Privacy Policy
Your health data is sensitive. Here's exactly how Flowa handles it.
Flowa ("we", "our", or "the app") is a health and spiritual companion app for Muslim women, available on iOS. This Privacy Policy explains what information we collect, how we store and use it, and the rights you have over your data. We are committed to handling your health information with the care and respect it deserves.
1. Information We Collect
When you create an account and use Flowa, we collect the following:
Account Information
- Name and email address (when signing up with email/password)
- Name and email address provided by Google or Apple when using OAuth sign-in
- Date of birth, marital status, and typical cycle length (entered during onboarding)
Health Data
- Menstrual cycle dates (logged and predicted)
- Daily logs: flow intensity, symptoms (e.g., cramps, fatigue), and mood
- Qada fast records: Ramadan year, days missed, reason, and progress made up
- Prayer tracking (stored locally on-device only — see Section 3)
- Ghusl completion dates (stored locally on-device only)
Device & Usage Information
- Notification permission status
- App version and device type (for troubleshooting)
2. How We Store Your Data
Flowa uses Supabase as its backend infrastructure. Your account information and health data (periods, Qada records, daily logs) are stored in a Supabase PostgreSQL database hosted on secure, encrypted servers. Supabase is SOC 2 Type II compliant and encrypts data at rest and in transit.
Certain preference data — including prayer tracking, ghusl reminders, and notification settings — is stored locally on your device using AsyncStorage and is never transmitted to our servers.
3. Apple HealthKit
Flowa does not currently integrate with Apple HealthKit. If HealthKit integration is added in a future version, this policy will be updated prior to the release.
4. How We Use Your Data
We use your data solely to provide and improve the Flowa app experience:
- To calculate cycle predictions and phase information
- To track and display your Qada fast progress
- To send scheduled notifications (period reminders, ghusl reminders)
- To show your cycle insights and daily log history
We do not use your data for advertising, sell it to third parties, or share it with any external services beyond what is described in this policy.
5. Authentication & Third-Party Sign-In
Flowa supports sign-in via email/password, Google, and Apple. When you use Google or Apple sign-in, we receive only your name and email address from those providers. We do not receive access to your Google or Apple account beyond these fields. Each provider's privacy practices are governed by their own policies.
6. Data Retention & Deletion
You can permanently delete your Flowa account at any time from the app's Profile → Settings screen. Deleting your account removes all of your health data, logs, and Qada records from our database. This action cannot be undone.
7. Analytics & Crash Reporting
Flowa does not currently integrate any third-party analytics or crash reporting SDKs. If this changes in a future version, this policy will be updated and users will be notified.
8. Children's Privacy
Flowa is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and notify users within the app where appropriate. Continued use of Flowa after changes constitutes your acceptance of the updated policy.
10. Contact Us
If you have any questions or concerns about this Privacy Policy or how your data is handled, please reach out: