining written permission, which may be withdrawn at any time as to new materials.
12.6 Others' obligations. Our Terms of Service prohibit Participants from making their own recordings and from sharing another Participant's contribution outside the engagement. We enforce those rules, but we cannot guarantee that every person in a room will follow them.
↑ Back to top13.AI Tools & the Content You Generate
This is the part organizations most often overlook. When your people use a third-party AI tool, they are sending prompts, uploads, and documents to that company — not to us. What happens to that data is governed by that company's terms and privacy policy and by whatever plan your organization holds with it, not by this Policy.
13.1 We do not control third-party tools. Our programs reference and demonstrate third-party AI tools. We have no access to your organization's accounts with those providers, no visibility into what your people submit to them, and no ability to delete data from them on your behalf.
13.2 Providers may retain and use what is submitted. Many AI providers retain prompts and uploaded files, and some use submitted content to improve or train their models, sometimes depending on plan tier or account settings. Enterprise and business plans often carry different data-handling terms from consumer plans. Review each provider's terms and settings, and confirm what your organization's plan actually says, before anyone uploads organizational information.
13.3 Do not upload confidential or personal information without approval. Take particular care with customer, member, patient, donor, and employee data, with anything covered by a confidentiality agreement, and with regulated information. A tool demonstrated in one of our sessions is not thereby approved for your organization's data — that decision is yours to make under your own policies.
13.4 Take care with images of people. Do not upload a person's photograph or likeness to an AI tool without that person's informed consent. In some jurisdictions a facial image is treated as biometric data with its own consent requirements.
13.5 What we see. We see only what you choose to share with us or raise in a session. That is handled under this Policy like any other information you give us.
↑ Back to top14.Data Retention
We keep personal information only as long as necessary for the purposes described in this Policy, and then delete or de-identify it. In general:
- Inquiries that do not become engagements — retained while we follow up and for a reasonable period afterward.
- Client and engagement records — retained for the duration of the relationship and for a period afterward to support accounting, tax, and legal defense needs.
- Participant rosters — retained for the engagement and a reasonable period afterward, or deleted earlier on the organization's written request under Section 11.5.
- Session recordings — retained for as long as they remain available to the organization under its access period, plus our own archival copy.
- Assessment responses — retained so that results can be revisited and compared over time, unless you ask us to delete them.
- Client confidential information — retained only as long as needed to deliver and support the engagement, then deleted or returned on request, subject to routine backups and one archival copy retained for legal and audit purposes.
- Billing and tax records — retained for the period required by applicable law.
- Marketing lists — retained until you opt out.
- Opt-out and do-not-contact records — retained indefinitely, because we need them to keep honoring your request.
- Consent records — retained for at least the period of any applicable statute of limitations, so that we can demonstrate that consent was given.
15.Data Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, limiting access to personnel with a business need, and selecting vendors that maintain appropriate security practices.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping any credentials we issue confidential, for not forwarding session links outside your organization, and for notifying us promptly at [email protected] if you believe an account or link has been compromised. Where a breach affecting your information occurs, we will notify you and, where required, the relevant authority, within the time limits applicable law requires.
↑ Back to top16.Your Privacy Rights & Choices
Regardless of where you live, you may ask us to:
- Access the personal information we hold about you;
- Correct information that is inaccurate or out of date;
- Delete information we no longer need to retain;
- Stop marketing to you by email, text message, or telephone; or
- Receive a copy of information you provided to us in a portable electronic format.
How to make a request. Email [email protected] with the subject line “Privacy Request” and tell us what you would like us to do. We will verify your identity, usually by confirming information already in our records or by asking you to respond from the email address on file. We respond within forty-five (45) days and may extend once where reasonably necessary, in which case we will tell you.
If your details came from your employer. Where the information relates to a roster or engagement arranged by an organization, we may need to consult that organization before acting, and may refer the request to it where it is the party that decided to collect the information. See Section 11.6.
Authorized agents. An agent may submit a request on your behalf with written proof of authorization; we may also contact you to confirm.
No retaliation. We will not deny you services, charge you a different price, or provide a different level of service because you exercised a privacy right.
Limits. We may decline a request where an exception applies — for example, where we must keep information to complete a transaction, comply with a legal obligation, maintain security, or establish or defend legal claims. We will tell you the reason. Note also that deleting your contact record does not automatically remove your appearance in a session recording; tell us if you want that addressed as well and we will do so where technically practicable.
↑ Back to top17.State-Specific Privacy Rights
17.1 A note on business contact information. Most state privacy laws apply to information about individuals acting in a personal or household capacity, and several exclude information about a person acting in a commercial or employment context. Where an exclusion applies to your information, we nonetheless extend the rights described in Section 16 to you as a matter of practice.
17.2 Florida residents. The Florida Digital Bill of Rights applies to companies meeting revenue and activity thresholds that Flourish does not currently meet. We nonetheless extend the rights described in Section 16 to Florida residents as a matter of practice.
17.3 California residents. Under the California Consumer Privacy Act as amended by the CPRA, you have the rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and be free from retaliation. The categories of personal information we have collected in the past twelve (12) months, the sources, purposes, and recipients are described in Sections 2, 5, and 9. We have not sold or shared personal information as those terms are defined by the CCPA, and we do not knowingly collect or sell the personal information of consumers under sixteen (16) years of age. Under California's “Shine the Light” law, you may request information about disclosures to third parties for their direct marketing purposes; we do not make such disclosures.
17.4 Other states. Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, and other states with comprehensive privacy laws have similar rights, which may include the right to appeal a denied request. To appeal, reply to our response or email [email protected] with the subject line “Privacy Appeal.” If your appeal is denied, you may contact your state Attorney General.
17.5 Nevada residents. Nevada law allows residents to opt out of the sale of certain covered information. We do not sell covered information, but you may submit a request to [email protected].
↑ Back to top18.Do Not Track & Global Privacy Control
Web browsers may offer a “Do Not Track” signal. Because there is no common industry standard for interpreting it, the Site does not respond to Do Not Track signals. We do honor the Global Privacy Control (GPC) signal, where technically feasible, as a valid request to opt out of any sale or sharing of personal information for the browser and device on which it is sent. As described in Section 4, we do not currently engage in any activity that would constitute a sale or share.
↑ Back to top19.Third-Party Websites & Platforms
The Site and our Services link to and run on third-party websites, tools, and platforms that we do not control — including video conferencing, scheduling, payment processing, form and survey tools, and the AI tools described in Section 13. This Policy does not apply to them. We encourage you to read the privacy policy of any service you use.
↑ Back to top20.Children's Privacy
The Site and our Services are intended for adults. We do not knowingly collect personal information from anyone under eighteen (18) years of age, and our programs are not offered to minors. If you believe a minor has provided us personal information, contact [email protected] and we will delete it.
↑ Back to top21.Users Outside the United States
Flourish is based in the United States and our Site and Services are directed to the United States. If you access the Site or engage us from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.
↑ Back to top22.Changes to This Policy
We may update this Policy from time to time. The “Last Updated” date at the top reflects the most recent revision. If we make a material change to how we use personal information — including if we begin using advertising or analytics technology as described in Section 4 — we will provide notice by posting the updated Policy on this page and, where required or appropriate, by email. Your continued use of the Site after the effective date constitutes acceptance of the updated Policy.
↑ Back to top23.Contact Us
To ask a question, exercise a privacy right, or opt out of communications:
| Entity | Flourish AI LLC, d/b/a Flourish |
|---|---|
| Mailing address | 1317 Edgewater Dr #5781 Orlando, FL 32804 |
| Privacy, general & opt-out | [email protected] |
| Website | flourishwithai.co |