Privacy Policy

Last updated: April 8, 2026

1. What we collect

Flowdesk is a time tracking and productivity tool. We collect:

  • Account info — email, name, password (hashed)
  • Activity data — keystroke counts (never content), mouse click counts, active/idle time, application names
  • Screenshots — only when explicitly enabled by you or your workspace admin. Stored encrypted.
  • Time entries — manual time logs, project assignments, billing amounts
  • Usage analytics — page views, feature usage via PostHog (can be opted out)

2. What we never collect

  • Keystroke content (what you type)
  • Webcam or microphone data
  • Personal files or documents
  • Browsing history outside the tracked applications

3. How we use your data

  • Display your tracked time, productivity metrics, and invoices
  • Sync data between the desktop app and web dashboard
  • Generate reports and analytics for you and your workspace
  • Send transactional emails (invitations, password resets, invoices)
  • Improve the product based on aggregated, anonymized usage patterns

4. Data storage and security

Your data is stored on secure cloud infrastructure (PostgreSQL on Neon, file storage on Supabase). All connections use TLS encryption. Passwords are hashed with bcrypt. JWT tokens are used for authentication with automatic rotation.

5. Third-party services

  • PostHog — product analytics (you can opt out via cookie preferences)
  • Resend — transactional emails
  • Polar — payment processing (they handle payment data; we never see your card details)
  • Supabase — screenshot storage

6. Cookies

We use essential cookies for authentication and optional analytics cookies (PostHog) to understand how the product is used. You can accept or decline analytics cookies via the cookie banner. Your choice is stored in localStorage.

7. Your rights

You can:

  • Export your data at any time (CSV export from the dashboard)
  • Delete your account and all associated data from Settings
  • Opt out of analytics tracking
  • Request a copy of your data by contacting us

8. Data retention

We retain your data for as long as your account is active. When you delete your account, all associated data (sessions, time entries, screenshots, projects) is permanently removed within 30 days.

9. Contact

For privacy-related questions, contact us at flowdesk-onboarding@insetix.com or use our contact form.