Your agents, your rules, never our training data
Falrow has built-in AI features and lets you connect your own coding agents. These terms explain how both work, who is responsible for what, and how we meet the EU AI Act. They form part of the Terms of Service.
Version 1.0 · Effective 6 October 2026
- AI features are off until enabled for your workspace, each one separately, with a monthly spend cap.
- We never use your data, prompts or outputs to train any model, and we never store prompts or outputs.
- AI output can be wrong. It is labelled as AI-generated and a person reviews it before it becomes a ticket.
- Agents you connect (Claude Code, Codex and others) act with the access you grant, under your workspace's rules. You are responsible for them.
- You own the output.
This summary helps you read the document. It is not part of it: where they differ, the sections below apply.
1.Two different things
Built-in AI features are parts of Falrow that call an AI model on your behalf: today, deciding whether a Slack message in a connected channel is a request or an open question and writing a title for it, and reading a connected database schema to list the questions it leaves open. We choose the model and send the request; the Subprocessors page names the providers.
Connected agents are AI tools you run yourself, such as Claude Code, Codex or Cursor, that read and write Falrow over the MCP server or REST API. You choose the agent, its provider and its settings. Falrow sees only what the agent sends to it; the agent's provider is your vendor, not ours.
2.Turning AI features on and off
Built-in AI features are disabled unless a workspace owner or admin enables them, per feature. When we pay for model usage, a monthly cap applies and requests stop at the cap. A workspace can instead use its own model provider key, in which case the requests go to that provider under your agreement with it and it bills you directly.
3.What happens to your data
- Only the content needed for the request in progress is sent to the model. For example, classifying a Slack message sends that message and its channel context, not the workspace.
- Prompts and completions are not stored by Falrow. We record which feature was used, by whom, and the token count, to enforce your cap.
- We do not use Customer Data, prompts or Output to train, fine-tune or improve any AI model, and we instruct our gateway to route requests only to model endpoints that do not retain or train on them.
- Our system prompts tell the model that your content is data, never instructions, to reduce the risk of prompt injection from content such as a pasted email.
4.Output: ownership and review
As between you and us, you own Output, and we assign to you any rights we have in it. Output may not be protected by copyright in every country, and similar Output may be generated for other customers.
Output can be inaccurate, incomplete or out of date. Falrow is designed so that a person reviews AI proposals before they take effect: a request detected in Slack waits in the Slack to-dos list until someone turns it into work or dismisses it. You are responsible for reviewing Output before relying on it, and for how you use it, including what you send to your own clients.
5.Transparency and the EU AI Act
Falrow's AI features are not high-risk AI systems under the EU AI Act: they help plan software work and are not used for employment decisions, credit, education, access to essential services or any other use listed in Annex III. Falrow does not use emotion recognition, biometric categorisation or any practice the Act prohibits.
Under Article 50 of the Act, which applies from 2 August 2026, people must be told when they interact with an AI system and when text is AI-generated. In Falrow:
- requests detected by a built-in AI feature are labelled as AI-detected where they appear, and the page that lists them says an AI model found them;
- changes made by a connected agent are marked in the activity log with the door they came through (MCP, REST API or Slack), separately from changes a person made in the app;
- when Falrow replies in Slack, it posts as the Falrow app, not as a person.
If you use Falrow to deploy an AI system toward your own clients or staff, for example by sharing AI-written summaries with them, you are the deployer, and the Article 50 duties that apply to deployers, such as disclosing AI-generated text on matters of public interest, are yours. Our explainer covers what that means in practice.
Everyone at our company who works on AI features is trained on how they work and their limits, as Article 4 (AI literacy) requires. We recommend you do the same for the people in your workspace who use them.
6.Your connected agents
- An agent acts under the identity and scope of the User who connected it. Workspace roles, workflow rules and version checks apply to it exactly as to a person.
- You are responsible for each agent you connect: what you instruct it to do, the scope you grant, the provider you use and what that provider does with data the agent reads from Falrow.
- Grant read scope where an agent only needs to plan, and revoke connections you no longer use. Owners can see every connection and revoke it.
- The Acceptable Use Policy has rules specific to agents.
7.Restrictions
You may not use AI features to generate content the Acceptable Use Policy prohibits, to make decisions with legal or similarly significant effects on people without human review, or to try to extract the system prompts, model weights or other customers' data. Our model providers' usage policies also apply to requests made through built-in features.
Questions about AI at Falrow: bas@falrow.com.
Wilmington, DE 19802
United StatesEIN 35-2886201bas@falrow.com