Privacy
Privacy policy
Flownapse is designed as a local-first application. Your vault files are stored on your device or in a location you choose. Free local use does not create a product account or initialize Flownapse's account and subscription services.
Who is responsible
Flownapse is developed and published by Anand Sharma. Questions about this policy or Flownapse's data handling can be sent to the contact address below.
Information Flownapse handles
Flownapse handles the notes, tasks, mindmaps, saved Clip URLs and webpage snapshots, attachments, and settings you create. This content is stored locally unless you explicitly place a vault in, or connect it to, a cloud provider.
Optional Pro account and subscriptions
You can use Free without a product account. If you open the Pro upgrade flow, RevenueCat may create a temporary anonymous subscription identifier so Flownapse can display available purchases, complete a purchase, or restore an existing purchase. Opening or canceling this flow does not itself create a Flownapse product account.
If you buy Pro and choose to link it across devices, Supabase provides authentication and stores a minimal product-account record. This may include a stable opaque account identifier, your verified email address or Apple private-relay address, authentication identities and session information, the policy version you accepted, and account timestamps.
RevenueCat processes the opaque account identifier, app and device information needed to operate subscriptions, and purchase and subscription history. Flownapse uses that information to show localized offers, verify whether Pro is active, restore access, and understand subscription performance. RevenueCat does not receive your card details; the storefront or payment provider handles payment.
The product-account system does not receive your vault content, notes, tasks, mindmaps, Clips, attachments, connected-provider tokens, or provider passwords. Pro status is determined by RevenueCat and is not copied into your vault.
Connected cloud providers
If you connect Google Drive, Dropbox, iCloud Drive, or Private Git, Flownapse accesses the provider only to authenticate you and perform the vault operations you request, including creating, reading, updating, synchronizing, and sharing vault files where supported.
Activating a connection sends the vault content you selected, including notes, tasks, documents, images, or saved voice-note audio, and provider account information such as an email address or account identifier off your device to that provider. The information is linked to your provider account and is used only for authentication, synchronization, sharing, and other app functionality you request.
Automatic Google Drive discovery requires a Google permission that can technically cover all files the connected Google account can access. The installed Flownapse app on your device uses that permission to search folder metadata for Flownapse vault markers and to synchronize only the Flownapse vaults you add. Flownapse also offers a per-folder alternative that asks you to choose one folder through Google.
Flownapse may also store provider account identifiers, display names, email addresses, vault identifiers, and synchronization state on your device so it can label accounts and continue synchronization. The Flownapse publisher does not receive a copy through a Flownapse-operated sync server. The provider stores and handles its copy under its own retention rules, terms, and privacy practices.
The current app sends Google credentials and Drive requests directly between your device and Google. It does not send them through a Flownapse-operated server, so connecting Google Drive does not give the Flownapse publisher remote access to your Drive files.
Authentication credentials
Provider access and refresh tokens are stored using the secure credential facilities supplied by your operating system. Flownapse does not ask for your provider password. Public application identifiers and the Google desktop credential required for installed-app OAuth may be included in the app, but they are not user credentials and do not grant access to your account.
Security
Flownapse uses encrypted HTTPS connections for supported provider APIs and relies on operating-system protections for credentials and app storage. Vault files remain readable files in the location you choose, so use device encryption, a strong device passcode, and provider account protections appropriate for the sensitivity of your content. No storage or transmission method can guarantee absolute security.
Microphone and speech recognition
Flownapse requests microphone and speech-recognition access only when you use voice capture. Audio and transcribed text are used to create the voice note you requested and are stored in your chosen vault, which may synchronize if you connected that vault to a provider. Operating-system speech services may process audio according to the applicable platform privacy terms.
Optional Agent Host
Separately distributed macOS editions may let you explicitly enable Flownapse Agent Host for background automation and local command execution. It is disabled by default and is not included in the Mac App Store edition. When enabled, the commands and third-party agent tools you configure may process vault content under their own terms and settings.
Analytics and advertising
Flownapse does not use advertising or behavioral product analytics. RevenueCat provides subscription analytics based on purchase and subscription events. Supabase, storefronts, connected providers, and operating-system services may create operational, fraud, security, or billing records needed to provide their services.
Public website
This website does not set publisher analytics or advertising cookies. Its hosting and network providers may process technical request information such as an IP address, browser details, and timestamps as needed to deliver and protect the site under their own terms and retention practices.
Retention and deletion
You control retention of your vault files. Delete local content through Flownapse or your file system, and delete cloud copies through the connected provider. Disconnecting an account removes its stored Flownapse credentials but may not delete files already stored by that provider.
You can request deletion of a linked product account in Flownapse or by following the instructions on the support page. After verification, product-account deletion removes the associated Supabase account and submits deletion of the RevenueCat customer record, which RevenueCat may process asynchronously. It does not delete vault files stored on your devices or with a connected provider, and it does not cancel a storefront subscription. Cancel the subscription separately in the storefront that billed you. If that subscription remains active, verifying or restoring it afterward may create a new anonymous RevenueCat customer record until you link another product account.
Children
Flownapse is not directed to children under 13 and is not designed to knowingly collect personal information from children.
Contact
For privacy questions or requests, email anand14sk@gmail.com.