LEGAL
Privacy Policy
How Harmony Flow collects, uses, and protects your information.
Effective Date: April 14, 2026 · harmonyflow.me
1. Data Controller and Identity
The data controller responsible for your personal information is Lockhart Faith Enterprises LLC, Imperial, Missouri 63052, United States of America.
If you are located in the EEA, we are required under Article 27 GDPR to designate a representative in the European Union. We are in the process of appointing an EU representative and will update this Policy accordingly.
2. Information We Collect
Information you provide directly
- Account registration information — name, email address, password
- Payment information processed securely by our payment processor
- Content you submit to the AI Agents, including messages and queries
- Communications you send to us, including support requests
Information collected automatically
- Device information, OS, browser type, and unique identifiers
- Log data — IP address, access times, pages accessed, error data
- Usage data, including message frequency used to enforce the 160-message per 3-hour limit
- Push notification tokens and authentication session tokens (Supabase Auth)
Sensitive information (with express consent only)
- Location data, where access is granted
- Health-related information, voluntarily shared during AI Agent interactions
- Biometric data, where applicable features require it
From third parties and integrated services
- Data processed by the OpenAI API for AI Agent interactions
- Backend data processed by Supabase (accounts, conversations, sessions)
- Workflow routing data processed by BuildShip
- Interface data handled by FlutterFlow
3. How We Use Your Information
- Create and manage your account and authenticate your identity via Supabase Auth
- Operate the Finance Agent and Relationship Agent through the OpenAI API, routed via BuildShip
- Process payments and manage your subscription
- Enforce the 160-messages-per-3-hour rolling limit
- Send push notifications and in-app communications
- Monitor usage patterns to maintain, improve, and secure the Platform
- Detect and prevent fraudulent or unauthorized activity
- Comply with legal obligations and respond to your inquiries
4. Legal Bases for Processing (GDPR)
If you are located in the EEA, we rely on the following legal bases:
- Performance of a Contract — account creation, delivery of the Platform, payments, usage limits
- Legitimate Interests — fraud prevention, security, rate-limit enforcement, analytics
- Compliance with Legal Obligations — as required by applicable law
- Consent — sensitive data (health, biometric, location) and non-essential communications
- Vital Interests — where necessary to protect you or another individual
Where we rely on consent for special category data under Article 9 GDPR, you may withdraw consent at any time without affecting prior lawful processing.
5. Technology Infrastructure and Data Processing
The Platform is built using third-party providers who act as data processors under binding agreements and may not use your data for their own commercial purposes.
- FlutterFlow — develops the application interface; processes interface and device session data only
- Supabase — primary backend: database storage, authentication, and stores account, conversation, and message-limit records
- BuildShip — routes your messages to the OpenAI API and back; does not store conversation data beyond workflow execution
- OpenAI API — processes conversation inputs to generate AI Agent responses, as a sub-processor under a data processing agreement
Conversation history is stored server-side in Supabase to support session continuity. You may request deletion of your conversation history at any time, subject to legal retention obligations. We treat all Finance Agent and Relationship Agent conversation data as sensitive and apply enhanced protection across every infrastructure layer.
6. Data Sharing and Disclosure
We do not sell, rent, or license your personal information for third parties’ commercial purposes. We share data only with the following named sub-processors, each under a data processing agreement:
- OpenAI — AI language model processing (openai.com)
- Supabase — backend database and authentication (supabase.com)
- BuildShip — workflow automation and API routing (buildship.com)
- FlutterFlow — application development framework (flutterflow.io)
- Payment processor(s) — secure transaction handling under PCI-DSS
We may also disclose information where required by law, in connection with a business transfer, or to protect the rights and safety of our users. The Platform does not serve third-party advertisements and never shares data with advertisers.
7. International Data Transfers
The Platform is operated from the United States, and your data is processed and stored there, including through Supabase and OpenAI infrastructure. Where we transfer personal data from the EEA or UK, we rely on Standard Contractual Clauses, adequacy decisions, or other lawful transfer mechanisms recognized under applicable law.
8. Data Retention
- Account information — duration of your account, plus up to 3 years after closure
- Conversation and AI interaction data — up to 12 months, or duration of your account, subject to deletion requests
- Message-limit enforcement data — purged automatically outside the 3-hour rolling window
- Payment records — up to 7 years for tax and accounting compliance
- Log and security data — up to 12 months, or as required for investigations
- Biometric data — deleted promptly upon request, account closure, or purpose fulfillment
9. Biometric, Health, and Location Data
- Biometric data is collected only with explicit written consent, retained only as long as necessary, never sold or leased, and deleted promptly upon request, closure, or purpose fulfillment.
- Health-related data, voluntarily shared during AI Agent interactions, is processed solely to deliver a relevant response and stored per the retention terms above. Under GDPR this is special category data, processed only with your explicit consent.
- Location data is used solely to enhance the relevance of AI Agent responses. You may revoke access at any time through your device settings.
10. Cookies and Tracking Technologies
We use cookies and similar technologies on the web version of the Platform. Full details are available in our Cookie Policy at harmonyflow.me. The mobile app uses device-level tokens, including Supabase Auth session tokens and push notification tokens.
11. Push Notifications
With your consent, we send push notifications relating to your account, features, and service messages. You may opt out at any time through your device settings without affecting access to core features.
12. Security Measures
- TLS encryption in transit across all service integrations
- Supabase row-level security and database access controls
- Secure authentication and session handling via Supabase Auth
- Need-to-know access controls for employees and contractors
- Regular security assessments and vulnerability testing
No method of transmission or storage is entirely secure. In the event of a breach likely to affect your rights, we will notify you and relevant authorities within the timeframes required by law.
13. Your Rights Under GDPR (EEA Users)
- Right of Access — a copy of the data we hold about you
- Right to Rectification — correction of inaccurate data
- Right to Erasure — deletion across all storage systems, including Supabase
- Right to Restriction of Processing
- Right to Data Portability
- Right to Object to processing based on legitimate interests
- Rights related to automated decision-making
- Right to lodge a complaint with your local supervisory authority
We respond to verified requests generally within thirty (30) days.
14. California Privacy Rights (CCPA/CPRA)
- Right to Know what personal information we’ve collected
- Right to Delete personal information across all systems
- Right to Correct inaccurate information
- Right to Opt-Out — we do not sell or share data for behavioral advertising
- Right to Limit Use of Sensitive Personal Information
- Right to Non-Discrimination for exercising your rights
We respond to verifiable requests within forty-five (45) days. We do not currently respond to browser “Do Not Track” signals.
15. Children's Privacy
The Platform is not directed to, and is not intended for use by, individuals under eighteen (18). We do not knowingly collect personal information from anyone under 18. If we become aware that we have, we will promptly delete it from all systems, including Supabase.
16. AI and Automated Processing
Responses are generated computationally by OpenAI’s language models, routed through BuildShip, and are not reviewed by a human operator in real time. We do not subject you to legally significant decisions based solely on automated processing. Message-limit enforcement is an automated operational control applied uniformly to all users, not a decision with legal effect.
17. Third-Party Services
The Platform integrates OpenAI, BuildShip, Supabase, and FlutterFlow as described in Section 6. Links to external websites are for informational purposes only, and we are not responsible for their privacy practices.
18. Consent and Withdrawal of Consent
Where we rely on your consent, including for sensitive data, your consent is voluntary and may be withdrawn at any time via the details in Section 20 or in-app consent settings. Withdrawal does not affect the lawfulness of prior processing.
19. Changes to This Privacy Policy
We may update this Policy to reflect changes in our practices, technology, or legal requirements. Material changes will update the effective date above and, where required, be notified through the Platform or by email.
20. Contact Us and Data Subject Requests
For questions about this Privacy Policy or to exercise your rights, including deletion requests, please contact us:
Imperial, Missouri 63052, United States of America
Website: harmonyflow.me
