Sist oppdatert: 22. august 2026
De juridiske dokumentene foreligger foreløpig kun på engelsk. Den engelske teksten er den gjeldende versjonen.
FlowReader is local-first: by default your reading stays on your device and we never see it. This policy covers the exceptions: the optional services you can turn on, the subscription, and this website. It also covers what rights you have over all of it.
Who is responsible for your data
Privacy enquiries and data requests reach us through the contact form on this site or at contact@flowreader.io.
For data that never leaves your device, which is most of what FlowReader holds, there is no processing by us at all. We are not a controller of your local library, because we have no access to it.
What we process, why, and on what legal basis
Under the GDPR every processing activity needs a lawful basis. These are ours, activity by activity.
- Account and authentication (email address): performance of your contract with us, Art. 6(1)(b)
- Cross-device sync of your library: performance of your contract, Art. 6(1)(b), and only while you have sync turned on
- Subscription, entitlement and billing records: performance of your contract, Art. 6(1)(b), and legal obligation for accounting records, Art. 6(1)(c)
- Newsletter ingestion and server-side Flow execution: performance of your contract, Art. 6(1)(b)
- Sending your content to an AI provider: carried out on your explicit instruction, using your own credentials, and only when you trigger it
- Collection sharing: performance of your contract, and your own decision to invite a named person
- Contact and vulnerability report forms: our legitimate interest in answering you and in keeping the service secure, Art. 6(1)(f)
- Rate limiting the public contact endpoint using a salted hash of your IP address: our legitimate interest in not operating an open spam relay, Art. 6(1)(f)
- Remembering your light or dark theme choice on this website: strictly necessary to provide what you asked for; no consent is required and none is sought
Data stored locally on your device
This never leaves your device unless you enable cloud sync or a feature that sends it elsewhere. We cannot read it, and we cannot produce it for anyone who asks us to.
- Saved articles, web pages and ebook content
- Reading progress, annotations, highlights and notes
- Collections, tags and Smart Rules configuration
- Feed subscriptions and cached feed content
- Reading statistics and usage history
- Application preferences and settings
Optional synchronized data
If you enable Online Sync, your library data is synchronized to FlowReader’s Firebase project. Authentication is Firebase Auth; storage is Cloud Firestore, protected by per-user security rules so that one account cannot read another’s. Your entitlement and billing status are stored so paid features unlock across your devices.
Online Sync is not end-to-end encrypted: the service can technically read what it stores. Dropbox sync and local-folder sync are end-to-end encrypted with a passphrase only you hold, and involve no FlowReader-operated server at all. The security page explains the difference and when each matters.
Account and subscription data
If you subscribe, Stripe processes checkout and billing for desktop, Chrome and Firefox, and Apple processes iOS in-app purchases for the mobile app. We store entitlement status, trial dates, provider identifiers and the billing event records needed to unlock Pro and to support account recovery.
We never store full card numbers or Apple payment credentials. Billing support may involve looking at your account email, Firebase user id, entitlement document and provider event records, and nothing else.
Newsletter and Flow data
These are optional Pro services. Newsletters sent to your private alias are sanitized and delivered into your archive; raw message sources are not retained. A server-side Flow may fetch watchlist targets, search configured sources, collect items, track signals, or produce a cited briefing. The Flow definition states its scope, outputs, runtime and delivery.
Newsletters carry the sender’s data as well as yours. We process it only to deliver the issue into your archive, and we do not use it for anything else.
AI requests
If you use AI features, text from your saved content goes to the provider you select. FlowReader supports Anthropic, OpenAI, Google, Hugging Face and OpenCode Go as hosted providers, and Ollama and LM Studio for models running on your own machine. With a local model, the text never leaves your computer.
Some AI features and Flows can also search the web. When one does, the search query, which may contain text taken from whatever you are reading, goes to the search provider you configured: Brave, Perplexity, LangSearch, TinyFish or Tavily, each on an API key you supply yourself, or a SearXNG instance you point at. OpenAI and Anthropic can alternatively run the search inside the model request itself. Nothing is searched unless you have set a provider up for it.
You supply your own API key and we do not proxy the requests, so we never see the content or the responses. The provider’s privacy policy governs what happens to it there, and it is worth reading. Providers differ on retention and on training.
API keys are stored locally, in the system keychain on desktop, and are never synchronized. When a server-side Flow output requires AI, your key is encrypted on your device so only the Flow runtime can decrypt it. Deterministic collection and compatible signals do not require an AI key.
What we do not do
FlowReader collects no analytics and no telemetry. We do not track your reading, serve advertisements, use fingerprinting or tracking cookies, or build a profile of you. We do not sell your personal data, and we do not share it with anyone for their own purposes. The service providers listed below act only on our instructions.
This website
This site loads no analytics, no tracking scripts, no third-party fonts and no advertising, and it sets no cookies. One external resource is loaded, on two pages only: the contact page and the vulnerability disclosure page each run a Cloudflare Turnstile check, which is what stops the message form being used as a spam relay. It is named on the page it appears on, it is not analytics, and it does not follow you to any other site. Every other page on this site loads nothing but this site. It writes two things to local storage in your browser, both of which stay on your device and neither of which is ever sent anywhere: your language choice under “flowreader.lang” and, for as long as the site is in closed preview, the preview password you entered, under “flowreader-preview-unlock”. Both exist only so the site does not forget something you have already told it, which is what makes it strictly necessary and why no consent is asked for it.
The contact and vulnerability report forms do submit to us. When you send one, the name, email address, topic and message you typed are posted to a FlowReader Cloud Function hosted in europe-west1 and relayed by email to our contact or security mailbox through Resend, our email delivery provider. The message is not stored in a database and is not written to any log.
Before the message is relayed, the Turnstile check on the form is verified with Cloudflare. That verification sends Cloudflare the token the check produced and your IP address; it sets no cookie on this site and Cloudflare does not use it to build a profile of you. To stop the endpoint being used as a spam relay, it also rate-limits by IP address. What is written down is your address combined with a secret salt and hashed with SHA-256, never the address itself, and the record is deleted automatically two hours later. Nobody who does not hold that salt can work back from a stored value to an address. We still treat the hash as your personal data, because we hold the salt, so every right below applies to it. If you would rather not use the form at all, the same addresses accept ordinary email.
Service providers
Each of these is involved only when you use the feature it supports, and each acts on our instructions rather than for its own purposes. The subprocessors page lists them in full, with what each one receives, where it is, and the transfer mechanism relied on.
- Google Firebase: authentication, Firestore sync storage, Cloud Functions
- Stripe: subscription checkout, billing portal and payment processing
- Apple: in-app purchases for the mobile app
- Resend: delivery of contact and vulnerability report emails
- Cloudflare: the Workers running newsletter ingestion, subscriptions and flows, and the Turnstile spam check on this site’s contact and vulnerability report forms
- Your chosen AI provider: only the content you send it, using your own key
- Your chosen web search provider: only the query, when an AI feature or Flow searches the web, using your own key
Where your data is, and international transfers
The FlowReader-operated services are pinned to the EU. Cloud Firestore and our Cloud Functions run in europe-west1, in Belgium. That is where synced library data, entitlement records and the contact endpoint live.
Some of the providers above are established outside the EEA, or may process data outside it: Stripe, Apple, Resend, Cloudflare, and any hosted AI provider you choose. Where that happens, the transfer relies on the European Commission’s Standard Contractual Clauses or on an adequacy decision covering that provider. The mechanism relied on for each one is stated on the subprocessors page.
If you use a local model through Ollama or LM Studio, no transfer occurs at all, because nothing leaves your machine.
How long things are kept
Data on your device is kept until you delete it: that is your decision, not ours, and we cannot delete it for you.
- Synchronized library data: while sync is enabled, and until you delete it or your account. Account deletion removes it
- Account record: until you delete your account
- Billing and accounting records: for the statutory accounting retention period that applies to us, which is five years in Norway. These survive account deletion because the law requires it
- Contact and vulnerability messages: kept in the mailbox while the matter is open, and deleted within 24 months
- Contact rate-limit hashes: two hours, then deleted automatically
- Newsletter issues: held in your archive until you delete them
Security and what happens if something goes wrong
Local data is stored in a SQLite database on your device, and credentials in platform-secure storage. Online Sync is protected by account authentication, TLS in transit, and per-user Firestore rules. Folder and Dropbox sync are end-to-end encrypted with AES-256-GCM and keys derived with PBKDF2 at 600,000 iterations. We claim no security certification, no external audit and no zero-knowledge architecture, because we have none.
If a personal data breach happens and it is likely to result in a risk to your rights and freedoms, we will report it to Datatilsynet, the Norwegian Data Protection Authority within 72 hours of becoming aware of it. If the risk to you is high, we will tell you directly and without undue delay, and we will say what happened rather than what is comfortable.
If you have found a weakness, the vulnerability disclosure page tells you how to report it and what we commit to in return.
Your rights
If the GDPR or UK GDPR applies to you, you have the rights below. Most of them you can exercise yourself, in the app, without asking us, which is faster than any request process we could offer.
- Access: your data is visible in the app, and you can export the whole library at any time in JSON, OPML and FlowCollection formats
- Rectification: edit anything in the app; for account or billing records, ask us
- Erasure: delete local data from Settings; with sync on, delete your remote data and your account from the same place
- Restriction and objection: ask us to stop a particular processing, including anything we do on the basis of legitimate interests
- Portability: exports are in open formats, and importable elsewhere
- Withdraw consent: where processing rests on consent, withdrawing it is as easy as giving it, and does not affect what was lawful before
- Complain: you can lodge a complaint with Datatilsynet, the Norwegian Data Protection Authority, or with the supervisory authority where you live or work, at any time and without going through us first
Making a request
Send data requests through the contact form or to the address below. We answer within one month, and will tell you if a request is complex enough to need longer, up to two further months, with reasons. There is no charge unless a request is manifestly unfounded or excessive.
We may need to confirm you control the account email before acting on a request, because handing someone else’s reading history to whoever asks for it would be the worse failure.
If you are in the United States
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, under the CCPA definitions or any other. There is nothing to opt out of, because the thing you would opt out of does not happen.
California residents may request to know what personal information we hold, to have it deleted, to have it corrected, and to receive it in a portable form. Exercising any of these will never get you worse service or a different price. Use the same contact route as everyone else; we do not operate a separate, slower channel for privacy requests.
Children’s privacy
FlowReader is not directed at children and we do not knowingly collect personal data from children under 13. Across the EEA the age of consent for information society services is set nationally between 13 and 16; we do not knowingly process the data of anyone under the age that applies where they live without parental consent.
A subscription is a contract, and the terms of service set the minimum age for entering one. If you believe a child has given us data, tell us and we will delete it.
Changes to this policy
This policy may be updated. The date at the top always reflects the current version, and material changes are noted in the changelog. If a change affects how we process data you have already given us, we will tell you rather than rely on you re-reading this page.
Contact
For privacy questions or data requests: the contact form on this site, or contact@flowreader.io.