GDPR Compliant

Privacy Policy

Last updated: March 28, 2026  ·  Hopson & Cie Srl  ·  Brussels, Belgium

Table of Contents

  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis (GDPR)
  5. Google User Data — Full Disclosure
  6. Other Third-Party Integrations
  7. Data Sharing & Sub-processors
  8. Data Retention
  9. Your Rights (GDPR)
  10. Security
  11. Cookies & Local Storage
  12. Children's Privacy
  13. International Transfers
  14. Changes to This Policy
  15. Contact & DPO
Our commitment: We collect only what is strictly necessary to operate Flowo. We never sell your personal data. You can request deletion at any time.

1. Who We Are

Flowo is operated by Hopson & Cie Srl, a company incorporated under Belgian law:

Hopson & Cie Srl

149 avenue du Domaine, 1190 Bruxelles, Belgium

VAT: BE 0450.443.155

Email: privacy@getflowo.com

Website: https://getflowo.com

Hopson & Cie Srl acts as the data controller within the meaning of the EU General Data Protection Regulation (GDPR — Regulation 2016/679) for all personal data processed through the Flowo platform.

2. Data We Collect

2.1 Account Data

When you create an account, we collect:

2.2 Subscription & Payment Data

Payments are processed exclusively by Polar.sh (our payment processor). We do not store your credit card number or bank details. We receive and store:

2.3 Usage & App Data

To provide the service, we store:

2.4 Google Calendar Integration Data (Optional)

If you choose to connect Google Calendar:

2.5 Technical Data

CategoryExamplesStored inRetention
AccountEmail, username, password hashCloudflare D1 (SQLite)Until account deletion
SubscriptionPlan, status, datesCloudflare D1Until account deletion
Tasks & EventsTitles, dates, notesCloudflare D1Until account deletion
GCal TokensAccess + refresh tokenCloudflare D1 (encrypted)Until disconnection
Local preferencesLanguage, sidebar stateBrowser localStorageUntil browser clear

3. How We Use Your Data

We never use your data for advertising, never sell it to third parties, and never build marketing profiles based on your usage.

4. Legal Basis (GDPR Art. 6)

Processing activityLegal basis
Creating and managing your accountContract performance (Art. 6.1.b)
Processing subscription paymentsContract performance (Art. 6.1.b)
Sending transactional emailsContract performance (Art. 6.1.b)
Google Calendar integrationConsent (Art. 6.1.a) — you explicitly authorise via OAuth
AI task suggestionsLegitimate interest (Art. 6.1.f) — core product feature
Security monitoring & fraud preventionLegitimate interest (Art. 6.1.f)
Legal obligations (tax records)Legal obligation (Art. 6.1.c)

5. Google User Data — Full Disclosure

Flowo interacts with Google services in two distinct ways: (a) Google Sign-In for authentication, and (b) Google Calendar integration for calendar synchronisation. This section fully discloses how Flowo accesses, uses, stores, shares, retains, and allows deletion of Google user data, in compliance with the Google API Services User Data Policy, including the Limited Use requirements.

5.1 Google User Data Accessed

A. Google Sign-In (authentication)

When you sign in with Google, Flowo requests the following OAuth scopes:

Specifically, we access the following data from the googleapis.com/oauth2/v3/userinfo endpoint:

Data fieldWhat it isWhy we access it
sub (Google ID)Your unique Google account identifierTo link your Google identity to your Flowo account (stored as oauth_id)
emailYour Google email addressUsed as your account email for login, transactional emails, and account recovery
nameYour Google display nameUsed as your default username in the Flowo interface
pictureYour Google profile photo URLDisplayed as your avatar in the Flowo sidebar and settings

B. Google Calendar Integration (optional, user-initiated)

If you choose to connect Google Calendar (a separate action from signing in), Flowo requests these additional OAuth scopes:

Specifically, we access the following calendar data via the Google Calendar API v3:

Data fieldWhat it isWhy we access it
Event titlesNames of your calendar eventsDisplayed in the Flowo calendar view so you can plan tasks around meetings
Event dates/timesStart and end timestampsUsed by the AI scheduler to avoid double-booking and find free time slots
Event descriptionsNotes and details of eventsDisplayed in the event detail view within Flowo
Event locationsPhysical or virtual meeting locationsDisplayed in the event detail view
AttendeesEmail addresses of event participantsDisplayed in event details; used when creating new events to send invitations via Google
Google Meet linksVideo conference URLsDisplayed as clickable links in event details for easy access
Recurrence rulesRepeating event patternsUsed to correctly display recurring events in the Flowo calendar
Event statusConfirmed, tentative, or cancelledUsed to filter which events appear in your Flowo schedule
RemindersEvent reminder settingsStored for reference; Flowo does not send its own reminders for Google events

5.2 How We Use Google User Data

Flowo uses Google user data exclusively for the following purposes:

PurposeData usedDetails
Account authenticationGoogle ID, email, nameTo create and authenticate your Flowo account when you sign in with Google. Your email is used as your account identifier.
Profile displayName, profile picture URLTo show your name and avatar in the Flowo interface (sidebar, settings). The picture URL is stored as a link — we do not download or re-host the image.
Calendar displayAll calendar event fields listed aboveTo display your Google Calendar events alongside your Flowo tasks, enabling you to plan your work schedule without context-switching between apps.
AI-powered schedulingEvent dates/times onlyThe AI scheduler uses event time ranges (not titles or descriptions) to find available time slots when automatically scheduling your tasks.
Event creationCalendar write accessWhen you create an event in Flowo and choose to sync it to Google Calendar, we use the Calendar API to create the event on your behalf, including optional Google Meet links and attendee invitations.
Event modificationCalendar write accessWhen you edit or delete an event in Flowo that originated from Google Calendar, we propagate the change back to Google Calendar.
Real-time syncOAuth refresh tokenWe use the stored refresh token to periodically sync new, updated, or deleted events from Google Calendar to Flowo, keeping your calendar view up to date.
What we do NOT do with Google user data:
  • We do not use Google data for advertising, marketing, or user profiling
  • We do not sell, rent, or lease Google user data to any third party
  • We do not use Google data to train AI or machine learning models
  • We do not use Google data for any purpose unrelated to providing the Flowo productivity service
  • We do not allow any human to read your Google Calendar data, except with your explicit consent or where required by law

5.3 Google User Data Sharing

Google user data obtained through Google API Services is shared only with the following categories of third parties, and only for the purposes described:

RecipientData sharedPurposeLegal basis
Cloudflare, Inc.All stored Google data (encrypted in D1 database)Infrastructure provider — hosts the database where Google Calendar tokens and synced events are storedContract performance; SCCs for international transfer
Google LLCOAuth tokens (to authenticate API requests)Required for Calendar API calls to read/write events on your Google CalendarConsent (you authorise the connection)

Important: Google user data is never shared with OpenAI, Polar, Resend, or any other sub-processor. Specifically:

5.4 Google User Data Storage & Protection

Google user data is stored and protected using the following measures:

Data typeStorage locationProtection measures
Google OAuth tokens (access token, refresh token) Cloudflare D1 database (google_calendar_tokens table)
  • Database encrypted at rest (Cloudflare D1 default encryption)
  • Access restricted to authenticated Cloudflare Workers only
  • Tokens are never exposed to the frontend / browser
  • Each user's tokens are isolated by user_id — users cannot access other users' tokens
Synced calendar events Cloudflare D1 database (calendar_events table)
  • Encrypted at rest
  • Filtered by user_id on every API query — strict per-user isolation
  • All data transmitted over TLS 1.3 (HTTPS enforced)
Google profile data (email, name, avatar URL) Cloudflare D1 database (users table) Same protections as all account data — encrypted at rest, per-user isolation, TLS in transit

Additional security measures applicable to all Google user data:

5.5 Google User Data Retention & Deletion

We retain Google user data only for as long as necessary to provide the service:

Data typeRetained untilDeletion method
Google OAuth tokens Until you disconnect Google Calendar or delete your Flowo account Tokens are permanently deleted from the database. We also attempt to revoke the token with Google's API so your authorization is fully removed.
Synced calendar events Until you disconnect Google Calendar or delete your Flowo account All synced events with source='google' are permanently deleted from the database upon disconnection.
Google profile data (email, name, avatar) Until you delete your Flowo account All account data is permanently deleted within 30 days of an account deletion request.

How to delete your Google user data:

Google API Services Limited Use Disclosure: Flowo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5b. Other Third-Party Integrations

Microsoft (Outlook / Microsoft 365)

If you connect Microsoft Outlook or sign in with a Microsoft account where offered, Microsoft processes authentication and calendar data according to their terms. We use Microsoft identity and calendar APIs only to provide the features you enable (display sync, creating or updating events when you ask us to). We do not use Microsoft data for advertising or to train unrelated models. For how we store tokens and calendar events, the same security measures as for other calendar integrations apply (encrypted storage, per-user isolation, TLS). Microsoft's privacy statement: privacy.microsoft.com/privacystatement.

6. Data Sharing & Sub-processors

We share personal data only with the following categories of recipients:

Sub-processorPurposeLocation
Cloudflare, Inc.CDN, edge hosting, D1 database, DDoS protectionUSA (SCCs)
OpenAI, LLCAI task suggestions (task content only, no account data)USA (SCCs)
Polar.shPayment processing and subscription managementUSA (SCCs)
Resend, Inc.Transactional email deliveryUSA (SCCs)
Google LLCOAuth authentication, Calendar API (only if you connect)USA (SCCs)
Microsoft CorporationOAuth / Microsoft identity and Outlook calendar (only if you connect)USA / global (Microsoft DPA & SCCs where applicable)

SCCs = Standard Contractual Clauses (EU Commission Decision 2021/914) for GDPR-compliant international transfers.

We do not share data with advertisers, data brokers, analytics companies, or any other parties beyond the above.

7. Data Retention

8. Your Rights (GDPR)

As a data subject under the GDPR, you have the following rights:

To exercise any of these rights, email us at privacy@getflowo.com. We will respond within 30 days as required by GDPR.

9. Security

We implement appropriate technical and organisational measures to protect your personal data:

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by GDPR Art. 33, and affected individuals without undue delay as required by Art. 34.

10. Cookies & Local Storage

10.1 What we use

Flowo uses no third-party tracking cookies and no advertising cookies. We use only:

NameTypePurposeDuration
flowo_session / sa_user_*localStorageKeeping you logged in between visitsUntil logout or browser clear
sa_langlocalStorageRemembering your language preferencePersistent until changed
sa_sidebar_*localStorageSidebar width and mini/expanded statePersistent until changed
g_stateHTTP Cookie (HttpOnly)CSRF protection during Google OAuth flow10 minutes (auto-expires)
gcal_stateHTTP Cookie (HttpOnly)CSRF protection during Google Calendar OAuth10 minutes (auto-expires)
On public marketing pages, Google Tag Manager and the Google Ads (gtag) snippet load only after you opt in via the cookie banner (stored preference in flowo_cookie_consent). We do not use the Facebook Pixel or Hotjar. Cross-site profiling is not part of our product model.

10.2 Cloudflare

Cloudflare may set a cookie (__cf_bm) for bot detection and security purposes. This is a strictly necessary cookie. See Cloudflare's privacy policy.

10.3 Cookie consent (this website)

On marketing pages (e.g. homepage, guide, legal pages), we store your cookie choices in localStorage under the key flowo_cookie_consent (JSON with your analytics preference). This record is not used to track you across other companies' sites; it only remembers whether you accepted or rejected optional measurement tags on getflowo.com.

If you accept analytics & marketing measurement, we load Google Tag Manager (which may include Google Analytics 4 or other tags as configured) and the Google Ads gtag library. These tools are not injected before consent. If you reject optional tags, they are not loaded.

You can change your mind by clearing site data for getflowo.com in your browser or by deleting the flowo_cookie_consent entry; the banner will appear again on your next visit.

11. Children's Privacy

Flowo is not directed at children under the age of 16. We do not knowingly collect personal data from individuals under 16. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us at privacy@getflowo.com and we will delete the data promptly.

12. International Data Transfers

Our primary sub-processors (Cloudflare, OpenAI, Polar, Resend) are based in the United States. These transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission under Decision 2021/914, providing adequate safeguards for your personal data as required by GDPR Chapter V.

Data processed by Cloudflare is subject to their Data Processing Addendum and their binding corporate rules. Cloudflare Workers and D1 can be configured to process data exclusively within the EU — we are actively evaluating this option for future compliance improvements.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

Continued use of Flowo after the effective date of changes constitutes acceptance of the updated policy.

Previous versions of this Privacy Policy are available upon request at privacy@getflowo.com.

14. Contact & Data Protection

For any questions, requests, or complaints regarding this Privacy Policy or the processing of your personal data:

Data Controller & Privacy Contact

Hopson & Cie Srl

149 avenue du Domaine, 1190 Bruxelles, Belgium

Email: privacy@getflowo.com

VAT: BE 0450.443.155

If you are not satisfied with our response, you have the right to lodge a complaint with the Belgian Data Protection Authority (APD/GBA):

Autorité de protection des données (APD)

Rue de la Presse 35, 1000 Bruxelles

Website: www.dataprotectionauthority.be

Email: contact@apd-gba.be

Phone: +32 2 274 48 00

For cross-border disputes, you may also use the EU Online Dispute Resolution platform: ec.europa.eu/consumers/odr