Privacy policy
Last updated 6 October 2026
This policy explains what AuraFlow, an app by Tanner Frequency, collects, how it is used, who can see it, and how you can delete it. It covers the AuraFlow Android app, the AuraFlow Windows app, and these pages. We wrote it to be read, so it is plain on purpose.
The short version
- AuraFlow has no ads, no advertising or analytics trackers, and we do not sell your data.
- Your plans sync between your own devices through a private account on Google's Firebase. Only you, and the family members you invite, can see what is meant for them.
- Connecting Google is optional. If you do, AuraFlow asks for the narrowest permissions possible, keeps your Google sign-in keys on your device, and never reads your email.
- The assistant runs on your own device. Google user data is never used to train AI or machine learning models.
- You can delete your account and data at any time. See how to delete your account.
1. Who we are
AuraFlow is made by Tanner Frequency. Questions about this policy or your data go to support@tannerfrequency.com.
2. What we collect and why
AuraFlow only handles what it needs to do its job. Here is all of it.
| What | Details and why |
|---|---|
| Your account | You sign in with Google through Firebase Authentication. We receive your Google account email address, display name, profile picture address and a unique account ID. This is how AuraFlow knows which plans are yours and lets two devices belong to the same person. |
| What you put in AuraFlow | Tasks and appointments (including places you type), repeating appointments, habits and their history, water entries, medications and the doses you check off, body care and other routines and their logs, rooms and chores, side quests, progress points and levels, intentions and projects, bills and income entries you add, timers, wake-up alarms, sleep logs, rituals and a dream journal, tags, statuses, templates, goals and day plans, notes you capture, and your settings. This is stored in your private account area (Cloud Firestore) so your devices stay in step. It is also stored on each device. |
| Family sharing | Only if you create or join a family. See section 5. |
| Device identifiers for notifications | A Firebase Cloud Messaging token for each device, so AuraFlow can send you reminders and family notifications. It is removed when it stops working. |
| Rough location (Android, optional) | Only if you turn on "where I am" for drive time, or choose to set your place for sunrise and sunset rituals. See section 4. |
| Google Calendar and Google Tasks (optional) | Only if you tap Connect Google. See section 3. |
| Microphone (optional) | Only when you tap the microphone to dictate. See section 6. |
| Technical logs | Our servers (Google Cloud Functions) keep ordinary operational logs. For drive-time work we write only your account ID and an item ID in them, never titles, names or addresses. |
We do not collect your contacts, your files, your photos, your email, your advertising ID or your precise location in the background. AuraFlow has no analytics or advertising software in it.
Crash reporting
AuraFlow does not currently send crash reports. If crash reporting is enabled in a future version, it will use Firebase Crashlytics, we will describe exactly what it sends here before it ships, and it will have an off switch.
3. Google user data (Connect Google)
Connecting Google is optional and starts only when you tap Connect Google in Settings. Signing in to AuraFlow with Google is separate and uses only your basic account details (section 2).
Google API Services User Data Policy: Limited Use
AuraFlow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain words: we use Google user data only to provide the features you see in AuraFlow. We do not sell it, we do not use it for advertising, we do not let people read it except as described here, and we do not use it to develop, improve or train AI or machine learning models, whether generalized or not.
Permissions AuraFlow asks for
AuraFlow asks for the five narrowest Google permissions that do the job. The first three are asked when you connect. The last two are asked only if you turn on "Bring in my Google calendars".
| Permission | What it lets AuraFlow do, and why |
|---|---|
userinfo.email |
See your Google account email address, so AuraFlow can say "Connected as ..." and recognise that two of your devices use the same Google account. |
calendar.app.created |
Make a secondary calendar called AuraFlow and manage the events on that calendar only. This is where your appointments are put. It gives AuraFlow no access to your other calendars. |
tasks |
Create and update a Google Tasks list called AuraFlow with your to-dos that have a day, and notice when you tick one off in Google Tasks so AuraFlow can ask "Done in Google?". Google has no narrower permission for Tasks. |
calendar.calendarlist.readonly |
Import only: see the list of your calendars so you can choose which to show in AuraFlow. Read only. |
calendar.events.readonly |
Import only: read the events of the calendars you chose, so they appear beside your AuraFlow plans. Read only. |
The full permission addresses begin with https://www.googleapis.com/auth/. You can untick any of them on Google's consent screen, and AuraFlow will switch off only the feature that needs it.
How Google user data is accessed, used, stored and shared
- Sign-in keys stay on your device. On Android, Google Play services holds the grant. On Windows, the refresh token is kept in Windows Credential Manager for your Windows user only, and short-lived access tokens are kept in memory. AuraFlow's servers never receive or store a Google access or refresh token.
- What goes to Google: the titles, days, times, places and the leave-by line of your appointments and to-dos, sent straight from your device to Google Calendar and Google Tasks. Notes, subtasks, drive-time minutes and other people's data are never sent.
- What comes from Google: your email address (to show who is connected), the ticks you make in Google Tasks, and, only if you turn on import, your chosen calendars' names and their events from the past 7 days and the next 60 days, up to 200 events per calendar.
- What we store: a record in your private AuraFlow account area holding the Google ids of the calendar and list AuraFlow made, change markers, a one-way hash of your Google email (not the email itself), and the status shown on your devices. If you turn on import, a copy of the chosen calendars' events (the window above) is kept in your private account area so it can show on all your devices. Only you can read it.
- Who else can see it: no one. Google user data is not shown to your family members, not shared with other companies, and not used for advertising. We do not read it. The only exceptions are if you tell us to, if the law requires it, or if it is needed to keep AuraFlow secure.
- We never read your Gmail, ask for access to your whole Google Calendar, or change events on your own calendars.
- Stopping it: tap Disconnect in AuraFlow Settings, or remove AuraFlow at myaccount.google.com/permissions. When you disconnect, AuraFlow stops writing to Google and deletes its stored copy of imported events. The AuraFlow calendar and Tasks list already created stay in your Google account until you delete them there.
Optional: your own Apps Script
For people who prefer it, AuraFlow Settings has an advanced path that uses a small Google Apps Script running in your own Google account. It can send your plans to your Google Calendar and Tasks, and it can forward emails whose subject starts with "task:", or items you add to Google Tasks by voice, to AuraFlow. That script is yours, runs under your own Google authorization (not AuraFlow's), and signs what it sends to AuraFlow's servers with a secret only you hold. AuraFlow's servers receive only the items the script sends. You can remove the script at any time.
4. Maps, drive time and location
- Drive time is optional and works per appointment. When you ask for it, AuraFlow's server (a Google Cloud Function) sends the place you typed, and your saved home address or current position, to Google's Places and Routes APIs using AuraFlow's own project credentials. It returns a place and a drive estimate so AuraFlow can show when to leave. There is no Maps key inside the app.
- "Where I am" is Android only, asks for approximate (coarse) location on your tap, never runs in the background, and the position is rounded to about a city block (3 decimal places, roughly 110 metres) before it is used. While an appointment is coming up, that rounded position is kept on a server-only record used to send you a "time to leave" notification.
- The place coordinates live only in the drive-time record for that appointment. When that record is cleared, the coordinates are erased rather than kept.
- Sunrise and sunset rituals: if you choose "use my location", the position is rounded to one decimal place (about 11 kilometres) and stays on your device. Typing a city uses a list built into the app and calls no service.
- Directions: when you tap to navigate, AuraFlow opens Waze or Google Maps on your device with the destination. From then on, that app's own privacy policy applies.
- Limits: we cap how many place searches and drive checks one account can make per day, so a mistake cannot run up usage.
5. Family sharing
Family features exist only if you create a family or accept an invitation. A family is a household of people, each with their own AuraFlow account.
- What family members can see: your display name, and a daily summary made of numbers only: points and level, tasks finished, water, minutes moving, and the goals those are measured against. If you turn on "Share meds done", also a count of doses taken out of doses due. They never see task titles (except ones you send or share), medication names, doses or times. If you turn off "Share my daily progress", nothing is sent at all.
- What only two people see: a to-do you send to someone, a nudge, a cheer, or a note or proposal is visible only to the sender and the recipient.
- Shared household tasks are visible to every member of the family until one of you finishes them.
- Your control: you can allow or stop notes, proposals and voice from each person, pause them, and leave the family at any time. Family notes are kept for 12 months and then removed automatically. Scheduled notes are removed 30 days after delivery.
- Voice messages: AuraFlow has the permission screens for family voice messages, but sending voice recordings is not part of the current release. If it ships, recordings will be kept on our servers for 30 days at most, and we will update this page first.
6. On-device AI, voice and notifications
- The assistant runs on your device. AuraFlow uses WebLLM to run a language model on your own device's graphics hardware. What you type or say to it, and the plans it works from, are not sent to us or to an AI company. The first time you use it, the model files are downloaded to your device from a public model host.
- Dictation uses the speech recognition built into your device (on Android, the system speech recognizer; in desktop browsers, the browser's own; on Windows, Windows voice typing). That service may be run by your device maker or Google under its own privacy policy. AuraFlow receives only the text. AuraFlow does not record or keep audio.
- Reading aloud uses your device's text-to-speech engine.
- Notifications: AuraFlow asks permission before sending notifications. Most reminders are scheduled on the device itself. Some, like a family nudge or a "time to leave" alert, are sent through Firebase Cloud Messaging. On a locked phone they show only that something arrived, not what it says.
- Sharing into AuraFlow: on Android you can share text to AuraFlow from other apps. AuraFlow receives only what you choose to share.
7. Who processes your data
We use Google as our service provider:
- Firebase and Google Cloud (Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging) in the United States (
us-central1) to sign you in, store and sync your plans, run the server tasks above and deliver notifications. Google encrypts this data in transit and at rest. - Google Maps Platform (Places and Routes), through our servers, only for the drive-time feature.
- Google Calendar and Google Tasks, only if you connect Google.
We do not use advertising networks, data brokers or analytics companies. We may share data if the law requires it, or to protect the safety of AuraFlow's users. If AuraFlow is ever sold or merged, we will tell you first and this policy will continue to apply to your data. Because Firebase is run from the United States, your data is processed there, whatever country you are in.
8. How we protect it
- Everything travels over encrypted connections.
- Database rules mean each account can read and write only its own data, and family members only the shared parts above. Server-only records, like drive-time estimates, cannot be written by the app.
- Google sign-in keys stay on your device (section 3).
- No system is perfectly safe. If we learn of a breach that affects you, we will tell you.
9. How long we keep it
- Your plans and account data are kept while your account exists, so your devices can sync.
- Family notes: 12 months. Scheduled notes: 30 days after delivery.
- Notification tokens: until they stop working or you delete your account.
- Imported Google calendar events: until you disconnect or delete your account.
- Drive-time coordinates: erased when the drive-time record is cleared.
- When you delete your account, your data is deleted as described on the delete account page.
- Data on your own devices stays there until you sign out, delete it in the app, or uninstall AuraFlow.
10. Your choices and rights
- See and export your data: your plans are in the app, and Settings has a full backup export as a file.
- Change or delete anything you entered, directly in the app.
- Turn things off: notifications, location, microphone and each family sharing option can be switched off in AuraFlow or in your device settings.
- Disconnect Google at any time (section 3).
- Delete your account and everything in it: see delete your account.
- Depending on where you live, you may have extra rights, such as access, correction, deletion, portability, objection, and the right to complain to your local data protection authority. Write to support@tannerfrequency.com and we will respond within 30 days. We do not sell or share personal information in the sense used by US state privacy laws.
11. Children
AuraFlow is not directed to children under 13, and you must be at least 13 to use it. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us personal information, write to us and we will delete it.
12. Changes to this policy
If we change this policy in a way that matters, we will update the date at the top and tell you in the app before the change takes effect. If we ever want to use Google user data in a way not described here, we will ask for your consent first.
13. Contact
Tanner Frequency
support@tannerfrequency.com
Or visit the support page.