Privacy Policy
ProvaFlow is a daily focus app. It lets you create and run focus plans, track timed tasks and work logs, write journal entries, browse shared plans and journals, and manage a paid Pro subscription.
ProvaFlow is intended for people who are at least 16 years old.
ProvaFlow collects the information needed to run those features: account email, password credentials handled by Supabase, username, display name, avatar URL, authentication/session data, onboarding status, Pro status, publish-ban status, plans, task blocks, timer settings, selected active plan, daily session progress, focus time, break time, away time, work-log segments, streak data, journal entries, stars, suggestions, content reports, billing status, Stripe customer and subscription IDs, and first-party product analytics events. ProvaFlow also processes affiliate referral identifiers when a visitor arrives through an affiliate link.
If you sign in with Google, Google and Supabase handle the OAuth sign-in. ProvaFlow receives the account email and may use the Google profile name and avatar URL to prefill your ProvaFlow profile.
ProvaFlow stores app data in Supabase on United States servers. Supabase handles authentication, auth cookies, database storage, first-party analytics storage, and account deletion from ProvaFlow. Resend handles authentication email delivery, such as confirmation and password reset emails, and processes recipient email addresses and message delivery metadata. Stripe handles checkout, payment methods, invoices, subscription management, and the billing portal; ProvaFlow stores Stripe IDs and subscription status, not card numbers. Upstash Redis/Rate Limit is used in production for abuse prevention and rate limiting, including IP addresses and route, user, email, or username identifiers used as rate-limit keys. Vercel hosts the app and may process requests, IP addresses, headers, cookies, and operational logs. Google OAuth handles Google sign-in data. ProvaFlow's product analytics are custom first-party events stored in Supabase, not a separate third-party analytics provider. Tolt provides separate affiliate referral tracking: its script loads on ProvaFlow pages, may set or read a referral identifier in browser storage, and ProvaFlow passes that identifier to Stripe checkout and subscription metadata when one is present so a purchase can be attributed to an affiliate.
ProvaFlow stores some data in your browser so the app can keep working smoothly: active timers and breaks, daily progress, work-log state, offline sync queues, guest session archives, plan-builder drafts, journal drafts, journal remix state, local preferences, theme/audio settings, badge and hint state, first-party analytics IDs and once-only markers, affiliate referral state, and cached shell or audio files. Browser-stored data stays on your device until ProvaFlow overwrites it, removes it, or you clear browser storage. If your browser sends Do Not Track or Global Privacy Control, ProvaFlow's client analytics code does not create an analytics ID or send analytics events.
We do not sell your personal data. Public plans, public journal entries, and public profile pages are intentionally visible to anyone with the link or through community browsing. Public plans can show the plan title, description, tags, task blocks, timer settings, counts, and author profile fields. Public journal entries can show the entry content, date, word count, star count, and author profile fields.
You can delete your own ProvaFlow account and ProvaFlow-stored product data directly in account settings by using Delete account and typing DELETE. That self-service flow deletes your Supabase profile, plans, progress, work logs, journal entries, stars, suggestions, content reports tied to your profile, local billing profile row, and Supabase Auth user. It does not delete records that Stripe, Tolt, Vercel, Upstash, Google, or Supabase may keep in their own systems for billing, referral attribution, security, infrastructure, or operational purposes. After a successful request, the app also clears account-scoped timers, progress, work logs, offline queues, plan drafts, journal drafts, and badge state from the browser used to delete the account. Device-wide preferences, analytics IDs and once-only markers, affiliate referral state, guest archives, audio and hint state, and cached static or audio files remain until ProvaFlow or the relevant provider overwrites them or you clear browser storage.
If you cannot access account settings, contact support@provaflow.app. We may ask for enough information to confirm the account before acting on a request.