FlowPrismSign in

Privacy Policy

Last updated: August 13, 2026

Who we are

FlowPrism (“we”, “us”) is a record-keeping tool for independent instructors. Contact: support@getflowprism.com.

Scope of data collection

We collect and store only what the product needs to work:

Your session and earnings records are self-reported by you and private to your account. We do not verify or monitor them, we never sell them, and we never voluntarily report them to any tax or other government authority. We share data only with the service providers listed below, and we disclose account data beyond that only when required by valid legal process. We access an individual account's records only to provide support you request, to investigate abuse, or as required by law.

Signing in

You can sign in with an emailed link, with Google, or (in the iOS app) with Apple. We receive your email address from whichever method you use, and it becomes your account email. We never receive your Google or Apple password.

If you sign in with Apple and choose Hide My Email, Apple gives us a private relay address instead of your real one. That relay address is then your account email: it is where our emails go and how your account is identified. An account created that way is a separate account from one you already have under your real email address.

Cookies

We use cookies to keep you signed in (authentication session) and to remember functional device settings, such as your time zone, so dates and monthly totals display on your local calendar day. Where product analytics is enabled, our analytics provider may also set first-party cookies to measure feature usage tied to your account. We do not run advertising cookies or ad trackers, we do not sell cookie data, and we do not use third-party advertising networks.

Prohibited data

FlowPrism is not designed to store medical or health information. Student note fields are for teaching preferences and session context (e.g. “prefers mornings, working on balance”) — do not enter medical diagnoses, health conditions, or other protected health information. You are responsible for the content you store.

No HIPAA business associate relationship

FlowPrism is not a healthcare provider tool, does not create a Business Associate relationship under HIPAA, and must not be used to store data that would require one.

Google Calendar data

If you connect Google Calendar, FlowPrism requests read-only access to your calendar list and events, used solely to let you review calendar events and convert the ones you choose into session records inside your account. We never write to, modify, or delete anything in your calendar, and we never sell calendar data or use it for advertising. We store the events you sync and an encrypted token that lets us read your calendar until you disconnect; disconnecting (Import page) or deleting your account revokes our access and deletes the token.

FlowPrism's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Where a synced event title can't be read by our rule-based parser, it may be processed by the AI fallback described below strictly to provide this user-facing feature — never to train AI models.

Apple Calendar data

If you connect Apple Calendar (iCloud), you provide your Apple ID email and an app-specific password you generate at account.apple.com — never your Apple ID password. We store that app-specific password encrypted (AES-256-GCM, key held only on our servers) and use it solely to readyour calendar list and events over Apple's CalDAV interface, so you can review events and convert the ones you choose into session records. We only ever issue read requests: we never write to, modify, or delete anything in your calendar, and we never sell calendar data or use it for advertising. Disconnecting (Import page) or deleting your account deletes the stored credential immediately; you can also revoke the app-specific password itself at account.apple.com at any time, which instantly cuts off our access. Synced event titles the rule-based parser can't read may be processed by the AI fallback described below, strictly to provide this user-facing feature.

Alternatively, you can connect an Apple calendar by pasting its public calendar link(the Calendar app's "Public Calendar" share link). In that case we store only the link itself — no Apple credentials of any kind — and use it solely to readthat one calendar's events for import. Be aware that Apple's public links are readable by anyone who has the link; that is how Apple designed the feature, so we recommend it only for a dedicated teaching calendar. Disconnecting (Import page) or deleting your account deletes the stored link immediately; turning off Public Calendar in the Calendar app also cuts off our access (and everyone else's) instantly. Event titles from this source flow through the same rule-based parser and AI fallback described below.

Device calendar data (iOS app)

The FlowPrism iOS app can, with your explicit permission via the iOS calendar-access prompt, readthe calendars on your device (including iCloud, Google, and other accounts synced to your phone) to find teaching sessions. Events from the calendars you select — title, notes, location, and start/end times, up to 24 months back and 6 months ahead — are sent to our servers and stored in the same import review queue as every other calendar source, solely so you can review events and convert the ones you choose into session records. The app only ever reads: it never writes to, modifies, or deletes anything in your calendars, and we never sell calendar data or use it for advertising. You can revoke access at any time in iOS Settings → Privacy & Security → Calendars; deleting your account deletes the imported events. Event titles from this source flow through the same rule-based parser and AI fallback described below.

Bug reports and suggestions

When you send us a note from Report a bug (on the website or in the app), we store what you wrote, your account's email address, and technical details about where it came from: whether you were on the website or the iOS app, the app version and platform, and — on the website — the page you came from. We attach those details automatically so you don't have to describe them; they are about your device and the product, not about your students.

We use these notes only to answer you and to fix and improve FlowPrism. A copy is emailed to the operator (via Resend, listed below) so it can be read and replied to. Whatever you type is the part we cannot control — please don't paste student names, health details, or other sensitive information into it. Your notes are deleted along with the rest of your data if you delete your account.

AI processing

When our rule-based parser can't read a calendar event, its title/description may be sent to Anthropic's Claude API to extract the session details. This data is processed under Anthropic's commercial terms and is not used to train their models.

Service providers

We use Supabase (database and authentication), Vercel (hosting), Stripe (payments — we never see your card number), Anthropic (AI parsing fallback), Resend (transactional email delivery), and analytics/error tools (PostHog, Sentry). Each receives only what it needs to perform its function. Data is hosted in the United States; by using FlowPrism from elsewhere you consent to processing in the US.

Security

All data is encrypted in transit (TLS) and at rest, isolated per account with row-level security, and payments are handled entirely by Stripe. No system is perfectly secure; if a breach affects your personal information, we will notify you as required by applicable law.

Data retention

We keep your data while your account exists. When you delete your account (Settings → Delete account), all of it is deleted immediately and irreversibly from the production database. Limited residual copies may persist briefly in server logs and any encrypted database backups, which expire on a rolling basis. Product-analytics records held by our analytics provider are keyed to an account identifier rather than to your email or name, and expire on that provider's own schedule; write to us at support@getflowprism.com if you want those erased too.

Children

FlowPrism is for adults (18+) and is not directed at children. Do not create an account for anyone under 18. Student roster entries are names you choose to record about your own clients; do not store more about minors than you need to run your teaching business.

Your rights — export and deletion

You can export your records to Excel at any time, and you can permanently delete your account and all associated data from Settings. You may also email us to exercise any privacy right, including access, correction, and deletion. California residents: we do not sell or share personal information as defined by the CCPA/CPRA, and we honor access/deletion requests without discrimination.

Not tax or legal advice

FlowPrism is a record-keeping tool, not a tax advisor or tax-filing software. Reports and exports are generated from data you entered, for your own use. You choose what appears in every export.

Changes

We'll update this page when the policy changes and note the date above. Material changes will be announced in the app or by email.