Flowsophy

Privacy Policy

Last updated: 29 September 2026

This Privacy Policy describes how Flowsophy collects, uses, and shares personal information in connection with our application and related services (the "Service"). The Service is operated by the developer of Flowsophy ("Flowsophy," "we," or "us"), who is the data controller for the personal information described here. For questions about this policy, contact us at hi@flowsophyapp.com.

Information we collect

We collect the following categories of personal information:

CategoryDescription
Account informationThe user's name, email address, and the sign-in identifier from their authentication provider (Google, Apple, or a one-time code sent to the email address). We never receive a password.
Content the user providesThe topics the user enters, the Flowmaps generated for them, their notes, and any information the user chooses to make public, such as a profile or a shared Flowmap.
Usage and device informationThe user's IP address, an approximate location derived from it, device and browser characteristics, and records of activity on the Service.
Analytics informationWhere the user consents, masked and anonymized session analytics collected through Microsoft Clarity.
Payment informationWhere the user purchases Sparks or a subscription, transaction records processed by our payment provider or, in the iOS app, by Apple through our subscription management provider. We do not receive or store full payment card details.
Onboarding answersWhere the user answers the optional onboarding question (what kind of learner they are: a student and their level and, at university level, their major, an educator and the subjects they teach, or a curious person and their favorite subjects) and whether they made the learning promise. Held on the account, editable in Settings, and used in aggregate to understand who uses Flowsophy and to improve it. They are not sent to our AI provider and do not change the Flowmaps generated. The question can be skipped.
Notification informationWhere the user turns on push notifications in the iOS app, the device's push token and the user's account identifier, held by our notification delivery provider, together with the content of the notifications we send.
CommunicationsInformation the user submits through our feedback, support, or data-request channels.

How we use information

We use the information we collect to operate, maintain, and improve the Service, to authenticate users and secure accounts, to prevent fraud and abuse, to process transactions, to communicate with users, and to comply with legal obligations. Where required by law, we rely on the following legal bases: performance of our contract with the user, our legitimate interests in providing and improving the Service, the user's consent for optional analytics, and compliance with legal obligations. We do not sell personal information.

AI processing

When a Flowmap is generated, the input provided is transmitted to our third-party AI provider to produce the output. AI-generated output may be inaccurate or incomplete and should not be relied upon as a definitive source.

Cookies

We use cookies and similar technologies. Strictly necessary cookies are required to operate the Service and to keep the user signed in, and do not require consent. Analytics cookies are optional and are set only after the user provides consent, which may be withdrawn at any time.

CookiePurposeType
Strictly necessary cookiesAuthentication and session securityEssential
_clck, _clsk (Microsoft Clarity)Masked, anonymized analytics, set only with consentAnalytics

How we share information

We share personal information with third-party service providers that perform functions on our behalf, including hosting, database, authentication, AI processing, payment processing, subscription management, push notification delivery, email delivery, and analytics. These providers are permitted to use the information only to provide services to us. We may also disclose information where required by law, to enforce our Terms of Service, or to protect the rights, safety, and security of our users and the Service. We do not sell personal information.

International transfers

The Service is operated from the United States. If the user accesses it from outside the United States, their information will be transferred to and processed in the United States. Where required, such transfers are made under appropriate safeguards, including the Standard Contractual Clauses approved by the European Commission.

Data retention

We retain personal information for as long as the user's account is active or as necessary to provide the Service. Following account deletion, public content is removed immediately and personal information is deleted within 30 days, except where retention is required for legal, accounting, or security purposes.

Rights and choices

Depending on their location, the user may have the right to access, correct, delete, or obtain a copy of their personal information, and to object to or restrict certain processing. The user may withdraw consent to optional analytics at any time. The user can delete their account within the Service or through our account deletion page, or submit a request to hi@flowsophyapp.com. Users in the European Economic Area or the United Kingdom may also contact their local data protection authority.

Age

The user must be at least 13 years old, or older where the law of the user's country sets a higher age of digital consent (up to 16 in parts of the European Union). We do not knowingly collect personal information from anyone below that age, and will delete it if we become aware of it.

Flowsophy for schools

Schools use Flowsophy through a separate site, schools.flowsophyapp.com. There, a teacher creates an account for each student and gives the student a sign-in code. A student account holds the first and last name the teacher typed, the sign-in code stored hashed and encrypted, the Flowmaps the teacher assigned, the student's own notes, favorites, saved Wikipedia passages and scratchboard on those Flowmaps, the time of the last sign-in, and the IP address recorded at sign-in for security. A student account has no email address, no photo and no date of birth. It is used for no advertising and no analytics, and the analytics described above never load on the school site.

The teacher can read what a student writes on an assigned Flowmap, including notes, the scratchboard, favorites and saved passages. The AI processing described above happens for a student only when the teacher turns on the Guide for the class, and the request then carries the Flowmap as context and nothing about the student. The teacher can remove a student at any time, which deletes the account and everything in it. Students on the school site must be at least 13 years old, and the school is responsible for obtaining any consent its law requires before a teacher creates an account for a student. A school that needs a student data agreement can write to hi@flowsophyapp.com.

Security

We implement reasonable technical and organizational measures designed to protect personal information.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email, and the date above will be updated accordingly.

For questions about this policy, contact us at hi@flowsophyapp.com. Please also review our .