Privacy Policy

1. Introduction

We ("we", "us", "our") operate the web application available at https://flowtyping.app (the "Service"). This Privacy Policy explains how we collect, use, store, and protect personal data when you use the Service.

Effective date: 2026-08-17

For any privacy-related questions, contact us at: [email protected]

2. Data controller

The data controller is the entity operating the Service. For any questions about the processing of your personal data, you can contact us at:

Email: [email protected]

3. What data we collect

3.1 Information you provide via authentication

When you sign in using an OAuth provider (GitHub, Google, or Yandex), we receive and store:

  • Email address
  • Display name
  • Profile picture URL

We do not request access to your contacts, repositories, files, or any other data beyond the basic OAuth profile information listed above. We do not use your account to post, send messages, or act on your behalf.

3.2 Training and usage data

To provide the touch-typing training experience, we process:

  • Settings: interface language, text language, keyboard layout, finger layout, cursor style, theme, display name preference, rhythm channel preference, and session duration.
  • Skill profile: per-symbol learning statistics, including the number of exposures, first-try accuracy, and response latency averages.
  • Session summaries: duration, characters typed, speed (CPM/WPM), accuracy, rhythm score, and commonly confused symbol pairs.

3.3 Technical and diagnostic data

When the Service encounters an error in your browser, we may collect:

  • Error message and stack trace
  • Page URL where the error occurred
  • Browser user-agent string
  • Your user ID, if you are signed in

We do not use third-party error trackers such as Sentry. This data is stored in the same backend as your training data.

3.4 Product analytics

To understand how people use the Service, we collect anonymous usage statistics through PostHog (EU cloud). We collect:

  • Page view events: the page address within the Service, the referring address, and the time.
  • Page leave events: how long the page stayed open.
  • A first-keystroke event: the fact that a training session started. Neither the keys you press nor the text you type is sent to analytics.
  • Request metadata: browser user-agent and IP address, the latter used to derive an approximate region.
  • Your user ID, if you are signed in (including an anonymous account), so that one person's events are not counted as several.

Analytics run without cookies: PostHog is configured in cookieless mode and stores no identifier in your browser. Analytics requests go to our own domain (/ingest) and are forwarded to PostHog by our server.

3.5 Future data collection

We may introduce an optional raw keystroke capture feature for research and calibration purposes. If implemented, it will require explicit consent before any data is collected, and you will be able to opt out at any time.

4. How we use your data

We use your personal data to:

  • Provide, operate, and maintain the Service
  • Synchronize your settings and progress across devices
  • Adapt training content to your skill level
  • Diagnose and fix technical issues
  • Communicate with you about the Service, if necessary

We do not sell your personal data. We do not use your data for advertising profiling.

5. Legal basis for processing (GDPR)

For users in the European Economic Area and other jurisdictions with similar laws, our legal bases are:

  • Performance of a contract: processing necessary to provide the Service you requested.
  • Consent: where explicitly requested, for example for optional research data collection.
  • Legitimate interests: ensuring security, stability, and improving the Service, limited to what is reasonably expected and minimally intrusive.

6. Data sharing

We share your data only with:

  • OAuth providers: used solely for authentication.
  • Backend hosting provider: Convex, which stores data on our behalf.
  • Static hosting provider: Cloudflare Pages, which serves the application frontend and may process IP addresses and request metadata for technical delivery.
  • Product analytics provider: PostHog, which processes usage events on our behalf (section 3.4).

We do not share your data with advertisers, data brokers, or other unrelated third parties.

7. International data transfers

Our backend is hosted by Convex, which currently operates from the European Union (eu-west-1) and the United States. Product analytics data is processed in PostHog's EU cloud. OAuth providers may process data in their own jurisdictions. By using the Service, you acknowledge that your data may be transferred to and processed in countries outside your own, subject to applicable data protection safeguards.

8. Data retention

We retain your personal data for as long as your account exists. If you delete your account, all associated data is removed, including:

  • User profile
  • Settings
  • Skill profiles
  • Session summaries
  • Diagnostic error logs linked to your account
  • Authentication sessions and linked accounts

After deletion, only data that cannot be linked to you may remain for a limited period: guest error logs (not associated with any user ID), aggregated statistics stripped of personal identifiers, and short-term security or infrastructure logs.

9. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your account and associated data
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a data protection authority

To exercise your rights, contact us at [email protected].

10. Cookies and local storage

The Service uses browser storage for:

  • Authentication state: managed by the authentication library to keep you signed in.
  • Settings: your preferences are stored in localStorage under the key flow-typing-user-settings, so they persist between sessions and before you sign in.

We do not use third-party advertising cookies or trackers. Product analytics (section 3.4) runs in cookieless mode and stores nothing in your browser. Self-hosted fonts and assets mean your IP address is not leaked to external font providers.

11. Security

We use industry-standard measures to protect your data, including:

  • HTTPS/TLS encryption for data in transit
  • OAuth-based authentication
  • Server-side access controls and rate limiting
  • Fail-closed production environment checks

No system is completely secure. We act promptly to address vulnerabilities when discovered.

12. Children

The Service is not directed to children under 13 (or under 16 in jurisdictions where a higher age applies). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. If changes are material, we will notify you via the Service or by email. The updated policy will indicate the effective date.