Flowstate Privacy Policy
Effective 27 September 2026
Overview
Flowstate turns what you say into documents, notes and plans for your work. This policy says what we keep and why, who helps us run the app and how to see or delete what we hold. "We" means the people who make Flowstate.
How you sign in
You can sign in with Apple or with Google. If you do neither, the app starts a guest session on your phone the first time it opens, so you can try it without an account.
What we keep on our server
- Account. The id Apple, Google or the guest session gives us. If you sign in with Apple or Google, also the email address and name they share with us.
- Your profile. The name, email, business name, craft, rates, payment terms and writing preferences you set in the app, so documents can use them.
- Your work. The documents, templates, chats and meeting transcripts and summaries you make or import, so they are there next time you open the app. Deleting a document, chat or meeting deletes it along with the versions, search copies and memory made from it. A template you delete is hidden at once and removed from our server when you delete your account.
- Memory. Flow keeps a profile of you and your work. It also keeps pages about the clients, projects and people you work with. It also keeps notes on how you write, such as words you use often, how you sign off and the names of documents you wrote.
- Search copies. Short excerpts of your documents and memory, with numbers that let Flow find the right one when you ask.
- Tasks and goals. These live on your phone. The app also sends a copy to our server so Flow can read and add tasks when you chat. If you delete the app or move to a new phone, they do not come back.
- Document files. When a document is written or exported as a file, our server stores the file so your phone can download it. It stays in our storage until you delete the document or your account.
- Feedback. What you write when you send feedback, the app's recent log lines and a screenshot if you attach one.
- Google data. Only if you sign in with Google or connect it; the Google data section below says what and why.
- Purchases. Whether you have a plan. Apple takes the payment and RevenueCat tells us the result. We never see your card.
- Push token. A token from your phone so we can send the notifications you turn on.
What stays on your phone
- Recordings. The audio of a session you record is kept on your phone. It is streamed to Deepgram to be written out as you record. Our server keeps only the transcript.
- Voice. When you talk to Flow, your audio goes to Deepgram to become text and is not kept. Flow's spoken replies are made on our own server.
- Your Details. The address, phone number, website and city you add to Your Details stay on your phone. The app sends them only inside a document or export that uses them, such as a PDF footer.
We do not collect your location from your phone, your contacts or any biometric data. We never make a voiceprint.
Google data
This part applies when you sign in with Google or connect it. Google shows you what Flowstate asks for, and you can turn off any part of it on that screen.
- Your Google account. Your name, email address and Google account id, to sign you in.
- Google Calendar (the calendar.events permission). Flowstate reads the events on your main calendar to name your meetings and pair them with their notes, to show today's meetings, to prepare your routines and to answer when you ask about your schedule. It adds an event only when you tap Add to Calendar, and Google then emails the invitation to the guests you chose. It never changes or deletes an event.
- Google Meet (the meetings.space.readonly permission). When you open the app and in the background, Flowstate checks your recent Meet calls for transcripts. It brings each transcript, with the names of the people in the call, into Meetings and writes notes from it.
- Google Drive (the drive.file permission). Flowstate saves the documents you export as Google Docs in a Flowstate folder in your Drive. It can see only the files it created, never the rest of your Drive.
What we keep. The meetings brought in from Google, with their transcripts and the notes written from them, like any meeting you import; the link to each Google Doc you export; and your Google access, stored encrypted on our server so meeting import works while the app is closed.
Who else receives it. Anthropic receives what it needs to write what you ask for: a transcript for meeting notes, your events when you ask about your schedule or a routine runs, or a Flowstate file from your Drive when you ask about it. Voyage AI receives meeting summaries, with contact details taken out, to make them searchable. Neither trains on it.
How we use it. We use Google data only for the features you see in Flowstate. We do not sell it or use it for advertising, and we do not use it to create, train or improve any AI model, ours or anyone else's. We do not read it ourselves unless you ask us to, for security, or when the law requires.
Flowstate's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Turning it off. Disconnect Google in the app to end Flowstate's access; meetings already brought in stay until you delete them. Delete Account revokes the access and deletes everything that came from Google. You can also remove Flowstate at myaccount.google.com/permissions.
Counts we keep
To run your plan and improve Flowstate we keep counts that hold no text from your work. They record how many documents, chats and minutes you use, how long each step took, which AI model answered and what it cost. They also record whether a document was exported as written, exported after edits or thrown away.
Who helps us run Flowstate
Each of these gets only what its job needs.
- Anthropic: writes your documents, chat replies, meeting summaries and memory. Anthropic's terms for business use do not let it train on what we send.
- Deepgram: turns meeting audio and your voice into text. The setting that would let Deepgram use it to improve its models is off.
- Voyage AI: makes your documents and memory searchable. It receives short excerpts with phone numbers, email addresses and street addresses taken out. We have opted out of it training on anything we send.
- Sentry: receives error reports from our server. A report says what kind of error happened and where in our code, with a scrambled id instead of your account id. It never includes your words.
- Supabase: our database and file storage.
- Railway: hosts our server.
- RevenueCat: tells us whether you have a plan.
- Apple and Google: sign in. Apple also takes the payment for your plan.
- Expo: delivers push notifications. A notification says only that something is ready, never what it says.
We do not use OpenAI.
AI and your work
We do not train AI models on anyone's work. We do not sell your data or share it for advertising.
The app asks your permission before your words or voice first go to Anthropic, Deepgram or Voyage AI. You can turn this off at any time: in Settings, tap Privacy Policy, then Turn Off AI Partners.
Recording other people
When you record a meeting or a call, telling the people in it and getting their consent where the law requires it is your responsibility.
Seeing and deleting what we keep
- Memory. Open Profile, then Memory, to see what Flow remembers. You can forget a single page or everything. A forgotten page is hidden from Flow at once. Its earlier versions are kept, so a forget can be undone, until you delete your account.
- A copy. Settings, then Export My Data, gives you a copy of what our server keeps for you.
- Delete Account. Settings, then Delete Account, removes your account and everything our server keeps for you: documents, templates, chats, meetings, memory, search copies, tasks, goals, document files, feedback and counts. It also revokes the Apple and Google sign in you gave Flowstate. The app then removes the recordings on your phone.
You can disconnect Google at any time in the app. To cancel a plan, use your Apple ID settings.
How we protect it
Everything travels over encrypted connections. Your sign in stays in your phone's secure keychain. The Google access you grant is stored encrypted on our server.
Do Not Track
Flowstate does not track you across other apps or websites. It does not respond to Do Not Track signals because there is no tracking for them to turn off.
Children
Flowstate is for people 18 and older and is not directed to children. We do not knowingly collect information from anyone under 18. If we learn we have, we delete it.
Changes to this policy
When this policy changes, the date at the top changes. Before a change to what we keep or who helps us run Flowstate, we will tell you in the app.
Contact
For privacy questions or requests, email privacy@flowstate.build.