Effective date:
Flowlary is an independent writing companion product. This Privacy Policy describes how information is handled for the Flowlary marketing website (flowlary.com), the Flowlary Chrome extension, and the Flowlary API (api.flowlary.com) when you use managed AI features.
This policy is written to match the implemented product. It is not a legal certification and does not claim compliance with every jurisdiction.
1. Scope
This policy covers: (a) the public marketing website and optional account pages; (b) the Flowlary browser extension; and (c) the Flowlary API when the extension or website calls it for authentication, billing, learning sync, or managed AI.
2. Who operates Flowlary
Flowlary is offered as an independent product at flowlary.com. The legal entity name, registered address, and data-protection contact details for the operator are not published in this repository and must be confirmed before treating this page as complete for regulatory filings.
3. Website
The marketing website is informational. You may create an account, manage billing when checkout is enabled, use the Writing Lab when signed in, and read product documentation.
- Theme preference (light or dark) may be stored in your browser so the site remembers your choice.
- Locale preference may be stored in your browser when you change language.
- Writing Lab AI use may require a per-account consent choice stored locally in your browser before text is sent for correction.
- We do not embed a third-party analytics or advertising SDK on this website in the current implementation.
- When you start checkout, Paddle (our payment partner) may set cookies or use similar storage on its own domains. Flowlary does not receive your full card number.
4. Browser extension
The Flowlary extension runs in Chrome (and compatible Chromium browsers). A content script is injected on web pages so Flowlary can read and update text in editable fields when you invoke a feature or when an enabled feature runs after safety checks.
- Permissions declared: storage, activeTab, and clipboardWrite (for Speed Box copy).
- Host permission in release builds: https://api.flowlary.com/* for API calls.
- The extension does not declare tabs, scripting, or externally_connectable access.
- Flowlary reads focused field text only when a feature runs, not your full browsing history.
5. Account information
If you register, the Flowlary API stores account information needed to authenticate you and apply your plan.
- Email address and a password verifier (hashed; Flowlary does not store your plain-text password).
- Session identifiers: short-lived access tokens and longer-lived refresh tokens tied to device sessions.
- Extension install ID linked to your account when you sign in from the extension.
- Email verification and password-reset tokens (stored as hashes with expiry).
- Plan, trial status, daily AI writing-check counters, and capability flags.
6. Writing content
Flowlary processes the text you type when you use writing assistance. This is central to the product and is not hidden.
- Correction: up to the last 2,000 characters of the active field (plus optional short context) are sent to api.flowlary.com when you use writing correction.
- Translation: the text you request to translate is sent to api.flowlary.com.
- Layout classification fallback: when local keyboard remapping cannot decide, a word and short context may be sent.
- Before network features run, Flowlary attempts to block password, OTP, payment, username, email, and URL fields; code editors; excluded sites; and high-risk tokens such as API keys.
- Safety heuristics are not perfect. Do not type secrets into fields you ask Flowlary to process.
7. AI processing
Managed Flowlary AI features require a signed-in account. Text needed for a feature is transmitted from your browser to the Flowlary API over HTTPS, then processed using server-side AI infrastructure.
- Correction, translation, layout classification, explanation localization (Pro), learning coach narration (Pro), and learning report narration (Pro) may invoke managed AI providers through the backend.
- The backend currently routes work to Groq and, for translation, may use Google Cloud Translation when configured.
- Flowlary application logs and usage records are designed to store operation metadata (such as model, latency, and credit usage), not the writing text itself.
- We do not claim that third-party AI providers never retain data. Their handling is governed by their terms and our agreements with them.
- AI output can be wrong or incomplete. You remain responsible for reviewing important text.
8. Translation
Translation requests include your text, source and target languages, and mode metadata. Routing depends on plan and server configuration: Google Cloud Translation may be used, with optional Groq refinement for some Pro requests. When Google is not configured, Groq may handle translation directly.
The server may keep an in-memory translation cache keyed by a hash of normalized text (not plaintext) for up to about one hour to reduce duplicate provider calls.
9. Learning data
When you are signed in, Flowlary records learning signals from accepted corrections and layout fixes to help you track patterns and practice.
- Locally on your device: learning events, optional sample text, learning profile preferences, and practice session history under account-scoped extension storage.
- On Flowlary servers when signed in: learning events with original and corrected snippets (each up to 512 characters), category, action, timestamps, and sample metadata (word count and hash — not the full sample text). Up to 2,000 events per account.
- Learning profile and practice session aggregates may sync between your browser and the server.
- You can clear learning data locally from extension Settings → Data and delete server-side learning data with DELETE /api/learning/events when signed in.
- Pro AI learning coach and report narration send aggregated learning context to managed AI — not your full documents.
10. Local-only processing
- Keyboard layout remapping when local mapping is sufficient.
- Speed Box layout conversion mode (no network).
- Settings, pause state, site exclusions, and UI preferences.
- Bounded local activity log (up to 50 entries when privacy rules allow).
- AI response cache in extension storage (hashed keys; sensitive content excluded).
11. Billing and subscriptions
Paid Pro access is handled by Paddle when checkout is enabled. Flowlary stores Paddle customer and subscription identifiers, subscription status, and billing period metadata needed to grant entitlement. Flowlary does not store your payment card number.
12. Student verification
The Student program verifies control of an academic email address. It does not verify active enrollment, identity documents, or ongoing student status unless separately stated in product copy.
- You submit an academic email address that matches accepted academic domains.
- A verification link is emailed through the configured SMTP service.
- Pending verification stores the academic email and a hashed token on the server.
- After confirmation, a student benefit record grants Pro-tier access for 12 months according to the current program rules.
- Each academic email reference can be linked to one account.
13. Cookies and browser storage
Flowlary does not use a site-wide cookie consent banner in the current implementation because we do not run third-party analytics cookies on the marketing site. See the Cookie Policy for details on local storage, extension storage, and payment-partner cookies.
15. Security
Flowlary uses HTTPS for API communication in production release builds. Passwords are stored as password verifiers, not plain text. Session tokens are required for managed AI. We do not claim a specific certification (such as SOC 2 or ISO 27001) unless separately published.
16. Retention
- Local extension data remains until you change settings, clear data, or uninstall the extension.
- Server account records persist while your account exists.
- Usage metadata records are bounded (currently up to 50,000 entries per store, FIFO trimmed).
- Learning events on the server are capped at 2,000 per account.
- Email verification and password-reset tokens expire and are cleared after use or expiry.
- Specific statutory retention periods for billing records have not been defined in this repository.
17. Your choices and deletion
- Pause Flowlary globally or exclude specific sites.
- Disable live translation (off by default).
- Clear local activity, learning data, or reset all local extension data from Settings → Data.
- Delete server-side learning data when signed in (extension sync or API).
- Sign out to end the current session; logout removes the server session record.
- Uninstall the extension to remove extension-local storage from that browser.
- Full account deletion is not implemented as a self-service feature in the current API. Account deletion requests must be handled through operator confirmation when a privacy contact is published.
18. International transfers
Flowlary and its subprocessors may process data in countries other than yours. The legal mechanism for international transfers (for example, Standard Contractual Clauses) has not been documented in this repository.
19. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict processing of personal data. How to exercise those rights depends on the operator entity and applicable law. Use the Contact page to reach the appropriate channel once published.
20. Children
Flowlary is not directed at children. Do not use the product to process children’s personal data if you are not permitted to do so.
21. Changes
We may update this policy as the product changes. The effective date at the top will change when we do. Material changes should appear here before they are relied on for store listings.
22. Contact
Privacy questions: use the Contact page and choose Privacy requests. Product and billing help: Support and Account pages. Do not send passwords, API keys, or payment card numbers.