Privacy Policy
Effective date: August 16, 2026
PersonalFLOW is a privacy-first desktop application. Your contact data is stored locally on your device and is never transmitted to our servers or any third party.
1. About PersonalFLOW
PersonalFLOW is a desktop contact management application (Electron) licensed under the European Union Public Licence (EUPL). It is designed so that your personal and professional relationship data remains entirely under your control.
2. Data That Stays on Your Device
The following data is created and stored exclusively on your local machine:
- Contact records and relationship metadata
- Notes, tags, and interaction history
- Knowledge graph data and connections
- Application preferences and settings
This data is never sent to PersonalFLOW servers, cloud services, or third parties. We have no ability to access, read, or recover your local data.
3. Data We May Collect
If you interact with our website (e.g., joining the waitlist), we may collect:
- Email address — to send you product updates and early access information
- Basic analytics — anonymous page views via Vercel Analytics (no cookies, no personal identifiers)
4. How We Use Website Data
- Waitlist emails are stored in a private Google Sheet and used solely to contact you about PersonalFLOW
- We send emails via Resend. You can unsubscribe at any time
- We do not sell, share, or rent your email address to third parties
5. No Telemetry in the Application
The PersonalFLOW desktop application does not include telemetry, analytics, crash reporting, or any form of data collection. It makes no network requests unless you explicitly configure an integration.
6. Google API Data Protection
PersonalFLOW integrates with Google services (Gmail and Google Calendar) to enrich your contact relationships. If you authorize these integrations, the following protections apply:
- Limited Scope: We request only the minimum permissions necessary:
gmail.metadata— email metadata only (sender, subject, date; not message body)calendar.events.readonly— read-only calendar event access
- Local Storage Only: All Google API data is downloaded, processed, and stored exclusively on your device. No data is sent to PersonalFLOW servers
- No Retention on Google Servers: We do not cache, backup, or retain any Google data beyond what you explicitly choose to store in PersonalFLOW
- Encryption at Rest: Data stored locally is protected by your device's built-in storage encryption (FileVault on macOS, BitLocker on Windows)
- Access Controls: You can revoke access at any time via your Google Account settings. Revoking access immediately stops all new data retrieval
- No Third-Party Sharing: Google API data is never shared with third parties. It remains under your exclusive control
7. Third-Party Services
The application itself uses no third-party services. The website uses:
- Vercel — hosting and anonymous analytics
- Google Sheets API — waitlist storage
- Resend — transactional email delivery
8. Data Retention
- Local app data: Persists until you delete it. Uninstalling the app removes all data
- Waitlist emails: Retained until you unsubscribe or request deletion
- Google API data: Retained only as long as you keep it in PersonalFLOW. Deleting from PersonalFLOW does not affect your Google account data
9. Your Rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Withdraw consent at any time
- Lodge a complaint with your local data protection authority
For any request, contact us at privacy@personalflow.ai.
10. Open Source
PersonalFLOW is licensed under the EUPL v1.2. You can inspect the source code to verify our privacy claims.
11. Changes to This Policy
We may update this policy as the product evolves. Changes will be posted on this page with an updated effective date.