Effective and last updated: September 22, 2026
1. Scope
This policy applies to flowlax.app, Self Bank at selfbank.flowlax.app, and support requests sent to Flowlax. Other Flowlax prototypes may receive separate notices before they add accounts or cloud services.
2. Information we process
- Account information, including email address, user ID, authentication status, and account timestamps.
- Content you choose to record, including goals, check-ins, habit events, notes, action lists, settings, and progress data.
- Technical information needed to deliver and secure the service, such as IP address, browser information, requested page, timestamps, and error or security logs.
- Support messages and the contact details you include when emailing us.
- When paid plans begin, subscription status, product, billing period, payment outcome, and transaction identifiers supplied by our merchant of record. Flowlax does not receive or store full payment card numbers.
3. Local storage and cloud sync
Self Bank first stores working data in the browser. After you sign in, supported records are copied to your account in Supabase for cross-device sync. Signing out clears the app's private cache on that browser, while cloud records remain until they are deleted through an available control or support request. The brand website stores only the selected language in browser storage.
4. Why we use information
We use information to create and secure accounts, sync records, provide product features, answer support requests, manage subscriptions, prevent abuse, fix errors, and comply with legal obligations. We do not sell personal information or use private habit records for targeted advertising.
5. Service providers
We use Cloudflare for hosting and security, Supabase for authentication and cloud data, Resend for account email, and CREEM as the planned merchant of record for checkout, tax handling, receipts, subscription management, and refunds. These providers process information under their own terms and privacy commitments. Information may be processed outside your country.
6. Retention and deletion
Account and cloud records are generally kept while the account is active. Support, security, transaction, and legal records may be retained as needed for legitimate operational or legal purposes. You can clear local records in the app. To request account or cloud-data deletion, email [email protected] from the account email address. We may retain limited records when required for fraud prevention, tax, dispute, or legal compliance.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to certain processing. You may also withdraw consent where consent is the basis for processing. Email [email protected] to make a request. We may need to verify that you control the account.
8. Security and sensitive content
We use access controls, encrypted connections, and row-level database rules designed to separate user accounts. No online service can guarantee absolute security. Self Bank may hold sensitive personal reflections, so record only what you are comfortable storing and never place passwords, government identifiers, or payment card details in notes.
9. Adults only
Self Bank is intended only for people aged 18 or older. We do not knowingly collect account information from children. Contact us if you believe a minor has created an account.
10. Changes and contact
We may update this policy as the products or legal requirements change. The current version and effective date will remain available on this page. Privacy questions and requests can be sent to [email protected].