Skip to content

Privacy Policy

Version 2.4 — Effective August 2, 2026

1. What we collect

  • Account info: Name, email address, hashed password (bcrypt with cost factor 12), and custom profile avatars or workspace branding assets (stored as compressed Base64 Data URLs).
  • Workspace data: Projects, subtask ledgers, nested checklists, project chat messages, in-app notifications, and custom team roles created inside Flowly.
  • Flowly Journal entries: Private daily shift notes and personal to-do lists entered in the Flowly Journal module.
  • Push notification delivery data: If you install the Flowly Android app and enable notifications, we store a private device delivery address (per-device token) so we can route task, completion, and chat alerts to your phone. This token identifies a device endpoint — it does not include your message content beyond what is needed to display the notification.
  • Operational & browser data: Client IP address (used strictly for rate limiting and security enforcement), User-Agent header, session tokens stored in HTTP-only secure cookies, and local layout preferences stored in your browser's localStorage.

2. How we use your data

We use your data strictly to operate the service — rendering your visual dashboard, delivering transactional email notifications and team invitations, generating PDF executive briefings, and notifying you about project milestones. We do not sell your data, monetize user lists, or train third-party artificial intelligence models on your content.

3. Infrastructure & sub-processors

Three trusted cloud infrastructure partners process data on our behalf to deliver Flowly:

  • Railway — Cloud infrastructure platform hosting the Next.js application server, Prisma MySQL database, and Redis cache.
  • Hostinger — Domain registration, DNS management (flowlycloud.cc), and transactional email delivery via the Hostinger Agentic Mail REST API.
  • Sentry — Receives anonymized, privacy-masked error traces when system exceptions occur.

Push notifications are delivered through Flowly's own web-push server — we do not route mobile notifications through Firebase or any third-party analytics SDK.

We do not share your data with advertisers, third-party trackers, or marketing data brokers.

4. Flowly Journal & personal notes privacy

Entries created inside the Flowly Journal module are bound strictly to your individual profile (userId) with zero-exception per-user isolation. Journal entries are strictly private to you and are never accessible or visible to workspace managers, organization admins, or other team members.

The Flowly Journal interface includes a 1-click Privacy Blur Mode to visually obscure sensitive shift notes on screen when working in shared operational environments.

5. Your rights & GDPR compliance

You retain full ownership and control of your data:

  • 1-Click Data Export: Download a complete JSON archive of your personal profile, assigned tasks, project chat messages, and notifications at any time from Profile Settings.
  • Self-Service Account Deletion: Delete your account permanently from Profile Settings. For Manager accounts, deletion triggers a complete cascade purge of the entire workspace and all related project data.

6. Security measures

Passwords are hashed using bcrypt with a cost factor of 12. Authentication sessions rely on HTTP-only, SameSite secure cookies. All web traffic is encrypted in transit via TLS/HTTPS. Rate limiting is enforced on authentication and contact endpoints to block brute-force attempts.

To report security vulnerabilities, email hello@flowlycloud.cc.

7. Contact us

Privacy inquiries: hello@flowlycloud.cc.