Information we collect
We collect information you provide, including your name, email address, profile and workplace information, workspace membership, tasks, projects, messages, comments, files, time records, invoices, leave records, and notification preferences. We also process authentication, device, browser, IP address, diagnostic, security, and usage information needed to operate and protect Flowva.
Desktop tracking: while a desktop timer is actively running and not paused, Flowva processes idle status, the foreground application name, its window title (which may contain a website or document title), and screenshots of connected displays. These records are associated with the user, workspace, project or task, and time entry and may be visible to authorized workspace users.
The current desktop application schedules two screenshots at randomized times in each 10-minute tracking window. It automatically pauses after two minutes without system activity and resumes when activity returns. Flowva records window context; it does not claim to collect a user’s complete browser history.
Google Calendar information
Connecting Google Calendar is optional. Flowva uses the access you grant only to create, update, and delete Flowva task reminders in your calendar and to identify the connected account and calendar timezone.
When connected, we process your Google account email address, calendar timezone, OAuth authorization credentials, and identifiers for events created by Flowva. We do not use Google Calendar information for advertising, sell it, or allow humans to read it except when necessary for security, support requested by you, legal compliance, or service operation.
Flowva’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
How we use information
- Provide, synchronize, maintain, and improve Flowva.
- Authenticate users and administer workspaces and permissions.
- Send task, due-date, account, security, email, in-app, browser, and calendar notifications.
- Provide support, diagnose errors, prevent fraud, and comply with law.
How we share information
Workspace content is shared with workspace users according to roles and assignments. Service providers help operate Flowva, including Supabase for backend and authentication, Vercel for web delivery, Google for connected Calendar functionality, and SendGrid for email delivery. They process information on our behalf under applicable safeguards. We may disclose information where required by law or during a corporate transaction. We do not sell personal information.
Storage, security, and retention
We use reasonable administrative, technical, and organizational safeguards. No system is completely secure. We retain information while an account or workspace is active and as needed to operate Flowva, meet legal obligations, resolve disputes, and maintain security. The product currently presents screenshots within a 30-day viewing window; other activity and time records follow applicable workspace and operational retention requirements.
Your choices and rights
You may update profile information and disconnect Google Calendar in Settings. Disconnecting revokes Flowva’s Google authorization and removes stored connection credentials and Flowva event mappings. You may also revoke access through Google Account connections. You may request access, correction, export, or deletion, subject to applicable law and legitimate retention requirements.
Children and international processing
Flowva is not directed to children under 13, or the higher minimum age required locally. Information may be processed outside your country; where required, we use appropriate transfer safeguards.
Changes and contact
We may update this policy and will post the revised effective date here. For privacy questions or requests, email info@exprova.tech.