Privacy Policy
Last updated: April 2026
With The Flow (“we”, “us”, or “our”) is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and how we keep it safe.
1. What We Collect
1.1 Account Information
- Email address (when you sign in)
- Profile details you provide during onboarding (name, life chapter, focus themes)
1.2 Your Writing & Reflections
- Notes and posts you write in The Flow
- Mood logs
- Your Sankalpa (personal intention)
- Autobiography entries generated from your writing
1.3 Device Information
- A device identifier used for data sync across sessions
- Basic usage data (app opens, feature usage) to improve the experience
1.4 Payment Information
Subscription status is managed by your device account's app marketplace. We never see or store your payment card details.
2. How We Use Your Data
- To power the app — your writing is processed by AI (DeepSeek) to generate autobiography chapters, monthly reports, and Flow Friend responses
- To personalise your experience — your story and profile shape what your AI companions say to you
- To send reminders — daily notification prompts, if you enable them
- To improve the app — anonymous usage patterns help us fix bugs and improve features
2.1 How Data Is Collected
- You provide data directly in onboarding, The Flow, journal, mood logs, and chat
- The app records technical metadata (timestamps, device/session identifiers) during use
- Subscription status is returned by RevenueCat and app marketplaces
2.2 AI Data Processing Consent (Opt-in)
- Before third-party AI processing, the app shows an in-app disclosure and asks permission
- The disclosure identifies what data is sent, who receives it, and why
- You can change this in Settings → AI Data Processing Permission
- If disabled, AI generation features are paused
3. Who We Share Data With
We do not sell your personal data. We share limited data with:
- Supabase — our backend database and authentication provider
- DeepSeek AI — processes your writing to generate AI responses (data is not used to train their models per their enterprise terms)
- RevenueCat — manages subscription status
- Sentry — receives anonymised crash reports to help us fix bugs
3.1 Data Sent to Third-Party AI
When AI permission is enabled, the app may send to DeepSeek AI:
- Writing and journal content
- Mood log notes
- Chat messages
- Selected onboarding context for personalization
Purpose: generate AI responses, daily prompts, autobiography entries, and monthly reports.
3.2 Third-Party Protection Standard
We require processors and service providers to provide data protection measures equal to or stronger than our security baseline for confidentiality, transport encryption, and access control.
4. Data Storage & Security
- Your data is stored on Supabase servers protected by Row Level Security (RLS) — only you can read your own data
- All connections are encrypted with TLS
- We never store plaintext passwords
5. Your Rights
You have the right to:
- Access your data at any time within the app
- Delete your account and all associated data by contacting us
- Export your autobiography and story entries (coming soon)
6. Data Retention
We retain your data for as long as your account is active. When you delete your account, all personal data is permanently removed within 30 days.
7. Children
With The Flow is not intended for users under 17 years of age. We do not knowingly collect data from minors.
8. Contact
For privacy questions or data deletion requests, contact us at:
This policy may be updated periodically. We will notify you of significant changes through the app.