Flowy

Privacy Policy

Last updated September 23, 2026

Flowy is a personal inbox: you share things to it, and it reads them so you can find them later. That means Flowy holds content you chose to save. This page explains exactly what it holds, which companies process it on our behalf, and how to destroy it.

Who we are

Flowy is operated by Calcura Software, LLC. You can reach us at [email protected].

What we collect

Account information. An email address, and an identifier from Apple or Google if you sign in with them. If you use Sign in with Apple with “Hide My Email”, we only ever receive Apple’s private relay address, not your real one.

Content you save. Whatever you share to Flowy: links, screenshots, photos, videos, PDFs, other files, and emails you forward to your Flowy address. We also store what we derive from it — titles, summaries, tags, categories, transcripts, and text recognised in images — along with any notes or tags you add yourself.

Optional personalization profile. Answers you choose to give about your work or learning, current goals, and preferences. We store them with your account so you can review and update them across your devices. Completing this profile does not enable automatic memory extraction from your conversations.

Preferences and delivery. Your daily digest settings, your Flowy email alias, and, on mobile, a device push token so we can tell you when something you saved has finished processing.

We do not use advertising trackers, we do not sell personal information, and we do not use your content to train AI models.

Who processes it

Flowy cannot do its job without sending your content to a few processors. Each one receives only what it needs:

  • Anthropic — the text, images, and transcripts of what you save are sent to Claude to produce titles, summaries, tags, and to answer your questions in chat. When personalization is enabled, your declared profile is also sent as context to tailor those answers.
  • OpenAI — extracted text is sent to generate embeddings (numeric representations) and audio from saved videos is sent for transcription.
  • Voyage AI — extracted text and chat questions are sent to create search embeddings and, when enabled, improve the ranking of search results.
  • OpenRouter (OpenRouter, Inc., openrouter.ai) — added on September 23, 2026: used for accounts that accepted the disclosure dated September 23, 2026 or later, and for earlier accounts from September 30, 2026 (see “Changes to our AI providers” below). OpenRouter routes each request to the hosting provider it selects for an open-weight model (currently Qwen). We use it for two things: to produce titles, summaries, tags, and categories of the content you save, and, during evaluation, to generate a parallel result that we compare with Claude’s and never show you in its place. We send every request to OpenRouter with its data-collection setting set to “deny”, which excludes hosting providers that retain prompts or train on them.
  • SocialVault — when you save a link from Instagram, TikTok, LinkedIn, Facebook, or Threads, the link is sent to fetch the post’s publicly available media and captions.
  • Cloudflare — files you upload are stored in Cloudflare R2.
  • Railway — hosts the application and the database.
  • Expo — delivers push notifications to your device.

Your permission for AI processing

Before we create an account or send your content to Anthropic, OpenAI, Voyage AI, or OpenRouter, we ask for your explicit permission. By checking the AI processing box during sign-up, you authorize those disclosures solely to provide Flowy’s summaries, transcription, search, and chat features, and to compare the quality of the models that produce them.

You may decline by not creating an account.

Changes to our AI providers

Which AI providers Flowy uses is Flowy’s decision. We may add, replace, or stop using an AI provider at our discretion, for example to improve quality, reduce cost, or keep the service running, without asking you for a new permission. Every provider that processes your content is always listed on this page, receives only what it needs for the purposes above, and may not train AI models on your content.

Before a newly added provider starts processing your content, we will tell you in the app or by email at least 7 days in advance and update this page. If you do not agree, you can delete your account at any time before the change takes effect, and we will destroy your data as described below. Continuing to use Flowy after the change takes effect means you accept it.

Accounts that accepted the disclosure before September 23, 2026 were told on that date that OpenRouter was being added; their content may be processed by OpenRouter from September 30, 2026.

Our shared cache

When you save a public web page, Flowy keeps the text it extracted — the title, summary, tags, and article text — in a shared cache keyed by the page’s address. If someone else later saves the same public page, they get that text instead of us fetching and analysing it again. This makes Flowy faster and cheaper.

This cache holds only text derived from publicly reachable pages. It never contains your files, your notes, your tags, your personalization profile, or anything identifying you, and files you upload are never shared with another account.

How long we keep it

We keep your content until you delete it. Deleting an item removes it from your library. Deleting your account destroys the account and everything attached to it.

You can pause personalization while keeping your answers, or clear your profile from Settings. Clearing removes the profile answers and turns personalization off. Existing chat messages, including any that mention those details, remain in your chat history.

Model evaluation records. While we are evaluating models, the text a model returns for your content — for example a summary or a digest draft — may be kept together with the request’s metadata (which model ran, how long it took, what it cost, and whether its output was accepted) so we can compare quality between models. Only Flowy staff can see these records. We remove the returned text within 30 days, and sooner when you delete the item or digest it came from or when you delete your account.

Deleting your account

You can delete your account from Settings, in the web app and in the iOS app. Deletion is immediate and cannot be undone.

When you delete your account, we destroy:

  • your account record, email address, and sign-in identifiers;
  • every item you saved, with its summaries, tags, notes, and transcripts;
  • every file you uploaded, from our file storage;
  • your search embeddings, digests, personalization profile, and push token;
  • any model evaluation records linked to your account.

If you signed in with Apple, we also tell Apple to revoke Flowy’s access to your Apple Account.

Text already contributed to the shared cache described above stays, because it is derived from public pages and is not linked to you after your account is gone.

Your rights

You can access and correct your information in the app, and delete it at any time. If you want a copy of your data or have a request we can’t action in the app, email us and we will respond.

Children

Flowy is not directed to children under 13, and we do not knowingly collect their data.

Changes

If we change this policy in a way that materially affects you, we will update the date at the top and notify you in the app.

Privacy Policy — Flowy