Draft for operator and legal review — last updated 2026-10-06
Privacy Policy
1. Controller
The controller under Art. 4(7) GDPR is:
Abdullah Faruk GonulluAnkaraContact for privacy requests: Hello@goodxp.com. See also the Impressum.
2. Data we process, why, and on what basis
Flowmind processes the data below to provide the service you asked for. We do not use it for advertising and we do not make decisions with legal effect about you by automated means: AI features produce drafts that you review and confirm.
| Category | Data | Purpose | Legal basis |
|---|---|---|---|
| Account and sign-in | Email address, sign-in method (email and password, Google or GitHub), authentication identifiers and session tokens, kept by Supabase Auth. | Create and secure your account. | Art. 6(1)(b) GDPR (contract). |
| Profile | Username, display name, bio, profile visibility setting, level, experience points, streaks and badges. | Provide your profile and personal progress. Public profiles show weeks active and published weeks, not your level or experience points. | Art. 6(1)(b) GDPR (contract). |
| Timezone and preferences | Timezone and when you confirmed it. | Group new work by your local day and week and remember your choices. Existing entries keep their recorded day and week. | Art. 6(1)(b) GDPR (contract). |
| Projects and routines | Names, descriptions, categories, estimates, launch details and launch link. | Provide the ledger you asked for. | Art. 6(1)(b) GDPR (contract). |
| Time entries | Start time, duration, intention or description, outcome note, artifact link, local day and week, flow-session flag, capture source, and whether an entry was voided or replaced. | Store your proof and compute totals, streaks and reviews. Approved agent execution is kept separate from personal effort. | Art. 6(1)(b) GDPR (contract). |
| Daily closes, weekly reviews and published weeks | What shipped, next intention and project, private reflection, next commitment and its result; publication date and optional public note for a week you publish. | Help you resume and review work. Make selected weeks public when you publish them, as explained below. | Art. 6(1)(b) GDPR (contract). |
| Weekly emails (only if you opt in) | Confirmed email address, timezone, opt-in setting, recorded outcomes and commitments, an unsubscribe token, and delivery records containing email kind, week, status, attempt/completion times, provider message identifier and failure code. | Send Friday recaps and Monday commitment reminders at local times, honour unsubscribe requests, and prevent sending the same kind of email to you more than once per week. | Art. 6(1)(a) GDPR (consent). |
| Seven-day challenge | Enrollment day and completion time, with daily progress derived from your saved proof, daily closes and weekly reviews. | Show challenge progress and your recap when you choose to join. | Art. 6(1)(b) GDPR (contract). |
| Social features | Follows, reactions, comments, circle membership, check-ins and commitments, invitations and in-app notifications. | Provide the social features you choose to use. | Art. 6(1)(b) GDPR (contract). |
| Voice capture | Recorded audio, its transcript, duration, transcription provider and model, and the number of entries extracted. | Turn your recording into draft entries when you use voice capture. | Art. 6(1)(b) GDPR (contract). |
| AI features | Notes you submit for drafting, your active project names, your local date and time zone, data used to draft weekly reflections and retrospectives, recorded outcomes and the next commitment used for update drafts you request, and job records (status, provider, model, usage and cost). | Draft entries, reflections, retrospectives and requested updates for your review, and operate and limit AI usage. Private reflection text is not used for update drafts, and generated update text is not stored by Flowmind on the server. | Art. 6(1)(b); Art. 6(1)(f) for usage limits and cost control. |
| Billing (where paid plans are enabled) | Stripe customer identifier, subscription status and billing lifecycle events. Card details are handled by Stripe and not stored by us. | Provide and account for paid plans. | Art. 6(1)(b); Art. 6(1)(c) for statutory accounting duties. |
| API keys and agent access | Key name, scope, a hash and short prefix of the key, last use, expiry and revocation; command-line login requests; entries staged by agents for your review. | Let you connect the command-line client and your own automation safely. | Art. 6(1)(b) GDPR (contract). |
| Product events and security records | Product events (event name, source, page or route, related record identifiers and coarse values such as duration), audit events, rate-limit counters, idempotency records and error reports. | Operate, secure and improve Flowmind, prevent abuse and find faults. | Art. 6(1)(f) (legitimate interest in a secure, working service). |
| Hosting logs | IP address and request metadata processed by our hosting providers when you visit the site or call the API. | Deliver the site and protect it against attacks. | Art. 6(1)(f). |
| Website analytics (only after you allow it) | Google Analytics measures visits to public pages: page route templates, coarse campaign tags, and technical data such as browser, device and approximate location that Google derives from your connection. | Understand how public pages perform. | Art. 6(1)(a) GDPR (consent) and § 25(1) TDDDG. |
3. Public profiles and published weeks
Profiles start private. If you make yours public, your username, display name, bio, member-since date, weeks active, published weeks, personal-effort totals, heatmap, proof badges, top projects and routines, launched projects and share cards are visible to anyone with the address. Public profiles do not show your level or experience points. You can change profile visibility in Settings. If your profile is public, people who follow you can see your logged sessions in their feed, including the project name, duration, outcome note and agent attribution. Circle commitments and check-ins are visible to members of that circle.
Publishing a week is a separate choice. Its page is public to anyone with the link even when your profile is private. It shows your username and display name, the week and public note, project names, recorded outcomes, artifact links, dates and durations, and labels for approved agent work. Personal and agent time are shown separately. The page has link previews and is marked noindex to ask search engines not to list it; this does not restrict access to the link. It does not include intentions, private reflections, commitments, daily-close notes, voice data or voided entries. The page reads current records, so later corrections affect it. You can unpublish it from the weekly share dialog. Making your profile private does not unpublish weeks you already shared.
4. Processors, recipients and international transfers
We use the providers below to run Flowmind. They process data on our behalf under data processing terms, or as independent controllers for the sign-in method you choose.
| Provider | Purpose | Data and location |
|---|---|---|
| Supabase | Sign-in, Postgres database, file storage for voice audio. | All account and ledger data. Hosted in Ireland (AWS eu-west-1). |
| Hetzner Online GmbH (Germany) | Hosts the API, the background worker and a private Redis queue. | Data in transit through the API; queue entries carry job identifiers only. |
| Vercel Inc. (USA) | Hosts the web application. | IP address and request metadata. Transfer to the USA. |
| OpenAI (USA) | Text drafting, voice transcription, reflections, and drafting updates you request from your recorded outcomes through its API. | Notes and audio you submit to those features, relevant project and effort data, and recorded outcomes, artifact links and next commitment for requested update drafts. Transfer to the USA. |
| Stripe | Payments and subscriptions, where paid plans are enabled. | Billing and payment data. May involve transfer to the USA. |
| Sentry (USA) | Error monitoring, where enabled. Configured not to collect default personal data. | Technical error information and build details. Transfer to the USA. |
| Google (USA / Ireland) | Google Analytics, only if you click "Allow analytics". Also sign-in with Google, if you choose it. | Analytics data described above; sign-in identity data. |
| GitHub (USA) | Sign-in with GitHub, if you choose it. | Sign-in identity data. |
Where data goes to a country outside the European Economic Area, we rely on an adequacy decision such as the EU–US Data Privacy Framework for certified providers, or on the EU Standard Contractual Clauses together with supplementary measures. You can request a copy of the safeguards from the contact above.
5. Cookies and local storage
Flowmind stores the items below in your browser. Items that are strictly necessary, or necessary for a feature you use, need no consent under § 25(2) TDDDG. Google Analytics is off until you click "Allow analytics": before that no request is sent to Google. You can change your choice at any time with "Cookie settings" in the footer; declining stops further events and removes Google Analytics cookies.
| Name | Type | Purpose | Duration | Basis |
|---|---|---|---|---|
| Supabase session cookies (sb-…) | Cookie | Keep you signed in. | Set by Supabase; renewed while you use the app. | Strictly necessary |
| flowmind_focus_session | Local storage | Restore a running focus timer after a reload. | Until the session ends or you clear it. | Necessary for a feature you use |
| flowmind.theme | Local storage | Remember light or dark theme. | Until you clear it. | Necessary for a feature you use |
| flowmind.interaction-sounds | Local storage | Remember your sound preference. | Until you clear it. | Necessary for a feature you use |
| flowmind.ai-capture… | Session storage | Recover an unsaved AI note draft. Cleared on save, cancel and sign-out. | Until the tab closes. | Necessary for a feature you use |
| flowmind.analytics-consent | Local storage | Store your analytics choice and when you made it. | Until you clear it or change your choice. | Necessary to honour your choice |
| _ga, _ga_… (Google) | Cookies | Google Analytics measurement. | Set only after you allow analytics; removed when you decline. | Consent |
6. Retention
- Account, profile, ledger and social data are kept while your account exists and are deleted when you ask us to delete your account, unless the law requires us to keep specific records, such as billing records.
- Voice audio is deleted automatically once it has been transcribed or found unusable. An upload that is never used expires after one hour. Deletion is retried; cases we cannot resolve automatically are flagged for manual review and kept until resolved. The transcript is kept as part of your account data until you delete it or your account.
- API keys expire after 90 days by default and can be revoked at any time.
- Product events and audit records are linked to your account and removed with it.
- Weekly-email preferences, the unsubscribe token and delivery records are retained with your account. Opting out stops future weekly emails; it does not erase those records. Delivery records prevent repeated sends of the same email kind for a week, including after a failed attempt. The code does not currently apply a separate timed deletion policy to these records.
- Local browser storage stays on your device until you clear it or, for session storage, close the tab.
7. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), including to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time with effect for the future (Art. 7(3)); withdrawal does not affect earlier processing. To exercise a right, or to delete your account, email the contact above.
You can withdraw weekly-email consent in Settings or through the unsubscribe link in an email; supported email clients also offer one-click unsubscribe. Weekly-email consent is separate from website analytics consent. You can change the analytics choice through Cookie settings in the footer.
8. Complaint to a supervisory authority
You may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state where you live or work, or where the alleged infringement took place. The authority responsible for the controller is the data protection authority of the German federal state in which the controller is based.
9. Changes to this policy
We update this policy when features, providers or the law change. The date at the top shows the current version. We will tell registered users about material changes.