Privacy Policy
Last updated: July 11, 2026
1. Introduction
Flowe ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered neural reset platform.
Please read this privacy policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Name (if provided)
- Organization name (for team accounts)
- Authentication credentials (managed by our identity provider)
Usage Data
We automatically collect certain information when you use the Service:
- Session start and end times
- Session types completed
- Feature usage patterns
- Device and browser information
Session Data
Important: We do NOT record or store the audio content of your NSDR sessions. Voice interactions are processed in real-time and are not retained. Only session metadata (duration, completion status) is stored for analytics purposes.
3. How We Use Your Information
We use the information we collect to:
- Provide and maintain the Service
- Process your subscription and payments
- Generate aggregated team analytics (for organization administrators)
- Improve and personalize user experience
- Communicate with you about service updates
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. Team Analytics & Privacy
For organization accounts, administrators can view aggregated team metrics. We design our analytics with privacy in mind:
- Aggregated Data: Burnout metrics are shown as team averages, not individual scores
- No Content Access: Administrators cannot access session content or listen to recordings
- Usage Only: Only completion rates and session counts are visible to admins
5. Information Sharing
We do not sell your personal information. We may share information with:
- Service Providers: Third-party services that help us operate the platform (payment processing, authentication, hosting)
- Organization Administrators: Limited aggregated data for team accounts as described above
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
6. Data Security
We implement appropriate security measures to protect your information:
- End-to-end encryption for voice sessions
- Encrypted data transmission (HTTPS/TLS)
- Secure cloud infrastructure with SOC2-ready architecture
- Regular security audits and updates
- Access controls and authentication requirements
7. Data Retention
We retain your information for as long as your account is active or as needed to provide services. Specifically:
- Account Data: Retained until account deletion
- Session Metadata: Retained for analytics purposes, anonymized after 2 years
- Billing Records: Retained as required by law (typically 7 years)
- Voice Data: NOT retained - processed in real-time only
8. Your Rights
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Export your data in a portable format
- Opt out of marketing communications
- Withdraw consent where applicable
To exercise these rights, contact us at privacy@flowe.ai.
9. Cookies and Tracking
We use essential cookies to:
- Maintain your session authentication
- Remember your preferences
- Provide security features
We do not use third-party advertising trackers. Analytics cookies are used only to improve the service and can be disabled in your browser settings.
10. International Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
11. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
12. Google User Data & API Services
Flowe offers an optional Google Calendar connection. It is never required to use Flowe. If you choose to connect it, you grant access on Google's own consent screen, and you can disconnect at any time (see "Your controls" below).
What we access
When you connect Google Calendar, Flowe requests read-only access using these Google OAuth scopes:
calendar.readonlyandcalendar.events.readonly— read your events, including their times, titles, and descriptions, and your busy/free blockscalendar.calendarlist.readonly— read the list of your calendars so you can choose which one Flowe reads
Flowe requests no write access. We never create, edit, or delete events on your calendar.
How we use it
Google Calendar data is used for a single purpose: to time neural resets and ambient check-ins around your day and to make each suggestion fit the moment. Flowe looks at two things — the shape of your schedule (how many meetings you have and where the dense or back-to-back blocks fall) and what an upcoming meeting is about — so it can recommend the right kind of reset.
To understand what a meeting is about, Flowe reads the event's title and a short excerpt of its description and processes them in the moment, in memory — including by our AI model — to infer the meeting's nature (for example, a heads-down focus block versus a high-stakes review). Event titles and descriptions are never stored; they are used only to generate that suggestion and are then discarded.
Flowe does not collect the names or email addresses of the people on your invites. It only looks at whether a meeting includes other people — to tell a real meeting from solo blocked time — and how many.
What Flowe stores is limited to minimized, derived signals — counts and timing such as "four meetings today, two back-to-back." Stored signals never contain the raw contents of your events (titles, descriptions, locations, notes, or attendee lists); this is enforced in our sync pipeline. They are also short-lived and expire automatically.
Limited Use and the Google API Services User Data Policy
Flowe's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Your controls
You can disconnect Google Calendar at any time in Settings → Ambient, which stops future syncs and revokes the access tokens Flowe holds. You can also review or revoke Flowe's access directly from your Google Account permissions. The meeting signals Flowe derives from your calendar expire automatically, and you can delete them immediately with the ambient memory delete control in Settings → Ambient. Deleting your Flowe account removes this data. For any request, email privacy@flowe.ai.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at privacy@flowe.ai.