Legal Notice

Flowcus is not affiliated with, endorsed by, or sponsored by any task management software company. All trademarks belong to their respective owners.

Data Collection & Usage

Flowcus communicates with OmniFocus, Things, Todoist, and TaskPaper using each app's supported automation methods to read and update your tasks.

Local Data Storage

Flowcus stores all application data locally on your device:

  • ~/Library/Application Support/net.rhydlewis.apps.Flowcus/flowcus.db (stores your board configuration, task history, and app data)
  • Built-in local storage for UI settings and preferences

These files contain your configuration and task information. They do not contain account credentials — API keys and calendar tokens are held separately in the macOS Keychain. If you connect a calendar, they also hold the identifiers of any calendars you have chosen to hide, which for some calendars take the form of an email address.

Sidekick AI Assistant

Flowcus includes Sidekick, an optional AI assistant for task refinement and planning. Sidekick is switched off by default and does nothing until you enable it and supply your own credentials.

What Sidekick sends, and where

Sidekick connects to an AI model provider that you choose and configure in Settings › Sidekick. Flowcus operates no AI infrastructure of its own and holds no account with any AI provider: you supply your own API key (or run a model locally), and your use of that provider is governed by your own agreement with them. Your API keys are stored in the macOS Keychain on your device and are sent only to the provider they belong to.

The supported providers are:

  • Ollama — runs entirely on your own Mac. Prompts never leave your device and are never transmitted to any model provider.
  • Anthropic, OpenAI and Google (Gemini) — remote services you connect with your own API key.
  • OpenRouter — a gateway that routes your request to an upstream model of your choosing.

Sidekick sends only the task and board content it needs for the action you invoked: task names and notes, project and tag names, column and swimlane names, and your own instruction. Requests are made only in response to an explicit action you take in the Sidekick interface — Flowcus never sends data to an AI provider in the background.

Calendar data is never sent to any AI model

Your calendar data is strictly isolated from Sidekick. Events read from Google Calendar or from macOS Calendar are used only to draw the calendar lane in the Blueprint day planner and the agenda in Settings › Calendar. They are never included in any prompt, never passed to any AI model, whether local or remote, and never used to create, train, or improve any machine learning or artificial intelligence model. This separation is enforced in the design of the application: the AI layer has no access path to calendar data at all.

Accordingly, and in line with the Limited Use requirements of the Google API Services User Data Policy: Flowcus does not use, transfer, or sell Google user data — raw, aggregated, anonymised, or derived — to create, train, or improve any foundational or generalised artificial intelligence or machine learning model, and does not transfer Google user data to any third-party artificial intelligence or machine learning service.

Restricting third-party retention

Although no Google user data ever reaches an AI provider, Flowcus additionally configures its requests to limit what providers may retain of the task content you do send:

  • Requests to OpenRouter set data_collection: "deny", restricting routing to upstream providers that do not collect user data.
  • Requests to OpenAI set store: false, opting out of retention of the request and response for model distillation.
  • Anthropic does not train on data submitted through its API under its commercial terms, and offers no per-request setting to change this.
  • Google (Gemini) determines this by API tier rather than by request: Google states that free-tier Gemini API usage may be used to improve Google products, while paid-tier usage is not. If this matters to you, use a paid-tier key or choose a different provider.
  • Ollama needs no such setting, as no data leaves your Mac.

Flowcus does not control and cannot store data once it has been processed by a third-party AI service. Review your chosen provider's privacy policy and terms for their full data handling practices.

Calendar Integration

Flowcus can optionally display your calendar events alongside your planned tasks in the Blueprint day planner. Calendar integration is off by default and only activated when you connect a calendar in Settings › Calendar.

macOS Calendar

If you grant access, Flowcus reads events from the calendars you select using Apple's EventKit framework. Access is read-only: Flowcus never creates, modifies or deletes calendar events. You can revoke access at any time in System Settings › Privacy & Security › Calendars.

Google Calendar

If you connect a Google account, Flowcus requests read-only access to your Google Calendar (the calendar.readonly scope) and your account email address (to identify the connected account in Settings). Flowcus uses this access only to:

  • List your calendars so you can choose which to show
  • Fetch events for the day you are viewing and display them in the Blueprint planner and in Settings › Calendar

Calendar data is fetched directly from Google to your Mac. It is not sent to Flowcus servers (Flowcus has no servers), not shared with any third party, and never sent to any artificial intelligence or machine learning service (see Sidekick AI Assistant above).

Retention and deletion of Google user data

Flowcus retains the minimum Google user data needed to show your calendar, and deletes it as follows:

  • Calendar events are held only in the running application's memory, for the days you are currently viewing. They are never written to disk. They are discarded when you disconnect the account, and in any case when you quit Flowcus. Nothing about your events survives a restart — each session re-fetches them from Google.
  • Your Google account email address and OAuth tokens are stored in the macOS Keychain on your Mac, for as long as the account stays connected, so that Flowcus can identify the connected account and refresh its access without asking you to sign in repeatedly. They are deleted from the Keychain the moment you disconnect the account.
  • The identifiers of calendars you have chosen to hide are stored in the local Flowcus database on your Mac so your choice persists between launches. They are removed when you disconnect the account or delete the Flowcus database.

Disconnecting your Google account in Settings › Calendar performs all of this at once: it revokes Flowcus's access token with Google, deletes the stored account, tokens and calendar preferences, and clears all fetched events from memory immediately. You can also revoke Flowcus's access at any time from your Google account at myaccount.google.com/permissions. Deleting the Flowcus application and the files listed under Local Data Storage, together with disconnecting the account, removes all Google user data from your device.

Because Flowcus has no servers and no account system, there is no copy of your Google user data anywhere for Flowcus to retain or for you to request deletion of. All of it lives on your own Mac and is under your direct control.

Flowcus's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Network Connections

Flowcus uses network connections for:

  • Automatic updates via auto-update mechanism
  • Crash reporting
  • Anonymous install and upgrade analytics (a single event per version)
  • Sidekick AI requests to your configured LLM service (only when you use Sidekick)
  • Google Calendar API requests (only if you connect a Google calendar)

Crash Reporting & Diagnostics

If the app crashes, diagnostic information may be collected which could include:

  • App version
  • Operating system version
  • Device model
  • Time of crash
  • Technical crash logs

No personally identifiable information is included in crash reports unless you explicitly opt-in to sharing additional information.

Anonymous Analytics

Flowcus sends a single anonymous event when the app is first installed or upgraded to a new version. This helps us understand how many people are using Flowcus and which versions are in use.

Each event contains only:

  • Event type (install or upgrade)
  • App version number
  • Operating system (macOS)

No personal data, device identifiers, IP addresses, usage patterns, or session information is collected. Analytics events are processed by GoatCounter, an open-source, privacy-first analytics service that does not track personal data.

Website Analytics

This website (getflowcus.app) uses GoatCounter for anonymous page view analytics. GoatCounter does not use cookies, does not collect personal data, and is fully compliant with GDPR, CCPA, and PECR. No personally identifiable information is collected from website visitors.

Personal Data

Flowcus does not collect, store, or transmit personally identifying information (PII) outside your device unless you explicitly opt-in to share your name and email address when sending feedback. If you connect a Google account, your Google email address is stored locally in the macOS Keychain solely to identify the connected account; it is never transmitted to Flowcus or third parties.

Data Retention and Deletion

Flowcus stores data only on your own device and retains none of it anywhere else. All locally stored data remains on your device until you delete it.

To remove everything:

  • Disconnect any connected calendar and AI provider in Settings. This deletes their credentials from the macOS Keychain and clears any data fetched from them. Uninstalling the app alone does not remove Keychain entries, so do this first.
  • Delete the Flowcus application.
  • Delete the files listed under Local Data Storage.

For the specific retention and deletion terms that apply to data received from Google, see Retention and deletion of Google user data above.

Children's Data

Flowcus is not directed at children under 13 and does not knowingly collect any data from children.

International Data Transfer

As Flowcus does not routinely collect or transmit personal data, there are no international data transfers to disclose.

Your Rights

You have the right to:

  • Access your data (all data is stored locally on your device)
  • Delete your data (by removing the application and associated files)
  • Opt-out of crash reporting through the application settings
  • Disconnect calendar accounts and revoke calendar access at any time (in Settings › Calendar, System Settings › Privacy & Security › Calendars, or your Google account permissions)

Privacy Policy Changes

Although most changes are likely to be minor, Flowcus may change its Privacy Policy from time to time at our sole discretion. We encourage you to check this page for any updates. Your continued use of this app after any change in this Privacy Policy will constitute your acceptance of such changes.

Contact Information

If you have any questions about this Privacy Policy, please contact support@getflowcus.app.