Effective 22 August 2026
Privacy Policy
How ReFlow handles account, planning, connected-service and operational data while keeping you in control.
Data we handle
ReFlow handles the information needed to provide your account and planning experience. This can include your email address, ReFlow account identifier, Tasks, Events, Task Blocks, preferences, planning history, reminder settings and the feedback you choose to send.
If you connect Google Calendar, ReFlow receives read-only Google Calendar event information so fixed commitments can appear beside your ReFlow plan. Google connection credentials stay on ReFlow’s server and are not returned to the app.
How we use data
We use account and planning data to authenticate you, synchronize your ReFlow data, show your plan, provide reminders, calculate deterministic planning suggestions and support optional personalisation controls.
Beta analytics are content-free: they record bounded operational actions and categories, not Task titles, Calendar titles, Starter text or free-form planner content. Crash reports are scrubbed before delivery and exclude account identity, request bodies, breadcrumbs, screenshots, replay and arbitrary context.
Connected services
ReFlow uses Supabase for authentication, cloud data and server-side integrations. Optional read-only Google Calendar access is used only after you connect it. Optional OpenAI assistance receives a minimized planning context only when AI personalisation is enabled; deterministic planning remains available when AI is off or unavailable.
Sentry may process privacy-scrubbed technical diagnostics. RevenueCat and the App Store or Google Play may process your account identifier, product and transaction state when subscriptions are activated. ReFlow does not receive your payment-card or bank-account details from the stores.
ReFlow does not sell personal data, use behavioural advertising, or use your data for cross-app tracking.
Retention
ReFlow keeps account and planning data while your account is active so the service can work across sessions and devices. Owner-linked planner, preference, analytics, feedback, Calendar connection and entitlement records are removed through the account-deletion flow.
A content-minimized deletion receipt is retained for 35 days to verify deletion outcomes and is then automatically purged. Provider-side operational records can follow the provider retention settings disclosed for the active service.
Your choices and controls
You can manage reminders, optional AI personalisation, behavioural-memory controls and Google Calendar connection from ReFlow. Disconnecting Calendar removes ReFlow’s stored Calendar credentials. You can delete your ReFlow account and associated owner-linked data from Profile.
You may also contact ReFlow support to ask about access, correction or deletion. We may need to verify that the request belongs to your account before acting on it.
Security and international processing
ReFlow uses authenticated owner boundaries, encrypted network connections, server-side provider credentials and data-minimization controls. No internet service can promise absolute security, but ReFlow is designed to fail closed when authorization or validation is uncertain.
Some service providers may process data outside Australia. Where that occurs, ReFlow relies on the provider terms and safeguards applicable to the service.
Contact
For privacy questions or requests, contact the dedicated ReFlow support address shown on this site. This policy may be updated when the Beta services or legal requirements change; the current effective date remains visible at the top of the page.
Direct contact
Contact ReFlow
For support questions or account help:
support@reflowapp.techFor privacy questions or requests:
privacy@reflowapp.tech