Privacy Policy

Effective Date: December 12, 2025
Last Updated: July 10, 2026


1. The Short Version

Your Flowsta account is created in the Flowsta Vault on your own device. Your keys derive from a 24-word recovery phrase only you hold, and your private data lives on your device - not on our servers.

Key principle: by design, we CANNOT read your private data. This policy explains the small amount we do hold, and why.


2. Data We Hold on Our Servers

2.1 Account Records

DataPurposeCan we read it?
Email - one-way hashVerify it's yours; prevent duplicates❌ Hash only
Email - encrypted copyAccount recovery❌ Only your recovery phrase decrypts it
Public key & W3C DIDYour public identity✅ Yes (public by design)
Username, display name, pictureYour public profile✅ Yes (public by design)
Connected apps & granted permissionsThe sign-ins you've approved✅ Yes
App activity markerOne record per app per month, for developer billing - no activity details✅ Yes

When we send you an account email (like address verification), we use the address at that moment - afterwards only the hash and the encrypted copy remain.

What we never hold:

  • ❌ Passwords - there are none anywhere in the system
  • ❌ Your recovery phrase - never stored by anyone, including you-on-our-servers
  • ❌ Your private keys - they live in your Vault
  • ❌ Your activity - what you do stays on your device

2.2 Your Private Data - On Your Device

Everything else lives in the Flowsta Vault on your own machine: your profile details, your activity, your apps' data and backups. It's encrypted with keys derived from your recovery phrase, and it never touches our servers.

That also means deleting it is literally in your hands - Vault → Settings → Reset erases it from your device, and there's no copy anywhere else. Export it first from Vault → Your Data if you want to keep it.

2.3 Public Network Data (Immutable)

Your DID, profile picture, and registration timestamp live on a public Holochain network. This data cannot be deleted - it's immutable by design, for censorship resistance.

2.4 Premium Billing Data (If You Subscribe)

Stored by us: subscription tier, billing interval, status, period dates, invoice history.

Processed by Stripe: payment method, billing address, payment history - we never see these. We use a proxy email with Stripe, so your real address isn't shared with them. We don't store card numbers. Stripe is PCI DSS compliant.

2.5 Support Services (Gleap)

We use Gleap for AI chat and support tickets. Data is shared only when you open the support widget:

  • Anonymous users: nothing personal - you can use the AI chat without identifying yourself.
  • Signed-in users: user ID, display name, email (when your account has one on file), DID, and subscription tier - so tickets can reach you and be prioritized.

Gleap is GDPR-compliant and bound by their privacy policy. You can request deletion of your support data at privacy@flowsta.com.

2.6 Sign It - File Signing (If You Use It)

Signing happens in your Vault - your signing keys never leave your device, and you approve every signature. When you sign, this is committed to the public signing network:

  • Your public key, a SHA-256 hash of your file, and a timestamp
  • Optional metadata you declare: intent, AI-generation disclosure, content rights, and a thumbnail (≤15 KB)

Never uploaded: the file itself (only its hash), your email, or your name unless you choose to show it.

Signatures are immutable - revocation is a separate signed entry alongside the original. Content rights are your own public statement, backed by your signature; Flowsta doesn't enforce them. If you enable contact requests, messages reach you through a blind relay - your email is never exposed.

2.7 Vault Data on Your Device

DataWhere
Your encrypted private dataYour device (OS app data directory)
Your signing keysYour device, encrypted with your vault password
Your recovery-phrase-derived seedIn memory only while unlocked - never written to disk in plaintext

The Vault's local bridge listens on localhost only - not accessible over the network. Auto-lock clears keys from memory. Your local files are yours to back up (use Your Data → Export All Data) and yours to secure.

Linking your identity to an app commits a cryptographic attestation to the public identity network. It contains only public keys, signatures, and a timestamp - no personal data - and is immutable once created. Links are only ever created after you approve a dialog in your Vault.

2.9 What We Don't Log

Our API logs contain only: endpoint, method, status code, response time. No IP addresses, no browser or device details, no browsing behavior, no location.


3. How We Use Your Data

To operate your account: verifying your email, resolving your public profile, and completing the sign-ins you approve.

What we DON'T do:

  • ❌ Sell your data
  • ❌ Use it for advertising
  • ❌ Share it without your consent
  • ❌ Read your private data (we can't)
  • ❌ Train AI models on your data

4. Data Sharing

When you sign in with Flowsta, the app receives your DID, display name, username, profile picture, and public key. Your email is shared only if you explicitly choose to share it on the consent screen - the shared copy is held on that app's grant, and revoking the app deletes it.

With Service Providers

  • Google Cloud - hosting
  • Stripe - Premium billing only (proxy email; your real address isn't shared)
  • Mailgun - delivers your account emails (verification, security notices)
  • Gleap - support, only when you open the widget
  • Cloudflare Web Analytics - cookieless page-view counts; never used to identify you

With Law Enforcement

Valid legal process only. We can provide the account records in section 2.1. We cannot provide your private data, your keys, your activity, or a password - none of these exist on our servers.


5. Your Rights

Access & Portability (CAL)

Flowsta runs on Holochain, licensed under the Cryptographic Autonomy License, which guarantees your control of your data:

  • Export everything from Vault → Your Data - your private records and your apps' backups, decrypted only on your device.
  • Your identity is portable: your recovery phrase - which only you hold - rebuilds your identity on any compatible Holochain conductor, with or without Flowsta. Even if we ceased operating, your identity and signed work keep working.
  • We impose no technical or legal restrictions on using your own data (CAL §4.2.1-4.2.3).

Erasure

  • On your device: Reset Vault erases your private data - no copy exists anywhere else.
  • On our servers: email privacy@flowsta.com and we'll delete your account records (email hash, profile cache, grants, billing records).
  • On the public network: your DID, profile picture, and identity links are immutable and cannot be deleted - by design.

6. Cookies

One cookie: flowsta_session - keeps you signed in on flowsta.com. 7 days, HTTP-only, HTTPS-only, strictly necessary. No tracking, advertising, or third-party cookies.


7. Children's Privacy

Flowsta is not for children under 13 (16 in the EU). We don't knowingly collect data from children; if we learn we have, we'll delete it. Parents: privacy@flowsta.com.


8. Security

Ours: zero-knowledge architecture, HTTPS/TLS everywhere, security audits, no sensitive data in logs.

Yours: keep your vault password strong, your recovery phrase safe and offline, and an export of your data somewhere secure. Your phrase restores your identity; your export restores your private data.


9. Changes to This Policy

We'll give notice of material changes on this page and by email. Continued use means acceptance.


10. Governing Law

Jurisdiction: Victoria, Australia. Disputes are governed by the laws of Victoria, Australia, in its courts.


11. Contact