Privacy
Last updated: 9 October 2026
The short version: Flowspace has no accounts, no ads and no tracking. Your workspace lives in your browser, with a private backup on our server. What you send to the AI is passed to Google's Gemini to produce your notes. You can export or delete everything at any time.
What Flowspace stores, and where
- On your device. Your schedule, assignments, notebooks, study notes, flashcards, focus history and settings are kept in your browser's storage on the device you use.
- On our server. A compressed backup of that workspace, so that it can be restored on the same browser. It is filed under a random workspace number that only your browser knows. Next to it we keep which plan the workspace is on and how many AI imports and AI actions it has used this month.
- If you sign in with Google. Signing in is optional, except for buying Flowspace Pro. Google tells us who signed in: we keep Google's identifier for your account, your e-mail address and your name, and which workspace is yours, so that it opens on any device you sign in on. We never see your Google password. One cookie keeps you signed in on that browser, for up to two months. You can sign out or delete the account in Settings; deleting it removes those details from our server.
- If you do not sign in. We do not ask for your real name, e-mail address or password. A name or university you type during setup is part of your workspace and is only used to greet you.
When you use AI features
AI note taking, note checks, flashcards, tables, AI planning, handwriting recognition and the semester look-up need a language model. When you use one of them, the content it needs (for example the pages of the file you uploaded, the selected part of a note, or your list of tasks) is sent through our server to Google's Gemini API, which returns the result. Our server does not keep the files you upload after the request has finished. Google handles this content under the terms of its Gemini API.
Please do not upload documents that contain sensitive personal information about you or other people.
YouTube videos
When you import a lecture from YouTube, we send the public link of the video to Google's Gemini API, which watches the video and writes the notes. We do not download or store the video. When you open the video beside your notes, it is played by YouTube's privacy-enhanced player, which is only loaded at that moment. YouTube's terms and Google's privacy policy apply to the player.
Services we rely on
- Hosting: Render, in Frankfurt, Germany. Like every web server, it sees the network address of a request. We use that address briefly to limit how many requests one network can send, and it can appear in short-lived technical logs.
- AI: Google Gemini API, as described above.
- Signing in: Google. If you choose “Continue with Google”, you sign in on Google's own page, and Google sends us your account's identifier, your e-mail address and your name. Nothing else from your Google account is asked for or read.
- Payments: Stripe. If you buy Flowspace Pro, you pay on Stripe's checkout page. Stripe asks for and receives your name, e-mail address, country and payment details, works out the tax, and may be the seller of record for the purchase. We never see your card. From Stripe we keep only the identifiers of your customer record and subscription, and whether it is active, filed under your workspace number. If you cancel and choose to tell us why, that answer is saved with your subscription at Stripe; the question is optional.
- Building blocks: fonts, icons, the PDF reader and the maths renderer are loaded from public content networks (Google Fonts, cdnjs, jsDelivr and unpkg). They receive your network address when your browser fetches these files.
Flowspace sets no advertising or analytics cookies, and nothing about you is sold or shared for marketing. The only cookie is the one that keeps you signed in, if you sign in.
Notifications
If you allow them, reminders are created by your own browser on your own device. We do not send them from our server.
How long things are kept
Your workspace stays on your device until you delete it or clear your browser's data. The server backup is kept until you delete your workspace. Backups that have not been used for twelve months may be removed. The backup is a convenience, not an archive: use Settings → Export to keep your own copy.
Your choices and rights
- Export: Settings → Export downloads your whole workspace as one file.
- Delete: Settings → Delete everything erases the workspace on your device and the backup on our server. The plan and this month's count of AI uses stay with the workspace number; they contain none of your content.
- Ask us: you can ask what we hold about your workspace, or ask us to correct or delete it, at the address below. If you live in the European Union you also have the right to complain to your data protection authority.
Age
Flowspace is made for students aged 16 and over. If you are younger, please use it only with the agreement of a parent or guardian.
Security
- All traffic between your browser and Flowspace is encrypted (HTTPS).
- The key for the AI service stays on our server and is never sent to your browser.
- Plan limits are checked on the server, not in the browser.
- Your workspace number works like a key to your backup. It is long and random, and it stays in your browser. Anyone who uses your browser profile can open your workspace, so lock shared devices.
Changes
If the way Flowspace handles data changes, this page changes first, and the date at the top is updated.
Contact
Questions about privacy, your data or anything else: write to flowspace.team@gmail.com.