LEGAL
Privacy Policy
Anry is operated by Flowganise Pty Ltd (ACN 47 683 893 183). This policy covers what the Anry tag, the application and the MCP server collect, where it is stored, and what you can ask us to do with it.
Last updated 26 August 2026
This Privacy Policy describes how Flowganise Pty Ltd (ACN 47 683 893 183) (Flowganise, we, us or our) collects, uses, stores and discloses personal information in connection with Anry and the services provided through it (the Service). It applies to visitors to our website (anry.io), our customers (you or Customer) — including agencies running Anry for their clients — and the end users who visit our customers' websites (End Users).
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, do not use the Service.
1. Who We Are
Anry is operated by Flowganise Pty Ltd, a company incorporated in Australia and operating globally. Anry reads a store's whole funnel — on-site behaviour and connected advertising accounts, watched together — finds where revenue is slipping out, estimates what each issue is costing in dollars, and returns a prioritised fix.
Anry's access is read-only. It never creates, edits, pauses or deletes anything on your website or in your advertising accounts.
The Service is delivered through the Anry web application, the emails we send you (including the Monday brief), and the Anry MCP server. The application and your account are hosted under our company domain, flowganise.com, so that is the domain you will see when you log in.
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR:
- In relation to Customer personal data (e.g. your account and billing information), Flowganise is the data controller.
- In relation to End User data collected through the Anry tag on your website, Flowganise is the data processor acting on your instructions. You, the Customer, are the data controller of your End Users' data.
Where an agency runs Anry on behalf of its clients, each client workspace is treated as a separate set of instructions, and Flowganise acts as processor for the data in that workspace. How controller and processor roles fall between an agency and its client is a matter for the agreement between them.
2. Information We Collect
2.1 Information You Provide to Us (Customer Data)
When you register for an account, subscribe to a plan, book a demo or contact us, we may collect:
- Full name and job title
- Email address
- Company name and website URL
- Billing and payment information (processed by our third-party payment provider — we do not store full credit card details)
- Any other information you voluntarily provide through support requests or communications
If you choose to sign in with Google, we receive basic profile information from your Google account (your name, email address and profile picture) to create and authenticate your account.
2.2 Information Collected by the Anry Tag (End User Data)
When you install the Anry tag on your website, the Service collects data from your End Users, including:
- Session and behavioural data: pages visited, page sequences, scroll depth, click interactions, time on page, exit pages and session duration
- Traffic source data: referral URLs, UTM parameters, campaign identifiers and acquisition channels
- Device and browser data: browser type and version, operating system, screen resolution and device type
- Network data: IP addresses (which may be anonymised or truncated depending on your configuration and applicable legal requirements)
- Funnel and commerce data: conversion events, goal completions, order and average order values, and page-level drop-off rates as configured by you. These are the figures Anry uses to price a leak in dollars.
We do not intentionally collect names, email addresses, passwords, payment details or any other directly identifying personal information of End Users through the Anry tag, and we do not use it to collect the contents of form fields or text inputs.
2.3 Information Collected on anry.io
When you visit anry.io, our hosting provider records the standard request data needed to serve and secure the page, including your IP address, the pages requested and your browser and device type. We do not run third-party advertising or analytics trackers on anry.io, and our fonts are served from our own domain, so loading a page here makes no request to a third-party font service.
2.4 Cookies and Similar Technologies
- The Anry application: strictly necessary cookies, required for the Service to function (session management and authentication).
- Booking a demo: our demo page embeds a third-party scheduling widget. Loading it sets that provider's own cookies and storage, and the name, email and notes you submit are processed by them to make the booking. Marketing parameters already on the URL (such as utm_ values) are passed into the booking so we know which link brought you.
- The Anry tag: uses first-party browser storage (localStorage) on your website rather than cookies to recognise returning sessions. The identifier it stores contains no personally identifiable information and is used solely to provide accurate session and funnel analytics.
You can manage your cookie preferences through your browser settings. Note that blocking strictly necessary cookies will stop the application from working.
2.5 Information from Connected Advertising Accounts
When you connect an advertising account (such as Google Ads, Meta Ads or TikTok Ads) to the Service, you authorise us to access, on your behalf and through each platform's API, your advertising performance data. For Google Ads, this includes account, manager account and campaign identifiers and names, and daily performance metrics (spend, impressions, clicks and conversions). Equivalent campaign, spend and performance data is accessed for Meta Ads and TikTok Ads.
This access is read-only. We never create, edit, pause or delete campaigns, ads or account settings.
We use this data solely to display it to you in your own dashboard, alongside your website analytics, so you can measure return on ad spend and receive recommendations. Access tokens are stored encrypted, and performance data is stored within our infrastructure and processed only by the sub-processors necessary to operate the Service (see our sub-processor list). We do not sell this data, use it to serve advertising, or share it other than with those sub-processors.
Anry's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2.6 The Anry MCP Server
If you connect an AI coding agent or assistant to the Anry MCP server, that agent authenticates against your workspace and can read your findings, reports and analytics through it. The connection is read-only, and it is scoped to the workspace you connect it to.
Data returned over MCP then passes through the client and model provider you have chosen, and is handled under that provider's own terms rather than ours — so connect only the agents you are comfortable sharing your workspace data with. We do not send End User personal data over MCP.
3. How We Use Information
3.1 Customer Data
We use your personal information to:
- Create and manage your account
- Provide, maintain and improve the Service
- Process payments and manage your subscription
- Communicate with you about the Service, including your Monday brief, product updates, security alerts and support
- Respond to your enquiries and support requests
- Comply with legal obligations
- Protect against fraud, abuse and unauthorised access
3.2 End User Data
We process End User data on your behalf to:
- Detect leaks, friction and anomalies across your funnel — on-site and paid — using algorithmic and statistical analysis
- Estimate the dollar value at stake for each detected issue, using your own traffic, conversion rates and average order value rather than benchmarks
- Generate prioritised fixes and recommendations using a combination of algorithmic detection and AI-assisted analysis
- Measure what changed after you ship a fix, so the result can be reported back to you
- Provide you with accurate session, traffic and conversion analytics
We do not use End User data collected from your website to:
- Build profiles of individual End Users across different customers' websites
- Sell or rent End User data to third parties
- Serve advertising to End Users
- Contact End Users directly
3.3 Aggregated and Anonymised Data
We may create aggregated or anonymised data from Customer Data and End User Data for the purpose of improving the Service, conducting research and generating benchmarks. Aggregated and anonymised data cannot be used to identify any individual or Customer, and is not subject to the restrictions that apply to personal data under this Privacy Policy.
4. Legal Basis for Processing (GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract (Article 6(1)(b)): providing the Service, managing your account, processing End User data on your behalf as processor, and sending essential service communications.
- Consent (Article 6(1)(a)): sending marketing communications. You may withdraw consent at any time.
- Legitimate interests (Article 6(1)(f)): improving and securing the Service, conducting analytics, and protecting against fraud and abuse.
- Legal obligation (Article 6(1)(c)): complying with applicable laws and regulations.
6. Data Storage and Security
6.1 Where We Store Data
- EEA and UK Customer Data: End User data originating from the European Economic Area (EEA) or the United Kingdom is stored and processed within the EEA, in Germany.
- Other Customer Data: data from customers outside the EEA may be stored in other regions, as described in our sub-processor list.
6.2 International Transfers
Where personal data originating from the EEA or the United Kingdom is processed outside the EEA — including by sub-processors — we ensure that appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses (SCCs) or other legally recognised transfer mechanisms under Chapter V of the GDPR.
6.3 Security Measures
We implement commercially reasonable technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure or destruction. These include encryption in transit and at rest, encrypted storage of advertising platform access tokens, access controls, regular security reviews and incident response procedures.
No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security.
7. Data Retention
7.1 Customer Data
We retain your account information and billing data for the duration of your subscription and for a reasonable period thereafter, to comply with legal, accounting and reporting obligations.
7.2 End User Data
We retain End User data for the duration of your subscription. Upon termination, we retain your data for 30 days to allow you to request an export. After this period, we will delete or anonymise End User data in accordance with our data retention schedule.
7.3 Other Data
Aggregated and anonymised data may be retained indefinitely, as it cannot be used to identify any individual.
We may retain certain information for longer periods where required by law (e.g. tax or accounting records), or where necessary to establish, exercise or defend legal claims.
8. Your Rights
8.1 All Customers
Regardless of your location, you may:
- Request access to the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data (subject to legal retention requirements) — see how to delete your data for the steps
- Opt out of marketing communications at any time
8.2 Rights Under the GDPR (EEA and UK)
If you are located in the EEA or the United Kingdom, you have the following additional rights:
- Access: the right to request a copy of the personal data we hold about you.
- Rectification: the right to request correction of inaccurate or incomplete personal data.
- Erasure: the right to request deletion of your personal data, subject to legal retention requirements.
- Restriction: the right to request that we restrict the processing of your personal data in certain circumstances.
- Portability: the right to receive your personal data in a structured, commonly used, machine-readable format.
- Objection: the right to object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw consent: where processing is based on consent, the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
- Automated decision-making: the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you.
To exercise any of these rights, contact us at hello@anry.io. We will respond within 30 days, or within the timeframe required by applicable law.
8.3 Rights Under the Australian Privacy Act
If you are located in Australia, you have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including the right to access and correct your personal information. If you believe we have breached the APPs, you may lodge a complaint with us at hello@anry.io or with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
8.4 End User Rights
If you are an End User visiting one of our customers' websites and wish to exercise your data protection rights in relation to data collected through the Anry tag, please contact the website operator directly. As the data controller of your data, they are responsible for responding to your request. We will assist our customers in fulfilling such requests in accordance with our Terms and Conditions and applicable law.
9. Children's Privacy
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal information from children under 16 through the Service. If you are a Customer, you are responsible for ensuring that your website does not use the Service to collect data from children without verified parental consent where required by law.
If we become aware that we have collected personal data from a child under 16 without appropriate consent, we will take steps to delete that data promptly.
10. Third-Party Links and Services
Our website and the Service may contain links to third-party websites or integrate with third-party services — advertising platforms, scheduling tools, and the AI clients you connect over MCP. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policy of any third-party service you interact with.
11. Emails from Anry
Your Monday brief, your findings, and account, billing and security notices are part of the Service. We send them for as long as you have an account, and they are not marketing.
We may also send you marketing communications about our products and services where you have given consent, or where we have a legitimate interest in doing so (e.g. if you are an existing customer). You can opt out at any time by clicking the unsubscribe link in any marketing email, or by contacting us at hello@anry.io. Opting out of marketing will not affect the service emails described above.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before the changes take effect. Your continued use of the Service after the updated Privacy Policy takes effect constitutes your acceptance of the changes.
We encourage you to review this Privacy Policy periodically for the latest information on our data practices.
Contact us
Questions about this policy, or about what we hold on you? Write to us and a person answers.
- Entity
- Flowganise Pty Ltd, the company behind Anry
- ACN
- 47 683 893 183
- hello@anry.io