flo / your repairs

Staging privacy notice

Prepared September 5, 2026 for a limited test preview. Deployment verification and owner review are required before enabling public sign-in.

Operator and contact

Alexander Ammann operates Flo. Privacy requests: xyes47314@gmail.com. Do not email passwords or authorization tokens or post private information in public issues.

What this preview does

Flo lets invited testers review fictional repair status and estimates. Do not submit real repair, vehicle, payment or sensitive information. The customer preview does not approve work, take payments, purchase parts or change appointments. It is not directed at children.

Amazon sign-in and repair ownership

When enabled, Login with Amazon supplies an Amazon user identifier and temporary authorization credentials. Flo does not receive your Amazon password and does not request your name, email, postal address or payment information. Signing in does not establish repair ownership. A separately verified, operator-controlled link to a test customer record is required. An unlinked identity cannot access repairs.

Storage and service providers

Amazon processes sign-in under its own policies. The staging design uses AWS API Gateway, Lambda and DynamoDB. Temporary login and session values are application-encrypted before database storage. Customer links record the Amazon identifier, customer identifier, verification operator, time and evidence reference. Only fictional, customer-visible repair projections are stored in the staging repair table. Customer data is not sent to the separate Bedrock narrator. No advertising or analytics trackers are included.

Cookies, retention and deletion

Essential secure cookies bind sign-in to your browser and hold an opaque Flo session ID. Login state is valid for five minutes. Sessions are valid for at most 15 minutes or until the Amazon credential expires, whichever is earlier. Flo checks expiry during authorization even if expired database records have not yet been removed. DynamoDB TTL cleanup can take several days. Logout deletes the server session and clears Flo cookies; it does not sign you out of Amazon. Refresh tokens are not retained.

Test customer links and fictional repair projections remain until the operator removes them or retires the test. Ask the contact above to remove your association. Deactivation is checked on subsequent authorized requests. The proposed customer stack retains operational logs for seven days, excludes request bodies, cookies and query strings from configured access logs, and does not enable backups for short-lived authentication state. These deployment settings must be verified before sign-in is enabled. AWS also processes connection information needed to provide its services.

Your choices

You may decline sign-in, sign out, or request access, correction or deletion through the privacy contact. Amazon account linking for Alexa+ is a separate integration and is not established by this website. This notice must be updated when the deployed data practices change.