Privacy Policy

This Policy explains what data Daily Flow collects, how it is used, and who it is shared with. By using the App, you agree to what is described here.

1. What data we collect

Account data: email, name (optional), chosen language and currency. If you sign in with Google, we receive the email and name from your Google account.

Financial data you enter: transactions (amount, category, description, date), recurring bills, savings goals, investments, and reported income. This data is used solely to show your own information back to you, in summaries, history, and analysis.

Technical data: a push notification subscription identifier (if you enable it), your billing region (Brazil or rest of the world, set from the country detected on your first visit), and usage events tied to your account, such as which screens are used, time spent, whether an entry was completed and, when typed text is not understood, the text itself. This helps us understand and improve the App. These events stay in our own database and are not sent to third-party analytics tools. The exceptions are described in sections 2 and 3.

Voice: when you use voice entry, speech recognition is done by your browser or your device system. We do not receive or store the audio, only the text of the entry.

2. Who we share data with

We do not sell your data. We use the following service providers, which process data on our behalf:

• Supabase: database hosting and authentication.

• Vercel: website hosting.

• Stripe: payments for subscriptions made on the website. We never see your card number.

• Apple (App Store) and Google (Google Play): payments for subscriptions made in the mobile apps.

• RevenueCat: manages and syncs the status of subscriptions made in the stores, using your account identifier.

• Resend: transactional emails, such as signup confirmation and password reset.

• Sentry: error monitoring on the website, so we know when something breaks. Reports may include technical data about your browser and the page where the error happened.

• Meta Platforms (Meta Pixel): ad effectiveness measurement, on the website only and only if you accept. See section 3.

• Google: sign-in with your Google account, if you choose that method.

Push notifications are delivered by the notification service of your browser or your system.

3. Meta Pixel (website only)

On the website (browser and installable version), we use the Meta Pixel to measure whether Daily Flow ads lead to signups. It is only loaded after you accept the consent notice. The legal basis is your consent.

If you accept, the Pixel sends Meta Platforms page view and completed signup events, along with technical browser information such as IP address and identifiers. It may set cookies or identifiers in your browser. Meta may use this data under its own policy.

If you decline, the Meta script is not loaded and no data is sent to Meta.

You can change your mind at any time under Settings > Privacy or with the "Privacy preferences" link in the footer of the home page. When you withdraw consent, the Pixel stops sending data and we remove its cookies from our domain.

To know how many visitors accept, we record anonymously, without identifying you, only the choice itself (accept, decline, or withdraw). This record does not store an IP address, an identifier, or device data.

Regardless of the Pixel, we anonymously count visits to the home page of the website, along with where the visit came from (such as the link of a promotion or the site you came from). The count does not store an IP address or an identifier. We keep that origin on your device for up to 30 days and, if you create an account, it is linked to your signup so we know which promotion you came from.

The Pixel is not loaded in the mobile apps (Android and iPhone). We do not send it your entries, amounts, or categories.

4. International data transfers

Our database is located in Ireland (European Union, within the European Economic Area), hosted by Supabase. This means data is transferred outside Brazil. Other providers listed above, such as Stripe, Vercel, Meta, RevenueCat, Sentry, Resend, Google, and Apple, may also process data in other countries, as applicable. In these cases, the data is subject to the protection rules of each provider and of the country where it is processed.

5. Administrative access

As the party technically responsible for the App, the operator has administrator-level database access, needed for operation, support, and troubleshooting, but does not actively monitor individual users' entries. The operator's own actions on their test account are excluded from aggregate usage statistics.

6. Security

We apply access controls (Row Level Security) that ensure each user can only access their own data through the App. Passwords are never stored in plain text.

7. Your rights

Under the Brazilian data protection law (LGPD), you can ask for confirmation that we process your data, access to it, correction, portability, information about who we share it with, deletion, and withdrawal of consent, where processing depends on it.

Within the App, you can review and edit your entries, withdraw your Pixel consent under Settings > Privacy, and close your account and delete all associated data under Settings > Delete account. For other requests, write to suporte@dailyflow-app.com.

8. Retention

We keep your data while your account is active. When you close your account, data is permanently erased, except where retention is legally required, such as for payment tax records. Data sent to the providers in section 2, such as error reports and Pixel events, is subject to their retention rules.

9. Controller and contact

The data controller is the operator of the App identified in the Terms of Use. Questions and requests about this Policy can be sent to suporte@dailyflow-app.com.