Back to home

Privacy Policy

Last updated 5 September 2026

This describes what Flows collects, why it is collected, and what control you have over it. It is written to be read, not to be survived.

What we collect

  • Account details: your email, display name and, if you set one, an avatar.
  • Content you create: workspaces, projects, tasks, comments, messages and files.
  • Activity: which tasks you complete and focus sessions you finish, so the contribution heatmap has something to show.
  • Technical data: a session cookie and standard server logs.

What we do not collect

No third-party advertising or analytics trackers. Your passwords are stored only as a bcrypt hash and are never recoverable, by us or anyone else.

How your data is isolated

Every request is scoped to the workspace you are a member of. Content in one workspace is not readable from another, and uploaded files are served through the API so the same permission check applies to a download as to any other read.

Sub-processors

  • Resend: transactional email (verification codes, invitations).
  • Google and Discord: only if you choose to sign in with them.
  • Our hosting and database providers, which store data at rest.

Retention

Content persists until you delete it. Deleting a workspace removes its projects, tasks and conversations. Deleting your account removes your profile; content you created in shared workspaces is retained for the other members, with your authorship anonymised.

Your rights

You can export or delete your data at any time. Email us and we will action it within 30 days.

Contact

Questions about this policy: support@flowsapp.work.