1. Scope and contact
This policy explains how the Flumate mobile application (“Flumate”, “the app”, “we”) collects, uses, stores and shares personal data.
For privacy questions and data requests, contact orkundayi@flutech.org.
2. Data we collect
- Account data: user ID, name, email address, profile photo and sign-in provider supplied through Firebase Authentication.
- Planning data: tasks, activities, routines, goals, work/sleep/meal preferences, notes, reminders and completion records.
- Assistant data: messages, responses, confirmed actions and a limited conversation history.
- Optional health data: consented daily aggregates such as steps, sleep duration, workout duration and active energy. Raw health samples are not uploaded by default.
- Device and usage data: notification token, platform, time zone, low-cardinality interaction events and crash diagnostics.
Free-text assistant messages, private notes, OAuth tokens and health values are not included in analytics events.
3. Google user data
Connecting Google Calendar is optional and separate from signing in with Google. When you initiate the connection, Flumate may read and modify events only on calendars you own through the OAuth scope you approve on Google’s consent screen.
To import the near-term schedule, Flumate may process necessary details such as event title, start/end time, all-day status, event status, location and whether attendees are present. This data is used only to:
- display upcoming commitments inside Flumate;
- detect scheduling conflicts and calculate real free time;
- prepare planning and time suggestions requested by the user; and
- perform synchronization explicitly initiated by the user; and
- write a selected Flumate activity to the primary calendar only when the user chooses “Add to Google Calendar” or “Update in Google Calendar.”
The Google OAuth refresh token is never returned to the mobile app; it is encrypted and stored server-side. Disconnecting Calendar attempts to revoke access, deletes the stored token and removes imported event copies.
4. How we use data
- Create and authenticate your account and synchronize data across devices.
- Provide planning, routine, progress, notification and assistant features.
- Check conflicts, find free time and prepare suggestions at your request.
- Protect the service, prevent abuse, diagnose faults and improve reliability.
- Comply with legal obligations and protect legal rights.
5. AI and service providers
When you use the AI assistant, your message and limited context needed to answer it—such as near-term schedule blocks, goals, preferences and daily aggregates—may be sent to the OpenAI API. For a calendar-related request, necessary event titles and times may be part of that limited context.
OpenAI processes this data to generate a response for Flumate. API inputs and outputs are not used to train models by default. See OpenAI’s current API Data Controls for retention and processing details.
We use Google Firebase for infrastructure, authentication, storage, server functions, notifications, analytics and crash diagnostics. Providers process data to deliver and secure their services and meet legal obligations.
We do not sell personal or Google user data, use it for advertising, or share it with data brokers.
6. Retention, security and deletion
Account and planning data is retained while your account is active or as needed to provide the service. You can separately clear assistant history, disconnect Calendar, delete Flumate data or delete your account.
Account deletion initiates revocation/deletion of the Google token, deletion of user-owned app data and removal of the authentication account. Limited records may be retained when required for security, fraud prevention or law.
Safeguards include encryption in transit, user-scoped access controls, server-side secret management and server-side encryption for Calendar refresh tokens. No electronic system can guarantee absolute security.
7. Choices and rights
Calendar, health, microphone and notification permissions are optional and can be withdrawn through the operating system, Google Account or app settings. You may update data, clear assistant history, delete app data or close your account in the app.
Contact orkundayi@flutech.org to exercise access, correction, deletion, objection or other rights available under applicable law. We may need to verify your identity and account ownership.
8. Children and changes
Flumate is not directed to children who cannot lawfully consent to digital services without parental authorization. We may update this policy as the service or law changes and will provide appropriate notice of material changes.