Legal ยท FlowState Reasoning
Privacy Policy
This policy is for FlowState Reasoning, the adult / professional product. It is not the policy for FlowState Logic. Logic keeps its own pages at /privacy.html.
1. Who this is for
Reasoning is built for adults. You must be 18 or older to create an account. It is not a child, school, or student product. If we later ship education features, those will have a separate privacy profile.
2. What we collect
Account. The email address you use to sign in. We send a one-time code to that address. We do not use passwords, and we do not sign you in with Google.
Session. A server-side session, delivered as an HttpOnly cookie. We store a keyed digest of the session token, not the token itself.
Learning record. Diagnostic answers, activity attempts, traces of those attempts, mastery snapshots, your reasoning profile, onboarding state, and optional feedback you submit. This is how the product adapts and how we tell whether it is actually teaching.
Billing. If you subscribe, Stripe processes the payment. We store Stripe customer / subscription identifiers and entitlement state so we can unlock Pro. We do not see your card number or billing address.
Product events. We record domain events (for example sign-in, diagnostic completed, attempt scored) so we can operate, debug, and improve the product. These are not advertising profiles.
We do not collect your legal name, precise location, contacts, photos, or advertising identifiers. We do not sell your data.
3. Why
- to create and keep your account
- to run the diagnostic, recommendations, and practice
- to take payment and honor Pro access
- to grant founding / welcome rewards
- to fix failures and understand where learners stall
4. Who else sees it
Only processors that run the service:
- Supabase โ PostgreSQL hosting. We do not use Supabase Auth. Identity is email codes in our API.
- Resend โ delivers sign-in codes from our mail domain.
- Stripe โ checkout, invoices, and the customer portal.
If we add crash reporting (for example Sentry) later, this policy will name it before we turn it on. We do not currently send Reasoning data to advertising or analytics vendors.
Each processor acts under its own terms, only for the jobs above.
5. Code you write in the product
Practice code runs in a sandbox: time and memory limits, no production network, no secrets, no production filesystem. We keep attempts and traces as part of your learning record. We do not run your code on the API process.
6. Cookies
The session cookie is what keeps you signed in. It is required for the signed-in product. We do not use it for advertising.
7. How long we keep it
- Sign-in codes are short-lived. Spent and expired challenges are pruned.
- Account and learning record last until you ask us to delete the account, unless a longer period is required for billing, tax, or a legal hold.
- Billing records last as long as Stripe and tax rules require.
- Domain events: while the account is open, then 24 months after deletion or last activity, whichever we implement first.
8. Your choices
There is not yet an in-product delete-account control. Email [email protected] from the address on the account and we will delete the learning record we control. Stripe may retain payment records they are required to keep.
You can cancel a subscription in the Stripe customer portal. Access lasts until the end of the period you already paid.
Where law gives you more (access, correction, portability, restriction), email the same address.
9. Security
Traffic is encrypted in transit. Data at rest uses our host's standard encryption. No method is perfect. Do not put secrets into practice code or feedback.
10. Changes
If we change this policy in a material way, we will post the new version and, when we have the product surface for it, tell signed-in users before it takes effect.
11. Contact
Cinderway Interactive, Nokomis, Florida, United States, [email protected]
This page is hosted by Cinderway Interactive as the canonical privacy policy for FlowState Reasoning. See also the Terms of Service.