Skip to content
Flumate
homeprivacytermscontact
TREN

legal/privacy.md

Privacy Policy

Last updated: August 23, 2026 · Version 1.6

1. Scope and contact

This policy explains how the Flumate mobile application (“Flumate”, “the app”, “we”) collects, uses, stores and shares personal data.

For privacy questions and data requests, contact orkundayi@flutech.org.

2. Data we collect

  • Account data: user ID, name, email address, profile photo and sign-in provider supplied through Firebase Authentication.
  • Planning data: tasks, activities, routines, goals, work/sleep/meal preferences, notes, reminders and completion records.
  • Assistant data: messages, responses, confirmed actions and a limited conversation history.
  • Optional health data (Apple HealthKit / Android Health Connect): consented daily aggregates such as steps, sleep duration, workout duration and active energy. Raw health samples are not uploaded.
  • Device and usage data: notification token, platform, time zone, low-cardinality interaction events and crash diagnostics.
  • Subscription data: store and product identifier, subscription/trial status, entitlement, renewal and expiration information, and transaction identifiers. Flumate does not receive your card or bank-account details.

Free-text assistant messages, private notes, OAuth tokens and health values are not included in analytics events.

How HealthKit and Health Connect data is used

  • Data read from HealthKit and Health Connect is used solely to show you your own progress and your day.
  • It is never used for advertising, marketing or similar services.
  • It is never sold or transferred to data brokers, advertising networks or other third parties.
  • Health values are excluded from analytics events, and health data reaches assistant prompts only when you ask something health-related, as daily aggregates.
  • You can withdraw permission at any time: iOS — Settings → Privacy & Security → Health → Flumate; Android — the Health Connect app. Flumate then stops reading new data, and you can delete previously stored daily aggregates from within the app.

3. Google user data

Connecting Google Calendar is optional and separate from signing in with Google. When you initiate the connection, Flumate may read and modify events only on calendars you own through the OAuth scope you approve on Google’s consent screen.

To import the near-term schedule, Flumate may process necessary details such as event title, start/end time, all-day status, event status, location and whether attendees are present. This data is used only to:

  • display upcoming commitments inside Flumate;
  • detect scheduling conflicts and calculate real free time;
  • prepare planning and time suggestions requested by the user; and
  • perform synchronization explicitly initiated by the user; and
  • write a selected Flumate activity to the primary calendar only when the user chooses “Add to Google Calendar” or “Update in Google Calendar.”

The Google OAuth refresh token is never returned to the mobile app; it is encrypted and stored server-side. Disconnecting Calendar attempts to revoke access, deletes the stored token and removes imported event copies. If the grant ends on Google’s side instead — you revoke access from your Google account, change your password, or the token expires — Flumate deletes the stored token and stops syncing; previously imported event copies remain in the app and are shown with the time of the last sync, so nothing of yours is deleted without notice. You can remove them at any time from Settings → Connections → Disconnect.

Flumate’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. How we use data

  • Create and authenticate your account and synchronize data across devices.
  • Provide planning, routine, progress, notification and assistant features.
  • Check conflicts, find free time and prepare suggestions at your request.
  • Protect the service, prevent abuse, diagnose faults and improve reliability.
  • Comply with legal obligations and protect legal rights.

5. AI and service providers

When you use the AI assistant or AI-assisted notifications, your message, the generated response and limited Flumate context needed to fulfill the request—such as in-app schedule blocks, goals, preferences, routines and daily aggregates—may be sent to the OpenAI API.

Input and output sharing is enabled for the OpenAI API project used by Flumate. OpenAI may therefore use transferred content not only to generate responses, but also to develop and improve its services and models, including for research, evaluation, testing and model training. OpenAI may act as an independent data controller for this development processing. Do not enter sensitive, confidential or proprietary information, or anything you do not want used for these purposes, into AI features. See OpenAI’s current API Data Controls for retention and processing details.

Raw or derived Google user data obtained through Google APIs is excluded from this shared AI traffic and is not used to develop, improve or train generalized AI models. AI proposals are separately checked server-side against Google Calendar busy times that are not disclosed to OpenAI.

We use Google Firebase for infrastructure, authentication, storage, server functions, notifications, analytics and crash diagnostics. Providers process data to deliver and secure their services and meet legal obligations.

Apple App Store or Google Play collects mobile subscription payments. RevenueCat processes your pseudonymous Firebase user ID and store subscription/transaction data to display offers, associate a purchase with your Flumate account, verify Pro entitlement, restore purchases and manage subscription status. We do not send your email address or payment-card details to RevenueCat.

We do not sell personal or Google user data, use it for advertising, or share it with data brokers.

6. Retention, security and deletion

Account and planning data is retained while your account is active or as needed to provide the service. You can separately clear assistant history, disconnect Calendar, delete Flumate data or delete your account.

Account deletion initiates revocation/deletion of the Apple/Google sign-in grant and Google Calendar token, deletion of user-owned app data and the server subscription mirror, a request to delete the RevenueCat customer record, and removal of the authentication account. A security barrier containing only the pseudonymous user ID and deletion status is kept for 30 days to stop old devices from recreating deleted data or a RevenueCat record; provider cleanup may repeat during that period, after which automatic deletion applies. Apple, Google and RevenueCat may retain transaction, tax, fraud-prevention or legal records under their own obligations. Deleting your Flumate account does not cancel the store subscription; you must separately cancel through Apple or Google to stop renewal. Limited records may be retained when required for security, fraud prevention or law.

The “Delete Flumate data only” option keeps your authentication account, RevenueCat customer record, Pro access and commercial usage quota. To prevent data from being recreated, Firebase refresh tokens are revoked, your devices are signed out and a server security barrier containing only the pseudonymous user ID and cleanup status is retained for final verification. This secure cleanup takes at least two hours and may take longer during temporary service failures; if you sign in before it finishes, you may be signed out again. The barrier is deleted after the final sweep succeeds.

Safeguards include encryption in transit, user-scoped access controls, server-side secret management and server-side encryption for Calendar refresh tokens. No electronic system can guarantee absolute security.

7. Choices and rights

Calendar, health, microphone and notification permissions are optional and can be withdrawn through the operating system, Google Account or app settings. You can prevent new assistant content from being sent to OpenAI by not using AI features and disabling AI-assisted notifications. You may update data, clear assistant history, delete app data or close your account in the app. Clearing assistant history in Flumate does not automatically withdraw content previously shared with OpenAI for development purposes from OpenAI systems.

Contact orkundayi@flutech.org to exercise access, correction, deletion, objection or other rights available under applicable law. We may need to verify your identity and account ownership.

8. Children and changes

Flumate is not directed to children who cannot lawfully consent to digital services without parental authorization. We may update this policy as the service or law changes and will provide appropriate notice of material changes.

© 2026 Flumate · flutech.org

HomeTerms of ServiceContactTürkçe