Privacy Policy

Last Updated: March 27, 2026

Flowo Technologies Inc. (pre-incorporation), operating as "Flowo" from Halifax, Nova Scotia, Canada, is committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, and what rights you have in relation to it. We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and the European Union's General Data Protection Regulation (GDPR). If you have any questions, please contact us at privacy@flowoapp.com.

1. Who We Are

Flowo is a secure environment designed to help users manage tasks and executive function. The data controller responsible for your personal information is Flowo Technologies Inc. (Pre-incorporation), c/o Volta, 1505 Barrington St, Unit 100, Halifax, Nova Scotia, B3J 3K5, Canada. Data Protection Contact: privacy@flowoapp.com. For the purposes of the GDPR, we act as the "Data Controller" for the personal information we process.

2. Data We Collect

We adhere to the principle of data minimization and collect only what is strictly necessary. This includes: Account Information (email, encrypted auth token via Supabase with AES-256), Task & Application Data, Product Analytics via PostHog with strict input masking, Technical & Log Data via Cloudflare, and Payment Information handled entirely by our payment provider.

3. How We Use Your Data

We process data to: Provide the Service (contract performance), Improve the Product (legitimate interest via anonymized analytics), Communicate With You (consent/legitimate interest), Process Payments (contract performance), and Ensure Security (legitimate interest via Cloudflare).

4. Sub-Processors & Third-Party Services

We share data only with trusted sub-processors: Supabase (Database & Auth), PostHog (Analytics), Cloudflare (CDN & Security), GitHub Pages (Hosting), and our Payment Provider. Flowo's intelligent processing occurs exclusively on our own secure servers. We do not sell, rent, or trade personal information.

5. Privacy-First Intelligent Architecture

Flowo's core features are powered by models on our own secure servers with enterprise-grade encryption. Your data is never shared with third-party providers or used to train external models.

6. International Data Transfers

For EEA transfers, we use Standard Contractual Clauses (SCCs) or the EU-U.S. Data Privacy Framework. For Canadian users, we comply with PIPEDA requirements.

7. Data Retention

Account & Task Data: retained while your account is active, erased within 30 days of deletion. Analytics Data: max 12 months. Payment Records: up to 7 years per tax legislation.

8. Your Rights Under GDPR

If located in the EEA/UK: Access, Rectification, Erasure, Restriction, Portability, and Objection. Contact: privacy@flowoapp.com. Response within 30 days.

9. Your Rights Under PIPEDA

Canadian residents: right to access, challenge accuracy, and withdraw consent. Contact: privacy@flowoapp.com.

10. Cookies & Tracking

We use cookies for core functionality and anonymous analytics. No third-party advertising cookies.

11. Data Security

Industry-standard measures: TLS 1.2+ in transit, AES-256 at rest, strict access controls.

12. Children's Privacy

Not intended for children under 16. We do not knowingly collect data from children.

13. Changes to This Policy

We may update this policy. Material changes will be posted with an updated "Last Updated" date.

14. Contact Us

Questions? Contact us at privacy@flowoapp.com or at our Halifax office.