Privacy Policy

Effective Date: August 11, 2026 Last Updated: August 11, 2026

AI scheduling is optional. Before S-Flow sends an AI request, the app explains what will be sent, names the approved external AI providers, and asks for your permission. Choosing “Not now” sends no AI request. You can withdraw permission in Settings at any time.

This Privacy Policy explains how Castilho Enterprises (“S-Flow”, “we”, “us”, or “our”) collects, uses, shares, stores, and deletes information when you use the S-Flow day-planning application, cloud synchronization, backups, calendar integration, widgets, and AI scheduling.

1. Information we process and how we receive it

CategoryExamples and sourceWhy we use it
Schedule and user contentTask and event titles, notes, subtasks, tags, completion status, recurrence, durations, start/end times, reminders, and planning preferences that you enter or import.Display and manage your schedule, synchronize your devices, create backups, resolve conflicts, and prepare AI proposals when requested.
Calendar informationCalendar names, availability, and event details accessed through system calendar permission. S-Flow reads or writes only when the relevant calendar feature is enabled.Show integrated events, write approved changes to a selected calendar, find availability, and warn about conflicts.
AI request contentText requests, raw voice recordings, and follow-up answers you choose to submit. This can contain personal information depending on what you say or type.Interpret the request and prepare a scheduling proposal.
AI request metadataRequest time, time zone, language/locale, first day of week, calendar capability flags, and planning preferences such as scheduling hours, lunch protection, or buffers.Understand dates and constraints and produce a relevant proposal.
Account informationFirebase user identifier and, if you link an account, the sign-in provider, provider identifier, email address, and profile details made available by Apple or Google.Create and secure your S-Flow account, link devices, and provide cloud features.
Subscription informationProduct, entitlement, purchase, renewal, expiration, and restore status supplied by Apple and RevenueCat.Provide Premium features and prevent unauthorized access.
Device and operational informationApp version, platform, installation/device identifier, synchronization revisions, request outcome, latency, token usage, error codes, IP address, and short-lived server logs. Our privacy-safe AI diagnostics are designed not to store raw prompts, voice recordings, or schedule content.Operate, secure, troubleshoot, measure, and control the cost and reliability of the service.
Support communicationsMessages and information you send when contacting support.Respond to requests and investigate problems.

2. Where information is stored

Your schedule is stored locally on your device. If you enable Premium cloud synchronization or backups, supported schedule records and preferences are also sent securely to S-Flow’s backend and PostgreSQL database so they can be synchronized or restored across your devices. Provider-owned native calendar events are not copied into ordinary S-Flow cloud backups; however, relevant calendar details may be sent temporarily to S-Flow’s server when you ask AI scheduling to reason about availability, targets, or conflicts.

3. AI scheduling and external AI providers

S-Flow may route a request to one of the following approved external AI processors depending on availability, performance, and cost:

  • Google Gemini API — Google LLC / applicable Google contracting entity
  • OpenAI API — OpenAI, L.L.C. / applicable OpenAI contracting entity
  • Anthropic Claude API — Anthropic, PBC / applicable Anthropic contracting entity

After you grant permission and submit a request, the selected provider receives your typed request or voice recording, follow-up answers, request time, time zone, language, planning preferences, and any personal information you include in the request. Relevant task and calendar context is sent to S-Flow’s own backend for deterministic target matching, availability, and conflict resolution. Your full schedule is not sent to the external AI provider by default unless you put those details in the request itself.

We use commercial/API offerings under which customer content is processed to provide and secure the service and is not used to train the provider’s general models unless we separately disclose that change and obtain any required permission. Providers may retain limited data for safety, abuse prevention, legal compliance, or as described in their commercial terms and data-processing agreements.

Nothing is added, moved, edited, completed, or deleted until you review the proposal and approve selected changes. AI output can be inaccurate; review every proposal before applying it.

Your AI permission

AI permission is separate from calendar, microphone, account, and notification permissions. You can decline AI processing and continue using non-AI parts of S-Flow. You can review or withdraw AI permission at Settings → AI Planner → AI data sharing. After withdrawal, S-Flow blocks new text, voice, and follow-up AI requests until you grant permission again. If we add a new AI provider or materially change the disclosed processing, the app will require permission for the updated disclosure.

AI scheduling is restricted to users who confirm they are at least 18 years old.

4. Other service providers

We share only the information needed for the following providers to perform services for S-Flow:

  • Google Firebase for anonymous authentication, Google sign-in, and related account infrastructure.
  • Apple for Sign in with Apple, App Store purchases, system calendar access, and device services you choose to enable.
  • Google for Google sign-in and Google calendar functionality you choose to enable.
  • RevenueCat for subscription entitlement and purchase-status management.
  • Google Gemini API, OpenAI API, or Anthropic Claude API for optional AI processing as described above.

We require processors that receive personal data to provide the same or equivalent protection described in this policy and required by applicable law. We do not sell personal information, serve behavioral advertising, or use this information to track you across other companies’ apps or websites.

5. Legal reasons for processing

Depending on where you live, we rely on: performance of our contract to provide the app, account, subscription, synchronization, and backup features; your consent for optional AI sharing and device permissions; legitimate interests in securing, debugging, and improving service reliability; and legal obligations such as responding to valid requests or maintaining transaction records.

6. Retention and deletion

  • Local data: remains on your device until you delete it, reset the app, or uninstall the app, subject to device backups controlled by you or the operating system.
  • Active cloud data: remains while cloud synchronization/backups are active and as needed to provide the service.
  • Expired Premium cloud data: is retained for three months by default to permit resubscription and recovery. Support may grant a longer or indefinite hold when requested. Account deletion and valid privacy-deletion requests override these holds.
  • AI audio and request bodies: are processed for the request and are not intentionally stored by S-Flow as ordinary account content. External providers may retain limited copies under their commercial/API terms for safety, abuse prevention, or law.
  • Operational and diagnostic records: are retained only as long as reasonably necessary for security, troubleshooting, abuse prevention, cost control, and legal compliance, then deleted or aggregated.
  • Purchase records: may be retained as required for accounting, fraud prevention, and legal obligations.

You can delete your cloud account from the Cloud & Account screen. Deleting the cloud account removes server-side account and synchronized content according to the deletion workflow; local schedule data can remain on the device unless you separately remove it.

7. International transfers and security

S-Flow and its processors may handle information in countries other than yours. Where required, we use contractual and legal safeguards for transfers. We use transport encryption, authentication, access controls, data minimization, and operational safeguards. No system is completely secure, so please avoid putting unnecessary sensitive information into task names, notes, or AI requests.

8. Your choices and rights

You can edit or delete schedule content, disable calendar synchronization, deny or revoke microphone/calendar/notification permissions in system settings, withdraw AI permission in S-Flow, unlink a cloud account where available, restore purchases, and delete your account. Depending on your location, you may also request access, correction, portability, restriction, objection, or deletion and may complain to your local data-protection authority.

9. Children

S-Flow’s AI scheduling feature is not directed to people under 18 and requires an age confirmation before use. We do not knowingly allow an under-18 user to submit data to the AI feature. If you believe a minor has provided personal data through AI scheduling, contact us so we can investigate and delete it where appropriate.

10. Changes to this policy

We may update this policy as the app, providers, or law changes. We will update the effective date and provide additional notice or request permission again when required. The in-app AI disclosure always names the providers approved for AI request processing at that time.

11. Contact

For privacy questions or requests, contact Castilho Enterprises at realcastilhoenterprises@gmail.com.