Privacy Policy
Scope & Controller
This Privacy Policy explains how the developer of ClientFlow ("ClientFlow," "we," "us," or "our") handles information when you use the ClientFlow iOS and Apple Watch applications, contact us, or use related features.
For personal information processed directly for ClientFlow analytics, purchase management, support, and administration, the ClientFlow developer is the controller. For client information that you enter while running your own business, you determine why and how that information is used and are responsible for complying with laws applicable to your business.
Data You Store in ClientFlow
The App lets you enter client names, phone numbers, notes, visit history, appointment dates and times, services, prices, statuses, reminders, and business settings. This content is stored locally on your device and is used there to provide the App's core features.
We do not operate a server that receives or stores your client database. Client names, phone numbers, note contents, service names, exact appointment dates, and exact appointment prices are not intentionally sent to Firebase Analytics or RevenueCat.
ClientFlow does not request access to your address book, precise location, photos, health data, payment-card number, microphone, or camera for its core client-management features.
Backups & Exports
Encrypted backups
Automatic and manually created backups stored by ClientFlow are encrypted on your device using AES-GCM before storage. If iCloud backup is enabled, the encrypted file is saved in your personal iCloud Drive container. The encryption key is stored as a synchronizable Keychain item so that it can become available through iCloud Keychain on your trusted devices.
Apple processes iCloud Drive and iCloud Keychain data under your Apple Account and Apple's terms. ClientFlow does not receive your Apple Account password or a copy of your backup through its own server.
Manual exports
When you manually export or share a JSON backup, CSV history, or report, that exported file may contain personal and business information and is not necessarily encrypted by ClientFlow. You choose the destination and are responsible for protecting the file and its recipients. The destination app or service handles it under its own privacy terms.
Analytics & Remote Configuration
ClientFlow currently uses Google Firebase Analytics to understand App usage and improve reliability, onboarding, features, and purchase flows. Firebase may automatically process an app-instance identifier, device and operating-system information, App version, language or locale, general geographic information derived from network data, app opens, session information, and in-app purchase events.
We also send limited interaction events, such as whether onboarding was completed, which features or paywall options were used, whether an appointment or client was created, counts of records involved in certain actions, and whether a record contains a phone number, note, reminder, or price. These events are designed not to include client names, phone numbers, note text, service names, exact appointment dates, or exact appointment prices.
Firebase Remote Config is used to retrieve limited App configuration, such as whether a promotional paywall presentation is enabled. Requests may involve ordinary technical data such as IP address, App identifier, and device or connection information.
ClientFlow does not request App Tracking Transparency permission, does not intentionally access the iOS advertising identifier (IDFA), and does not use Firebase data for cross-app advertising tracking or personalized third-party ads.
Purchases & Subscriptions
Apple processes App Store payments. We do not receive your full payment-card details.
ClientFlow uses RevenueCat to display offerings, validate purchases, restore purchases, and determine Premium entitlement status. RevenueCat may process an anonymous App User ID, product identifiers, purchase and subscription history, entitlement status, price and currency, country or locale, App version, device and operating-system information, and related request data. ClientFlow also passes its Firebase app-instance identifier to RevenueCat to measure purchase attribution and product performance. No client or appointment content is sent to RevenueCat.
Notifications, SMS & Sharing
If you grant notification permission, ClientFlow schedules appointment and product-lifecycle reminders locally on your device. Core appointment reminders do not require us to send the client or appointment content to a ClientFlow server.
If you choose an SMS, export, report, or system sharing action, the App prepares the content for the Apple share sheet or relevant system app. You decide whether to send it. Apple, your carrier, the recipient, and any selected third-party service may then process that content.
How We Use Information
Depending on the information and applicable law, we use data to:
- Provide local appointment, client, income, report, reminder, Watch, backup, and restore features
- Process and validate subscriptions, trials, purchases, and entitlements
- Measure aggregate use, diagnose problems, improve features, and configure App experiences
- Prevent fraud, protect the App, enforce our terms, and comply with legal obligations
- Respond when you contact support
Where required, processing is based on your consent. Other processing may be necessary to provide requested features or purchases, comply with law, or pursue legitimate interests such as security, support, and product improvement, balanced against your rights.
Disclosure & International Transfers
We do not sell your personal information. We do not share it for cross-context behavioral advertising. Information is disclosed only as needed to:
- Apple, for App Store purchases, iCloud Drive, iCloud Keychain, notifications, and device services you use
- Google Firebase, for analytics and remote configuration
- RevenueCat, for purchase and entitlement management
- Professional advisers, authorities, or other parties when reasonably necessary to comply with law, prevent harm, or protect legal rights
- A successor in connection with a merger, acquisition, financing, or transfer of the App, subject to appropriate safeguards
These providers may process information in countries other than yours, including the United States. Their contractual safeguards and privacy terms govern those transfers.
Provider information: Apple Privacy, Firebase Privacy and Security, Google Privacy Policy, and RevenueCat Privacy Policy.
Data Retention
Local records remain until you delete them in ClientFlow, erase the App's data, or delete the App. iCloud files remain under your control until you remove them from ClientFlow or iCloud. Deleting the App does not necessarily delete iCloud backups.
Firebase and RevenueCat data is retained according to our applicable service settings, operational needs, legal obligations, and provider terms. Support emails are kept as long as reasonably necessary to respond, maintain records, resolve disputes, and comply with law. Aggregated or de-identified information may be retained where it no longer identifies you.
Your Choices & Rights
You can access and edit local records in the App; delete clients, appointments, and backups; disable iCloud backup; change notification permission in iOS Settings; export supported data; and cancel or manage subscriptions through your Apple Account.
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection regarding personal information we control, and to withdraw consent where processing relies on consent. You may also complain to your local data-protection authority.
Because we do not have a ClientFlow account system and RevenueCat generally uses an anonymous identifier, we may need information such as your RevenueCat App User ID to locate provider-side records. We may be unable to identify records from an email address alone. Contact us for assistance.
Security
ClientFlow minimizes exposure by keeping client records on your device and encrypting stored backup payloads before local or iCloud storage. iOS protects local application data through device security, and network communications with providers use encrypted connections.
No storage or transmission method is completely secure. Protect your device passcode and Apple Account, enable appropriate iCloud security settings, verify backups, and treat manual exports as sensitive files.
Children
ClientFlow is a business tool intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information directly from children. If you believe a child has provided information to us, contact us so we can investigate and take appropriate action.
Changes to This Policy
We may update this Privacy Policy when the App, providers, legal requirements, or our practices change. The updated version will appear on this page with a revised effective date. We will provide additional notice when required by law.
Contact
For privacy questions or requests, contact the ClientFlow developer at: privatecapacity.dev@gmail.com