Privacy Policy
Version 1.5 · Last updated 2026-08-27
Language: English (the only official version of this Policy)
This Privacy Policy explains how we handle personal data when you use the Flowky beta (a macOS time-tracking app) and its website. It is written to be readable: it starts with a short summary, then gives the full detail. It applies together with the Beta Terms of Service.
What changed in version 1.5. Window titles and full page addresses (without query strings) were added to what the telemetry collects, together with a per-application exclusion list in Settings → Privacy. This collection starts with a future release of the App; until you update to it, nothing described here as new is being collected from your Mac. The App will ask you to accept the updated Terms when that release arrives.
1. Who we are (Data Controller)
Flowky is run by an independent (indie) developer based in Lecce, Italy. The data controller is Andrea Selmi, a natural person.
Contact for privacy matters: support@getflowky.com
There is no Data Protection Officer (DPO) and no EU representative, as neither is legally required for an operation of this size and nature. If that changes, we will update this Policy.
2. Summary (the short version)
| Question | Short answer |
|---|---|
| Who runs Flowky? | An independent developer based in Italy. |
| Can I use the app without an account? | Yes. The beta works in guest / local mode, and your tracking data is not synced to our backend. (Usage telemetry is still collected — see the next rows.) |
| What does the app collect? | Pseudonymous usage telemetry (including tag names, session notes, which apps you use while the app is running, the titles of the windows you have open, and, for browsers, the address of the page you are on, without anything after the ?) to improve Flowky and develop future AI features. You can exclude any application from this in Settings, and domains that could reveal health, sex life, religion, politics, union membership or ethnic origin are filtered on your Mac before anything is sent. |
| Is the telemetry linked to me? | No. It uses a random per-install identifier, never linked to your account or email. |
| Can I turn it off? | The telemetry is a core part of the beta, so there is no in-app off switch. If you’d rather not share it, don’t join the beta — or uninstall the App. You can still ask us to delete your data (see Section 5), and all raw telemetry auto-deletes within 90 days. |
| Do you use my email? | Only for beta updates and functional feedback. Marketing emails are separate and require your explicit opt-in. |
| Do you sell my data or run ads? | No. Never. No selling, no advertising, no profiling with legal effects. |
| How long do you keep telemetry? | Raw events are auto-deleted within 90 days; longer-term AI datasets are de-identified first. |
| Do you use AI to analyse the data? | Yes — to develop future AI features we analyse de-identified datasets, which may involve third-party AI/LLM API providers. They never receive your name, email, or install identifier. |
| Who else processes data? | A small set of sub-processors: Cloudflare, Railway, Sentry, Google, PostHog, and third-party AI API providers. See Section 7. |
| Does the website track me? | By default only with cookieless analytics (PostHog, EU servers): nothing stored on your device, and the visitor hash rotates daily. Cookies and session replay happen only if you allow them in the banner. See Section 3a. |
| What are my rights? | Access, rectification, erasure, restriction, portability, and objection under the GDPR, plus the right to complain to the Italian Garante. |
The rest of this Policy explains each point in full.
3. Data we collect
We collect data in four contexts.
a. Website / landing page
-
Beta tester email — if you give it to us to join the beta or (separately and optionally) to receive launch news.
-
Technical logs and IP address — our website and services run behind Cloudflare, which processes connection data (including your IP address) in edge logs to deliver the site and protect it from abuse.
-
Analytics — our landing page uses PostHog (EU servers) to measure page views, clicks on the download buttons, downloads served, and newsletter sign-ups. It runs in cookieless mode unless you allow cookies:
- By default, and if you decline — nothing is stored on your device: no cookies, no local or session storage. Visitors are counted using a privacy-preserving hash that changes every day, generated from technical data (IP address, browser user agent, site address) and never stored as such. Because the hash rotates daily, we cannot recognise you from one day to the next.
- If you allow cookies in the banner — PostHog sets a first-party analytics cookie so we can recognise a returning visit, and records a session replay: a reconstruction of your interaction with the page (clicks, scrolling, navigation). Text you type into form fields is masked by default and we do not use replays for advertising or profiling with legal effects. You can withdraw this at any time by clearing your browser storage for this site, which brings the banner back.
- Either way we never use profiling or advertising cookies, and we do not track you across other websites.
Downloads are also counted by our own server, which records the version served and the country resolved by Cloudflare — your IP address is never sent to PostHog.
b. App — local data on your device
When you use the beta in guest / local mode, your sessions, tags, presets, and notes are stored locally on your device (in a local database and in the Tauri Store), and are not synced to our backend.
Important: this is separate from the beta telemetry. Even in guest mode, the App still sends the usage telemetry described in Section 3d — which includes your tag names, preset names, and session note text — to the telemetry service. “Stored locally” refers to your working copy and the sync backend; it does not mean this content is withheld from the telemetry.
c. Optional account
If you create or use an optional account, we process:
- your email address (if your account uses email and password), or the email, name, and profile picture provided by Google if you sign in with Google (OAuth);
- the tracking data you choose to sync (sessions, tags, presets), stored on our backend (Railway) to enable multi-device sync.
Note for the current beta: the beta is designed to run fully locally, without an account. Accounts and backend sync are described here so this Policy stays accurate if you use them; if the beta ships with accounts disabled, this section simply does not apply to you.
d. Beta telemetry (pseudonymous)
Separately from the above, the App sends usage telemetry to a dedicated, isolated telemetry service hosted on Cloudflare, kept fully separate from the main backend. It includes:
- application usage events (app launch, onboarding steps, settings changes, surfaces opened, session lifecycle, sync diagnostics, upgrade-prompt interactions);
- the names of tags and presets you create (raw text);
- the content of your session notes (raw free text, capped at 200 characters);
- the names and bundle identifiers of applications you use while the App is running, plus how long each was in the foreground; the title of the window in the foreground (for example
auth.service.ts — flowky-api), which we use to tell your different pieces of work apart; for browsers, the address of the page open, including its path (for examplegithub.com/andreaselmi/flowky) but never the part after the?, which is where session tokens and similar values live and which is discarded on your Mac before anything is sent; - session metadata (planned/actual durations, pauses, completion or abort status, notification counts);
- a randomly generated install identifier (UUID, created locally on first launch);
- App version, operating system, and OS version.
Cloudflare also sees the IP address of telemetry requests in its edge logs.
What is NEVER sent to the telemetry service:
- your account
user_id; - your email address or any account credentials;
- your profile picture;
- authentication tokens;
- backend session / sync internal identifiers;
- screenshots or keystrokes;
- anything you type into a page or an application — we record window titles and page addresses, never their content, never form fields, never keystrokes;
- the query string of a page address — everything after the
?is discarded on your Mac before the address is sent; - titles or addresses from applications you have excluded in Settings — those applications still contribute how long they were used, and nothing else;
- Sentry breadcrumbs or stack traces (crash data is handled separately — see Section 7).
Special-category domains are filtered on your device. Domains that could reveal special categories of data under Article 9 GDPR — health, sex life or sexual orientation, religion, political opinions, trade union membership, or racial or ethnic origin — are removed on your Mac, before anything is sent, and never reach us. The filter combines a public academic blocklist with a list we curate, and we review it monthly against the domains actually received. It is not exhaustive and we do not claim it is; it is a technical measure to keep this category of data out of the collection, not a guarantee that no such domain will ever slip through.
Window titles are not filtered the same way, and we say so plainly. The domain filter above works because a domain is a short value we can match against a list. A window title is free text produced by another application, so no equivalent filter is possible, and one could occasionally contain something sensitive — the name of a document, a message subject, a channel name. Two things are in place instead. You can exclude any application in Settings → Privacy, and nothing from it is ever sent. And all raw telemetry is deleted within 90 days. If you would rather not share this at all, the beta may not be for you: telemetry is a condition of taking part.
By design, the telemetry install identifier is kept completely separate from the email you give us on the landing page. The two are never joined.
⚠️ Please do not enter sensitive data or other people’s personal data into your session notes, tag names, or preset names. These free-text fields are collected as part of the telemetry. Do not paste passwords, payment card numbers, health details, or third parties’ personal information.
4. Purposes and legal bases
| Data / activity | Purpose | Legal basis (GDPR) |
|---|---|---|
| Beta program email | Send build updates, operational notices, and requests for functional feedback | Performance of a contract / pre-contractual measures, Art. 6(1)(b) |
| Launch / marketing email (optional) | Tell you about the public launch and future Pro version | Consent, Art. 6(1)(a) — separate, non-preselected opt-in; withdrawable anytime |
| Optional account & data sync | Create your account and sync your data across devices | Performance of a contract, Art. 6(1)(b) |
| Beta telemetry — product improvement | Understand real usage and improve Flowky | Legitimate interest, Art. 6(1)(f), and a core condition of the beta program you choose to join. Telemetry has no in-app off switch during the beta; the ways to stop are described in Section 5 |
| Beta telemetry — AI dataset (distinct purpose) | Build de-identified datasets to develop and tune future AI features, which may be analysed using third-party AI/LLM API providers | Legitimate interest, Art. 6(1)(f) — declared as a separate, distinct purpose; same conditions as above |
| Crash & error reporting (Sentry) | Diagnose crashes and errors to keep the app stable | Legitimate interest, Art. 6(1)(f) |
| Website delivery, security & anti-abuse (Cloudflare) | Serve the site and protect against attacks | Legitimate interest, Art. 6(1)(f) |
| Website analytics — cookieless (PostHog) | Measure page views, download clicks and downloads to understand what works on the landing page | Legitimate interest, Art. 6(1)(f) — no cookies, no device storage, no advertising and no cross-site tracking, so no consent is required under the ePrivacy rules |
| Website analytics — cookies & session replay (PostHog) | Recognise returning visits and see where the page loses people | Consent, Art. 6(1)(a) — given through the banner, never pre-ticked, withdrawable at any time by clearing this site’s browser storage |
For our legitimate-interest processing we have carried out a balancing assessment (a lightweight Legitimate Interest Assessment). The beta telemetry is intrinsic to the beta and has no in-app off switch; you can still exercise your rights (including objection and erasure) by contacting us and by the means described in Sections 5 and 9. We do not sell your data, do not use it for advertising, and do not carry out profiling that produces legal or similarly significant effects on you.
The assessment was re-run when window titles and page addresses were added to the collection, because free text produced by other applications is more intrusive than event data. The measures that carry the balance are the per-application exclusion list, the removal of query strings on your device, the 90-day deletion of raw data, and the fact that the beta is entirely voluntary.
A note on AI processing. To develop future AI features, we analyse datasets built from the telemetry. Before any such analysis, these datasets are de-identified (the install identifier is removed or hashed, and detectable personal-data patterns such as emails and phone numbers are scrubbed from notes and tag names — see Sections 5 and 6). This analysis may be carried out using third-party AI/LLM API providers acting as our processors. Those providers never receive your account name, email address, or install identifier. We do not use this processing to make automated decisions that produce legal or similarly significant effects on you.
5. “Pseudonymous” — what it means for you
The beta telemetry is pseudonymous, not anonymous. Here is what that means in plain terms:
- The telemetry is tagged with a random identifier generated on your device when you first launch the App. It is not connected to your name, email, or account.
- We cannot ordinarily identify you from the telemetry. Because we cannot identify you, several GDPR rights (such as access and erasure of specific records) do not automatically apply — this is the mechanism in Article 11 GDPR — unless you give us the extra information needed to find your data.
- That extra information is your install identifier, which you can view in the App’s Settings. If you send it to us, we can locate and delete the data from your installation.
No in-app off switch during the beta. Usage telemetry is a core part of the Flowky beta — understanding real usage is the reason the beta exists — so there is no toggle to disable it inside the App. If you do not want to share telemetry, please do not join the beta, or uninstall the App to stop all future collection.
How to have your telemetry deleted:
- Open Flowky → Settings → find your install identifier.
- Email it to us at support@getflowky.com.
- We will delete the telemetry data from that installation, normally within 30 days.
And in any case, all raw telemetry events are automatically deleted within 90 days of collection. Your non-waivable rights under the GDPR — including the right to object (Article 21) and to erasure (Article 17) — remain: contact us and we will act on them as described in Section 9.
6. How long we keep data (retention)
| Data | Retention |
|---|---|
| Raw telemetry events | Automatically deleted within 90 days |
| Long-term AI-development datasets | Only kept longer after de-identification: the install identifier is removed or hashed, and detectable personal-data patterns (emails, phone numbers) are scrubbed from notes and tag names before longer retention |
| Beta program email | Kept for the duration of the beta plus 6 months after it ends |
| Marketing email (if you opted in) | Until you withdraw consent or unsubscribe |
| Optional account data (incl. synced data) | Kept while your account exists; deleted within 30 days after account deletion |
| Crash / error logs (Sentry) | 90 days (Sentry’s default retention) |
| Cloudflare edge / security logs | Retained by Cloudflare per its standard periods (typically short-lived, on the order of days) |
| Website analytics events (PostHog) | Retained per PostHog’s retention on our plan (currently 12 months). The daily visitor hash rotates every day, so older cookieless events cannot be tied to a current visitor |
| Session replays (only if you allowed cookies) | 30 days, then deleted by PostHog |
7. Recipients / Sub-processors
We keep our supplier list small. We use the following processors, each only for the purpose shown. We do not sell your data, do not share it for advertising, and do not carry out profiling with legal effects.
| Sub-processor | Purpose | Location | Privacy information | Transfer mechanism |
|---|---|---|---|---|
| Cloudflare | Telemetry service hosting (Workers, D1, R2), DNS, website delivery, security; processes request IPs | US / global edge | https://www.cloudflare.com/privacypolicy/ | EU–US Data Privacy Framework; SCCs as fallback |
| PostHog | Website analytics for the landing page (page views, download clicks, downloads); with your consent, cookies and session replay | European Union (Frankfurt) — EU Cloud | https://posthog.com/privacy | No transfer required: the data stays in the EU. SCCs cover any support access from the US |
| Railway | Hosting for the main backend API and database (optional account + data sync) | United States | https://railway.com/legal/privacy | Standard Contractual Clauses (SCCs) |
| Sentry | Crash and error reporting | US | https://sentry.io/privacy/ | EU–US Data Privacy Framework; SCCs as fallback |
| Sign-in with Google (OAuth) for the optional account | US / global | https://policies.google.com/privacy | EU–US Data Privacy Framework; SCCs as fallback | |
| Third-party AI/LLM API providers | Analysing de-identified datasets to develop future AI features (Section 4). Never receive your account name, email, or install identifier | US / global | Named here once a specific provider is selected | Standard Contractual Clauses (SCCs), and the EU–US Data Privacy Framework where the selected provider is certified |
If we add or change a sub-processor, we will update this Policy. We will name the specific AI provider(s) here before any such processing begins.
8. International data transfers
Some of our sub-processors are based in, or process data in, the United States or other countries outside the EU/EEA. Where personal data is transferred outside the EU/EEA, we rely on:
- the EU–US Data Privacy Framework where the recipient is certified; and
- the European Commission’s Standard Contractual Clauses (SCCs) as a fallback safeguard,
together with additional measures where appropriate. You can contact us for more information about these safeguards.
9. Your rights
Under the GDPR you have the right to:
- access your personal data (Art. 15);
- request rectification of inaccurate data (Art. 16);
- request erasure (“right to be forgotten”, Art. 17);
- request restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interest, including the telemetry (Art. 21) — the beta telemetry has no in-app off switch, so to object you contact us (or uninstall the App to stop collection), and we will stop processing your data and delete it by your install identifier;
- withdraw consent at any time where processing is based on consent (e.g. marketing email), without affecting prior processing.
A note on the telemetry (Article 11). Because the telemetry is pseudonymous and we cannot normally identify you, we may be unable to action access or erasure requests for it unless you provide your install identifier (see Section 5). This does not remove your rights — it reflects that we genuinely cannot find your records without that key. In all cases, raw telemetry is auto-deleted within 90 days.
How to exercise your rights. Email support@getflowky.com. We will respond within one month (extendable for complex requests, in which case we will tell you). Exercising your rights is free in ordinary cases.
Right to complain. You can lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the authority in your country of residence.
10. Security
We take reasonable technical and organisational measures to protect personal data, including:
- encryption in transit (TLS/HTTPS) for all network communication;
- password hashing for account credentials, and secure token storage (the app keeps refresh tokens in the macOS Keychain);
- restricted access to backend systems and telemetry data;
- pseudonymisation by design for the telemetry (random per-install identifier, no account linkage);
- rate limiting and anti-abuse controls on our services.
No system is perfectly secure, and — as noted in the Beta Terms — beta software carries additional risk, including possible data loss.
11. Children
The Flowky beta is not intended for anyone under 16 years of age, and we do not knowingly collect personal data from children under 16. If we become aware that we hold such data, we will delete it (where we are able to identify it) and terminate the associated access.
12. Cookies & local storage
-
Website. Our landing page uses no profiling or advertising cookies and no cross-site tracking. Our analytics tool (PostHog) starts in cookieless mode, writing nothing at all to your browser. A banner asks whether you’ll allow analytics cookies:
- if you decline, or ignore it, nothing is stored and measurement stays cookieless;
- if you allow, PostHog sets a first-party analytics cookie and enables session replay (see Section 3a).
We store your answer itself in your browser’s local storage (key
flowky.analytics-consent) — that entry is strictly necessary to honour your choice, so it needs no consent. We keep it for 6 months and then ask you again. Clearing this site’s storage in your browser withdraws consent immediately and brings the banner back. -
App. Flowky is a desktop app and does not use web cookies. It stores data locally on your device using a local database and the Tauri Store (for preferences and the telemetry install identifier). This local storage stays on your device.
13. Data breach
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Garante within 72 hours of becoming aware of it, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will also inform you without undue delay, as required by Article 34 GDPR.
14. Changes to this Policy
We may update this Policy from time to time. When we do, we will change the version number and “Last updated” date at the top and make the new version available on our website and in the App.
For material changes to how we collect or use your data, we will take appropriate steps to inform you and, where required, ask for renewed acceptance or consent before the change applies to you.
15. Contact
For any question about this Policy or your personal data:
Flowky Lecce, Italy Email: support@getflowky.com
You also have the right to contact the Garante per la protezione dei dati personali (www.garanteprivacy.it) at any time.