Privacy
EFFECTIVE AUGUST 4, 2026
Your data is yours.
A plain-language summary of what we do and don't do with your information. No dark patterns.
The short version
Flow is operated by PLLAR, an unincorporated software business based in the United States. We store the account and product data needed to run Flow. Held items are available offline on your device and are also encrypted before durable account sync so they can survive reinstalling or changing devices. We do not sell personal data, show ads, or share personal information for third-party marketing.
What we collect
• Account and profile information you provide, including your email and first name.
• Content and optional check-ins you create in Flow, including Held items, journal entries, Flow AI conversations, and entries made with supporting tools.
• Your approximate location (only if you grant permission) to fetch live weather. The server rounds coordinates to 2 decimal places before storing or sending them to weather and location-name services.
• Limited security and service metadata, such as a pseudonymous account ID, sign-in/session records, IP address, browser or app version, and technical error details.
• Notes saved by an earlier beta remain part of your account and export until you delete them or delete your account. Flow AI does not use that legacy note store during this beta.
What we do not collect
• Your contacts or photos.
• Background location.
• Advertising IDs.
• Biometric data.
Local and protected data
• The worries and thoughts you normally hand to Flow remain available offline on your device. For signed-in accounts, Held text receives additional app-layer encryption before durable storage, syncs to that account after a successful connection, and is decrypted only when returned to that account. An offline change cannot reach another device until it syncs. Held text is never sent to PostHog or Sentry.
• Journal entries, Flow AI conversations, and account/profile fields do not receive Held’s additional app-layer encryption. They are stored by our hosting and database providers and protected with those providers’ encryption in transit and at rest.
• If you choose Let It Go, Flow requires the encrypted Held service to accept the text before showing success and does not add it to normal local Held history. The server immediately omits it from normal app and export responses, connected devices reconcile it away when they next sync, and the active encrypted content is permanently deleted after 7 days. A device that is offline cannot receive that update until it reconnects. Flow keeps only a one-way, content-free deletion receipt needed to prevent a stale device from restoring the item. Restricted disaster-recovery backups may retain an inaccessible copy until the backup expires naturally.
• Optional device context, when enabled, is read-only and processed on your device. Flow does not upload private device events or health metrics.
AI processing
When you use Flow AI or another AI feature, the text needed to answer is sent to Anthropic's Claude. Anthropic states that commercial API inputs and outputs are not used for model training by default unless the customer opts in or submits feedback. Standard API inputs and outputs are typically deleted within 30 days, but may be retained longer when required for usage-policy enforcement or law. Responses and chat history may also be stored in your Flow account so the experience persists. If optional spoken replies are available on the web and you choose to play one, Flow sends that Flow AI reply text to OpenAI solely to create the audio response. The speech request does not include separate profile or conversation-history fields, but the reply itself may repeat or summarize information from the conversation. When provider speech is unavailable, Flow falls back to the browser's built-in voice. Do not use Flow for emergencies or as medical, legal, or financial advice.
Service providers
• Anthropic processes prompts for AI responses. When Connected context in Flow AI is enabled, Flow AI may receive only context you approved in a PLLAR app and only when it is relevant to your request. This setting does not create AI memories or automatically add saved check-ins.
• OpenAI processes the text of a Flow AI reply only when optional provider-generated spoken playback is used on the web. The request is made only to synthesize that reply into audio.
• Resend sends invitations, password resets, welcome messages, and essential account email.
• Open-Meteo and OpenStreetMap's Nominatim service receive rounded coordinates when you enable weather and location labels.
• Expo's notification service may relay push notifications when you enable them.
• PostHog receives only manual, content-free product events tied to a pseudonymous Flow account ID when analytics is enabled. We never send journal, chat, Held, email, or name content. You can opt out in Settings.
• Vercel hosts the Flow and PLLAR web services. On the public PLLAR marketing site, Vercel Web Analytics may receive pageviews and content-free custom events such as section views, scroll milestones, CTA labels, and outbound-link destinations. Those custom events do not include form-field values, submitted email addresses, or Flow account content.
• Sentry receives scrubbed technical error information tied only to the same kind of pseudonymous account ID. Request bodies, cookies, sensitive headers, URL query strings, and free-form error messages are removed; console and network breadcrumbs are discarded, while retained breadcrumbs contain no message or payload data.
• Our hosting and database providers process account data to operate and recover the service and protect it with provider-level encryption in transit and at rest. Held text also receives the separate app-layer encryption described above.
Your controls
• Export your account data from Settings → Export data.
• Delete your account from Settings → Delete my account. This removes the live account data, including synced Held items, and revokes active sessions.
• Turn pseudonymous, content-free product analytics off in Settings.
• Revoke location access anytime via your device settings.
• Ask support to remove a launch-notification, original-waitlist, or careers submission.
Retention
Account data is kept while your account is active and until you delete it, unless a longer period is required for security, fraud prevention, or law. Deleted live data may remain temporarily in restricted disaster-recovery backups until those backups roll off; it is not used for product activity. Original-waitlist and launch-notification details are kept through beta and launch communications or until you ask us to remove them.
Children
Flow is not intended for users under 13. We do not knowingly collect data from children.
Changes
We will post updates to this policy in-app. Material changes will be highlighted.
Contact
Questions? Email pllardev.support@gmail.com — we read every message.
Flow
Set it down.
from PLLAR