Effective October 2, 2026
Privacy policy
Flow is a personal wellness app in private beta. This page says what it reads, why, where it's kept, and how to remove it.
What Flow reads from Google
When you connect your wearable through the Google Health API, Flow asks for read-only access to:
- Sleep — how long, the sleep stages, and when you fell asleep and woke.
- Activity and fitness — daily steps, and the workouts your device logged (type, start time and length).
- Health metrics and measurements — weight and height you've logged.
Flow never writes to your Google account and never asks for anything else in it.
What Flow reads from Oura
If you connect an Oura Ring instead, Flow asks Oura for read-only access to your daily summaries and sleep sessions: sleep timing and stages, sleep and readiness scores, heart rate variability, resting heart rate, breathing rate, temperature deviation, blood oxygen and daily steps. Flow never writes to your Oura account.
What you tell Flow
Answers you give in the app (for example, your kind of work or what time you wake), quick daily check-ins (energy, focus, mood, where you are), food totals you choose to log, and which suggestions you mark as done.
How it's used
Only to show you your own trends, explain why you might be tired, and suggest what to do today. Flow does not sell your data, shows no ads, and uses no third-party analytics or tracking. It is shared with no one, except as described under Ask Flow below.
Ask Flow
If you ask Flow a question in the Ask tab, your question and a written summary of your Flow data (your recent nights, the patterns Flow has found, today's plan and your check-ins) are sent to Anthropic's API, where the Claude model writes the answer you see. This happens only when you ask, only to answer you, and the app says so on that screen. Under Anthropic's commercial terms, data sent through its API is not used to train its models. Your questions and Flow's answers are saved with the rest of your Flow data.
Flow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is not used for advertising and is not used to train AI models.
Where it's kept
On the app's server (hosted on Render) and in a private, access-controlled storage repository (on GitHub) that only the developer can read, in a folder of your own that no other account can reach. The app itself is locked behind your name and PIN. Your Google or Oura sign-in is stored only encrypted, with a key that never leaves the server.
Removing it
- Stop Flow reading from Google at any time: myaccount.google.com/connections → Flow → remove access.
- Stop Flow reading from Oura at any time: in your Oura account's connected apps, remove Flow.
- To have everything Flow stored about you deleted, contact the developer at the support email shown on Flow's Google sign-in screen. It's deleted within 30 days.
Changes
If this policy changes, the date at the top changes with it.