AuraFlow

Privacy policy

Last updated 6 October 2026

This policy explains what AuraFlow, an app by Tanner Frequency, collects, how it is used, who can see it, and how you can delete it. It covers the AuraFlow Android app, the AuraFlow Windows app, and these pages. We wrote it to be read, so it is plain on purpose.

The short version

  • AuraFlow has no ads, no advertising or analytics trackers, and we do not sell your data.
  • Your plans sync between your own devices through a private account on Google's Firebase. Only you, and the family members you invite, can see what is meant for them.
  • Connecting Google is optional. If you do, AuraFlow asks for the narrowest permissions possible, keeps your Google sign-in keys on your device, and never reads your email.
  • The assistant runs on your own device. Google user data is never used to train AI or machine learning models.
  • You can delete your account and data at any time. See how to delete your account.

1. Who we are

AuraFlow is made by Tanner Frequency. Questions about this policy or your data go to support@tannerfrequency.com.

2. What we collect and why

AuraFlow only handles what it needs to do its job. Here is all of it.

WhatDetails and why
Your account You sign in with Google through Firebase Authentication. We receive your Google account email address, display name, profile picture address and a unique account ID. This is how AuraFlow knows which plans are yours and lets two devices belong to the same person.
What you put in AuraFlow Tasks and appointments (including places you type), repeating appointments, habits and their history, water entries, medications and the doses you check off, body care and other routines and their logs, rooms and chores, side quests, progress points and levels, intentions and projects, bills and income entries you add, timers, wake-up alarms, sleep logs, rituals and a dream journal, tags, statuses, templates, goals and day plans, notes you capture, and your settings. This is stored in your private account area (Cloud Firestore) so your devices stay in step. It is also stored on each device.
Family sharing Only if you create or join a family. See section 5.
Device identifiers for notifications A Firebase Cloud Messaging token for each device, so AuraFlow can send you reminders and family notifications. It is removed when it stops working.
Rough location (Android, optional) Only if you turn on "where I am" for drive time, or choose to set your place for sunrise and sunset rituals. See section 4.
Google Calendar and Google Tasks (optional) Only if you tap Connect Google. See section 3.
Microphone (optional) Only when you tap the microphone to dictate. See section 6.
Technical logs Our servers (Google Cloud Functions) keep ordinary operational logs. For drive-time work we write only your account ID and an item ID in them, never titles, names or addresses.

We do not collect your contacts, your files, your photos, your email, your advertising ID or your precise location in the background. AuraFlow has no analytics or advertising software in it.

Crash reporting

AuraFlow does not currently send crash reports. If crash reporting is enabled in a future version, it will use Firebase Crashlytics, we will describe exactly what it sends here before it ships, and it will have an off switch.

3. Google user data (Connect Google)

Connecting Google is optional and starts only when you tap Connect Google in Settings. Signing in to AuraFlow with Google is separate and uses only your basic account details (section 2).

Google API Services User Data Policy: Limited Use

AuraFlow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain words: we use Google user data only to provide the features you see in AuraFlow. We do not sell it, we do not use it for advertising, we do not let people read it except as described here, and we do not use it to develop, improve or train AI or machine learning models, whether generalized or not.

Permissions AuraFlow asks for

AuraFlow asks for the five narrowest Google permissions that do the job. The first three are asked when you connect. The last two are asked only if you turn on "Bring in my Google calendars".

PermissionWhat it lets AuraFlow do, and why
userinfo.email See your Google account email address, so AuraFlow can say "Connected as ..." and recognise that two of your devices use the same Google account.
calendar.app.created Make a secondary calendar called AuraFlow and manage the events on that calendar only. This is where your appointments are put. It gives AuraFlow no access to your other calendars.
tasks Create and update a Google Tasks list called AuraFlow with your to-dos that have a day, and notice when you tick one off in Google Tasks so AuraFlow can ask "Done in Google?". Google has no narrower permission for Tasks.
calendar.calendarlist.readonly Import only: see the list of your calendars so you can choose which to show in AuraFlow. Read only.
calendar.events.readonly Import only: read the events of the calendars you chose, so they appear beside your AuraFlow plans. Read only.

The full permission addresses begin with https://www.googleapis.com/auth/. You can untick any of them on Google's consent screen, and AuraFlow will switch off only the feature that needs it.

How Google user data is accessed, used, stored and shared

Optional: your own Apps Script

For people who prefer it, AuraFlow Settings has an advanced path that uses a small Google Apps Script running in your own Google account. It can send your plans to your Google Calendar and Tasks, and it can forward emails whose subject starts with "task:", or items you add to Google Tasks by voice, to AuraFlow. That script is yours, runs under your own Google authorization (not AuraFlow's), and signs what it sends to AuraFlow's servers with a secret only you hold. AuraFlow's servers receive only the items the script sends. You can remove the script at any time.

4. Maps, drive time and location

5. Family sharing

Family features exist only if you create a family or accept an invitation. A family is a household of people, each with their own AuraFlow account.

6. On-device AI, voice and notifications

7. Who processes your data

We use Google as our service provider:

We do not use advertising networks, data brokers or analytics companies. We may share data if the law requires it, or to protect the safety of AuraFlow's users. If AuraFlow is ever sold or merged, we will tell you first and this policy will continue to apply to your data. Because Firebase is run from the United States, your data is processed there, whatever country you are in.

8. How we protect it

9. How long we keep it

10. Your choices and rights

11. Children

AuraFlow is not directed to children under 13, and you must be at least 13 to use it. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us personal information, write to us and we will delete it.

12. Changes to this policy

If we change this policy in a way that matters, we will update the date at the top and tell you in the app before the change takes effect. If we ever want to use Google user data in a way not described here, we will ask for your consent first.

13. Contact

Tanner Frequency
support@tannerfrequency.com
Or visit the support page.