HostFlow

Privacy Policy

Effective 14 September 2026

HostFlow is a flexible work management tool for teams and individuals. This policy describes what the service stores, why it stores it, and how to have it removed. It is written to be accurate about what the software actually does rather than to be broad enough to cover anything it might do.

Who runs the service

HostFlow is operated by Youness Nait Oufkir. Contact for any privacy question, including access and deletion requests: contact@hostflow-app.com.

What is stored

  • Account details — your email address, your name, an optional profile picture, your chosen interface language, and a display colour. Passwords are handled by our authentication provider and stored only as a hash; HostFlow never sees your password.
  • The work you enter — workspaces, boards, tasks, dates, assignments, statuses, comments, file attachments, and the activity log of changes made to them.
  • Notification settings — whether you want email, Telegram, or in-app alerts, and which single channel your daily digest is sent on.
  • Integration credentials — if you connect Google Calendar or Telegram, the tokens or chat identifier needed to reach those services on your behalf. These are held server-side and are never sent to the browser.

HostFlow does not use advertising cookies, does not track you across other websites, and does not sell or rent personal data to anyone.

How Google user data is used

This section describes HostFlow's use of Google APIs specifically. Connecting Google Calendar is entirely optional and the rest of the product works without it.

  • What is requested. A single scope, calendar.events, which permits viewing and editing calendar events. HostFlow does not request access to your contacts, your email, your files, or any other Google service.
  • What it is used for. One thing only: when a task with a date is assigned to you, HostFlow creates or updates a single all-day event for that task on your primary calendar, so your schedule reflects your work.
  • What is read. HostFlow looks up only events it created itself, identified by a private marker it attaches to them. It does not read, index, or store the contents of your existing calendar events.
  • What is stored. The access and refresh tokens Google issues, held server-side so the sync can run when you are not at your screen. The event identifier is derived from the task, so no copy of your calendar is kept.
  • Who it is shared with. Exactly two parties ever touch this data: Google itself, when HostFlow writes an event to or reads it from your calendar, and Supabase, our database provider (hosted in the European Union), which stores the access and refresh tokens so the sync can run. No other company, contractor, advertiser, analytics provider, or third party of any kind receives, views, or is given access to it.
  • What is never done. Google user data is not transferred, sold, or disclosed to anyone beyond the two parties above, is not used for advertising, is not used to build profiles, and is not used to train any artificial intelligence or machine learning model.
  • How to revoke it. Disconnect Google Calendar in Profile Settings, which deletes the stored tokens immediately. You can also revoke access at myaccount.google.com/permissions. Events already written to your calendar remain yours and are not deleted; you can remove them from Google Calendar directly.

HostFlow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Who processes the data

HostFlow runs on a small number of service providers, each handling data only to operate the product:

  • Supabase — database, authentication and file storage, hosted in the European Union (eu-west-1).
  • Vercel — application hosting and delivery.
  • Resend — sending notification and digest emails.
  • Google — calendar synchronisation, only if you connect it.
  • Telegram — instant notifications, only if you connect it.

How long it is kept

Your account and the work in it are kept for as long as the account exists. Deleted tasks are retained in the trash so they can be restored, and are removed permanently when the trash is emptied. Integration tokens are deleted as soon as you disconnect the integration, and are also cleared automatically when the provider stops accepting them.

Your rights

You can view and correct most of your data directly in the app. You may request a copy of your data, or its deletion, by writing to contact@hostflow-app.com. Deletion requests are honoured within 30 days, other than anything we are required to keep by law.

Security

Access to data is enforced in the database itself, per row and per column, so an account can only reach the workspaces and boards it has been granted. Integration tokens are not readable by the browser at all. No system is perfectly secure, and this policy is not a warranty against every possible failure.

Changes

If this policy changes in a way that affects how your data is used, the effective date above will change and material changes will be announced in the app.