Privacy Policy
Privacy Policy for Flowstake.com
Last Updated: September 14th, 2026
This Privacy Policy is part of our Terms and Conditions. Please read both documents carefully before using our Platform.
Plain-English Summary: FlowStake collects your GPS location and activity data to verify athletic performance. We use Supabase for database storage and Mapbox for maps; we use Stripe only if and when a payment feature is available to you, and none is today. On iOS you can optionally connect Apple Health so your Watch workouts, heart rate and step counts count toward your activities — that data is used only for fitness features, never for advertising, and never sold (Section 1.5). New activities are visible to your friends unless you change that; if you make an activity public, a route preview with the start and end trimmed may appear when its link is shared. We publish cryptographic fingerprints of activity records so verification can be checked independently — a fingerprint reveals nothing about you. We do not sell your data. You can export or delete your data at any time.
1. Information Collection
1.1 Required Information
- Email address
- Date of birth (to confirm you are 18 or older; the date itself is not shown to anyone)
- Activity data
- Location data (during activities)
A wallet address is not required and is collected only if you choose to connect one (Section 13.2) or to sign in with one (Section 13.3). We do not currently collect identity documents. If a future feature requires identity verification, we will update this Policy before you can use that feature.
1.2 GPS and Location Data
When you record an activity, FlowStake collects precise GPS coordinates, altitude, timestamps, and derived metrics (speed, pace, distance) for the duration of your session. This data is used exclusively to:
- Verify that your activity meets the challenge completion criteria
- Detect anomalous data that may indicate fraudulent submission (Section 1.7)
- Generate route maps shown on your activity detail page, and route previews for activities you make public (Section 1.6)
GPS tracks are stored in encrypted form in our database. They are never sold to third parties and are not used for advertising. You may request deletion of your GPS tracks at any time; note that published fingerprints (hashes) of your activity records, and any on-chain attestations you opted into, cannot be deleted because they are designed to be permanent — a fingerprint reveals nothing about the content it describes (Section 1.8).
1.3 Optional Information
- Profile picture
- Social connections
- Device specifications
- Fitness preferences
- Performance metrics
- Training history
- A streaming channel handle, if you choose to link one (Section 3.2)
- Official race-result details you choose to match to an activity (provider, external race and result identifiers, bib if you give it, official start and finish times, official distance, and optional split times) — used only for verification corroboration and verifier calibration (Section 1.7a)
1.4 Health and Wearable Data
FlowStake collects "consumer health data," including precise GPS location,
heart rate, step counts, cadence, and activity/workout metrics. With your
explicit, separate opt-in consent, we may also import workouts from connected
sources you authorize, such as Apple Health (Apple Watch), or read heart rate
from a Bluetooth heart-rate monitor you choose to pair. We collect this data
only after you grant consent in the app and only to provide activity tracking,
challenge verification, and the features you use. We do not sell your health
data, use it for advertising, or disclose it to other users beyond your chosen
sharing setting (your activities default to friends-only and are shown publicly
only if you choose). You can withdraw consent, change sharing, or delete this
data at any time (see Section 4); deletion is completed within 45 days, except
for published fingerprints and on-chain attestation hashes that are immutable by
design. These practices are intended to align with the FTC Health Breach
Notification Rule and U.S. state consumer-health-data laws (e.g., the Washington
My Health My Data Act). (This section is informational and pending final legal review.)
1.5 Apple Health (HealthKit) on iOS
The FlowStake iOS app can read from, and write to, Apple Health — but only after
you explicitly grant permission in the iOS Health permission sheet. Apple Health
access is entirely optional: FlowStake's core features work using the app's
own GPS recording, and nothing is read from Apple Health unless you turn it on.
What we read (only the types you authorize): workouts, heart rate, step
count, walking/running distance, active energy burned, and workout routes. When
you save an activity recorded in FlowStake, we may read heart rate from an
Apple Watch workout that overlapped it, so that heart rate appears alongside
your activity.
What we write: the activities you record in FlowStake, so your workout
history stays complete in Apple Health. We only write activities you actually
recorded — we never write estimated, synthetic, or inaccurate data.
Why we read it: so activities recorded on your Apple Watch or in other apps
count toward your FlowStake challenges, streaks, and step goals, and so heart
rate and distance appear alongside your activity.
Limits we hold ourselves to. Data obtained from Apple Health is used only
for the health and fitness features described above. Specifically, we do not:
- use it for advertising, marketing, or any advertising-related purpose;
- sell it, or share it with data brokers or advertising networks;
- disclose it to any third party without your separate permission, other than
the infrastructure providers listed in Section 3.2 who process data on our
behalf under contract; - use it to train machine-learning models; or
- use it for any purpose other than health, fitness, or activity verification.
Verification note. Activities imported from Apple Health are treated as
lower-assurance than activities recorded live in FlowStake, because any app can
write to Apple Health. Imported activities are labelled as imported and may not
be eligible for verification tiers that require first-party GPS capture.
How to turn it off, and what happens. You can revoke access at any time in
iOS Settings → Privacy & Security → Health → FlowStake, or by disconnecting
Apple Health in FlowStake's settings. Revoking stops all future reads
immediately. Activities already imported into your FlowStake account remain in
your account until you delete them — delete individual activities, or delete your
whole account (Section 4), which removes them. Revoking access in iOS does not,
by itself, delete data already imported.
1.5a Strava (optional connection)
If you choose to connect a Strava account, FlowStake can import your Strava
activities and send activities you recorded in FlowStake to Strava. Both
directions are optional and happen only when you tap the button.
What we import: for each Strava activity, its name, type, date, distance,
moving time, elevation, start and end point, and — where Strava has them —
average and maximum heart rate. We keep the access token Strava issues so the
import can continue without asking you to sign in again.
How imported activities are treated. Imported Strava activities are
private to you: they never appear on the feed, the public board, the live
map, or anyone else's screen, and they are not counted as verified. They are a
record of your history, shown only to you, and FlowStake never uses them to
train machine-learning models or for advertising.
Disconnecting removes the tokens immediately. Activities already imported
stay in your account until you delete them — individually, or by deleting your
account (Section 4). Strava's own handling of your data is governed by
Strava's privacy policy.
1.6 Sharing, Public Activities, and Link Previews
Each activity has a visibility you control: only you, friends, or
public. New activities default to friends. What each setting means:
- Friends: visible to accepted friends in the app.
- Public: visible to anyone using FlowStake, and eligible for the public
activity feed and the public stakes board. When a public activity's link is
shared — in a message, a social post, or anywhere a link preview is generated
— FlowStake serves a preview containing the activity type, distance, time,
and a small route image. The route image always has the start and end of
your route removed, and it is never generated for friends-only or private
activities. If you turn on "hide map" for an activity, no route image is
generated at all. - Live map: while you are recording an activity you have set to public,
FlowStake may show that you are currently active on a live map. Your position
on that map is deliberately coarse — rounded to roughly one kilometre — and
is refreshed no more often than every ten seconds; your exact position never
leaves your device for this purpose. You can hide yourself from the live map
with one tap at any time, and your profile can opt out of it entirely. - Territory map: once an activity you have set to public has been
verified, the map cells it crossed count toward a seasonal territory map
that other signed-in FlowStake users can see. Cells are the same coarse
grid as the live map — roughly one kilometre on a side — so the territory
map never shows a route, a start, an end, or anything finer than the live
map already does. It does show, for the current season, which cells you
have been through and how many times, and names you as the holder of a
cell when you have visited it more than anyone else. Only public, verified
activities count; friends-only and private activities never do. Changing an
activity to friends-only or private, or deleting it, removes its cells
immediately. Seasons end, and a new season starts from an empty map. The
territory map confers standing only — no payment, reward, or ranking used
for any payment is derived from it.
1.7 Verification and Anti-Cheat Analysis
To verify activity and detect fabricated or vehicle-assisted data, FlowStake
analyses the recorded data of every activity: speed and its consistency with
position, timing regularity, movement patterns, and — where you have provided
them — heart rate and other sensor readings. Where other athletes were recorded
nearby, their anonymous encounter records may raise the confidence of your
verification. This analysis is automated, is applied the same way to every
activity, and produces a verification result and an internal integrity flag.
Integrity flags are advisory: they are reviewed by a person before any
consequence to you, and they are never shown to other users.
1.7a Official Race Result Matching (optional)
If you choose to match an activity to an official race result, we store the
provider name, external race and result identifiers, race name, bib number (if
you provide it), official start and finish times, official distance, whether the
result was chip-timed, optional mat or finish split times, and the link to your
activity and scoring session. We use this only to corroborate verification
(institutional evidence on the shadow score) and to calibrate our verifier. We
do not sell it, do not use it for advertising, and do not change your live
verification tier solely because a match was claimed. You can ask us to delete
a match you submitted; published fingerprints of the underlying activity remain
subject to Section 1.8.
1.8 Public Fingerprints of Activity Records
So that verification can be checked by anyone without trusting FlowStake, we
publish cryptographic fingerprints (hashes) of activity records. Each day we
publish a single fingerprint of that day's records, chained to the previous
day's, and where you have opted in, an attestation of your activity may be
recorded on a public blockchain. A fingerprint is a one-way summary: it cannot
be reversed to recover your location, your identity, or anything about the
record. Once published it cannot be withdrawn, which is what makes it useful
as proof. Your underlying activity data remains yours to delete.
1.8a Flowstake Score
From the commitments you make in the app — which ones you completed, which you
did not, whether you came back after a miss, and how steadily you stay active —
FlowStake computes a Flowstake Score. It measures how reliably you follow
through, not how fast or far you go, and it is not the verification result
of any single activity. It is derived only from your own challenge and activity
records inside FlowStake; imported Strava or Apple Health activities do not feed
it. Your exact score is shown only to you. It is never shown to other users
and never published; the most another user could ever see is a coarse band,
and only if you turn that on yourself in your profile. Until you have completed
enough commitments for the score to mean anything, you see your progress toward
it rather than a number.
1.9 Reward Payments
If you take part in the Achievement Reward Program (see its Rules), we collect
from you directly — outside the app — the information needed to pay you: your
legal name, a mailing address or bank transfer details, and a completed tax form
(Form W-9 or equivalent). Your taxpayer identification number is never entered
into the FlowStake app or its database. We record in our systems only the fact
that your form is on file and where the paper is kept, the amount owed to you for
each verified completion, and each payment we send. You can see those records
for your own account in the app. See Section 8.3 for how long they are kept.
2. Data Usage
2.1 Essential Operations
- Activity verification and anti-cheat analysis
- Challenge management, including your own Flowstake Score (Section 1.8a)
- Reward payments under a published reward program
- Account security
- Service improvements
- Feature optimization
2.2 Public Verification Records
- Published daily fingerprints of activity records (Section 1.8)
- Public attestations on a blockchain, only where you have opted in
- Challenge participation records
- If you connect a wallet: the public address you chose to link
3. Data Protection
3.1 Security Measures
- Encryption for data in transit, and encrypted storage at rest by our database provider
- Secret keys held in isolated, access-controlled storage
- Row-level access controls so that database queries can only return the rows a signed-in user is entitled to see
- Automated checks that guard privacy-sensitive data paths, run on every code change
- Scheduled review of access grants and security advisories
3.2 Third-Party Service Providers
The following named third parties process your data on our behalf. Each link points to their own privacy policy:
| Provider | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Supabase | Database, authentication, file storage, server functions | Account data, activity records, GPS tracks | supabase.com/privacy |
| Netlify | Website hosting and edge delivery | Standard web request data (IP address, browser) | netlify.com/privacy |
| Mapbox | Interactive maps, route visualization, route preview images for public activities | GPS coordinates during map rendering; the trimmed route of a public activity when a preview is generated | mapbox.com/legal/privacy |
| OpenWeatherMap | Weather conditions at the start and end of an activity | The approximate location of your activity's start and end at the time of recording | openweathermap.org/privacy-policy |
| Sentry | Error monitoring | Technical error reports, which may include your account identifier and device details; never GPS tracks | sentry.io/privacy |
| Plausible | Privacy-preserving usage analytics | Aggregate page-view data without cookies or personal identifiers | plausible.io/privacy |
| Resend / Email provider | Transactional email delivery | Email address, name, notification content | Per provider policy |
| OpenRouter | Routing requests from FlowStake's AI features to the AI model provider that answers them | What those features send: messages you type to the in-app AI assistant together with the profile, activity and challenge context it uses to answer; the inputs to AI-written reports; and the text of a challenge you ask us to set up from a message | openrouter.ai/privacy |
| Anthropic | AI model provider for the in-app assistant and AI-written reports, reached directly or through OpenRouter | The same content as the OpenRouter row, for those features | anthropic.com/legal/privacy |
| OpenAI | AI model provider for turning a challenge described in a message into a structured challenge, reached directly or through OpenRouter | The message text and the participant names included with it | openai.com/policies/privacy-policy |
| Twitch / YouTube / Kick | Checking whether a streaming channel you have linked is currently live | Only the public channel handle you linked | Per provider policy |
| Strava | Importing your Strava activities and sending FlowStake activities to Strava — only if you connect Strava (Section 1.5a) | Activities you choose to send: route, distance, time, and a "Recorded with FlowStake" note | strava.com/legal/privacy |
| Stripe | Payment processing — not currently used for any user-facing feature; would process payouts if a payment feature is introduced, and this Policy will be updated first | None today | stripe.com/privacy |
| IPFS (Pinata or public nodes) | Decentralized storage of proof records, where used | Activity proof hashes, attestation metadata — never raw GPS tracks | Public network — irreversible |
We contractually require all service providers to process your data only on our instructions and to maintain appropriate security standards. We do not currently use an identity-verification (KYC) provider. (The OpenRouter, Anthropic and OpenAI entries are pending final legal review.)
3.3 Financial Data Handling
- FlowStake does not currently collect any payment from you, and stores no payment card data
- If you receive a reward under the Achievement Reward Program, the bank details or mailing address you give us are used to send that payment and are handled outside the app by FlowStake's operator; your tax form is kept on file outside the app; your taxpayer identification number is never stored in the FlowStake database (Section 1.9)
- Amounts owed and paid to you are recorded in our database so that you, and we, have an accurate record, and so that we can meet tax-reporting obligations
- If you choose to connect a cryptocurrency wallet, we store only its public address
4. User Rights
4.1 Access and Control
- View your data
- Download your data
- Correct inaccuracies
- Delete your account
- Manage preferences
- Opt out of communications
- Control third-party sharing
- Change the visibility of any activity at any time
4.2 Data Portability
- Export activity data (GPX/TCX)
- Transfer to other services
- Limits: published fingerprints and on-chain attestations are permanent by design (Section 1.8)
5. Data Sharing
5.1 With Your Consent
- Challenge participants
- Social features
- Public leaderboards
- Profile visibility
- Group memberships
- Friend connections
- Public activities and their link previews (Section 1.6)
5.2 Service Providers
The named providers in Section 3.2, and no others.
5.3 Legal Requirements
- Court orders
- Regulatory compliance
- Fraud prevention
- Terms enforcement
- Law enforcement requests
- Legal investigations
6. Cookies and Tracking
6.1 Essential Cookies and Storage
- Authentication and session management
- Security
- Preferences (for example units, map style, tracker settings), stored on your device
- Feature functionality
6.2 Analytics
We use Plausible, which measures page views in aggregate without cookies and without personal identifiers, and Sentry, which records technical errors. We do not use advertising trackers.
7. International Data Transfers
Our infrastructure providers may process data in the United States and other countries. Where data is transferred across borders we rely on our providers' contractual safeguards. Published fingerprints and any on-chain attestations are, by their nature, replicated globally and permanently.
8. Data Retention
8.1 Account Information
Kept while your account is active and deleted within 45 days of account deletion, subject to the exceptions below.
8.2 Activity Data
Kept while your account is active. You may delete individual activities at any time; account deletion removes them all within 45 days. Published fingerprints and on-chain attestations are permanent (Section 1.8).
8.3 Reward Payment Records
If you have received a reward payment, we retain a minimal record of it — your account identifier, the amount, the date, and that a tax form was on file — for as long as tax law requires, typically seven years, even if you delete your account. This record does not include your tax identification number, which is never stored in our systems. Everything else about your account is deleted as described above.
9. Children's Privacy
We do not knowingly collect information from children under 18. If you believe we have collected information from a child, please contact us immediately at privacy@flowstake.com.
10. Changes to Privacy Policy
Each version of this Policy is dated. We update it whenever we change what we collect, how we use it, who we share it with, or how long we keep it — before the change takes effect, not after. Material changes will be announced in the app and by email. Previous versions are archived and available on request.
11. Contact Information
11.1 Privacy Questions
- Email: privacy@flowstake.com
- Mail: 1209 Orange Street, Wilmington, DE 19801
- Response time: Within 48 hours on business days
11.2 Data Protection Officer
- Email: dpo@flowstake.com
- Responsibilities: Oversight, compliance, inquiries
12. Legal Basis for Processing
12.1 Consent
- Account creation
- Optional features, including Apple Health, Strava, heart-rate monitors, wallet connection, and streaming-channel links
- Marketing communications
- Public sharing of an activity
12.2 Contractual Necessity
- Challenge participation
- Reward payments under a published reward program
- Account management
- Service provision
12.3 Legitimate Interests
- Security measures
- Service improvements
- Fraud prevention and verification integrity
- Aggregate analytics
13. Specific Privacy Features
13.1 Activity Privacy
- Per-activity visibility: only you, friends, or public; default friends
- Start and end of every shared route removed from previews and shared maps
- "Hide map" option per activity
- Live map position rounded to roughly one kilometre, with one-tap hide and a profile-level opt-out
- Territory map built only from public, verified activities on the same roughly-one-kilometre grid; cells released the moment an activity stops being public (Section 1.6)
- Public link previews only for public activities (Section 1.6)
13.2 Wallet Privacy
- Connecting a wallet is optional
- We store only the public address you link
- We never ask for, and you must never provide, a private key or seed phrase
13.3 Signing In With a Wallet or a Passkey
You may, if you choose, sign in by proving control of a wallet or a passkey instead of using an email address and password. This is optional; email sign-in remains available and nothing here is required to use FlowStake.
When you sign in this way:
- We ask your wallet to sign a short message. It states the site you are signing in to, the network, a one-time code we issue, and the time. Signing it proves you hold the key. It is not a transaction, it moves no funds, and it grants us no ability to spend anything.
- Your public address becomes part of your account. Where you previously linked an address only to receive a payment, an address you sign in with also identifies your account and is used to authenticate you on each later sign-in. It is recorded on your profile.
- We create an account for you if you do not have one. Because an account needs an address of some kind, we generate a non-routable placeholder derived from your public address. No mail can be sent to it and it is not an email address you own or can receive at.
- The one-time codes are short-lived and single-use. We store the code, the address, the site and the network it was issued for, and when it was used. They expire within minutes and are deleted afterwards.
- A passkey never leaves your device. It is held by your device's secure hardware and unlocked by you. We receive only the resulting proof, never the key.
- Signing in does not move money and is not a payment feature. It tells us who you are. It does not enable staking, charging, or paying, and does not change what FlowStake may collect from you — which remains nothing.
Age and Terms acceptance are required for a wallet or passkey account exactly as they are for an email account; you will be asked for both before you can use the Platform.
14. Security Practices
14.1 Technical Measures
- Encryption in transit and at rest
- Role-based and row-level access control
- Isolated secret storage
- Automated guard tests on privacy-sensitive code paths
- Error and alert monitoring
14.2 Organizational Controls
- Access limited to what a role requires
- Security review of changes that touch personal data
- Incident response procedure
- Vendor assessment
15. Public Records and Blockchain
15.1 Published Fingerprints
See Section 1.8. Fingerprints are public, permanent, and reveal nothing about content.
15.2 If You Opt In to On-Chain Attestation
An attestation records that a verified activity occurred, by fingerprint, on a public blockchain. It is permanent, publicly visible, and pseudonymous — linked to a public address, not to your name. Only the fingerprint is recorded, never your route.
16. Compliance Framework
- GDPR and CCPA considerations
- FTC Health Breach Notification Rule and state consumer-health-data laws (Section 1.4)
- Tax-reporting obligations for reward payments (Section 8.3)
- Industry best practices and self-regulatory frameworks
For questions about our privacy practices, please contact us at privacy@flowstake.com.