Flow Privacy Policy
Effective date: August 9, 2026 | Last updated: August 16, 20261. Scope
This policy explains how Flow handles data when you use sign-in, ledgers, SMS automation, statement import, AI parsing, iCloud sync and sharing, Pro purchases, and exchange rates. The website feedback board is governed separately by the Frank's Apps Website Privacy Policy.
2. Information Flow Processes
2.1 Ledger and financial data
- This may include ledger names, accounts, financial institutions, account types and necessary suffixes, balances, transaction amounts, currencies, merchants, categories, dates, notes, refunds, repayments, transfers, parsing memories, and imported results.
- Data is stored in a local database inside the App Group container and synchronized through your Apple iCloud / CloudKit private or shared databases.
- The developer backend has no ledger sync, search, or browsing endpoint. The AI administration page can only manage model configuration and display connectivity status.
2.2 Sign in with Apple, iCloud, and device identifiers
- Using Flow requires authentication through Sign in with Apple and an available iCloud / CloudKit account to establish the data space.
- The App and isolated AI relay process the stable user identifier supplied by Apple. They do not receive your Apple Account password. A name or email is processed only if Apple supplies it under its rules and the feature needs it.
- The App creates an installation-scoped device identifier to bind a Flow session to the current installation, limit abuse, and diagnose failures. The relay database stores authentication, quota, and session records as needed; refresh tokens are stored only as irreversible SHA-256 hashes.
2.3 SMS and Shortcuts
- Flow does not scan your complete message inbox. It processes only the message text, sender (if available), and receipt time that you explicitly pass to Flow through a Shortcuts automation or the “Paste SMS” feature.
- The raw message is first stored in the creator's private local / CloudKit store before parsing or pending review. A failed or quota-limited request is not automatically retried on the next day.
- You can delete one or all raw message originals without automatically deleting structured transactions, pending review results, accounts, or categories already created from them.
2.4 Statement import
- A PDF, image, or text file you select is read and converted to text on the device. The original file or image is not sent to the Flow AI relay and is not saved in your ledger.
- The extracted statement text is sent to AI to determine whether it is a bill or statement and to parse transactions. Pro cleaning asks only questions related to cleaning bill data and does not perform unrelated tasks.
- An import can rebuild categories based on its results. Verify amounts, currencies, accounts, dates, and categories before saving.
2.5 AI parsing content
- A parse may contain the complete SMS or extracted statement text, sender, time and time zone, necessary current accounts and categories, and memories relevant to that parse.
- The isolated Flow relay validates the data contract and removes permanent request, ledger, account, category, and memory identifiers before forwarding. It replaces them with references valid only for that request.
- The selected model provider still receives the complete parsing content and handles it under its own terms, privacy policy, and retention rules. Flow cannot promise that a provider will not retain the content or use it for other purposes permitted by that provider's terms.
- AI output can be inaccurate. Verify amounts, accounts, direction, refunds, repayments, and transfers before confirming or saving.
2.6 Custom AI APIs
- Pro users can configure a compatible third-party AI API. The API key is kept in the iOS Keychain shared by the App and Intent and is not sent to the Flow backend.
- When a custom API is enabled, the device sends parsing requests directly to the provider you configured. That provider directly processes the complete text and necessary context; its security, retention, and permitted uses are governed by your agreement with it.
2.7 Pro and purchase verification
- Apple StoreKit and the App Store process purchases and subscriptions. Flow does not receive your card number, payment-account password, or complete payment credentials.
- To verify Pro access, prevent cross-account reuse, and handle refunds, revocations, grace periods, and Family Sharing, the App sends Apple-signed transaction information to the isolated relay for verification and retains necessary verification facts and account-binding records.
2.8 Exchange rates
- The Flow server retrieves a European Central Bank public exchange-rate snapshot for common currencies once a week, and the App downloads the cached snapshot when needed. This does not require uploading your ledger, amounts, or transaction details.
3. What the AI Relay Stores
- No raw-text persistence: The relay does not write SMS or statement text to its application database and does not log request bodies, model response bodies, or API keys.
- Short-lived result cache: For consistent duplicate handling, the relay stores a SHA-256 hash of the request body and the validated structured result. The App requests immediate deletion after successful receipt. Unacknowledged records are retained for no more than 24 hours by default and are removed by a scheduled cleanup.
- Authentication and entitlement: Apple user identifiers, installation device identifiers, authentication-session hashes, daily quota, Pro entitlements, and App Store verification records are retained as needed to provide the service, prevent abuse, handle refunds, and meet security obligations.
- Operational metadata: Logs may record request IDs, hashed user identifiers, status, model, latency, and error codes for security, rate limiting, and troubleshooting.
- The AI administration system cannot browse user ledgers or AI results. Strictly authorized server administrators may technically encounter transient plaintext in process memory or the private database while operating and securing the service. This is therefore a data-minimization design, not end-to-end encryption extending through the model provider.
4. iCloud Sync and Sharing
- What a participant can see depends on the CloudKit invitation and ledger role. Sensitive information that you enter in a shared transaction, note, or ledger field is also visible to participants who can access that ledger.
- The ledger owner can manage participants through Apple's sharing interface. Stopping a share or deleting records propagates according to CloudKit sync behavior.
- CloudKit is provided by Apple and is subject to the Apple Account, iCloud service status, and Apple Privacy Policy.
5. Permissions and System Capabilities
- Network: Used for Apple sign-in, CloudKit, AI parsing, Pro verification, and exchange-rate updates.
- App Group and Keychain: Allow the main App and SMS Intent to securely share the required database, preferences, session, and custom API key.
- Shortcuts / App Intents: Receive message content that you explicitly pass through an automation.
- File selection: Read a statement file you select and extract its text on-device.
Flow does not include ad SDKs, track you across apps, sell personal information, or require access to contacts, continuous location, or your complete SMS inbox.
6. Data Sharing and Third-Party Services
Flow allows the following categories of recipients to process data only as needed to provide a feature you request, protect the service, or comply with law:
- Apple, for sign-in, iCloud / CloudKit, StoreKit, App Store transaction verification, and system sharing;
- The AI model provider currently selected by the Flow backend, or the AI API provider you configure, to parse messages and statements;
- Network, hosting, and security infrastructure providers, to transmit requests, maintain availability, and prevent abuse;
- Law enforcement or other parties, only when required by law, necessary to protect rights, or needed to address a security incident.
Flow does not sell, rent, or share your ledgers, messages, or statements for advertising purposes.
7. Your Controls and Deletion Options
- Withdraw hosted-AI consent under “Me → Data → AI & Privacy.” After withdrawal, new messages and statements remain pending on-device and are not sent to the Flow AI relay.
- On the same page, clear the current account's unexpired server-side structured result cache.
- Delete one or all raw SMS originals while retaining structured transactions and pending review data already created.
- View, edit, or—after confirmation—delete transactions, accounts, categories, ledgers, and parsing memories in the App. Manage or stop sharing through Apple's sharing interface.
- Disable and clear custom API configuration and its Keychain secret. Manage sign-in authorization, iCloud data, and subscriptions through your Apple Account.
- Uninstalling the App normally removes its local container but does not automatically delete data already synchronized to iCloud, shared with other participants, or retained by the relay for authentication, quota, and purchase verification.
- To request access to or deletion of account, authentication, quota, or entitlement records in the isolated Flow relay, contact the address below. We may verify your identity to protect the account. Data retained by Apple, iCloud, or a model provider must be handled through that service's own process.
8. Retention
- On-device, private CloudKit, and shared CloudKit data remains until you or an authorized ledger participant deletes it, or Apple processes it under its service rules.
- Structured results in the Flow AI relay are deleted after successful receipt as described in Section 3; unacknowledged records are retained for no more than 24 hours by default.
- Authentication, quota, entitlement, transaction-binding, and security records are retained only as long as needed to provide the service, resolve disputes and refunds, prevent abuse, or meet security or legal requirements, then deleted or de-identified.
- Parse feedback you voluntarily submit is stored encrypted in the isolated Flow relay for at most 90 days, used only to improve parsing accuracy, and deleted automatically on expiry.
- Model-provider retention is outside Flow's control and is governed by that provider's policy.
9. Security
Flow uses protections including iOS file protection, Keychain, App Group access controls, CloudKit private/shared stores, encrypted-field options for sensitive CloudKit attributes, HTTPS, device-bound sessions, minimized upstream identifiers, and short-lived result caching. No network transmission, cloud service, or storage method can guarantee absolute security.
10. Children
Flow is not designed specifically for children under 14. Minors should use it with a guardian's knowledge and consent and should avoid submitting unnecessary sensitive personal information to AI services.
11. Policy Changes
If features, categories of AI providers, or data handling change, we will update this page and the “Last updated” date. Material changes will receive an additional notice in an appropriate place in the App or on the website.
12. Contact
For questions about this policy or a data request, contact: infox.feedback@gmail.com