Privacy Policy

Last updated: 13 August 2026

This Privacy Policy describes how Flow ("we", "us", or "our") collects, uses, stores, and shares information when you use our web application at https://flow-hq.app.

1. What Flow does

Flow is an inbox triage application that connects to your Gmail account with your permission. It presents your unread messages one at a time and lets you archive, reply, save, or turn them into tasks. AI features are optional and only run when you explicitly choose them.

2. Information we collect

  • Account information: email address and authentication details created when you sign up or sign in.
  • Gmail data: when you connect a Gmail account, we access message metadata and content needed to display, triage, draft, send, and manage your inbox. We only access data required to provide the service.
  • Google Workspace data: if you grant additional Google Workspace scopes, we may sync your Google Contacts and Google Calendar to support autocomplete and calendar views inside Flow.
  • Content you create: tasks, saved knowledge items, drafts, tags, signatures, AI tone preferences, and settings you save in Flow.
  • Waitlist emails: email addresses submitted through the public waitlist form.

3. How we use Gmail and Google Workspace data

We use your Google data solely to operate Flow on your behalf. Specifically, we may:

  • Read unread messages and message metadata to show them in the triage and inbox views.
  • Create, update, and delete Gmail drafts when you choose to reply or forward a message.
  • Move messages to and from trash when you delete or undo a delete.
  • Send a draft only when you explicitly press send inside Flow.
  • Read your Google Contacts and Calendar to support Flow's contacts and calendar features, if you grant those scopes.

We do not use your Gmail or Google Workspace data for advertising, and we do not sell, rent, or share it with third parties for marketing purposes.

4. AI processing

Flow can generate email summaries, reply drafts, and structured notes using the Lovable AI Gateway. Email content is only sent to the AI service when you explicitly invoke an AI feature. We do not use your emails to train AI models, and we instruct our AI provider not to retain or train on your data.

5. Third-party services and subprocessors

We rely on the following services to run Flow:

  • Lovable Cloud / Supabase: authentication, database, and server functions.
  • Google APIs: Gmail, Google Contacts, and Google Calendar access.
  • Lovable AI Gateway: optional AI summaries and drafting.
  • Notion: only when you connect your own Notion integration to save knowledge items.
  • TickTick or other task managers: only when you configure an email-forward address in settings.

Optional integrations are controlled by you. We only store the tokens or addresses needed to make those integrations work, and we never share more data than is necessary for the integration.

6. Data retention and deletion

We keep your account data and content for as long as your account is active. If you disconnect a Gmail account, we delete the associated OAuth tokens from our systems. If you delete tasks or saved knowledge items, they are removed from our database.

To request full deletion of your account and all associated data, email us at hello@flow-hq.app and we will process your request within 30 days.

7. Your rights

Depending on where you live, you may have rights to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request deletion of your data.
  • Export your tasks and saved knowledge.
  • Object to or restrict certain processing.
  • Withdraw consent for optional features such as Gmail access or AI processing.

To exercise any of these rights, contact us at hello@flow-hq.app.

8. Revoking access

You can disconnect any linked Gmail account inside Flow's settings at any time. You can also revoke Flow's access entirely through your Google Account permissions page.

9. Security

We use industry-standard measures to protect your data, including encrypted connections (HTTPS/TLS), row-level security in our database, and scoped OAuth tokens. Access tokens are refreshed automatically and stored securely.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of the page. Continued use of Flow after changes means you accept the revised policy.

11. Contact us

If you have questions about this Privacy Policy or how we handle your data, please email hello@flow-hq.app.