Efflow
FeaturesEcosystemPricingDonate
Sign inGet started

Privacy

Last updated August 12, 2026

The short versionWhat is storedWho it is shared withGoogle user dataHow your data is protectedThe calendar feedKeeping and deletingCookiesContact

The short version

Efflow stores what you put into it so it can show it back to you. It is a single-user app: nothing you write is visible to another account, and none of it is sold, rented or used for advertising.

What is stored

  • Account — your name, email address, and either a password hash or the fact that you signed in with Google or Microsoft.
  • Your content — events, tasks, notes, timers, calendars and the preferences that go with them.
  • Connected calendars (optional) — if you connect Google, Outlook or iCloud, the access tokens for that connection and a read-only mirror of the events it returns — their titles and times only, never descriptions or guests. An Apple app-specific password is encrypted at rest.
  • Billing — a Polar customer id and the status and dates of your subscription. Card numbers are never sent to or stored by Efflow; Polar handles the payment itself.
  • The notify list (optional) — if you ask to be told when mobile or Track opens, your email address and which of the two you asked about. Nothing else: no account is created, and it is used for that one message only. Write to support@efflow.app and the entry is deleted.

Who it is shared with

  • Polar — merchant of record: payments, subscription management, invoicing and sales tax. Polar is the seller of record for Pro, so it collects the billing details a purchase requires and is the data controller for them.
  • Neon (database) and Vercel (hosting) — where the app and its data run, and where the cookieless measurement described under Cookies is collected.
  • Resend — sends account emails such as verification and password resets.
  • Google / Microsoft / Apple — only if you connect a calendar, and only for that connection. Creating a meeting sends the event and its guest list to that provider, which then emails the invitations.
  • Anthropic — only if the optional day-plan polish runs. It sends the titles and times of the day's events and of the suggested blocks, never note bodies, event notes or guests.

Google user data

  • What is requested — signing in with Google shares your name, email address and profile picture. Connecting Google Calendar additionally requests two scopes: calendar.readonly, to read your calendar list and events, and calendar.events, to create the events you ask Efflow to create.
  • What is read and kept — from each calendar, its name and colour; from each event, its Google id, title, start, end and whether it is all-day. Nothing else is copied out of Google Calendar: descriptions, guest lists, locations, attachments and Meet links stay in Google and are never stored by Efflow.
  • What it is used for — exactly two things: showing your Google events alongside everything else on your timeline and planner, and writing back the events you create in Efflow, including a Meet link and the invitations when you add guests. It is not used for anything else, it is never sold or rented, and it is never used for advertising or profiling.
  • AI — Efflow has an optional day-plan feature. When you ask it for a plan, the titles and times of that day's events — which can include events synced from Google Calendar — and the titles and times of the blocks it is proposing are sent to Anthropic's Claude API, so it can drop suggestions that repeat something already on your day. Titles and times only: never descriptions, notes or guests. Anthropic processes them solely to return that response and does not use them to train its models. Nothing is sent unless you open the day-plan yourself.
  • Limited Use — Efflow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is never used to develop, improve or train generalized or foundational machine-learning or artificial-intelligence models, and is never transferred to any third party except as described above and as needed to provide or improve these features, for security purposes, or where required by law.
  • Withdrawing access — disconnect Google under Settings → Integrations, which deletes the mirrored events and imported calendars from Efflow, and revoke the grant itself at your Google account permissions page. Deleting your Efflow account removes the stored tokens along with everything else.

How your data is protected

  • In transit — every connection to Efflow, and every call it makes to Google, Anthropic or any other service listed above, runs over HTTPS with TLS. The database connection requires TLS too.
  • At rest — the database encrypts its contents at rest, as does its storage layer. An Apple app-specific password gets a second layer on top: AES-256-GCM, with a key held only in the server environment, so it is unreadable even to someone holding a copy of the database.
  • Access tokens — OAuth access and refresh tokens for Google and Microsoft are stored server-side and are never sent to the browser, never exposed through the API, and used only for the calendar calls described above.
  • Access control — every read and write is scoped to the id of the signed-in account, so no request can reach another account's data. Sessions are HttpOnly, Secure, SameSite cookies, and expire after 30 days.
  • Minimisation and operations — only the fields listed above are stored in the first place. Credentials and API keys live in a managed secrets store rather than the codebase, and access to the production database and hosting account is limited to the operator of Efflow.

The calendar feed

The subscribe URL under Settings is a secret link: anyone holding it can read your event titles and times. Event notes are stripped from the feed. You can revoke or regenerate the link at any time, which immediately invalidates the old one.

Keeping and deleting

Your data is kept until you delete it. Deleting your account from Settings → Account removes your content and cancels any live subscription; Polar keeps its own payment records for as long as its financial-record obligations require. To request a copy of your data, or deletion by hand, email support@efflow.app.

Cookies

Efflow sets a session cookie so you stay signed in, plus three preference cookies for your theme, accent colour and language. Two measurements run through Vercel, both cookieless and both aggregated: loading speed on every page, and page views with the site that referred them on the public pages only — never inside the app, and never joined to your account. There is no advertising cookie and no cross-site tracking.

Contact

Privacy questions or requests: support@efflow.app. See also the terms of service.

Efflow

A timeline-first day planner for one person. Live and in daily use.

Product
FeaturesPricingChangelogSign inGet started
Ecosystem
Plan for webPlan for mobileEfflow TrackNotify me
More
Support the projectTermsPrivacyContact
© 2026 Efflow · Built by Efflow Devhello@efflow.app