Privacy Policy

Effective Date: March 12, 2026  ·  Last Updated: March 12, 2026

At FlowStates, your privacy is a core value — not an afterthought. This policy explains in plain language what data we collect, why we collect it, how we protect it, and the rights you have over it. Please read it carefully.


1. Who We Are

FlowStates ("we", "our", or "us") is a personal productivity and well-being application that helps users track their focus sessions, manage tasks, and reflect on their daily progress through AI-assisted check-ins and voice journaling.

If you have any questions about this policy, you can reach us at: privacy@flowstates.ai

2. Information We Collect

2.1 Account & Identity Data

When you sign in with Google, we receive and store the following information provided by Google:

This data is used solely to create and identify your account. We do not collect your Google password or access any other Google account data beyond what you explicitly authorize.

2.2 Profile & Preferences

2.3 Check-In & Session Data

FlowStates is built around timed focus sessions called "check-ins." During a check-in we may collect:

2.4 Task & To-Do Data

2.5 Messages & AI Conversations

If you use the in-app AI assistant, message history is stored to maintain conversation context. Messages are subject to our retention policy; you can request deletion at any time (see Section 7).

2.6 File Uploads

Files you deliberately upload to the app (e.g., attachments, voice memos) are stored on our servers. Only you can access your uploaded files through your authenticated session.

2.7 Calendar Data

If you connect Google Calendar, we access your calendar events to synchronize tasks and sessions. We read only the calendar data necessary for this feature and never modify your calendar without explicit action from you.

2.8 Technical & Usage Data

3. How We Use Your Data

We use the data described above strictly for the following purposes:

We do not use your data for advertising. We do not build advertising profiles, sell your data, or share it with ad networks.

4. Third-Party Services

FlowStates integrates with the following third-party services to deliver its features. Each service is bound by its own privacy policy and data-processing terms.

Google OAuth 2.0 Google Calendar API ElevenLabs Hume AI OpenRouter

Google OAuth 2.0 & Google Calendar

Used for sign-in and optional calendar synchronization. Governed by the Google Privacy Policy. FlowStates' use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

ElevenLabs

Used to transcribe audio recordings you create during check-ins. Audio segments are sent to ElevenLabs' API for transcription and are not stored by us beyond the duration needed to process the request. See the ElevenLabs Privacy Policy.

Hume AI

Used to analyze the tone and emotional content of session transcripts to generate session summaries. Only text transcripts (not raw audio) are sent to Hume AI's API. See the Hume AI Privacy Policy.

OpenRouter

Powers the in-app AI assistant. Message threads are transmitted to OpenRouter's API to generate responses. See the OpenRouter Privacy Policy.

We never sell your personal data to any third party. Data shared with the above providers is transmitted solely to enable the feature you are actively using.

5. Data Storage & Security

Your data is stored in a secured database hosted on our servers. We apply the following safeguards:

While we take reasonable technical and organizational measures to protect your data, no system is completely immune to risk. We will notify you promptly in the event of a data breach that materially affects your personal information.

6. Data Retention

7. Your Rights & Choices

Depending on your jurisdiction, you may have the following rights:

To exercise any of these rights, contact us at privacy@flowstates.ai. We will respond within 30 days.

8. Children's Privacy

FlowStates is not directed at children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. International Data Transfers

Our servers are located in the European Union / Turkey. When data is transmitted to third-party services such as ElevenLabs, Hume AI, or OpenRouter, it may be processed in the United States or other countries. We ensure that appropriate safeguards are in place (e.g., Standard Contractual Clauses or equivalent mechanisms) to protect your data during such transfers.

10. Cookies & Local Storage

The FlowStates web app uses browser local storage and session storage to maintain your authenticated session and user preferences. We do not use third-party tracking cookies or advertising cookies. No cross-site tracking is performed.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you via email or an in-app notification. Continued use of FlowStates after the effective date constitutes acceptance of the revised policy.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact: