Privacy and Data Use
Effective July 22, 2026
This notice explains the product's actual data boundaries, including what remains local, what syncs after sign-in, and what Flowtime deliberately does not monitor.
Data Flowtime handles
You can use the basic timer as a guest. Guest tasks, timer state, settings, sessions, exercise progress, and learning progress stay in the local application database unless you choose to create or sign in to an account and synchronize them.
For signed-in accounts, Flowtime may process your Firebase account identifier and profile, tasks and projects, focus/break/idle sessions, timer recovery state, settings and presets, exercise preferences and completions, playlist metadata and playback progress, integration state, and synchronization records.
Idle and activity signals
Flowtime uses only the capability disclosed by the current platform: in-app interaction, page visibility, app lifecycle, or an explicitly permitted desktop system-idle API. It does not record typed text, individual keys, pointer coordinates, screenshots, or activity in other mobile apps. Mobile operating systems do not provide general system-wide idle tracking to normal applications.
Idle records keep a source label so an in-app estimate is never presented as system-wide observation. Flowtime is a personal productivity tool and must not be used for covert employee surveillance.
Accounts, synchronization, and integrations
Firebase provides account authentication and cloud document storage. The Flowtime API verifies Firebase identity tokens and derives record ownership from the verified account ID.
If you connect Notion, OAuth credentials remain encrypted in a server-only collection. Flowtime exposes only redacted connection status to clients and exchanges the task fields needed for two-way synchronization. YouTube features use video and playlist identifiers plus playback progress; Flowtime does not receive your YouTube password.
Service providers and operational data
Flowtime may use Firebase for authentication and database services, Vercel or a compatible server host to deliver the website and API, Resend to deliver feedback you submit, Notion for an integration you enable, and YouTube for media you choose to play. These providers process data under their own terms and privacy notices.
Security and reliability records are minimized and should not include task titles, OAuth tokens, message bodies, typed input, or raw activity events. Flowtime does not sell personal productivity data.
Your controls and retention
You can disconnect Notion, request a portable NDJSON account export, or request account deletion after a recent sign-in and explicit confirmation. A completed export link expires after 24 hours. Account deletion removes the Firebase identity, user document tree, integration credentials, OAuth state, synchronization leases, jobs, and export artifacts.
Local guest data remains on your device until you clear it or uninstall the application. Flowtime does not delete productivity history under an inactivity policy unless a separate retention policy is announced first.
Questions and requests
Use the authenticated feedback control in Flowtime for privacy questions, corrections, or requests that are not available through account controls. Depending on where you live, you may also have statutory rights concerning access, correction, deletion, portability, restriction, or objection.