Back to home

Privacy Policy

Last updated 2026-09-03 · Available in English only for now

This policy covers the FlowMic hosted service at flowmic.app, operated by FlowMic (flowmic.app).

It does not cover FlowMic running on your own hardware. If you self-host, no data reaches us and there is nothing for this policy to describe.

The short version

  • We do not store your transcripts. The table that used to hold them was deleted from the database in 2026, and the endpoints that wrote to it now refuse requests instead of accepting them.
  • The relay passes frames from your phone to your computer and forgets them.
  • When you use the built-in cloud engine, your audio is transcribed by Soniox, a speech-recognition provider working on our behalf — see "Who else sees your data". With your own engine, or a local one, it is not.
  • When the built-in language model is used, that text is processed by DeepSeek on our account — see "Who else sees your data". That happens for translation and clean-up, and also for the closing transcript in realtime mode whenever "AI polish" is switched on in the phone app ("What happens to your voice" below says how that switch reaches us). With a model endpoint you configured yourself, it is not.
  • We store your account, your paired devices, the engine routing and language-model endpoint you configured for your account in the console, monthly usage totals, and per-use usage events for traffic that went through our cloud relay (when, how many minutes / tokens / character counts) — never the words themselves. Local-network sessions are not written into that per-use table.
  • Your general preferences stay on your phone. That covers your scenario card (profession, field, term packs, custom terms and their aliases), the "AI polish" switch and its strength, second-pass refinement, your consent to situational inference, and the language you speak. Each time the phone connects to our relay it hands them over for that connection; the relay uses them while you are connected and does not keep them. They do not sync between devices. The phone can save them to a file on the phone and load that file back.
  • If an account is placed under restricted use, we store that status so the product can show the restriction notice; export and account deletion remain available.
  • We never see your card. Paid plans are billed by our payment provider, which acts as merchant of record; we receive a record that a payment happened and never the card number or the details behind it.
  • We do not sell your data, and we do not use it to train models.

What we collect and why

WhatWhyKept for
Email address, password hash, display name, languageTo have an account at all, and to sign you inUntil you delete the account
Device records — a name you chose, a device identifier, pairing tokens, last-seen timeSo your phone can find your computer, and so you can revoke a device you no longer haveUntil you remove the device or delete the account
Account configuration you set in the console — which engine handles which language for your account, and the language-model endpoint you choseTo call the engine and model you chose when your traffic goes through our relayUntil you change or delete them
Your phone's preferences — scenario card (profession, field, term packs, custom terms with aliases), "AI polish" on or off and its strength, second-pass refinement, consent to situational inference, the language you speakYour phone hands them to the relay each time it connects, so the relay transcribes and polishes the way you set it upOnly while the phone is connected. Held in memory for that connection and not written to the database. They do not sync between devices; the phone keeps its own copy
API keys you enter for third-party enginesTo call the engine you choseEncrypted at rest with a key we hold. Until you remove them
Monthly usage totals — minutes of audio, count of language-model tokensTo enforce the monthly plan limitsBucketed per calendar month; until you delete the account
Per-use usage events (cloud relay only) — timestamp, delivery channel (cloud relay), resource kind (speech / language-model), duration or token counts, character counts of transcripts / delivered finals, whether your own key was used, and a coarse outcome (ok / quota refused). Never the text itself. Sessions that stay on your local network are not recorded in this tableSo you can review detailed cloud-relay usage in the console, and so operators can answer billing and abuse questions without reading content90 days, then deleted automatically; deleting your account deletes them sooner
Account restriction status — when restricted use was applied (and when cleared)To show the in-product restriction notice and to refuse product actions while keeping sign-in, export, and delete availableUntil cleared or you delete the account
Last successful sign-in time — when you last signed in with your password or by scanning a sign-in code. Creating the account does not set it, and ordinary use of the app afterwards does not update itSo operators can tell an account somebody still signs into from one nobody has come back toThe most recent time only — each sign-in replaces the one before it, and we keep no history of sign-ins. Until you delete the account
Server logs — IP address, timestamp, endpoint, error codesTo keep the service running and to investigate abuseNot kept for a fixed number of days. Our own application log is limited by size, not by time: it rotates when it reaches a few megabytes and only the previous file is kept, so how far back it reaches depends on how busy the service has been — hours on a busy day, longer on a quiet one. Logs written by the systems we run on (the operating system's journal, the web front end, our hosting provider) follow those systems' own rotation settings; we have not measured a single figure across them, and we would rather not state a number we have not verified. These logs are not a product query surface and are not merged into the per-use usage table
Public website aggregate counts — path of a public page (no query string), interface language, referring hostname, optional UTM source/medium/campaign, download-button clicks on the site, successful registration / sign-in counts, and counts for the on-site voice demo (a visitor starting it, their phone pairing to it, text landing on the page, the trial running out, and a click through to download)So operators can see how the public site is used and where visitors convert, without identifying a visitor90 days, then deleted automatically. Counts only — no visitor id, no cookie, no fingerprint, no IP retained for this purpose
On-site voice demo trial record — a hashed bucket of the visitor's IP address (not the address itself) together with how many trials it has started and for how longTo enforce the per-address time limit on the on-site voice demo and to stop the same address from starting far more trials than a person would — see "Trying FlowMic on the website"No more than 48 hours, then deleted automatically

We do not collect the content of what you say or type, your contacts, your location, payment or card details, or any advertising identifier. There is no analytics SDK and no third-party tracker in the apps. The public website (flowmic.app) uses first-party aggregate counts only — daily buckets of page paths and named conversion events, never a per-visitor profile, and never a third-party analytics script. Character counts in usage events are counts only — not excerpts, keywords, or summaries of what you said.

What happens to your voice

Which engine hears you is a visible setting, not a guess, and there is no hidden fallback. FlowMic uses the engine your settings name for the language you are speaking; failing that, the catch-all engine in your settings; failing that, the hosted service's built-in cloud engine; failing that, the two engine routes we seeded for you at first boot. If none of those exists either, transcription stops with an error — your audio is never quietly sent somewhere you did not choose.

  1. The built-in cloud engine. Your audio streams through our server and is transcribed on our behalf by our speech-recognition provider Soniox (see "Who else sees your data"). If that provider is unavailable we may switch this step back to speech-recognition servers we operate ourselves; both act on our instructions, and moving between them is an operator action rather than something that re-routes you mid-sentence. We handle the audio in memory, only for as long as the transcription session needs it; we do not record it, write it to disk, or keep it afterwards. The resulting text is delivered to your devices and is not retained by us.
  2. A third-party engine you configured with your own key. Your audio goes to that provider under their policy, with your credentials. When your phone reaches your computer through our relay, the audio passes through our server on its way there — in memory, never stored. On your own network, we are not in the path at all.
  3. A local engine. Nothing leaves your own hardware. (You supply the speech model for the built-in engine yourself; it downloads one over the internet only if you explicitly set FLOWMIC_SHERPA_AUTO_DOWNLOAD=1 on the computer.)

Some of what you say is then handled by a language model, and the transcribed text follows the same rule: it goes to the language-model endpoint your settings name — the platform's, or one you configured — and we retain neither the input nor the output. The platform's language model is run by DeepSeek, on our account rather than yours (see "Who else sees your data"); a model endpoint you configured yourself is used with your credentials, under that provider's policy.

This happens in the following cases:

  • Translation and text clean-up, which is what you asked for when you chose those modes.
  • Realtime mode, whenever "AI polish" is on. The switch is in the phone app's settings, and the phone is where you see whether it is on right now. Each time the phone connects, it hands the switch and the polish strength to the server it connected to (our relay, or your own computer on the local network) for the length of that connection; the server does not keep them. While the switch is on, the closing transcript of each recording is sent once — including recordings you marked "Record only" and never sent to your computer. We would rather say this plainly than let "optional" cover it.
  • Any AI action you run by hand — on a line in your timeline, or on the text in the composer box. The composer box can hold text you typed rather than spoke; running an AI action on it sends that text the same way.

The provisional words that appear while you are still speaking are never sent to a language model — only the finished sentence is.

The transcript's home is your own devices — the timeline on your phone and the timeline on your computer. Both can export it.

Trying FlowMic on the website

The public site lets you try FlowMic in your browser, without creating an account or installing anything: you scan a code with your phone, speak, and the words appear on the page in front of you.

  • Cloudflare Turnstile checks that the visitor is not a bot before a demo starts. That check runs on Cloudflare's infrastructure, not ours; we receive a pass or fail answer, not an analysis of who you are.
  • Your audio follows the same path as the built-in cloud engine described above: it streams to Soniox in memory and is not written to disk or kept once the demo ends.
  • The trial is time-limited and shared by network address, not tied to any account or device. To enforce that limit, and to stop the same address from starting far more trials than a person would, we keep a hashed bucket of the visitor's IP address — not the address itself — together with how many trials it has started and for how long. That record is kept for no more than 48 hours, then deleted automatically.
  • The time you use in a demo is never charged to an account. If you sign in on your phone during a demo, everything from that point on is counted against your account's allowance, the same as ordinary use, and the demo's own time limit no longer applies.
  • The site-wide counts described in "What we collect and why" — a demo starting, a phone pairing to it, text landing on the page, the trial running out, or a click through to download — are aggregate, the same as the rest of that table, and are not tied to the hashed IP bucket above.

The local-network channel

When your phone and your computer are on the same network they connect directly, and we are not in that path at all. Whether that direct connection is encrypted depends on how the pairing was made.

  • A pairing created by scanning the QR code is encrypted. The code carries the identity of your computer — a fingerprint of its network key — and your phone stores it. That identity is checked on every later connection, not only the first, and a computer presenting a different one is refused rather than connected to.
  • A pairing created by typing an address is also encrypted, but its identity is not verified. There is nothing to check the address against, so your phone records the identity it sees on the first connection and refuses a different one afterwards. The app states this on the connection rather than presenting it as verified.
  • A pairing created before this encryption existed is still in the clear. Frames on those connections travel unencrypted, and anyone able to observe traffic on that network can read them. Pairing the phone with the computer again is what moves it onto an encrypted connection; nothing upgrades it on its own.
  • It can be switched off on the computer. Setting the environment variable FLOWMIC_LAN_TLS to 0 returns this channel to unencrypted operation and stops the QR code carrying the identity, so pairings made after that are in the clear. Two consequences are worth knowing before anyone does it. Phones that were already paired while encryption was on stop being able to connect — they are checking for an identity the computer no longer presents, and what they can tell you about it is only that the connection failed. The way back is to delete that pairing on the phone and pair again; nothing repairs it on its own.

Encryption here protects what you send from being read by someone else on the network. It is not a defence against someone actively impersonating your computer, and we do not present it as one. Your phone shows which of the above applies to the connection it currently has, under "Connection encryption", reached from the computer's name at the top of the screen.

Traffic to our relay is TLS-protected and is unaffected by any of this.

One thing we have not done yet

We would rather tell you than let you assume.

  1. 🔴 The zero-knowledge store is not in use yet. The design is that phone-side records synced to us are encrypted so that we cannot read them. The storage and the server-side enforcement exist; the client that would write to it does not. Nothing is in that store today — not because it is protected, but because the feature is unfinished. When it ships, this section will say so and will describe what is in it.

Who else sees your data

WhoWhat they getWhy
Soniox (speech recognition)The audio you speak while using the built-in cloud engine, streamed for transcription. Not your name, email, or account detailsThey transcribe it on our behalf. Their published policy commits that customer audio and transcripts are never used to improve their models or services, and that real-time audio is not stored
DeepSeek (language models)The text being translated or cleaned up when you use the built-in language-model engine — and, whenever "AI polish" is switched on in the phone app, the finished sentence in realtime mode too. Not your name, email, or account detailsThey run the model on our behalf, on our account rather than yours, under their platform terms. Unlike Soniox, we have found no written commitment from DeepSeek that text sent to their API is not used to improve their models — their platform terms are silent on it, and we would rather tell you that than assume the answer. If that matters for what you dictate, configure your own language-model endpoint: it replaces this engine entirely. This leg has one destination and no automatic failover; if we move it back to servers we operate, this table will say so
Third-party engines you configureThe audio — and, for language models, the text — you send themOnly when you choose them, with your own credentials, under their policy
Our hosting providerEncrypted data at rest and in transitTo run the servers

We do not sell personal data. We do not share it for advertising. We never use your content to train machine-learning models ourselves, and we never hand it to anyone for that purpose. What a built-in provider may do on its own side is stated provider by provider in the table above — where we have a provider's written commitment the table says so, and where we have found none the table says that just as plainly.

We disclose data to authorities only when legally compelled, and we will tell you unless the law forbids it.

Restricted use

We may place an account under restricted use when it is harming the Service or others. Restricted use is not a silent ban:

  • you can still sign in;
  • the product surfaces are replaced by a restriction notice;
  • you can still export your data and delete (close) your account from the console;
  • there is no appeal channel for the restriction itself.

Data-subject requests (see / export / delete) are not an “appeal” — those rights stay available and we still respond to them within 30 days.

Your rights

Wherever you live, you can:

  • see what we hold about you — the console shows your account, devices, monthly totals, and (when available) the last 90 days of per-use usage events;
  • correct it;
  • export it in a portable format — including while the account is under restricted use;
  • delete it. Deleting your account removes your user record, and the database cascades that deletion to your devices, the account configuration you set in the console, monthly usage rows, per-use usage events, restriction status, and stored records. The preferences on your phone are not on our servers, so deleting the account leaves them where they are.

What deletion does not remove

Two records survive a deletion, and we would rather say so here than let you discover it. Both keep your account identifier, and neither contains anything you said, typed, or transcribed.

  • Payment-event records. When a payment provider tells us something about a subscription, we write down that we received that message. Those entries are also how we avoid applying the same message twice, so removing one could make a re-sent message take effect a second time. An account that has never paid for anything has an empty set here — and when you close your account we tell you the real count rather than assuming it is zero.
  • Operations audit entries. These record what *we* did — which operator looked at an administrative page, and who applied or lifted a restricted-use decision, with the note they wrote. An audit record that can be erased by the person it is about is not an audit record, and closing an account is exactly the kind of action that has to leave a trace.

We keep both for as long as we run the Service, because their purpose is to be the record that we cannot quietly revise. If you need them removed and you have a right that requires it, write to us and we will deal with it individually rather than through the automatic path.

To exercise any of this, use your account console or write to github@flowmic.app. We will respond within 30 days.

If you are in the EEA or UK, the legal bases we rely on are contract (to provide the service you signed up for), legitimate interests (keeping the service secure and working), and legal obligation (where the law requires us to keep or disclose something). You may object, restrict processing, or complain to your data protection authority.

If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we do not discriminate against you for exercising your rights.

International transfers

Our servers may be in a different country from yours; if they are, using the Service transfers your data there. Where required, we rely on Standard Contractual Clauses.

Children

The Service is not for people under 16. We do not knowingly collect data from them; if we learn we have, we delete it.

Changes

If we change this policy in a way that materially affects you, we will give 30 days' notice by email and in the console. The date at the top always reflects the current version.

Contact

FlowMic (flowmic.app) · github@flowmic.app