FlowKeep — Privacy Policy

Effective Date: February 12, 2026 · Last Updated: June 20, 2026
Developer: Legend Made (com.legend-made.FlowKeep)

FlowKeep does not sell your personal data, show ads, or run third-party analytics or tracking SDKs, and there are no user accounts to create. Your project data stays on your device and, if you choose, in your own iCloud account.

The one exception is the optional Accountability Buddy feature: if — and only if — you choose to invite a partner, a small amount of invite data (a random code, the display name you enter, and an anonymous device identifier) is stored on a lightweight backend we operate so the invite can be delivered. This is described in detail in Section 7. If you never use the buddy feature, none of this data is created or transmitted.

1. Information We Collect

We do not collect any personal information.

FlowKeep does not ask for your name, email address, phone number, location, or any other personally identifiable information. There is no account creation or login process.

2. Data Stored on Your Device

FlowKeep stores the following data locally on your device to provide app functionality:

DataPurpose
Project titles, descriptions, icons, and colorsDisplaying and organizing your projects
Project notes and linksContext preservation — so you can pick up where you left off
Touch events (timestamps)Calculating freshness, streaks, and queue priority
User preferences (capacity, ratios, thresholds)Personalizing your experience
Notification settings and scheduleDelivering reminders you’ve opted into
Project templatesStoring built-in and user-created templates
Project dependenciesTracking prerequisites between projects

All of this data is stored in a local database on your device using Apple’s Core Data framework within the app’s sandboxed container.

3. iCloud Sync

If you are signed into iCloud on your device, FlowKeep can automatically sync your data across your Apple devices (iPhone and iPad) using Apple’s CloudKit service.

For details on how Apple handles iCloud data, see Apple’s iCloud Privacy Overview.

4. Notifications

FlowKeep may request permission to send you local notifications. These are used to:

Notifications are optional. You can enable or disable them at any time in the app’s settings or in iOS Settings. No notification data is sent to any external service.

5. Widgets & Siri Shortcuts

FlowKeep provides Home Screen widgets, Lock Screen widgets, and Siri Shortcuts integration. These features:

6. Template Sharing

FlowKeep allows you to share project templates via QR codes or links. When you share a template:

7. Accountability Buddy (Optional)

FlowKeep includes an optional Accountability Buddy feature that lets you connect with one partner so they can see your project titles and nudge you when a project goes stale. It is off until you choose to invite someone.

What is shared, and how

Invite delivery (our backend). When you create an invite, FlowKeep stores a small invite record on a lightweight backend we operate (hosted on Supabase). That record contains:

Invite records automatically expire after 14 days. This backend exists solely to deliver invites — it is never used for analytics, advertising, or profiling, and the data is never sold.

The connection and ongoing sync (Apple CloudKit). Once a buddy accepts, the actual sharing — your project titles, freshness status, and nudges — runs through Apple’s CloudKit/iCloud, not through our backend.

What stays private. Only project titles and freshness status are visible to a connected buddy. Notes, links, descriptions, time estimates, dependencies, and all other details remain private to you.

If you never use the buddy feature, no invite record is created and nothing is transmitted to our backend.

8. AI Features (Disabled)

FlowKeep contains code for optional AI-powered features (project advice via third-party AI providers). These features are currently disabled and no API calls are made to any AI service.

9. Analytics & Tracking

FlowKeep does not use any third-party analytics or tracking services.

FlowKeep maintains a minimal, privacy-safe local event log (last 100 events) stored entirely on your device for internal diagnostics. This log contains no personally identifiable information, is never transmitted anywhere, and is automatically pruned to the most recent 100 entries.

10. Third-Party SDKs & Services

FlowKeep bundles zero third-party SDKs. No external code from any third party runs inside the app. It is built entirely with native Apple frameworks: SwiftUI, Core Data, CloudKit, WidgetKit, UserNotifications, App Intents, Foundation, OSLog.

One third-party service is used, and only for the optional buddy-invite feature in Section 7: Supabase, which hosts the backend that stores and delivers invite records. No Supabase code or SDK is embedded in the app — FlowKeep simply makes network requests to that backend when you create or accept a buddy invite. No project content, notes, or links are sent to it. See Supabase’s privacy practices at supabase.com/privacy.

11. Data Retention & Deletion

12. Children’s Privacy

FlowKeep does not knowingly collect any information from children under the age of 13. Since the app collects no personal information from any user, it is compliant with COPPA (Children’s Online Privacy Protection Act).

13. Privacy Nutrition Label (App Store)

Based on the current implementation, FlowKeep’s App Store privacy label states:

14. Apple Privacy Manifest

FlowKeep includes a PrivacyInfo.xcprivacy file declaring the following Apple-required API usages, all for app functionality only:

APIReason
UserDefaults (CA92.1)Storing app preferences
File Timestamp (C617.1)App functionality
System Boot Time (35F9.1)App functionality
Disk Space (E174.1)App functionality

NSPrivacyTracking is set to false.

15. Changes to This Policy

If we make changes to this privacy policy — particularly when the Accountability Buddy or AI features become fully implemented — we will update this document and the effective date at the top.


16. Contact

If you have questions about this privacy policy or FlowKeep’s data practices, contact us at:

info@legend-made.com