GDPR Compliant

Privacy Policy

Last updated: August 14, 2026  ·  Hopson & Cie Srl  ·  Brussels, Belgium

Our commitment: We collect only what is strictly necessary to operate Flowo across web, desktop, and mobile. We never sell your personal data. You can request deletion at any time.

1. Who We Are

Flowo is operated by Hopson & Cie Srl, a company incorporated under Belgian law:

Hopson & Cie Srl

149 avenue du Domaine, 1190 Bruxelles, Belgium

VAT: BE 0450.443.155

Email: privacy@getflowo.com

Website: https://getflowo.com

Hopson & Cie Srl acts as the data controller within the meaning of the EU General Data Protection Regulation (GDPR — Regulation 2016/679) for personal data processed through Flowo, unless stated otherwise for Team workspaces (see Section 5d).

1b. What Is Flowo (Platforms)

This Privacy Policy applies to all Flowo products and channels that share the same account and backend, including:

  • Web application at getflowo.com (including progressive web app / browser install)
  • Desktop application (Flutter shell for Windows, macOS, and Linux) that opens Flowo in a secure WebView connected to getflowo.com
  • Mobile applications (iOS / Android) that authenticate against the same Flowo API
  • Public booking pages (e.g. /book/…) that hosts share with guests
  • Marketing pages on getflowo.com (subject to cookie preferences — Section 10)

Unless a feature is platform-specific (for example push notification tokens), the same account data model applies across devices.

2. Data We Collect

2.1 Account Data

  • Email address — authentication, notifications, recovery
  • Display name / username
  • Password hash (never plaintext) when you register with email
  • OAuth profile fields (Google / Microsoft): provider ID, email, name, avatar URL when you sign in with those providers
  • Optional 2FA (TOTP secrets / status) if you enable two-factor authentication
  • Account timestamps (creation, last login)

2.2 Subscription & Payment Data

Payments are processed by Stripe. We do not store card numbers. We store:

  • Subscription status and plan (Start, Max, or Team — monthly or annual; USD or EUR at checkout)
  • Billing cycle dates; Stripe customer / subscription IDs
  • AI credit balances (included monthly credits and purchased packs)

2.3 Usage & App Data

  • Tasks, events, projects, notes, folders — content you create
  • Preferences — language, time slots, theme, notification settings
  • Birthdays you choose to store (optional)
  • AI credit metering — usage counters (not used for advertising)
  • Support / AI chat messages when you use in-app AI or support chat — processed to deliver the feature; retention follows Section 7
  • Referral codes if you participate in a referral program

2.4 Calendar Integrations (Optional)

  • Google Calendar / Microsoft Outlook: OAuth tokens (encrypted), synced event fields (title, times, description, location, attendees, Meet/Teams links, recurrence, status)
  • ICS / iCal feeds: feed URL you provide and events fetched for display (read-only)

2.5 Devices, Sessions & Push

  • Session tokens (web cookie / JWT; mobile access + refresh tokens)
  • Web Push subscription endpoints (VAPID) when you enable browser notifications
  • Mobile push tokens (e.g. Expo push tokens) when you enable mobile notifications
  • Approximate device/app metadata needed to deliver reminders (platform type)

2.6 Booking Guests (When You Share a Booking Link)

If you publish a Flowo booking page, guests may provide name, email, and booking notes. We process that data to create the appointment, sync to your connected calendar when enabled, and send confirmation / reminder emails.

2.7 Technical Data

  • IP address (processed by Cloudflare for security — not used for advertising profiles)
  • User-Agent / browser or app type (for compatibility and security)
  • Error logs (anonymised where possible, retained up to 30 days)
  • Optional weather lookups (coordinates or place name you request) via our weather provider proxy
CategoryExamplesStored inRetention
AccountEmail, username, password hash, OAuth IDsCloudflare D1Until account deletion
SubscriptionPlan, status, Stripe IDs, creditsCloudflare D1See Section 7
ContentTasks, notes, events, projectsCloudflare D1Until deletion / account deletion
Calendar tokensGoogle / Microsoft OAuth tokensCloudflare D1 (encrypted)Until disconnect / account deletion
Push tokensWeb Push / Expo tokensCloudflare D1Until disable / account deletion
Local prefsLanguage, UI state, cookie consentBrowser / app local storageUntil cleared

3. How We Use Your Data

  • Providing the service — scheduling, tasks, notes, AI assistance, calendar sync, booking, Team collaboration
  • Authentication & security — login, sessions, 2FA, abuse prevention
  • Notifications — transactional email (Resend) and optional push reminders
  • AI features — sending relevant content you provide (e.g. task text, chat) to our AI provider to generate suggestions; Google Calendar content is not sent to AI providers (scheduler uses time ranges)
  • Billing — Stripe subscriptions and credit packs
  • Service improvement — aggregated / anonymous metrics only
We never sell your personal data, never use Google/Microsoft calendar contents for advertising, and never train foundation models on your personal Content without an explicit separate consent.

4. Legal Basis (GDPR Art. 6)

Processing activityLegal basis
Account, core product features, billingContract (Art. 6.1.b)
Calendar OAuth (Google / Microsoft)Consent (Art. 6.1.a)
Push notificationsConsent / contract (depending on channel and settings)
Booking guest data (host-initiated)Contract with host; host’s instructions (Art. 6.1.b) — see §5c
Security, fraud preventionLegitimate interest (Art. 6.1.f)
Optional marketing measurement cookiesConsent (Art. 6.1.a)
Tax / accounting recordsLegal obligation (Art. 6.1.c)

5. Google User Data — Full Disclosure

Flowo uses Google APIs for (a) Sign-In and/or (b) Google Calendar (and optionally Meet-related configuration). We comply with the Google API Services User Data Policy, including Limited Use.

5.1 Scopes & Data Accessed

Identity (Sign-In): openid, email, profile — Google account ID, email, name, picture URL.

Calendar (when you connect Calendar or when calendar access is part of the Google authorization you grant):

  • https://www.googleapis.com/auth/calendar
  • https://www.googleapis.com/auth/calendar.events

Google Meet space configuration (https://www.googleapis.com/auth/meetings.space.created) is requested only when enabled in our production configuration after Google OAuth verification of that sensitive scope. Until then, Meet links for bookings may still be created via Calendar conference data without that extra scope.

Calendar fields we may sync: titles, start/end, descriptions, locations, attendees, Meet links, recurrence, status, reminders metadata.

5.2 How We Use Google User Data

  • Authenticate your Flowo account and display your profile
  • Show Google events in Flowo and keep them in sync
  • Create / update / delete events you initiate in Flowo (including booking appointments and optional Meet links)
  • AI scheduling uses time ranges only — not Google event titles/descriptions/attendees
We do not sell Google user data, use it for ads, or use it to train AI models.

5.3 Sharing, Storage, Deletion

Tokens and synced events are stored in Cloudflare D1, encrypted at rest, isolated per user, transmitted over TLS. Tokens are never exposed to the browser. You can disconnect Calendar in Settings, revoke access at Google Account permissions, or delete your Flowo account. Deletion of Google tokens/events happens on disconnect; full account erasure within 30 days of account deletion.

Limited Use: Flowo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5b. Microsoft & Other Integrations

Microsoft (Outlook / Microsoft 365)

If you sign in with Microsoft and/or connect Outlook, we may request scopes such as openid, email, profile, offline_access, User.Read, Calendars.ReadWrite, and OnlineMeetings.ReadWrite as needed for the features you enable. We store OAuth tokens encrypted and sync calendar events similarly to Google. We do not use Microsoft data for advertising or model training. Disconnect in Settings or revoke in your Microsoft account. Privacy: privacy.microsoft.com.

  • OpenAI — AI suggestions from content you submit in Flowo (not Google Calendar payloads). openai.com/privacy
  • Stripe — payments. stripe.com/privacy
  • Resend — transactional email. resend.com/privacy
  • Open-Meteo (or equivalent) — weather when you use weather features (coordinates / place)
  • Expo / Apple / Google — delivery of mobile push notifications when enabled

5c. Public Booking Pages

When a Flowo user (“Host”) shares a booking link, guests submit booking details to Flowo so we can create the appointment for the Host. For that guest data, the Host is typically the party who decides why the booking exists; Flowo processes the data to provide the booking feature. Hosts should only collect what they need and inform guests as required by law.

We may email guests confirmations, updates, or reminders related to the booking, and may write the event to the Host’s connected Google or Microsoft calendar when the Host enabled that sync.

5d. Teams & Shared Workspaces

On a Team plan, organization admins invite members by email. Within a Team workspace, members may see shared projects, assigned tasks, and related collaboration data according to roles/permissions. AI credits may be pooled at organization level. Admins are responsible for lawful use of the workspace and for informing their members. If you leave a Team, organization-owned shared content may remain with the Team; your personal account data remains subject to this Policy.

6. Data Sharing & Sub-processors

Sub-processorPurposeLocation
Cloudflare, Inc.Hosting, CDN, Workers, D1, securityUSA / global (SCCs)
OpenAI, LLCAI featuresUSA (SCCs)
StripePayments & subscriptionsUSA (SCCs)
Resend, Inc.Transactional emailUSA (SCCs)
Google LLCOAuth / Calendar (if connected)USA (SCCs)
Microsoft CorporationOAuth / Outlook (if connected)USA / global

SCCs = EU Standard Contractual Clauses (Decision 2021/914).

7. Data Retention

  • Account & content — while active; deleted within 30 days after account deletion (backup purge windows may apply briefly)
  • Subscription / invoice metadata — up to 7 years where required for Belgian accounting/tax
  • Calendar tokens & synced events — until disconnect or account deletion
  • Push tokens — until you disable notifications or delete the account
  • Booking guest records — as needed for the booking lifecycle and Host account retention rules
  • Error logs — up to 30 days

8. Your Rights (GDPR)

You may exercise access, rectification, erasure, restriction, portability, objection, and withdrawal of consent (where processing is consent-based). Email privacy@getflowo.com — we respond within 30 days. You may lodge a complaint with the Belgian APD (dataprotectionauthority.be) or your local EU authority.

9. Security

  • TLS in transit; encryption at rest for D1
  • Password hashing; OAuth tokens server-side only
  • Per-user data isolation; Cloudflare WAF / DDoS protections
  • Rate limiting on sensitive auth endpoints

Personal data breaches likely to risk your rights will be notified to authorities within 72 hours (GDPR Art. 33) and to individuals when required (Art. 34).

10. Cookies & Local Storage

Flowo does not use advertising cookies inside the authenticated app by default. We use:

Name / typePurposeDuration
sa_session (HttpOnly cookie)Web session authenticationSession / JWT lifetime
OAuth state cookies (g_state, gcal_state, Microsoft equivalents)CSRF protection during OAuth~10 minutes
localStorage prefs (sa_lang, UI state, etc.)Remember settingsUntil cleared
flowo_cookie_consentRemember marketing cookie choiceUntil cleared
Cloudflare __cf_bmBot / securityShort-lived

On marketing pages, Google Tag Manager and Google Ads (gtag) load only after opt-in. Rejecting optional tags prevents loading them. Clear site data to reset the banner.

11. Children's Privacy

Flowo is not directed at children under 16. We do not knowingly collect personal data from under-16s. Contact privacy@getflowo.com for deletion requests. Separately, our Terms require users to have legal capacity to contract (generally 18+) to create a paid account.

12. International Data Transfers

Primary sub-processors listed in Section 6 may process data in the United States or other countries. Transfers rely on Standard Contractual Clauses and provider DPAs where applicable. Cloudflare may process traffic globally for performance and security.

13. Changes to This Policy

We may update this Policy. For material changes we will update the “Last updated” date, email registered users at least 14 days in advance where practicable, and/or show an in-app notice. Continued use after the effective date constitutes acceptance where permitted by law.

14. Contact

Data Controller — Privacy Contact

Hopson & Cie Srl — 149 avenue du Domaine, 1190 Bruxelles, Belgium

Email: privacy@getflowo.com

VAT: BE 0450.443.155

Belgian Data Protection Authority (APD/GBA): Rue de la Presse 35, 1000 Bruxelles — dataprotectionauthority.becontact@apd-gba.be

EU ODR: ec.europa.eu/consumers/odr