Privacy Policy
Last updated 5 September 2026
This describes what Flows collects, why it is collected, and what control you have over it. It is written to be read, not to be survived.
What we collect
- Account details: your email, display name and, if you set one, an avatar.
- Content you create: workspaces, projects, tasks, comments, messages and files.
- Activity: which tasks you complete and focus sessions you finish, so the contribution heatmap has something to show.
- Technical data: a session cookie and standard server logs.
What we do not collect
No third-party advertising or analytics trackers. Your passwords are stored only as a bcrypt hash and are never recoverable, by us or anyone else.
How your data is isolated
Every request is scoped to the workspace you are a member of. Content in one workspace is not readable from another, and uploaded files are served through the API so the same permission check applies to a download as to any other read.
Sub-processors
- Resend: transactional email (verification codes, invitations).
- Google and Discord: only if you choose to sign in with them.
- Our hosting and database providers, which store data at rest.
Retention
Content persists until you delete it. Deleting a workspace removes its projects, tasks and conversations. Deleting your account removes your profile; content you created in shared workspaces is retained for the other members, with your authorship anonymised.
Your rights
You can export or delete your data at any time. Email us and we will action it within 30 days.
Contact
Questions about this policy: support@flowsapp.work.