
Floot
Floot is a remote MCP server paired with a full-stack hosting platform: describe an app inside Claude, ChatGPT or Cursor and it builds the whole thing, backend, Postgres database and hosting included, for non-coders and founders.
What is Floot?
Floot is not a chat interface with a builder attached. It is a remote Model Context Protocol server, reachable at mcp.floot.com/mcp over Streamable HTTP with OAuth 2.0, bolted onto a full-stack hosting platform. There is no prompt box on floot.com at all: the assistant you already pay for, Claude, ChatGPT, Cursor, Codex, VS Code or Zed, drives the build, and Floot supplies everything that assistant cannot host on its own. The product registers as com.floot/floot and publishes a manifest at /.well-known/mcp.json.
A Floot project is a real TypeScript and React application: pages, components, helpers, serverless HTTP endpoints and static assets. Around it, Floot provisions a managed Postgres database, accounts with email and password or Google and Microsoft OAuth handled on Floot's side, file storage, transactional email with a send log, web and native push, scheduled tasks and hosting, none of which requires opening a third-party account. Publishing is one click to a yourname.floot.app subdomain; a custom domain comes with the paid plans.
The commercial model is the unusual part. Reasoning runs on the user's own AI subscription, so Floot bills no tokens. It counts two things instead: build actions, where one completed tool call equals one action and failures never count, and credits, reserved for image generation and the AI features embedded in the published app.
The assistant is handed a wide tool surface: creating projects, reading, writing, editing and patching files, searching code, managing dependencies, provisioning resources, querying the database and running SQL, reading logs, type-checking, running tests, executing code in a VM or in the live browser, capturing preview screenshots, generating images, publishing and creating checkpoints. Floot is equally explicit about what the assistant cannot do: enable native mobile builds, finish a domain's DNS, produce the code export zip, read secrets, or spend money. No payment tool exists, and that is claimed as a design decision.
Around the core sit hybrid server-side rendering with generated sitemap, robots.txt and canonicals, built-in visit analytics, the free Floot Infinity Chrome extension, a named integration catalogue, a public community gallery and nineteen free mini-tools built on Floot itself. The interface exists in seven languages.
What it does
- Describe an application in plain language from Claude, ChatGPT, Cursor or any MCP client and have it built end to end.
- Provision a managed Postgres database, authentication, file storage and transactional email without pasting a single key.
- Publish in one click to a yourname.floot.app subdomain.
- Attach a custom domain on the paid plans.
- Turn the same web project into native iOS and Android apps on the Power plan.
- Export the code and a SQL dump of the database.
- Have the assistant read the runtime logs and fix the errors it finds.
When to use Floot / When not to
A quick filter to help you decide if Floot is the right fit.
When to use Floot
- Non-coders and first-time founders who want a working application without touching git, a terminal or a build pipeline.
- People already paying for Claude, ChatGPT or Cursor: the reasoning runs on that subscription, and Floot never bills a token.
- Small teams shipping internal tools, MVPs and line-of-business apps, the kind on show in Floot's gallery: job-site tracking, orthodontic KPIs, staff scheduling, booking follow-up.
- Makers whose apps have to be found: server-side rendering, generated sitemap and robots.txt, automatic canonicals and social previews come built in.
- Builders who intend to keep what they build: a SQL dump on every plan, code export on paid plans and documented self-hosting elsewhere.
When not to use Floot
- Anyone without an MCP client. There is no prompt box on floot.com, so with no Claude, ChatGPT or Cursor connected there is nothing to build with, and the Claude connector requires a paid Claude plan.
- Teams handling health, financial or otherwise regulated data: the documentation sends them to legal counsel and asks them to contact Floot before launch, and the Terms forbid supplying Customer Data that constitutes personally identifiable information.
- Buyers working through a security questionnaire: no SOC 2, ISO 27001, HIPAA or PCI certification is published, no data processing agreement is offered, and no hosting country or region is declared.
- Studios expecting a store-ready mobile binary. Floot generates Xcode and Android Studio projects; compiling, signing and submitting stay with the user, and iOS needs a Mac.
- Anyone planning production work on the free plan, or anyone under 18: the free tier stops at 2 projects, 1 published app and 100 MB of storage with no custom domain and no code export, and the Terms restrict the Services to adults.
How to use Floot
A typical end-to-end flow, from setup to results.
- Pick your MCP client: Claude, ChatGPT, Cursor, Codex, VS Code or Zed. The Claude connector requires a paid Claude plan.
- In Claude, open Floot in the connector directory, click Connect and authenticate on Floot. On a team or enterprise workspace, an Owner enables the connector once and each member then clicks Connect.
- In ChatGPT, install the Floot app from the app directory, authorise it, then switch Floot on from the + menu or with @Floot; turn on "Allow all actions" to stop approving every call.
- In any other client, add a remote MCP server over Streamable HTTP, enter https://mcp.floot.com/mcp, sign in with OAuth and leave the bearer and header fields empty.
- In Claude, prefer Cowork mode over Chat and pick a capable model, Opus or equivalent, or GPT-5.5 Sol and above on ChatGPT, for long builds.
- Describe the project you want. The assistant creates it and returns a live preview link.
- Iterate in the chat: add a login page, adjust a screen, ask the assistant to read the logs and fix what broke.
- Use the project view on floot.com to watch the preview, point at an element and annotate a screenshot; it carries no prompt box.
- Ask the assistant to publish, then collect the yourname.floot.app URL.
- Finish the manual steps in the browser: native mobile builds, custom-domain DNS, the code zip download, third-party API keys, plan changes and purchases.
Pros & Cons
Pros
- No token billing. The reasoning runs on the AI subscription you already pay for, and the plans are flat.
- Failed or cancelled tool calls are never deducted, and monthly credits roll over for one month on a paid plan.
- A complete stack is provisioned without opening a third-party account or pasting an API key.
- Portability is genuine: SQL dump on every plan, code export and documented self-hosting.
- SEO is native, where most competing generators still serve empty pages to crawlers.
- No exposed tool can spend money, purchases and plan changes being pages you click, and secrets stay out of the AI payload by construction rather than by instruction to the model.
- One project serves web, iOS and Android, and connecting takes a single click from the Claude and ChatGPT directories.
Cons
- Unusable without an MCP client, since floot.com carries no build interface. The Claude connector needs a paid Claude plan, and opening a project someone else shared needs a paid Floot plan.
- Real database rows reach the AI provider's context whenever a query requires them.
- The privacy policy lists AI model training among its purposes, with no documented opt-out mechanism.
- No published security certification, no data processing agreement, and no declared hosting country or region.
- Preview links open without a login for anyone holding them, for seven days.
- Credits are non-refundable and lost on cancellation, monthly credits expire at the end of the cycle, a cancelled account's published app is pulled as soon as its hosting credit runs out with no grace period and the subdomain is released, and hosting can run a negative balance to settle.
- Store publishing is entirely on the user, with developer accounts, a Mac and Xcode for iOS and Android Studio for Android; support is live chat, Discord and an email address, with no documented contractual channel and no full postal address published.
Pricing & Plans
Floot operates a freemium model, with all fees stated and payable in US dollars. A permanent free plan is available at no cost, and no credit card is required to start; it is a free tier rather than a time-limited trial. The lowest paid entry point is Pro at USD 25.00 per month, with Power at USD 100.00 per month above it. Usage is governed by two separate counters: build actions, which meter the assistant's work, one completed tool call counting as one action and failures never counting, and credits, which cover image generation and the AI features embedded in the published app. Hosting is included as a credit allowance, USD 3 once on Free, USD 10 per month on Pro and USD 25 per month on Power, billed daily against that allowance and then against the credit balance, with any overuse becoming a negative balance to settle. Monthly credits roll over for one month on a paid plan; one-off top-ups start at USD 20, at USD 1 for 1,000 credits, are non-refundable and expire after 60 days. Upgrades are prorated immediately and the current period is not refunded on cancellation. The AI reasoning itself is paid for elsewhere, through the user's own Claude, ChatGPT or Cursor subscription.
- 100 build actions per UTC day plus 400 over a rolling 7 days
- 3
- 000 credits granted once at sign-up
- USD 3 of hosting credit once
- 2 projects
- 1 published app
- 100 MB of storage
- no custom domain
- 1
- 000 build actions per day with no weekly cap
- 5
- 000 credits per month
- USD 10 of hosting included per month
- unlimited projects and published apps
- unlimited storage
- custom domains with one domain free
- 5
- 000 build actions per day
- 15
- 000 credits per month
- USD 25 of hosting included per month
- everything in Pro
- and the only plan that converts a web project into native mobile apps.
- credits are retained
- but build actions fall back to the free plan's limits.
Data, GDPR & hosting
A consolidated view of how Floot handles your data.
GDPR overview
Floot never claims GDPR compliance anywhere on the site. The only occurrence of the phrase describes Plausible, a third-party analytics option offered to users' own apps, not Floot itself. What the privacy policy does provide is a rights list, access, rectification, erasure, export, objection to certain processing and withdrawal of consent, exercised through a single channel, feedback@floot.com, with a stated target of seven business days. International transfers within the provider network are acknowledged with "appropriate safeguards" that are never specified. No data processing agreement is published or announced as available on request, no Article 27 EU representative and no data protection officer is named, and no hosting country or region is declared. The Terms are governed by California law, the Services are restricted to users aged 18 and over, and the only address published is San Francisco, CA.
Who owns the data?
Floot's Terms reserve all right, title and interest in Customer Data, expressly including Prompts and Output, to the user, and the company assigns whatever rights it might hold in the Output; the security documentation states plainly that you own 100% of your app, its code and its data. Floot keeps the Services themselves and the Aggregate Data, the de-identified aggregated sets derived from customer content. Portability is real: a SQL dump is downloadable at any time on every plan, code export is reserved to paid plans, and self-hosting is documented. Two exceptions matter. Feedback is irrevocably assigned to Floot, and publishing a project grants Floot and other users a worldwide non-exclusive licence to remix it. Output may also be identical or similar to another customer's, and confers no rights over theirs.
Reuse rights
Because the user holds the rights to Prompts and Output, that material can be reused, published or sold on without asking Floot for permission. Floot's own use of data is declared broadly: delivering and improving the service, AI model training, quality, support, payments, updates, security, usage analysis, debugging and fraud prevention. Named recipients include model providers (Anthropic, OpenAI, Google, Mistral, Groq, Cerebras, Amazon Bedrock), infrastructure (AWS and a managed database provider), analytics (Amplitude, PostHog), payments (Stripe), email (Resend) and security (Cloudflare Turnstile). Floot states that it does not receive the conversation with the assistant: only MCP tool calls transit, and one event per call reaches PostHog carrying the tool name, status, duration, client and project identifier, not the full arguments or file contents. Tool outputs, however, re-enter the conversation and then fall under the AI provider's own policy, and the Terms record explicit consent to sharing Customer Data and Prompts with Third-Party Models at the minimum necessary. Secrets and API keys are never exposed to the AI, being collected through a dedicated form, stored server-side and injected at runtime; real database rows are exposed as soon as a query requires them.
Data retention & training
Hosting summary
Floot names its infrastructure but never its geography. The security documentation states that your database, your project source and your files are stored on managed AWS and Neon infrastructure with provider-level disk encryption, and adds explicitly that no additional application-layer encryption is applied; all traffic runs over HTTPS and TLS. The Y Combinator profile describes a scalable hosting system built directly on AWS. No hosting country and no region is declared anywhere on the site, and the privacy policy acknowledges that data may be transferred internationally within the provider network under unspecified appropriate safeguards. Internal access is limited to Floot staff and framed as part of handling an incident the user has reported. One observation from our own network checks, which is not a declaration by the company: the site's public IP (65.9.130.121, AS16509 Amazon) geolocates to Frankfurt, Germany, a CDN edge node that says nothing about where customer data actually resides. Buyers with a data-residency requirement therefore have nothing to rely on beyond the AWS and Neon names.
Where Floot works
Country-level availability.
Not available in
Things to keep in mind
Risks and trade-offs to weigh before adopting Floot.
- Preview links carry a ?ptoken in the clear, open with no login for anyone holding them and stay valid for seven days. Treat one exactly like a shared document link.
- Making a project public exposes its source, its project prompt and the assistant's activity history, and lets any paid account duplicate it.
- Your app users' real data reaches the AI provider's context whenever a query requires it, while the Terms forbid handing Floot Customer Data that constitutes personally identifiable information or falls under heightened security requirements. That line is easy to cross without noticing.
- The privacy policy lists AI model training among its declared purposes with no documented opt-out, and no certification (SOC 2, ISO 27001, HIPAA, PCI) or data processing agreement is published.
- The "Skip all approvals" option recommended for Claude Cowork also skips Claude's own safety pauses, trading away the very prompts that would otherwise stop a destructive action.
- Money and continuity: credits are non-refundable and lost immediately on cancellation or suspension for breach, a cancelled account's app disappears the moment its hosting credit runs out with no grace period and the subdomain is released, and the hosting balance can go negative and must be settled before you continue.
- Building entirely through someone else's model invites skill atrophy. The code is real TypeScript and React that you own, but if you never read it you cannot audit what it does with your users' data, and the only address published anywhere is "San Francisco, CA" should you ever need to reach the company formally.
Setup & Integrations
Technical difficulty
Low to connect, moderate to finish. One click from the Claude connector directory or the ChatGPT app directory, then an OAuth sign-in; other clients take a remote MCP server over Streamable HTTP at https://mcp.floot.com/mcp. No git, no terminal, no key to paste for the built-in services. Prerequisites: a paid Claude plan for that connector, a capable model for long builds, and on ChatGPT a setting change to stop approving every action. The browser is still required for native mobile builds, domain DNS, code export, third-party API keys and payments; store submission needs developer accounts, a Mac and Xcode.
Deployment
Integrations
Supported languages
Behind Floot
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Floot.
Frequently asked questions
Do I need to know how to code to use Floot?
Do I need a paid AI subscription?
Does Floot charge for tokens?
What is the cheapest paid plan?
Who owns the code and the data?
Can my AI assistant see my app users' data?
Is my data used to train AI models?
Can I publish to the App Store and Google Play?
What happens if I cancel?
What support and languages are available?
Should you pick Floot?
Floot's positioning is genuinely distinct: it does not sell you the model, it sells the infrastructure the model drives. The economic consequence follows directly, flat plans instead of per-token billing, because the reasoning runs on the Claude, ChatGPT or Cursor subscription you already hold. For a non-coder or a founder already working inside one of those assistants, that removes both the learning curve and the metered anxiety of building an app.
The product is strong where builder platforms are usually weak. Portability is real rather than rhetorical: a SQL dump on every plan, code export on paid plans, documented self-hosting. SEO is native, with server-side rendering, generated sitemap and canonicals, where many generators still hand crawlers an empty page. The documentation is unusually candid about what the tool cannot do, and no tool exposed to the assistant can spend your money.
The weakness is compliance paperwork. There is no published certification, no data processing agreement, no declared hosting country or region, and AI model training sits among the declared purposes with no documented way out. Your app users' real data reaches the AI provider's context whenever a query needs it, while the Terms forbid entrusting Floot with personally identifiable Customer Data, a tension worth resolving before launch rather than after.
It is also a young company: Y Combinator Summer 2025, a seed round, two founders, one open role. Judge it accordingly for anything that must outlive a startup's first two years. Best served are non-coders and entrepreneurs already paying for Claude or ChatGPT and building internal tools, MVPs and small-business apps they intend to own. Poorly served are regulated industries, procurement teams with a security questionnaire, and anyone expecting a finished mobile binary rather than an Xcode project.
- Choosing a selection results in a full page refresh.
- Opens in a new window.