1. Who We Are
Flowstate Finance is a personal finance management application. Flowstate Finance is the trading name of Christopher Matthews, a sole trader based in the United Kingdom, who is the data controller for your personal data. You can contact us at admin@flowstate-finance.com. This Privacy Policy explains how we handle your personal data.
2. What Data We Collect
We collect only the absolute minimum required to provide the service:
- Email address — to identify your account and send essential account emails (verification, password reset only)
- Your financial data — income, expenses, balances, debts, and savings that you choose to enter, stored exclusively for your own use
We do not collect your name unless you provide it. We do not collect payment card details (payments are handled directly by our payment processor).
3. How We Use Your Data
Your data is used for one purpose only: to provide you with the Flowstate Finance service.
- To maintain and display your account and financial entries
- To send account emails (verification, password reset, billing) and occasional service emails about your account, such as trial reminders, budget alerts and monthly summaries — you can unsubscribe from non-essential emails at any time
We will never send you third-party advertising. We will never sell, share, rent, or otherwise disclose your personal or financial data to any third party for any purpose.
4. Third Parties
We do not sell or share your data for anyone else’s purposes. We use a small number of service providers solely to run the app: hosting and authentication, Stripe (payments and, if you choose, bank connections), and an email provider. They process data only on our behalf to provide these services.
We do not use advertising networks or data brokers. We only collect basic, anonymous usage statistics (such as page visits) to improve the app.
5. Data Storage & Security
Your data is stored securely using encryption in transit (TLS) and at rest. Access to stored data is strictly limited to what is needed to serve your own account.
6. Data Retention
Your data is kept only for as long as your account is active. You can request full deletion of your account and all associated data at any time. We will complete deletion within 30 days of your request.
7. Your Rights (UK/EU)
Under UK GDPR you have the right to access, correct, delete, or export your data at any time. To exercise any of these rights, email admin@flowstate-finance.com.
You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies & Local Storage
We use only essential cookies and browser local storage to keep you logged in and save your in-app preferences. We use no advertising or cross-site tracking cookies whatsoever.
9. Changes to This Policy
If we ever need to change this policy in a material way, we will notify you via an in-app notice before any change takes effect. We will never retroactively weaken your privacy protections without your explicit consent.
10. Contact
For any privacy questions or data requests, email Christopher Matthews (trading as Flowstate Finance) at admin@flowstate-finance.com, or contact us through the app.
11. Bank Account Data & Bank Feed Providers
If you choose to connect a bank account, the connection is provided by Stripe Financial Connections (US banks) or Enable Banking Oy (UK and EU banks). You log in to your bank directly through the provider — we never see or store your bank login credentials.
With your permission, the provider shares account details (such as account name, type and last four digits), balances and transactions (descriptions, amounts and dates) with us so we can show them in your account.
We use this data solely to provide the bank feed feature for you — importing, categorising and forecasting your own transactions. We never sell it, share it, or use it for advertising or profiling. You can disconnect a bank account at any time and we will stop receiving new data from it; transactions already imported stay in your account until you delete them or your account.
Stripe and Enable Banking are separate companies with their own privacy policies. You can read how they handle this data at stripe.com/privacy, stripe.com/legal/end-users and enablebanking.com/privacy.
12. Data Security Measures
We take the security of your financial data seriously. Our security measures include:
- Encryption of all data in transit using TLS (Transport Layer Security)
- Encryption of data at rest in our database
- Strict access controls: each user can only read, modify, or delete their own records. No user can access another user’s data.
- Bank credentials are never stored by us — Stripe handles all bank authentication independently
- Payment processing handled entirely by Stripe (PCI-DSS compliant). We never see or store your card details.
Despite these measures, no system is completely secure. In the unlikely event of a data breach, we will notify affected users without undue delay in accordance with our legal obligations under UK GDPR.