Version 2.4 — Effective August 2, 2026
localStorage.We use your data strictly to operate the service — rendering your visual dashboard, delivering transactional email notifications and team invitations, generating PDF executive briefings, and notifying you about project milestones. We do not sell your data, monetize user lists, or train third-party artificial intelligence models on your content.
Three trusted cloud infrastructure partners process data on our behalf to deliver Flowly:
flowlycloud.cc), and transactional email delivery via the Hostinger Agentic Mail REST API.Push notifications are delivered through Flowly's own web-push server — we do not route mobile notifications through Firebase or any third-party analytics SDK.
We do not share your data with advertisers, third-party trackers, or marketing data brokers.
Entries created inside the Flowly Journal module are bound strictly to your individual profile (userId) with zero-exception per-user isolation. Journal entries are strictly private to you and are never accessible or visible to workspace managers, organization admins, or other team members.
The Flowly Journal interface includes a 1-click Privacy Blur Mode to visually obscure sensitive shift notes on screen when working in shared operational environments.
You retain full ownership and control of your data:
Passwords are hashed using bcrypt with a cost factor of 12. Authentication sessions rely on HTTP-only, SameSite secure cookies. All web traffic is encrypted in transit via TLS/HTTPS. Rate limiting is enforced on authentication and contact endpoints to block brute-force attempts.
To report security vulnerabilities, email hello@flowlycloud.cc.
Privacy inquiries: hello@flowlycloud.cc.