Privacy Policy
Last updated:
1. Who we are
FlowByFlow is a medication reminder and cycle tracking application for iOS and Android.
The controller of your personal data is:
ILVAR STUDIO LIMITED LIABILITY COMPANY Erebuni St. 14/1, office 5, Yerevan, Republic of Armenia support@flowbyflow.appWrite to that address about anything in this policy, including any of the requests described in section 10.
2. What the app is for
The app stores what you take, when you take it, and reminds you. Optionally it also tracks a menstrual cycle, so that medication schedules can follow the cycle rather than the calendar.
3. What we collect
Account
- An account is required to use the app, but an email address is not. You can continue as a guest; that creates an anonymous account with no personal identifier.
- If you sign up with email and password, we store your email address.
- If you sign in with Google, Apple or Facebook, we receive the identifier and, where the provider supplies it, the email address associated with that account. We request nothing beyond basic profile and email.
- Profile name and type (self, child, parent).
Health data you enter
- Medications: names, dosage, form, schedules, food relation, notes.
- Doses: planned and actual times, whether each was taken, skipped, snoozed or missed, notes.
- Inventory: stock counts and refill history.
- Prescription reminders: renewal dates and your own free-text note.
- Menstrual cycle, only if you turn cycle tracking on: period start and end dates, cycle lengths, and the predictions derived from them.
Device data
- A push notification token, so reminders can reach your device.
- Platform (iOS or Android) and app language.
Diagnostics
See section 5. They are separate from everything above and are deliberately stripped of your health data.
4. Where your data lives, and who processes it
On your device. The app is local-first: your data is held on the device and the app works fully offline. Reminders, logging and your recent history do not require a connection.
In your own cloud account. The same data syncs to Google Firebase (Firestore) under your account, so that changing or losing a phone does not cost you your history. Each account’s data is isolated by server-side security rules; no other user can read it. Data is encrypted in transit and at rest.
Where that is, physically. The Firestore database is hosted in Google’s nam5 multi-region, which is in the United States. Your data therefore leaves Armenia, and — if you are in the EEA, the United Kingdom or Switzerland — leaves that area too. The transfer is covered by the Standard Contractual Clauses in Google’s data processing terms for Firebase, which Google enters into as our processor.
Server-side processing. Some processing happens on our servers rather than on your device, and we say so plainly rather than describing the cloud copy as a passive backup:
- A scheduled job marks a dose as missed once 24 hours have passed since it was due without it being confirmed. This runs daily, for every account.
- Housekeeping jobs remove stale records, and delete anonymous guest accounts as described in section 9.
5. Diagnostics (crash and error reports)
If the app crashes or hits an error, a diagnostic report can be sent so the fault can be fixed. Two services are used: Google Crashlytics, which handles crashes in the app’s native layer, and Sentry, which handles errors in the app’s JavaScript layer. Sentry stores this data in its European region, in Germany; Crashlytics stores it on Google’s infrastructure.
Reports are deliberately stripped of your health data. Medicine names, dose records, cycle data and free-text notes are never included. Your email address and username are removed; a report is associated only with an internal account identifier. Interaction breadcrumbs are dropped entirely, because an accessibility label can contain a medicine name.
Whether they are on by default depends on where you are. In the EEA, the United Kingdom, Switzerland and China, diagnostics are off unless you turn them on, and the lawful basis is your consent. Everywhere else they are on unless you turn them off, and the lawful basis is our legitimate interest in a working, non-crashing app. Either way you can change it at any time in Settings → Privacy, and switching it off stops further reports immediately.
6. Contributing data to research
The app can contribute your data to health research, and it is off by default. If you turn it on, you choose which categories to include — cycles, symptoms, wearable data, imported data, medications, demographics — each separately, and you can switch any of them off again at any time. The lawful basis is your explicit consent.
At the time of writing, no research pipeline exists and no data has been shared with anyone under this setting. It is a permission you can grant in advance, not a transfer that is happening.
7. Third parties
These are every external party that receives anything, in the current version of the app:
- Google Firebase — your account data and health records, as described in section 4, for authentication, database and sync.
- Google (FCM) — a push token and the content of a reminder notification, to deliver reminders to your device.
- Google Crashlytics — diagnostic reports, per section 5, to diagnose crashes in the native layer.
- Sentry — diagnostic reports, per section 5, to diagnose errors in the JavaScript layer.
- Apple, Google or Meta — only what is required to sign you in, and only if you choose that sign-in method.
Each of them acts as our processor, on our instructions, except that Apple, Google and Meta act as independent controllers for the sign-in step itself, under their own privacy policies.
Meta’s SDK is present solely to support “Sign in with Facebook”. Its tracking, automatic event logging and advertiser-ID collection are disabled in the app’s configuration.
8. What we do not do
- We do not sell your data.
- We do not hand your data to pharmaceutical companies, insurers or employers.
- We do not use your health data for advertising. There is no advertising SDK in the app.
- There is no analytics, attribution or tracking SDK of any kind. Firebase Analytics is switched off in the app’s native configuration.
- We never ask for your location or your region.
- We do not use your data to train AI models.
9. How long we keep it
- Registered accounts. Your data is kept for as long as your account exists. If you ask us to erase it (section 10), we complete the erasure within 30 days of the request.
- Anonymous guest accounts. Deleted automatically once the account has existed for 30 days and has never been upgraded to a real sign-in — together with every record under it, and the authentication record itself.
- Diagnostic reports. Retained under Crashlytics’ and Sentry’s own retention windows, currently 90 days for both. We do not extend them and we keep no separate copy.
10. Your rights, and how to use them
Under the GDPR and comparable laws you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable form, and withdraw any consent you have given.
You can do the following in the app right now:
- See and correct everything you have entered — every record is editable.
- Delete individual records: a medication and its dose history, a cycle, a profile and everything under it.
- Switch diagnostics off (Settings → Privacy) and research contribution off — it is off unless you turned it on.
- Use the app without giving us an email address, as a guest.
Two of these rights the app cannot yet perform by itself, and this policy will not pretend otherwise:
- Erasing your whole account. There is no in-app way to do this yet. Email us from the address on the account, or tell us which account you are using, and we will erase the account and everything in it within 30 days.
- Exporting your data. In-app export is not available in this version. Ask at the same address and we will send you your data in a machine-readable format, within the same 30 days.
If you think we are handling your data wrongly, you can complain to a supervisory authority. In Armenia that is the Personal Data Protection Agency of the Ministry of Justice. If you are in the EEA or the UK, you may complain to the authority where you live or work.
11. Children
The app is not intended for children under 16, and you must be at least 16 to hold an account.
A parent can create a child profile to manage a child’s medications. That profile lives inside the parent’s own account, under the parent’s control; no separate account is created for the child and the child is not asked to agree to anything.
We do not verify age at sign-up. If you believe a child under 16 has created their own account, write to us and we will delete it.
12. Security
- Data is isolated per account by server-side security rules.
- All communication uses TLS.
- Sign-in is handled by Firebase Authentication.
- The app requests no location permission and no advertising identifier.
13. Changes to this policy
If we change it, we update the date at the top of this page. If a change materially affects how your data is used, we will say so in the app before it takes effect.
14. Contact
Questions, requests and complaints all go to the same place:
ILVAR STUDIO LIMITED LIABILITY COMPANY Erebuni St. 14/1, office 5, Yerevan, Republic of Armenia support@flowbyflow.app