Privacy Policy

Last updated: March 2026

Flowset LLC ("Flowset," "we," "us," or "our") operates the Flowset web application. This Privacy Policy explains how we collect, use, and protect your information when you use our service.

1. Information We Collect

Account Information: When you create an account, we collect your name, email address, and password. If you sign in with Google, we receive your name and email from Google.

Assessment Data: We collect your responses to onboarding and comprehensive assessments to personalize your experience and recommend sessions.

Usage Data: We collect information about your session playback history, ratings, favorites, streaks, and app interactions to improve the service.

Payment Information: Payments are processed by Stripe, Inc. We do not store your credit card number or payment details. Stripe collects and processes payment information in accordance with their privacy policy at stripe.com/privacy.

Push Notification Data: If you enable push notifications, we store your notification preferences and push subscription information to deliver reminders.

Device Information: We may collect basic device and browser information for analytics and to optimize the app experience.

2. How We Use Your Information

We use your information to:

  • Provide and personalize mental training sessions
  • Process payments and manage subscriptions
  • Send push notification reminders (if enabled)
  • Track your progress, streaks, and assessment scores
  • Improve and develop the service
  • Communicate with you about your account

3. Data Storage and Security

Your data is stored securely using Supabase, which provides encrypted database hosting and authentication services. Audio files are stored in Supabase Storage with signed URLs that expire after one hour. All data is transmitted over HTTPS.

We implement row-level security policies on all database tables to ensure users can only access their own data.

4. Third-Party Services

We use the following third-party services:

  • Supabase — Authentication, database, and file storage
  • Stripe — Payment processing
  • Google — OAuth sign-in (optional)
  • Vercel — Application hosting

Each of these services has their own privacy policies governing their handling of your data.

5. Data Retention

We retain your data for as long as your account is active. If you delete your account, we will delete your personal data, including your profile, assessment scores, session history, and preferences. Some data may be retained in backups for a limited period.

6. Your Rights

You have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Delete your account and associated data
  • Opt out of push notifications at any time

You can delete your account from the Settings page within the app.

7. Children's Privacy

Flowset is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy within the app. Your continued use of Flowset after changes constitutes acceptance of the updated policy.

9. Contact Us

If you have questions about this Privacy Policy, contact us at:

Flowset LLC
Email: flowsetapp@gmail.com