1. Introduction
Welcome to FlowE ("FlowE," "we," "us," or "our"). FlowE is a productivity and task management application designed for college students, graduate students, and adult learners. Our app helps you organize tasks, sync academic calendars, coordinate with family or household members, and stay motivated through gamification.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the FlowE mobile application and related services (collectively, the "Service"). Usage analytics begin after account setup and can be disabled at any time in Privacy settings.
If you have any questions or concerns about this policy, please contact us at support@flowe.cc.
2. Information We Collect
We collect information in the following categories:
a) Account Information
When you create an account, we collect:
- Email address
- Full name
- Profile information (e.g., school level, role selection)
- Authentication credentials managed through our authentication provider (Clerk)
b) Canvas Integration Data
If you choose to connect your Canvas LMS account, FlowE may use one or more of the following connection methods depending on what your school supports:
- Institution-managed Canvas OAuth
- Personal Canvas API token
- Canvas ICS calendar feed fallback
Depending on the connection method, we may access:
- Course names, sections, and course metadata
- Assignments, due dates, scheduling details, and calendar events
- Submission status and related assignment state
- Grade summaries, score information, and assignment grouping metadata
This data is used to power academic planning features inside FlowE, including task creation, calendar views, due date tracking, course organization, and grade-awareness features. The exact data available depends on the connection type you use and your institution's Canvas configuration.
c) Google Calendar Data
If you choose to connect Google Calendar, FlowE requests read-only access to the calendars you select and may access calendar names, event titles, descriptions, dates, times, locations, attendee details, recurrence information, and availability needed to show and organize your schedule inside FlowE.
FlowE's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. We use Google Calendar data only to provide or improve the user-facing calendar import and planning features you request. We do not use Google Calendar data for advertising, cross-app tracking, data brokerage, creditworthiness or lending decisions, unrelated analytics, or training general-purpose AI models. We do not allow humans to read this data except with your affirmative consent for a specific support purpose, when necessary for security or abuse investigation, or when required by law. We do not sell Google user data or transfer it to third parties except service providers acting on our behalf to provide or secure the requested feature, or as otherwise permitted by the Limited Use requirements.
d) Task and Productivity Data
As you use FlowE, we store:
- Tasks, projects, and events you create
- Tags, categories, and organizational preferences
- Focus timer session data
- Schedule and routine preferences
e) Family Coordination Data
If you use family features, we collect:
- Shared tasks and events between family members
- Family member display names and roles
- Family group membership information
f) Gamification Data
- FlowPoints earned and spent
- Achievement and badge progress
- Levels, streaks, and leaderboard standings
g) Usage Analytics
After account setup, we collect pseudonymous usage data through PostHog unless you opt out in Privacy settings, including:
- Feature usage patterns (e.g., which screens you visit, which features you use)
- App performance metrics (e.g., load times, error rates)
- Session duration and frequency
Analytics may be associated with your FlowE account identifier so we can understand reliability and feature use across sessions. We do not use this data for cross-app advertising. You may opt out at any time through Settings → Privacy & Data → Data Collection.
h) Institutional Onboarding Data
If a school administrator submits Canvas OAuth details through our admin onboarding portal, we collect:
- Institution name and Canvas domain
- Administrator contact details and role
- Canvas OAuth client ID, redirect URI, and encrypted client secret
- Verification and review metadata needed to approve the integration
i) Device Information
We collect limited device information needed for compatibility, notifications, security, and debugging, including operating system version, device type, app version, and a push-notification token if you enable notifications.
j) AI Feature Data
When you choose an AI-powered feature, the text or structured context needed for that request and the generated response are processed by FlowE's backend and an AI model provider. Do not submit passwords, authentication codes, financial credentials, or other information you do not want processed for that feature.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide Core Functionality: To operate FlowE, including task management, calendar views, and focus timers.
- Sync Canvas Academic Data: To import and update course, assignment, due date, calendar, submission-state, and grade-summary information supported by your Canvas connection.
- Import Google Calendar Data: At your request, to read selected calendars and events and display them in FlowE's schedule and planning features.
- Activate School OAuth Integrations: To verify, review, approve, and maintain institution-submitted Canvas OAuth configurations.
- Enable Family Coordination: To allow shared tasks and events between family members.
- Track Gamification Progress: To calculate FlowPoints, achievements, levels, streaks, and leaderboard positions.
- Improve the App: To analyze pseudonymous usage patterns and fix bugs; you can opt out in Privacy settings.
- Send Notifications: With your permission, to send reminders and updates.
- Provide AI-Powered Features: To offer task suggestions, time estimates, and schedule optimization.
- Authenticate Your Identity: To verify your account and manage sessions.
- Communicate With You: To respond to support requests and service announcements.
4. Data Sharing
We do not sell, rent, or trade your personal information to third parties. We only share information in limited circumstances:
a) Family Members
If you join a family group, members can see shared tasks, events, and your display name. Family data sharing is opt-in and revocable.
b) Service Providers
- Convex (backend database and real-time sync)
- Clerk (authentication)
- PostHog (analytics, opt-out available)
- OneSignal (push notifications)
- Apple and Google (sign-in and optional platform integrations such as WeatherKit or Google Calendar)
- Your Canvas institution (only when you connect a supported Canvas account)
- AI model providers (only when you invoke an AI-powered feature)
c) Legal Requirements
We may disclose information if required by law or to protect rights and safety.
d) Business Transfers
In the event of a merger or acquisition, we will notify you of ownership changes.
5. Data Storage & Security
- Backend: Convex with encryption at rest and access controls.
- Encryption in Transit: HTTPS using supported TLS connections.
- Canvas Admin Credentials: Institution client secrets submitted through the admin portal are encrypted at rest before storage.
- Secure Local Storage: Personal Canvas API tokens, ICS feed URLs, and locally managed app credentials are stored in iOS Keychain where applicable.
- Canvas Connection Data: We may store Canvas connection records, OAuth state, and sync metadata in our backend and on your device as needed to support the integration.
- Google Calendar Credentials: Google access and refresh tokens are stored in iOS Keychain. Disconnecting Google Calendar or signing out removes FlowE's local Google credentials; you can also revoke FlowE from your Google Account permissions.
- Authentication: Clerk with session management and OAuth 2.0.
- Access Controls: Account data is protected by server-side authorization. A limited set of invitation, referral, support, or integration endpoints may be public and are separately restricted.
No method is 100% secure, but we use commercially reasonable safeguards.
6. Your Rights
You have the following rights regarding your personal data:
a) Access Your Data
View all data via Settings → Privacy & Data.
b) Delete Your Data
Request deletion via Settings → Account → Delete Account or contact support. We remove active account data through our deletion process; limited records may remain where required for security, legal compliance, dispute resolution, or a service provider's bounded backup cycle.
c) Export Your Data
Export via Settings → Privacy & Data → Export My Data, or contact support@flowe.cc.
d) Opt Out of Analytics
Disable via Settings → Privacy & Data → Data Collection.
e) Correct Your Data
Update profile in-app or contact support@flowe.cc.
7. Data Retention
- Active accounts: Retained while needed to provide the Service and maintain your account.
- Deleted accounts: Removed from active product systems through our deletion process; bounded backup, security, and audit records expire under provider retention schedules unless law requires longer retention.
- Analytics: Pseudonymous analytics are retained according to our configured analytics retention and are subject to your opt-out and applicable deletion rights.
- Legal obligations: Limited records may be retained where required for legal compliance, fraud prevention, security, or dispute resolution.
8. Children's Privacy
FlowE requires account holders to be at least 18. App Store ratings may display differently by operating-system version or region. FlowE is not directed to children under 18. We do not knowingly collect information from anyone under 18.
If we learn that an ineligible minor provided personal information, we will take appropriate steps to remove it. Contact support@flowe.cc to report a concern.
9. Changes to This Policy
We may update this policy. For material changes:
- We will update the effective date.
- We will notify you via push notification or in-app notice.
- We will provide at least 30 days' notice.
Continued use after changes constitutes acceptance.
10. Contact Information
- Email: support@flowe.cc
- Privacy: privacy@flowe.cc
We respond to privacy inquiries within 30 days.