Privacy Policy
Privacy Policy for Flowstake.com
Last Updated: October 6th, 2026
This Privacy Policy is part of our Terms and Conditions. Please read both documents carefully before using our Platform.
Plain-English Summary: FlowStake collects your GPS location and activity data to verify athletic performance. We use Supabase for database storage and Mapbox for maps, and Google Analytics to measure how our website and app are used (Section 6.2); we use Stripe only if and when a payment feature is available to you, and none is today. On iOS you can optionally connect Apple Health so your Watch workouts, heart rate and step counts count toward your activities — that data is used only for fitness features, never for advertising, and never sold (Section 1.5). If you turn on presence checks, your phone's screen lock confirms it is you during an activity and your face, fingerprint or PIN never leaves your device (Section 1.7b). New activities are visible to your friends unless you change that; if you make an activity public, a route preview with the start and end trimmed may appear when its link is shared. Photos you add to an activity are shown to the people who can see that activity, and anyone who has a photo's web address can open it (Section 1.6a). We publish cryptographic fingerprints of activity records so verification can be checked independently — a fingerprint reveals nothing about you. We do not sell your data. You can export or delete your data at any time.
1. Information Collection
1.1 Required Information
- Email address
- Date of birth (to confirm you are 18 or older; the date itself is not shown to anyone)
- A record of each time you accept the Terms: which version you accepted and a fingerprint of its exact text, when, on which screen, and the IP address and browser or app details of that request (Section 8.5)
- Activity data
- Location data (during activities)
A wallet address is not required and is collected only if you choose to connect one (Section 13.2) or to sign in with one (Section 13.3). We do not currently collect identity documents. If a future feature requires identity verification, we will update this Policy before you can use that feature.
1.2 GPS and Location Data
When you record an activity, FlowStake collects precise GPS coordinates, altitude, timestamps, and derived metrics (speed, pace, distance) for the duration of your session. This data is used exclusively to:
- Verify that your activity meets the challenge completion criteria
- Detect anomalous data that may indicate fraudulent submission (Section 1.7)
- Generate route maps shown on your activity detail page, and route previews for activities you make public (Section 1.6)
GPS tracks are stored in encrypted form in our database. They are never sold to third parties and are not used for advertising. You may request deletion of your GPS tracks at any time; note that published fingerprints (hashes) of your activity records, and any on-chain attestations you opted into, cannot be deleted because they are designed to be permanent — a fingerprint reveals nothing about the content it describes (Section 1.8).
1.3 Optional Information
- Profile picture
- Social connections
- Device specifications
- Fitness preferences
- Performance metrics
- Training history
- A streaming channel handle, if you choose to link one (Section 3.2)
- Privacy zones, if you set any: a name, a centre point and a radius for each (Section 1.6)
- Photos you add to an activity (Section 1.6a)
- Official race-result details you choose to match to an activity (provider, external race and result identifiers, bib if you give it, official start and finish times, official distance, and optional split times) — used only for verification corroboration and verifier calibration (Section 1.7a)
1.4 Health and Wearable Data
FlowStake collects "consumer health data," including precise GPS location,
heart rate, step counts, cadence, and activity/workout metrics. With your
explicit, separate opt-in consent, we may also import workouts from connected
sources you authorize, such as Apple Health (Apple Watch), or read heart rate
from a Bluetooth heart-rate monitor you choose to pair. We collect this data
only after you grant consent in the app and only to provide activity tracking,
challenge verification, and the features you use. We do not sell your health
data, use it for advertising, or disclose it to other users beyond your chosen
sharing setting (your activities default to friends-only and are shown publicly
only if you choose). You can withdraw consent, change sharing, or delete this
data at any time (see Section 4); deletion is completed within 45 days, except
for published fingerprints and on-chain attestation hashes that are immutable by
design. These practices are intended to align with the FTC Health Breach
Notification Rule and U.S. state consumer-health-data laws (e.g., the Washington
My Health My Data Act). (This section is informational and pending final legal review.)
1.4a Perceived Effort (optional)
After you save an activity, FlowStake may ask how hard it felt, on a scale of 1
to 10. Answering is optional, never required to save, and you can change or
clear your answer later from the activity page. We treat it as consumer health
data under Section 1.4. It is:
- Private to you. It is not shown to your friends or the public, is not on
the feed or any board, and is not included in images or links you share. - Self-reported. It is never used to verify an activity, to score a
challenge, or in your Flowstake Score. - Not shared or sold. It is not sent to any third party other than our
database provider (Section 3.2). - Deleted with the activity. Deleting the activity, or your account,
deletes it (Section 8.2).
(This section is informational and pending final legal review.)
1.4b Paired Wrist Devices and the Wrist Code (optional)
If you pair a FlowStake watch app (for example on an Apple Watch) with the
FlowStake app on your phone, the watch creates a signing key that never leaves
the watch, and we store only the matching public key, the device model
name and its software version, and when the pairing was made, last used, or
removed. During an activity you record, the watch may show a code that changes
every 15 seconds. When your own phone, or another FlowStake athlete's phone,
scans that code, we store the activity it was scanned for, which pairing signed
it, the 15-second window it was shown in, whether it was scanned or typed in,
which athlete scanned it, and the fingerprint of your activity's recording at
that moment. We use these records only to check that the paired device was
with the phone during the activity (Section 1.7). They never contain your
location, your heart rate, or the athlete who scanned it in any public view;
another athlete who scans your code learns nothing about you beyond what they
already see on your wrist. While the watch app is running a workout it reads
heart rate, step count and cadence, elevation, and a coarse (once-a-minute)
position from the watch's own sensors and sends summaries of them to your
phone, where they are stored with your activity under Section 1.4; the watch
never sends continuous motion-sensor recordings, and we never read sleep,
blood oxygen, skin temperature or electrocardiogram data. You can remove a
pairing at any time in Settings; removing it stops all future wrist codes and
deletes the key from the watch, and the records already attached to your
activities are deleted with those activities or with your account (Section 8.2).
(This section is pending final legal review.)
1.5 Apple Health (HealthKit) on iOS
The FlowStake iOS app can read from, and write to, Apple Health — but only after
you explicitly grant permission in the iOS Health permission sheet. Apple Health
access is entirely optional: FlowStake's core features work using the app's
own GPS recording, and nothing is read from Apple Health unless you turn it on.
What we read (only the types you authorize): workouts, heart rate, step
count, walking/running distance, active energy burned, and workout routes. When
you save an activity recorded in FlowStake, we may read heart rate from an
Apple Watch workout that overlapped it, so that heart rate appears alongside
your activity.
Daily step totals. If you turn on Daily step count (Settings → Apple
Health), the app reads one step total per calendar day for the last 30 days
from Apple Health and stores it with your account, refreshing it when you open
the app. Steps you typed into the Health app by hand are left out. We use these
totals only for your step goals, your step-based challenges and the personal
daily target we suggest from your recent days. They are private: only you can
see them; they never appear on the feed, on leaderboards or on your public
profile. Turning Daily step count off deletes every stored total, and deleting
your account deletes them too. (This item is pending final legal review.)
What we write: the activities you record in FlowStake, so your workout
history stays complete in Apple Health. We only write activities you actually
recorded — we never write estimated, synthetic, or inaccurate data.
Why we read it: so activities recorded on your Apple Watch or in other apps
count toward your FlowStake challenges, streaks, and step goals, and so heart
rate and distance appear alongside your activity.
Limits we hold ourselves to. Data obtained from Apple Health is used only
for the health and fitness features described above. Specifically, we do not:
- use it for advertising, marketing, or any advertising-related purpose;
- sell it, or share it with data brokers or advertising networks;
- disclose it to any third party without your separate permission, other than
the infrastructure providers listed in Section 3.2 who process data on our
behalf under contract; - use it to train machine-learning models; or
- use it for any purpose other than health, fitness, or activity verification.
Verification note. Activities imported from Apple Health are treated as
lower-assurance than activities recorded live in FlowStake, because any app can
write to Apple Health. Imported activities are labelled as imported and may not
be eligible for verification tiers that require first-party GPS capture.
How to turn it off, and what happens. You can revoke access at any time in
iOS Settings → Privacy & Security → Health → FlowStake, or by disconnecting
Apple Health in FlowStake's settings. Revoking stops all future reads
immediately. Activities already imported into your FlowStake account remain in
your account until you delete them — delete individual activities, or delete your
whole account (Section 4), which removes them. Revoking access in iOS does not,
by itself, delete data already imported.
1.5a Strava (optional connection)
If you choose to connect a Strava account, FlowStake can import your Strava
activities and send activities you recorded in FlowStake to Strava. Both
directions are optional and happen only when you tap the button.
What we import: for each Strava activity, its name, type, date, distance,
moving time, elevation, start and end point, and — where Strava has them —
average and maximum heart rate. We keep the access token Strava issues so the
import can continue without asking you to sign in again.
How imported activities are treated. Imported Strava activities are
private to you: they never appear on the feed, the public board, the live
map, or anyone else's screen, and they are not counted as verified. They are a
record of your history, shown only to you, and FlowStake never uses them to
train machine-learning models or for advertising.
Disconnecting removes the tokens immediately. Activities already imported
stay in your account until you delete them — individually, or by deleting your
account (Section 4). Strava's own handling of your data is governed by
Strava's privacy policy.
1.6 Sharing, Public Activities, and Link Previews
Each activity has a visibility you control: only you, friends, or
public. New activities default to friends. What each setting means:
- Friends: visible to accepted friends in the app.
- Public: visible to anyone using FlowStake, and eligible for the public
activity feed and the public stakes board. When a public activity's link is
shared — in a message, a social post, or anywhere a link preview is generated
— FlowStake serves a preview containing the activity type, distance, time,
and a small route image. The route image always has the start and end of
your route removed, and it is never generated for friends-only or private
activities. If you turn on "hide map" for an activity, no route image is
generated at all. - Live map: while you are recording an activity you have set to public,
FlowStake may show that you are currently active on a live map. Your position
on that map is deliberately coarse — rounded to roughly one kilometre — and
is refreshed no more often than every ten seconds; your exact position never
leaves your device for this purpose. You can hide yourself from the live map
with one tap at any time, and your profile can opt out of it entirely. - Territory map: once an activity you have set to public has been
verified, the map cells it crossed count toward a seasonal territory map
that other signed-in FlowStake users can see. Anyone visiting flowstake.com,
signed in or not, can also see which cells have been covered this season
and whether more than one athlete covered each, but never who covered a
cell or how many times. Cells are hexagons of equal area, about 1.2
square kilometres each (roughly 1.2 kilometres across), which is never
smaller than the live map's cell anywhere on Earth — so the territory map
never shows a route, a start, an end, or anything finer than the live map
already does. It does show, for the current season, which cells you
have been through and how many times, and names you as the holder of a
cell when you have visited it more than anyone else. Only public, verified
activities count; friends-only and private activities never do. Changing an
activity to friends-only or private, or deleting it, removes its cells
immediately. Seasons end, and a new season starts from an empty map. The
territory map confers standing only — no payment, reward, or ranking used
for any payment is derived from it. (The signed-out view is pending final
legal review.) - Privacy zones: you can mark up to five places, such as your home, as
privacy zones. For each one we store the name you give it, its centre point,
its radius, and when you created it. No other user can see your zones.
Whenever someone else sees one of your saved routes — in the app or in a
link preview — every point inside your zones is left out, on past
activities as well as new ones, and the territory map counts only the
points that remain. A route that stops short of a place can still hint that
a zone is there, and a link preview that another app has already fetched
may keep the image it fetched. Zones apply to saved routes, not to what you
share while recording: they do not change the live map, which is already
rounded to roughly one kilometre, or the position that the other people in
a group session you join can see. We still use your full recording to
verify the activity (Section 1.7). Deleting a zone removes it at once, and
the points it covered show again to anyone who can see those activities;
deleting your account deletes all of your zones (Section 8). (This item is
pending final legal review.) - Photos: a photo you add to an activity is shown in the app to the people
who can see that activity, but its web address opens it for anyone who has
the address, whatever the setting (Section 1.6a).
1.6a Activity Photos
You can add photos to an activity you recorded. Adding them is optional.
- Details removed before upload. A photo file can carry details your
camera stored in it, such as where and when the photo was taken. Before
uploading, the app removes them by saving a fresh copy of the image on your
device. GIF and SVG files are uploaded as they are, and so is any image your
device cannot open, for example a HEIC photo on a computer without HEIC
support; whatever details those files hold stay in them. - Who sees them. A photo is shown with its activity, on the activity page
and on its card in the feed, to the people who can see that activity under
the visibility you chose (Section 1.6). Link previews never include photos. - Your "Challenge me" page. Anyone can open your "Challenge me" page
(flowstake.com/your-username/challenge-me). It shows a picture from your
recent public activities, a route whenever one can be shown. Only if you
turned on "hide map" for all of them does it show a photo instead: the first
photo of the most recent one that has a photo. - Share cards. A share card you make for an activity can include its first
photo. The card is made on your device and goes only where you send it. - Every photo has a web address. Photos are stored with our database
provider (Section 3.2). We give a photo's address only to the people who can
see its activity, but opening the address does not require signing in:
anyone who has it, for example because someone passed it on, can open the
photo, whatever the activity's visibility. Changing an activity's visibility
does not change the addresses of its photos. To put a photo out of reach,
remove it or delete the activity. - Used for nothing else. Photos are not used to verify activities, and we
never send them to IPFS, a blockchain, Strava, or our AI providers. - Removing and deleting. Removing a photo from an activity deletes the
photo at the same time. Deleting an activity deletes its photos within 45
days. Deleting your account deletes all of your photos at once (Section 8).
A copy that someone has already saved stays with them.
(This section is pending final legal review.)
1.7 Verification and Anti-Cheat Analysis
To verify activity and detect fabricated or vehicle-assisted data, FlowStake
analyses the recorded data of every activity: speed and its consistency with
position, timing regularity, movement patterns, and — where you have provided
them — heart rate and other sensor readings. Where other athletes were recorded
nearby, their anonymous encounter records may raise the confidence of your
verification. This analysis is automated, is applied the same way to every
activity, and produces a verification result and an internal integrity flag.
Integrity flags are advisory: they are reviewed by a person before any
consequence to you, and they are never shown to other users.
1.7a Official Race Result Matching (optional)
If you choose to match an activity to an official race result, we store the
provider name, external race and result identifiers, race name, bib number (if
you provide it), official start and finish times, official distance, whether the
result was chip-timed, optional mat or finish split times, and the link to your
activity and scoring session. We use this only to corroborate verification
(institutional evidence on the shadow score) and to calibrate our verifier. We
do not sell it, do not use it for advertising, and do not change your live
verification tier solely because a match was claimed. You can ask us to delete
a match you submitted; published fingerprints of the underlying activity remain
subject to Section 1.8.
1.7b Presence Checks (optional)
If you turn on presence checks in Settings → Security, your phone's own screen
lock (for example Face ID, Touch ID, or an Android fingerprint or PIN) is used
to confirm that you are the person holding the phone at the start and at the
finish of an activity, and once at a moment during the activity that you cannot
predict. This uses the WebAuthn standard: your device creates a signing key
and keeps it; your face, fingerprint or PIN never leaves your device and is
never sent to us. We store only the matching public key, a counter the device
increments on each use, the kind of device credential (for example whether it
is backed up to your platform account), and, for each check, the time, whether
it was at the start, mid-activity or the finish, whether your device reported
that it verified you, and the activity it belongs to. We use these records only
to corroborate verification (device evidence on the shadow score, Section 1.7)
and never for advertising or any other purpose. Declining or missing a check
never counts against an activity; it simply is not counted for it. You can turn
presence checks off at any time in Settings, and the stored public key and
check records are deleted with your account (Section 8.2).
(This section is pending final legal review.)
1.8 Public Fingerprints of Activity Records
So that verification can be checked by anyone without trusting FlowStake, we
publish cryptographic fingerprints (hashes) of activity records. Each day we
publish a single fingerprint of that day's records, chained to the previous
day's, and where you have opted in, an attestation of your activity may be
recorded on a public blockchain. A fingerprint is a one-way summary: it cannot
be reversed to recover your location, your identity, or anything about the
record. Once published it cannot be withdrawn, which is what makes it useful
as proof. Your underlying activity data remains yours to delete.
1.8a Flowstake Score
From the commitments you make in the app — which ones you completed, which you
did not, whether you came back after a miss, and how steadily you stay active —
FlowStake computes a Flowstake Score. It measures how reliably you follow
through, not how fast or far you go, and it is not the verification result
of any single activity. It is derived only from your own challenge and activity
records inside FlowStake; imported Strava or Apple Health activities do not feed
it. Your exact score is shown only to you. It is never shown to other users
and never published; the most another user could ever see is a coarse band,
and only if you turn that on yourself in your profile. Until you have completed
enough commitments for the score to mean anything, you see your progress toward
it rather than a number.
1.9 Reward Payments
If you take part in the Achievement Reward Program (see its Rules), we collect
from you directly — outside the app — the information needed to pay you: your
legal name, a mailing address or bank transfer details, and a completed tax form
(Form W-9 or equivalent). Your taxpayer identification number is never entered
into the FlowStake app or its database. We record in our systems only the fact
that your form is on file and where the paper is kept, the amount owed to you for
each verified completion, and each payment we send. You can see those records
for your own account in the app. See Section 8.3 for how long they are kept.
2. Data Usage
2.1 Essential Operations
- Activity verification and anti-cheat analysis
- Challenge management, including your own Flowstake Score (Section 1.8a)
- Reward payments under a published reward program
- Account security
- Service improvements
- Feature optimization
2.2 Public Verification Records
- Published daily fingerprints of activity records (Section 1.8)
- Public attestations on a blockchain, only where you have opted in
- Challenge participation records
- If you connect a wallet: the public address you chose to link
3. Data Protection
3.1 Security Measures
- Encryption for data in transit, and encrypted storage at rest by our database provider
- Secret keys held in isolated, access-controlled storage
- Row-level access controls so that database queries can only return the rows a signed-in user is entitled to see
- Automated checks that guard privacy-sensitive data paths, run on every code change
- Scheduled review of access grants and security advisories
3.2 Third-Party Service Providers
The following named third parties process your data on our behalf. Each link points to their own privacy policy:
| Provider | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Supabase | Database, authentication, file storage, server functions | Account data, activity records, GPS tracks, photos you add to activities | supabase.com/privacy |
| Netlify | Website hosting and edge delivery | Standard web request data (IP address, browser) | netlify.com/privacy |
| Mapbox | Interactive maps, route visualization, route preview images for public activities | GPS coordinates during map rendering; the trimmed route of a public activity when a preview is generated | mapbox.com/legal/privacy |
| OpenWeatherMap | Weather conditions at the start and end of an activity | The approximate location of your activity's start and end at the time of recording | openweathermap.org/privacy-policy |
| OpenStreetMap Foundation (Nominatim) | Finding a place when you search for a challenge location | The place name you type, with standard web request data (IP address, browser) | osmfoundation.org/wiki/Privacy_Policy |
| Sentry | Error monitoring | Technical error reports, which may include your account identifier and device details; never GPS tracks | sentry.io/privacy |
| Google Analytics (Google LLC) | Measuring how the website and app are used: which pages are opened, how often, and on what kind of device | The address of each page you open (when you arrive from a link, we remove codes and personal details from that address first), the referring page, browser and device type, your approximate location (city or region) which Google derives from your IP address, and a random identifier kept in a cookie on your device; never your GPS tracks, activity data or health data | policies.google.com/privacy |
| Resend / Email provider | Transactional email delivery | Email address, name, notification content | Per provider policy |
| OpenRouter | Routing requests from FlowStake's AI features to the AI model provider that answers them | What those features send: messages you type to the in-app AI assistant together with the profile, activity and challenge context it uses to answer; the inputs to AI-written reports; and the text of a challenge you ask us to set up from a message | openrouter.ai/privacy |
| Anthropic | AI model provider for the in-app assistant and AI-written reports, reached directly or through OpenRouter | The same content as the OpenRouter row, for those features | anthropic.com/legal/privacy |
| OpenAI | AI model provider for turning a challenge described in a message into a structured challenge, reached directly or through OpenRouter | The message text and the participant names included with it | openai.com/policies/privacy-policy |
| Twitch / YouTube / Kick | Checking whether a streaming channel you have linked is currently live | Only the public channel handle you linked | Per provider policy |
| Strava | Importing your Strava activities and sending FlowStake activities to Strava — only if you connect Strava (Section 1.5a) | Activities you choose to send: route, distance, time, and a "Recorded with FlowStake" note | strava.com/legal/privacy |
| Stripe | Payment processing — not currently used for any user-facing feature; would process payouts if a payment feature is introduced, and this Policy will be updated first | None today | stripe.com/privacy |
| IPFS (Pinata or public nodes) | Decentralized storage of proof records, where used | Activity proof hashes, attestation metadata — never raw GPS tracks | Public network — irreversible |
We contractually require all service providers to process your data only on our instructions and to maintain appropriate security standards. We do not currently use an identity-verification (KYC) provider. (The Google Analytics, OpenStreetMap Foundation, OpenRouter, Anthropic and OpenAI entries are pending final legal review.)
3.3 Financial Data Handling
- FlowStake does not currently collect any payment from you, and stores no payment card data
- If you receive a reward under the Achievement Reward Program, the bank details or mailing address you give us are used to send that payment and are handled outside the app by FlowStake's operator; your tax form is kept on file outside the app; your taxpayer identification number is never stored in the FlowStake database (Section 1.9)
- Amounts owed and paid to you are recorded in our database so that you, and we, have an accurate record, and so that we can meet tax-reporting obligations
- If you choose to connect a cryptocurrency wallet, we store only its public address
4. User Rights
4.1 Access and Control
- View your data
- Download your data
- Correct inaccuracies
- Delete your account
- Manage preferences
- Opt out of communications: every email you can switch off has an Unsubscribe link at the bottom. It works in one step and without signing in, and mail apps such as Gmail offer the same thing as an Unsubscribe button. Emails about your account, sign-in and payments still arrive. To choose individual kinds of email, sign in and open Email preferences. (This item is pending final legal review.)
- Control third-party sharing
- Change the visibility of any activity at any time
4.2 Data Portability
- Export activity data (GPX/TCX)
- Transfer to other services
- Limits: published fingerprints and on-chain attestations are permanent by design (Section 1.8)
5. Data Sharing
5.1 With Your Consent
- Challenge participants
- Social features
- Public leaderboards
- Profile visibility
- Group memberships
- Friend connections
- Public activities and their link previews (Section 1.6)
5.2 Service Providers
The named providers in Section 3.2, and no others.
5.3 Legal Requirements
- Court orders
- Regulatory compliance
- Fraud prevention
- Terms enforcement
- Law enforcement requests
- Legal investigations
6. Cookies and Tracking
6.1 Essential Cookies and Storage
- Authentication and session management
- Security
- Preferences (for example units, map style, tracker settings), stored on your device
- Feature functionality
6.2 Analytics
We use Google Analytics (Google LLC) to understand how the website and the app are used, for example which pages are opened and how often. It stores a cookie on your device holding a random identifier, and it receives the details listed for it in Section 3.2. When you arrive from a link, we remove sign-in codes, invite and referral codes, and email addresses from the page address before it is sent. We do not send Google Analytics your GPS tracks, activity data or health data, and we do not use it, or any other tool, for advertising. You can block it with your browser's privacy settings or Google's opt-out add-on (tools.google.com/dlpage/gaoptout). Sentry records technical errors. (This section is pending final legal review.)
7. International Data Transfers
Our infrastructure providers may process data in the United States and other countries. Where data is transferred across borders we rely on our providers' contractual safeguards. Published fingerprints and any on-chain attestations are, by their nature, replicated globally and permanently.
8. Data Retention
8.1 Account Information
Kept while your account is active and deleted within 45 days of account deletion, subject to the exceptions below.
8.2 Activity Data
Kept while your account is active. You may delete individual activities at any time; account deletion removes them all within 45 days. Photos you add to an activity are deleted as Section 1.6a describes: at once when you remove one, within 45 days when you delete its activity, and at once when you delete your account. Published fingerprints and on-chain attestations are permanent (Section 1.8).
8.3 Reward Payment Records
If you have received a reward payment, we retain a minimal record of it — your account identifier, the amount, the date, and that a tax form was on file — for as long as tax law requires, typically seven years, even if you delete your account. This record does not include your tax identification number, which is never stored in our systems. Everything else about your account is deleted as described above.
8.4 Email Opt-Outs
When you unsubscribe, we keep a coded form of your email address so that we keep honoring your choice. The code is made with a secret key and cannot be turned back into the address; it only lets us recognize the address if we are about to email it again. We keep it even if you delete your account, because deleting it would let those emails start again. It is removed when you turn email back on from Email preferences. Unsubscribe links carry the same kind of code, never your address. (This section is pending final legal review.)
8.5 Terms Acceptance Records
Kept while your account is active, as the record of which version of the Terms you agreed to and when. When you delete your account, the link to your account, your IP address and your browser or app details are removed from these records at once. What remains is an anonymous entry saying that a given version of the Terms was accepted at a given time and on which screen; it no longer says by whom. (This section is pending final legal review.)
8.6 Accounts We Remove
If we remove an account because it broke our Terms, we keep a short record that we did: the account identifier, the reason we recorded, and when. If we also ban the account, we may keep its email address, its username and its account identifier on a ban list, so that they cannot be used to create a new account. Apart from that, a removed account is deleted exactly as described above. Deleting your own account never puts you on a ban list. (This section is pending final legal review.)
9. Children's Privacy
We do not knowingly collect information from children under 18. If you believe we have collected information from a child, please contact us immediately at privacy@flowstake.com.
10. Changes to Privacy Policy
Each version of this Policy is dated. We update it whenever we change what we collect, how we use it, who we share it with, or how long we keep it — before the change takes effect, not after. Material changes will be announced in the app and by email. Previous versions are archived and available on request.
11. Contact Information
11.1 Privacy Questions
- Email: privacy@flowstake.com
- Mail: 1209 Orange Street, Wilmington, DE 19801
- Response time: Within 48 hours on business days
11.2 Data Protection Officer
- Email: dpo@flowstake.com
- Responsibilities: Oversight, compliance, inquiries
12. Legal Basis for Processing
12.1 Consent
- Account creation
- Optional features, including Apple Health, Strava, heart-rate monitors, wallet connection, and streaming-channel links
- Marketing communications
- Public sharing of an activity
12.2 Contractual Necessity
- Challenge participation
- Reward payments under a published reward program
- Account management
- Service provision
12.3 Legitimate Interests
- Security measures
- Service improvements
- Fraud prevention and verification integrity
- Aggregate analytics
- Keeping a record of email opt-outs so they are honored (Section 8.4)
- Keeping short-lived records of changes to your profile, activities and challenges (Section 14.3)
13. Specific Privacy Features
13.1 Activity Privacy
- Per-activity visibility: only you, friends, or public; default friends
- Start and end of every shared route removed from previews and shared maps
- "Hide map" option per activity
- Live map position rounded to roughly one kilometre, with one-tap hide and a profile-level opt-out
- Territory map built only from public, verified activities on an equal-area hexagon grid about 1.2 km across, never finer than the live map; cells released the moment an activity stops being public; signed-out visitors see only which cells are covered, never who covered them (Section 1.6)
- Public link previews only for public activities (Section 1.6)
- Up to five privacy zones, left out of every saved route other people see and of the territory map (Section 1.6)
- Photos: details stored in the file, such as where it was taken, removed before upload when your device can open the image; a photo's web address opens it for anyone who has the address, so remove a photo to put it out of reach (Section 1.6a)
13.2 Wallet Privacy
- Connecting a wallet is optional
- We store only the public address you link
- We never ask for, and you must never provide, a private key or seed phrase
13.3 Signing In With a Wallet or a Passkey
You may, if you choose, sign in by proving control of a wallet or a passkey instead of using an email address and password. This is optional; email sign-in remains available and nothing here is required to use FlowStake.
When you sign in this way:
- We ask your wallet to sign a short message. It states the site you are signing in to, the network, a one-time code we issue, and the time. Signing it proves you hold the key. It is not a transaction, it moves no funds, and it grants us no ability to spend anything.
- Your public address becomes part of your account. Where you previously linked an address only to receive a payment, an address you sign in with also identifies your account and is used to authenticate you on each later sign-in. It is recorded on your profile.
- We create an account for you if you do not have one. Because an account needs an address of some kind, we generate a non-routable placeholder derived from your public address. No mail can be sent to it and it is not an email address you own or can receive at.
- The one-time codes are short-lived and single-use. We store the code, the address, the site and the network it was issued for, and when it was used. They expire within minutes and are deleted afterwards.
- A passkey never leaves your device. It is held by your device's secure hardware and unlocked by you. We receive only the resulting proof, never the key.
- Signing in does not move money and is not a payment feature. It tells us who you are. It does not enable staking, charging, or paying, and does not change what FlowStake may collect from you — which remains nothing.
Age and Terms acceptance are required for a wallet or passkey account exactly as they are for an email account; you will be asked for both before you can use the Platform.
14. Security Practices
14.1 Technical Measures
- Encryption in transit and at rest
- Role-based and row-level access control
- Isolated secret storage
- Automated guard tests on privacy-sensitive code paths
- Error and alert monitoring
14.2 Organizational Controls
- Access limited to what a role requires
- Security review of changes that touch personal data
- Incident response procedure
- Vendor assessment
14.3 Change Records
When your profile, one of your activities or challenges, or your place in a challenge is created, changed or deleted — by you, by another user, or by FlowStake — we record which record it was, what kind of change it was, the names of the fields that changed (never what they contained), who made the change, and when. For a challenge that is deleted or completed automatically, we also keep its status, its stake amount, how many participants had paid, and whether rewards were paid. Settings → Security shows you your own recent changes, and we use these records to investigate problems and misuse. No other user can see the change records about your information. Each change record is deleted after 180 days. When you delete your account, every change record about you is deleted at once, and your account is removed from the records of changes you made to anyone else's information. (This section is pending final legal review.)
15. Public Records and Blockchain
15.1 Published Fingerprints
See Section 1.8. Fingerprints are public, permanent, and reveal nothing about content.
15.2 If You Opt In to On-Chain Attestation
An attestation records that a verified activity occurred, by fingerprint, on a public blockchain. It is permanent, publicly visible, and pseudonymous — linked to a public address, not to your name. Only the fingerprint is recorded, never your route.
16. Compliance Framework
- GDPR and CCPA considerations
- FTC Health Breach Notification Rule and state consumer-health-data laws (Section 1.4)
- Tax-reporting obligations for reward payments (Section 8.3)
- Industry best practices and self-regulatory frameworks
For questions about our privacy practices, please contact us at privacy@flowstake.com.