Legal · FlowState Logic
Privacy Policy
1. What We Collect
When you sign up, we store the email address and display name you provide. If you sign in with Google, we receive your email, display name, and profile picture from Google and store the same fields on our side.
As you play, we store your in-app progress - completed lessons, embers, crystals, achievements, and the settings you've chosen. None of this leaves your device unless you've signed in.
If you purchase a subscription or one-time upgrade, our payment partner (RevenueCat) and the relevant app store (Google Play or Apple) process the purchase. We receive a purchase token and the resulting entitlement status so we can unlock Pro features for your account. We never see your payment card or billing address.
Crash reports may include diagnostic details such as app version, device model, operating system version, and error logs so we can identify and fix bugs.
We don't collect your real name, precise location, contacts, photos, or advertising identifiers.
2. How We Store It
Local-only play: your data lives on your device in the app's standard private storage, isolated from other apps by the operating system. It is not separately encrypted by us, so if your device itself is unencrypted and someone has physical access, the data could be read.
Signed-in play: your data syncs to a row tied to your account on Supabase, a managed Postgres backend. Communication is encrypted in transit; data at rest is protected by Supabase's standard storage encryption.
3. Why We Collect It
To run the Service: authenticate you, sync your progress across devices, personalise lesson recommendations, deliver notifications you enable, unlock features tied to a purchase you made, and diagnose crashes.
We do not sell your data, share it with advertisers, or build advertising profiles.
4. Service Providers
We use Supabase (database, authentication, and the website's aggregate TestFlight count), Sentry (crash reporting), RevenueCat (subscription and entitlement management), Google Play Billing and Apple In-App Purchase (payment processing), Buttondown (newsletter subscriptions), and Expo / Apple Push / Google Push (notification delivery). Each provider handles information under its own privacy terms and only for the services described here.
Our website serves its fonts and store badge artwork directly from Cinderway Interactive, so loading those visual assets does not contact Google.
To show iOS beta availability, the website requests an aggregate tester count from our Supabase function. That request does not include your FlowState Logic account, email address, or other account identifier.
If you choose to join the newsletter, the email address you submit and signup metadata such as your IP address and referring page are sent to Buttondown to manage the subscription and deliver messages. Every newsletter includes an unsubscribe option.
Our website uses Plausible to produce aggregate page-traffic statistics. Plausible does not use cookies or persistent identifiers and does not store visitor IP addresses.
5. Children
The Service is intended for users 13 and older. If you believe a child under 13 has created an account, contact us and we'll remove it.
6. Your Rights
Access: see your account email and display name in Settings → Account at any time.
Deletion: erase your account and cloud-synced progress via Settings → Account → Delete account. This is permanent. The web deletion guide explains what happens afterwards.
Where required by law (e.g. GDPR, CCPA), you have additional rights to access, port, or correct your data - contact us to exercise them.
7. Changes
We may update this policy. Material changes will be surfaced in-app before they take effect.
8. Contact
Privacy questions? Email [email protected].
This page is hosted by Cinderway Interactive as the canonical privacy policy for FlowState Logic. A summary is also available in-app at Settings → About → Privacy Policy.