← FlowingAway

Privacy Policy

Version 2.4 · Last updated 25 July 2026 · Maintained by Everyday Flow

Who is responsible for your data

FlowingAway by Everyday Flow is the service described in this policy. Everyday Flow is the data controller for the personal information you save here, and decides how it is handled. You can reach us at support@everydayflow.app for any question about your data.

Introduction

FlowingAway by Everyday Flow is a place to save your memories, your life story, the letters you want to leave for people, and the practical information your family may need one day. That is personal information, and this policy explains exactly how it is handled.

You decide what you save. Nothing is required. You can write one memory and stop there, or use every part of the app. Whatever you save stays private to your account unless you choose otherwise.

Privacy is one of the core principles of this product, not a setting added at the end. Protecting what you write is part of how the application is built.

Privacy by design

FlowingAway follows a privacy-by-design approach. Privacy and security are considered when a feature is designed, not fixed afterwards. In practice that means:

  • Every feature starts private. Sharing is something you turn on, never a default.
  • We ask for information only when it does something useful for you in the app.
  • Access rules are enforced in the database, not only in the interface.
  • New features are checked against these rules before they ship.

What information we collect

You choose what to save. FlowingAway never writes personal content on your behalf. The categories below are the kinds of information the app can hold.

  • Account information. Your email address and password, held by our authentication provider. Passwords are stored as secure hashes and are never visible to us.
  • Profile information and onboarding answers. Your name or how you want to be addressed, your country, where you chose to begin, who you are preserving things for, and whether Flow Guide learning is on.
  • Memories, life chapters, values and lessons. The entries you write, including titles, dates and notes you add.
  • Weekly conversations. The reflective question shown each week and the answer you write, if you answer it.
  • Personal notes. Anything you write in free-text fields across the app.
  • Letters and messages. Words written for a specific person, including who they are for.
  • Uploaded documents. Files you add, with the title, category and notes you give them. Files are stored in a private bucket tied to your account.
  • Practical information and ceremony wishes. Where things are kept, who can help, and what you would prefer to happen.
  • Digital Life inventory. A list of the accounts and services you want recorded. Note where things are, not how to get into them. Do not store passwords, PINs or recovery codes.
  • Emergency information. Anything you mark as needed first, so it can be found quickly.
  • Trusted Release settings. Who you have named, what you allowed, and a record of changes to those settings.
  • People and support contacts. Names and contact details you add. Add only what you are comfortable holding on someone else’s behalf.
  • Activity records. A short record of privacy-relevant actions you take, such as changing Trusted Release settings, exporting your data or deleting your account. Each record holds the action and the time, never the content itself.

Voice recording, transcription and memory photographs are not active in this version. Nothing of that kind is recorded or stored today. If those features are released, this policy is updated first.

Why we collect information

Each category is stored for a reason you can point to in the product.

  • Account information lets you sign in securely and recover access if you forget it.
  • Profile information lets the app address you correctly and skip questions you answered.
  • Your entries are the product. They are stored so you can find and edit them later.
  • Weekly answers are stored so you can keep them and turn them into entries later.
  • Documents are stored so important paperwork stays in one findable place.
  • Practical and emergency information exists to save your family time and guesswork.
  • Trusted Release settings record your intentions so they do not have to be guessed.
  • Activity records give you a clear history of decisions about sharing and deletion.

We do not collect information for advertising, profiling or resale, and we do not sell personal data.

Our legal basis for using your data

Under the GDPR we rely on the following grounds.

  • Contract — running your account and storing what you save is how we provide the service you signed up for.
  • Consent — optional features such as Trusted Release and Flow Guide learning are used only when you turn them on, and you can withdraw at any time in Settings.
  • Legitimate interests — keeping accounts secure, preventing abuse and fixing faults.
  • Legal obligation — the limited records we must keep by law.

There is no automated decision-making or profiling that produces legal or similarly significant effects for you.

Flow Guide and AI

Flow Guide is the assistive part of FlowingAway. In this version it works inside the app: it shows prompts and questions and points you to areas you have not filled in. No external AI provider is connected, and your content is not sent to one.

  • Flow Guide assists. It never writes, edits, deletes or shares anything for you.
  • Anything it suggests is a draft you can change, ignore or remove.
  • Your content is never used to train shared or public AI models.
  • You can turn Flow Guide learning off in Settings at any time.
  • If assistance is ever unavailable, the rest of the app keeps working.

If a model provider is added later, it will be named in the third-party list below and described here before the feature is switched on.

Who owns your content

You do. Your memories, stories, letters and documents remain yours. Everyday Flow does not claim ownership of anything you write or upload, and does not use it for any purpose other than running the service for you.

Data storage and security

Your data is stored using Supabase infrastructure: database, authentication and file storage.

  • Traffic between your device and our servers is encrypted in transit over HTTPS.
  • Access requires an authenticated session tied to your account.
  • Row Level Security is enabled on every table holding personal content, so a request can only read or change rows belonging to the signed-in account.
  • Server-side code follows least-privilege access. Elevated database access is used only for specific operations, such as deleting an account, and never for ordinary reads.
  • Documents are held in a private bucket and are not reachable by a public URL.

No system can promise perfect security, and we will not claim otherwise. If an incident ever affects your personal data, we will inform affected users and the relevant authority as required by law.

Where your data is stored

FlowingAway stores data in its configured Supabase region. That region is currently AWS eu-west-1 (Ireland), inside the European Union.

If a supporting service processes data outside the EU, it is used only where appropriate safeguards apply. This section is updated if the region changes.

Trusted Release

Trusted Release records what may one day reach the people you name. It is optional and stays off until you set it up.

  • You choose exactly which content is eligible. Everything else is out of scope.
  • Nothing is shared automatically in this version of the app.
  • Guardians cannot browse, search or preview your content. Not signing in for a while is never treated as evidence of death.
  • You can change or remove guardians and included content at any time.
  • Changes are written to an audit trail that records the action and the time, never your content or access keys.

Uploaded documents

Uploaded documents are private by default. They are stored in a private bucket under a path tied to your account, and only your authenticated account can open them. When you open a file, the app creates a short-lived link that expires soon after.

If future versions of the app add sharing options for documents, they will be off until you turn them on. Deleting a document removes both the record and the stored file.

Cookies and analytics

We use only what the app needs to work. Your session is kept in your browser’s local storage so you stay signed in, and a small number of preferences may be stored the same way.

There is no advertising, no tracking pixel, and no third-party analytics or marketing cookie in this version of FlowingAway.

Third-party services

This list is short on purpose. FlowingAway currently uses:

  • Supabase — database, authentication, file storage and server functions.
  • Authentication provider — we use our authentication provider to deliver essential account emails, such as account verification, password reset and account recovery messages. These emails are sent solely to give you access to your account and keep it secure. No separate marketing or campaign email service is used.

When you write to support, your message goes straight to our support inbox by email from your own email app. FlowingAway has no contact form in this version, so no message content passes through the app or through a separate email delivery service.

No AI provider is connected in this version. If one is added, it will be named here before the feature is released.

How long we keep information

Your content is kept for as long as your account exists, because that is the point of the app. Anything you delete is removed at the time you delete it. Technical logs are kept for a limited period for security and troubleshooting.

A small amount of information may be kept longer where the law requires it, for example records related to accounting or fraud prevention. We keep only what is required, and only for as long as required.

Backups

Encrypted backups exist so data can be restored after a failure. Backups are held on a rolling schedule and are used only for recovery.

This means deleted content can remain in a backup for a short period before that backup expires. We will not claim that deletion is instant everywhere. It is removed from the live service immediately and cycles out of backups on their normal schedule.

Your rights

Under the GDPR you have the rights below. We apply them to everyone using FlowingAway, wherever you are.

  • Access — ask what personal data we hold about you.
  • Correction — fix anything wrong, in the app or by asking us.
  • Deletion — remove individual entries, or your whole account.
  • Export — download a copy of everything you have written as a JSON file from Settings. Uploaded files are not in that file; you can download each one from the Documents page.
  • Restriction — ask us to pause processing while a question is settled.
  • Objection — object to processing based on legitimate interests, and withdraw consent for optional features at any time.
  • Complaint — contact your national data protection authority if you think we have handled something badly.

Most of this is available in Settings. For anything else, email us and we will respond within 30 days.

Deleting your account

You can delete your account at any time from Settings → Delete account. You will be asked to confirm, because it cannot be undone.

When you confirm, we permanently remove:

  • your memories, chapters, values, lessons, letters and messages;
  • your weekly answers and your uploaded documents, including the stored files;
  • your practical information, emergency notes, ceremony wishes and Digital Life list;
  • your people, support contacts and Trusted Release settings;
  • your profile and your sign-in credentials.

Deletion runs on the server and is not reversible. As described above, copies may remain in encrypted backups until those backups expire, and a limited number of records may be kept where the law requires it.

Children

FlowingAway is for adults. It is not intended for anyone under 16, and accounts should not be created for children. If we learn that an account belongs to someone under the minimum age, we will remove it.

What FlowingAway is not

FlowingAway is not a legal will service and does not provide legal, medical or crisis care. Nothing stored here is a legally binding document.

Changes to this policy

This policy will change as the app develops. Every version is numbered and dated, and the current version is always shown at the top of this page.

If something significant changes, we will tell you in the app before it takes effect, and we keep a record of the version you agreed to and when.

Contact

For any question or request about your data, email support@everydayflow.app. A person reads every message.

You can also use the contact page, before or after signing in.

Version

Privacy Policy version 2.4. Last updated 25 July 2026. Maintained by Everyday Flow.

Terms of Service