Legal
Privacy Policy
Last updated: July 13, 2026
FlowLearn is built to be calm, focused, and respectful of your data. This policy explains who we are, what we collect, why, how we store and share it, and the choices you have.
FlowLearn is operated by Jasper McEligott, an individual sole developer based in the United States (“FlowLearn”, “we”, “us”, or “our”). For data-protection purposes, Jasper McEligott is the data controller responsible for your personal information. This policy covers the FlowLearn iOS app and our website at flowearn.app.
Questions? Reach us any time at [email protected].
Information we collect
We collect only what we need to run FlowLearn:
- Profile. The username, first name, and avatar you choose to identify yourself.
- Setup answers. The responses you give when you set up FlowLearn, such as your age range, goals, interests, learning preferences, and optional answers about memory, focus, or brain fog, used to personalize your experience. Optional health-related setup answers remain in your private iCloud data and are never included in our product-insight records. Selected non-sensitive setup choices are also kept as product-insight responses, as described below.
- Learning activity. Your lessons, progress, streaks, XP, quiz results, and the topics you study, so we can save your progress and tailor what you see.
- Content you create. The topics, prompts, and any source material you give FlowLearn to build lessons, and your chat history with the app.
- Settings. Choices like your daily goal, reminders, sounds, and haptics.
- Subscription status and purchase identity. App Store product and transaction information, your current subscription status, and an opaque pseudonymous identifier used to keep paid access consistent. A random secret stored in your private iCloud is processed briefly by our server to derive that identifier; the secret is not shared with RevenueCat. We never receive your card or payment details.
- Optional feedback. If you choose to answer the optional question shown when you close the subscription screen (for example, “the price is too expensive”), we keep the answer you selected.
- Support messages. If you email us, we keep your message and contact details to help you.
We do not sell your data, we show no ads, and we do not track you across other companies’ apps or websites. We never collect the Apple advertising identifier (IDFA), and we do not collect your precise location, your photos, or your contact list.
No advertising tracking
FlowLearn does not include an advertising or install-attribution SDK, does not show ads, and does not track you across other companies’ apps or websites. We do not collect the Apple advertising identifier (IDFA) or send in-app activity to advertising partners.
Product insight responses
To understand how people set up and experience FlowLearn, selected non-sensitive setup choices (such as learning goals and preferences) and the optional subscription-screen feedback answer are stored with a pseudonymous identifier in our shared database (Apple CloudKit). These records never include your name, username, age range, gender answer, or optional health-related setup answers; they are visible only to the developer, are never used for advertising, and are deleted when you delete your account.
Voice input
If you choose to type by voice, FlowLearn uses your device microphone and Apple’s speech recognition to turn your speech into text. Depending on your device settings and language, Apple may process the audio on its servers to provide this service. We never receive or keep audio recordings; only the resulting text becomes part of your message.
Adding friends
If you add a friend from your contacts, you pick one contact with Apple’s system contact picker. FlowLearn receives only that contact’s name or email prefix, turns it into a temporary search term, and sends the term to Apple CloudKit to look for matching public FlowLearn profiles. We do not retain the contact search, access contacts you did not choose, or upload your address book. The FlowLearn follow relationships you choose are stored as your social graph so the friends feature works.
Information visible to other users
FlowLearn has social features. During setup, the app shows a public-profile disclosure before you choose Acknowledge & continue and create your community profile. The following is then visible to other FlowLearn users and can be found by username search:
- Your username and avatar.
- Your level, XP, streak, current league, and a country flag derived from your device’s region setting.
- The subjects you’re studying, shown on your public knowledge map.
Friends you connect with can see your profile and progress. When you choose to share a creation with the community, that lesson and its title, your creator name and avatar, and its view and adopt counts become publicly visible, and other people can adopt it. Creations stay private unless you explicitly choose to share them with the community; you can make a shared creation private again from the app. Your chats, your detailed activity, and any private creations are never made public. Deleting your account removes your public profile.
How we use your information
- Provide and sync the Service: run the app and sync your progress through your private iCloud.
- Build lessons and power chat: turn the topics, prompts, and source material you provide into lessons and responses.
- Personalize FlowLearn: tailor what you see to your goals, interests, and activity.
- Run leagues, streaks, and friends: keep your progress and social features accurate.
- Process subscriptions: confirm your subscription and unlock paid features.
- Measure and improve: review setup and feedback responses to make FlowLearn better.
- Keep FlowLearn secure: prevent abuse and protect the integrity of the Service.
- Respond to support requests.
AI features
When you generate a lesson or chat, the topic, prompt, or source material you provide is sent to our server-side processing service (a Cloudflare Worker), which uses Cloudflare Workers AI to produce your result, along with a pseudonymous account identifier. Requests are verified with Apple App Attest and are subject to rate limits and usage quotas. We don’t use your prompts, source material, or chats to train AI models; they’re processed only to generate your result.
How your data is stored
Your profile, settings, and progress are stored on your device and synced through your private iCloud account using Apple’s CloudKit. We don’t have access to your iCloud credentials, and we cannot read your private CloudKit data. Your public profile, community creations you explicitly share, social connections, and product insight responses are stored in a shared CloudKit database. Public profiles, shared creations, and the social relationships needed for the friends feature are visible to other FlowLearn users as described above; product insight responses are restricted to the developer. To keep subscription access consistent, FlowLearn stores a random subscription secret in your private CloudKit database so it can sync across devices signed in to the same iCloud account. A signed request sends the secret to our Cloudflare Worker, which derives an opaque pseudonymous subscription identifier; the secret is not stored in public CloudKit or sent to RevenueCat.
Focus Zone
If you use Focus Zone, your choice of apps or websites to limit is handled through Apple’s Screen Time and stored privately on your device and in your iCloud as opaque tokens. FlowLearn can’t see which specific apps or websites you select.
How we share information
We share personal information only as needed to run FlowLearn, and only with providers acting on our behalf:
- Apple. Hosts your private iCloud (CloudKit) data, processes App Store purchases, and provides App Attest and speech recognition.
- Cloudflare. Runs our server-side processing and the Workers AI that generates your lessons and chat responses.
- RevenueCat. Manages your subscription and powers the paywall. We share the derived opaque pseudonymous subscription identifier, App Store product and transaction information, and subscription status so RevenueCat can manage entitlements. The private iCloud secret used to derive the identifier is not shared with RevenueCat. We don’t share your name, setup answers, email, chats, or learning activity.
For ordinary pasted webpage sources, FlowLearn sends the public URL to our Cloudflare Worker. The Worker fetches the page, so the destination host sees ordinary metadata for Cloudflare’s outbound request rather than your device’s IP address. Extracted page text is processed transiently for that request and is not intentionally logged or cached by the source-fetching endpoint beyond the request. Lesson images from Wikimedia Commons are loaded directly from Wikimedia, and the app may request public YouTube caption feeds directly from YouTube when you import a video transcript. Those direct hosts may receive the requested URL, your IP address, and ordinary connection metadata under their own privacy practices. FlowLearn does not attach your profile, subscription identifier, prompts, or chat text to those direct requests. We may disclose information where we believe in good faith it’s necessary to comply with the law or protect the rights and safety of our users, the public, or FlowLearn. We do not sell your personal data, and we don’t use it to build advertising profiles.
Legal bases for processing
If you’re in the European Economic Area (EEA) or the United Kingdom, we rely on these bases under the GDPR and UK GDPR:
- Performance of a contract to provide the Service, sync your progress, generate lessons, and manage your subscription.
- Legitimate interests to keep FlowLearn stable and secure, prevent abuse and understand product usage, balanced against your rights.
- Consent where we ask for it, such as microphone access; you can withdraw it at any time.
- Legal obligation to comply with applicable law.
Data retention
We keep your information while your account is active and stored in your iCloud. You can request account deletion at any time from Settings → Delete account in the app. After deletion completes, the app removes your private FlowLearn data (including the private subscription secret), public profile and shared creations, social connections you created, and product insight responses. FlowLearn also removes the server binding for your subscription identity and asks RevenueCat to delete its pseudonymous customer record. To stop an old signed-in device or delayed provider event from recreating deleted data, FlowLearn keeps only narrow deletion-suppression records. Your private iCloud keeps a random account-generation identifier and deleted-state marker, which are replaced if you create a new FlowLearn account. A hash-addressed Cloudflare tombstone keeps the deletion time and opaque pseudonymous subscription identifier needed exclusively to repeat provider deletion, while credential-free completion receipts keep only deletion status and time. These records contain no name, profile, lesson, progress, prompt, chat, payment-card information, App Attest credential, or generated content, and the server records remain only to enforce the deletion. If an App Store checkout outcome is still pending or unresolved, this device may retain only the opaque customer identifier and checkout state needed to prevent a duplicate charge; this marker is not synced and contains no payment details. Deleting your FlowLearn account does not cancel, refund, or revoke an App Store subscription. To stop future renewals, you must cancel separately through your Apple ID or App Store subscription settings. Apple may retain App Store transaction and subscription records under its own policies and legal obligations.
Server-side operational data uses limited retention: daily quota counters expire after the current day plus about one hour, and weekly quota counters expire after the current UTC week plus about one hour (at most about eight days). Request de-duplication records and cached generated-lesson results expire within 24 hours. Device-integrity registrations (Apple App Attest) expire after about 180 days of inactivity and are removed when account deletion completes. Temporary migration-era deletion receipts expire within seven days; final credential-free deletion receipts and the hash-addressed subscription-deletion suppression tombstone do not expire, because they prevent a deleted account or provider record from being recreated. Those permanent records retain only deletion status and time, plus the opaque pseudonymous subscription identifier in the suppression tombstone; they contain no App Attest credential, profile, learning data, payment details, or generated content. Identity-linked community view and adoption markers expire within 24 hours, and like-membership markers expire within about 180 days. Anonymous item-level view, adoption, and like totals may be retained as service statistics and are not linked to an account. Cloudflare may retain operational request and error logs, including standard request metadata and a pseudonymous integrity identifier, for up to seven days; we do not intentionally log prompts, source material, or chat text. When account deletion completes, we ask RevenueCat to delete its pseudonymous customer record and periodically repeat that deletion against the retained opaque identifier so delayed provider events cannot recreate it; RevenueCat may retain limited records where required for fraud prevention or legal compliance. Apple may retain App Store transaction and subscription records under its policies and legal obligations. We may retain safety reports and records needed to investigate abuse.
Security
We use reasonable technical measures to protect your information, including App Attest verification, encrypted transport, rate limiting, and keeping server secrets off the device. No method of transmission or storage is completely secure, and we can’t guarantee absolute security.
International data transfers
FlowLearn is operated from the United States, and your information may be processed there and in other countries where our providers operate. If you’re in the EEA or the UK, we take steps to ensure appropriate safeguards for such transfers.
Your privacy rights
EEA / UK (GDPR). You have the right to access, rectify, erase, restrict, or port your information, to object to processing based on legitimate interests, to withdraw consent, and to complain to your local data protection supervisory authority.
California (CCPA / CPRA). You have the right to know what we collect and how we use it, to delete and correct your information, to opt out of the sale or sharing of personal information (note: we do not sell personal information, and we do not share it for cross-context behavioral advertising), and to non-discrimination for exercising your rights.
To exercise any of these, email [email protected] or use the in-app controls: delete your account and cloud data from Settings → Delete account, and edit your profile and settings at any time.
Children’s privacy
FlowLearn is for general audiences and isn’t directed to children under 13. We don’t knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us at [email protected] and we’ll remove it. You must be 13 or older to use FlowLearn; if you are under the age of digital consent where you live, you may use FlowLearn only with the involvement of a parent or guardian.
Our website
Our website at flowearn.app sets no cookies, runs no analytics scripts, and stores nothing in your browser. App Store links open Apple’s website, and email links open your own email app; if you email us, we keep the message as support correspondence. The IQ test on the site runs entirely in your browser; its answers are not sent to us.
Changes to this policy
We may update this policy from time to time. When we do, we’ll revise the “Last updated” date above and, for significant changes, note it in the app or on our website.
Contact
Privacy questions? Email [email protected].