Privacy Policy
Last updated: 22 May 2026
FlowBeam (“we”, “us”, “our”) respects your privacy. This Privacy Policy explains what information we collect, how we use it, and what choices you have.
1. Information We Collect
Account Information
When you create an account, we collect your email address and password. Passwords are securely hashed — we never store them in plain text.
Usage Data
We collect data about how you use FlowBeam to provide and improve the service:
- Focus session durations and completion status
- Notes, goals, and task content you create
- Calendar events you choose to sync
- Analytics data (streaks, heatmaps, session counts)
Device & Browser Information
We may collect basic device information (browser type, operating system, screen size) to optimise your experience and diagnose issues.
2. How We Use Your Information
- Provide, maintain, and improve FlowBeam's features
- Sync your data across devices
- Send you essential account notifications (verification, password resets)
- Generate your personal analytics and insights
- Monitor account activity and respond to user feedback using internal operational tools
- Enforce our Terms of Service and prevent abuse
We do not sell your personal data to third parties. We do not use your data for advertising.
3. Data Storage & Security
Your data is stored securely on Amazon Web Services (AWS) infrastructure. We use encryption in transit (TLS) and at rest. Authentication is managed through AWS Cognito with industry-standard security practices.
4. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will remove your personal data within 60 days, except where we are required by law to retain it.
Operational logs and internal notifications (such as anonymised account activity alerts) may be retained beyond the 60-day deletion period for audit, security, and fraud prevention purposes. These records contain only masked identifiers and do not include your full email address or account content.
5. Third-Party Services
FlowBeam integrates with third-party services only when you explicitly connect them (e.g., Google Calendar, Outlook Calendar). We only access the data necessary to provide the integration and do not share it further.
Google API Services — Limited Use Disclosure
FlowBeam’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, when you connect your Google Calendar to FlowBeam:
- What we access: calendar event titles, descriptions, start and end times, locations, attendee email addresses, and free/busy data from the Google calendars you authorise.
- How we use it: to display your schedule inside FlowBeam, calculate available focus time, surface conflicts in the time-box planner, and create or update events on your behalf when you schedule tasks or focus sessions.
- Where it is stored: encrypted at rest in our AWS-hosted database, in the same region as your account.
- Who can see it: only you. FlowBeam staff do not view your calendar data except where strictly required to investigate a support ticket you have raised, and only with your explicit consent.
- What we do NOT do: we do not transfer your Google user data to third parties except as necessary to provide or improve user-facing features that are prominent in the FlowBeam interface; we do not use it for advertising, including personalised, retargeted, or interest-based advertising; we do not use it to train any generalised or non-personalised AI/ML models; and we do not sell your Google user data to anyone.
- Revoking access: you can disconnect Google Calendar at any time from FlowBeam Settings → Integrations, which immediately revokes our access tokens at Google. You can also revoke access directly from your Google Account → Third-party apps with account access.
- Data deletion: when you disconnect or delete your FlowBeam account, all stored Google Calendar data and tokens are deleted from our systems within 30 days.
Microsoft Graph (Outlook Calendar)
The same handling principles above apply to Outlook / Microsoft 365 calendar data accessed via Microsoft Graph: minimum necessary scopes, encrypted storage, no advertising use, no training of generalised AI models, and deletion within 30 days of disconnection.
Google Analytics
We use Google Analytics 4 (GA4) to collect anonymous, aggregated usage data such as page views, session duration, and general traffic patterns. This helps us understand how users interact with FlowBeam so we can improve the product. GA4 may set cookies (e.g., _ga, _ga_*) to distinguish unique users and sessions. No personally identifiable information is sent to Google Analytics. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
Google Play Billing
If you subscribe to FlowBeam Pro through the Google Play Store, your subscription and payment are processed by Google Play. We receive confirmation of your subscription status (active, cancelled, or expired) and your Google Play order ID, but we do not receive or store your payment card details. Google’s handling of your payment information is governed by the Google Privacy Policy.
We also use internal operational tools (e.g., team communication platforms) to monitor service health, process support requests, and respond to user feedback. Any personal data shared with these tools is limited to the minimum necessary for operational purposes, and email addresses are masked (partially redacted) in automated notifications except where you have voluntarily submitted a support or feedback request.
6. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and data
- Request a copy of the personal data we hold about you
To exercise any of these rights, contact us at support@flowbeam.net.
7. Cookies
FlowBeam uses essential cookies for authentication and session management. We also use Google Analytics cookies (_ga, _ga_*) to collect anonymous usage statistics. We do not use third-party advertising cookies.
8. Children's Privacy
FlowBeam is not intended for children under 13. We do not knowingly collect personal information from children under 13.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make significant changes, we will use reasonable efforts to notify you (for example, by posting a notice in the app). Your continued use of FlowBeam after changes constitutes acceptance of the updated policy.
Questions about privacy? Contact us.