← Ascenda

Transparency

Trust — what Flow does with your data

Versioned · Last updated: October 2026

Flow is local-first. Your journal, your reflections, your check-ins, and the conversations you have with the on-device Guide live on your machine, in an encrypted database, and stay there unless you turn on sync. What syncs is counts and timings, never your words. What leaves your device beyond that is a short list of derived numbers, and only if you turn that on. This page says exactly what that means, and how to check it yourself.

What never leaves your device

These stay on your machine, full stop:

  • Your journal entries and written reflections — the actual text.
  • Your conversations with the on-device Guide — the full transcript.
  • Calendar detail — meeting titles, attendees, notes.
  • Raw health data — HRV samples, heart-rate readings, sleep stages, straight from Apple Health.
  • Your per-check-in emotion selections and the exact position you set on the mood grid.

On the Mac, all of this sits in a local, SQLCipher-encrypted database. It leaves only through the specific, listed flows below — nothing else reaches for it.

What leaves your device — and only if you opt in

Two kinds of thing, both narrow:

To make the app work at all.

If you use the cloud Coach, your message goes to our server to be answered. Signing in (optional) runs through Kinde. A check-in you record syncs as a mood entry. Push tokens register so reminders can arrive. That's the baseline, and it's covered by the privacy policy.

A weekly derived summary — off by default, on if you choose.

Once a week, if you've opted in, Flow sends a small set of derived, categorical values computed from what you told it during your check-ins: counts, averages, and ratios. Not the text. Not the raw signals. You report; Flow summarises what you reported. Flow does not watch how you work or infer your state on its own.

The summary is grouped into: things you told Flow about how the week went, how much you used the practices, a few optional health-derived averages (only if you've granted Apple Health access), and light context values. The full metric-by-metric registry, with exact field names and units, is published in our data-transparency document so an auditor can check it line by line.

If you pair a coding tool

Flow can take telemetry from your editor or CLI agent — Claude Code, Codex, VS Code, Cursor. That is a separate thing from everything above: it comes from the tool, not from this app, and only for a tool you have paired. Pairing is the grant. Revoking the pairing ends it.

What a paired tool reports.

Shape of the work, not the work. Per session: when it started and ended, which tool and model, how many prompts and replies, tokens, errors, a duration bucket. Project and branch names are hashed before they leave.

Per turn, two more. That your agent asked you a question — this one has been in the count for months, and we should have named it here sooner. And that it stopped and waited for you — a permission prompt, or an idle prompt, or something else. Both are counts. Neither carries what was said.

We count interruptions, and we say so.

Two of those signals are about being interrupted: when your agent pauses to ask you something, and when it pauses and waits. We decided to record both deliberately, and this is us saying so rather than letting it ride in under a heading that said “IDE telemetry” and left you to guess.

The question count is already running — it has been for months, under this same pairing. The waiting count is not: it exists in the collectors but no released version sends it yet, and a machine only starts once you update the tool there. Collectors never update themselves, so what yours sends is always a fact about the version you installed.

When it does arrive, an interruption is a single word — permission_request, idle_prompt, or other — attached to a timestamp. Not the question. Not the options. Not your answer. Not the wording of the notification, and not the command it was waiting for approval to run.

Nothing is built on this yet. It is measured and stored; there is no budget, no streak, no indicator, and nothing that goes off when your day gets chopped up. If that changes, it changes on this page first.

What a paired tool never sends

  • The text of any question your agent asked you.
  • The options it offered, or which one you chose.
  • The wording of any notification, or the command it was waiting to run.
  • File paths, file contents, source code, or your prompts.
  • Unhashed project or branch names.

What Flow never sends

To be explicit, the weekly summary never includes:

  • Your name, email, phone number, or any personal identifier.
  • Your journal entries, reflections, or any free-form writing.
  • Meeting titles, attendee names, or calendar detail.
  • Raw HRV samples, heart-rate readings, or sleep-stage data.
  • Your individual emotion selections (only weekly frequency counts).
  • The content of your Guide or Coach conversations (only how many messages, not what was said).
  • Your location, IP address, or device identifiers beyond keeping you signed in.
  • Anything from other apps on your device.

When there's nothing to say

Some records are thin, and Flow says so instead of filling the silence. A phone with no health history shows an empty body record, not a borrowed one. A day you can't remember is recorded as a gap, never a rating nobody gave. And if you're new to these tools, months of history simply aren't there — the Reveal will be honestly thin, and Flow won't pretend otherwise.

The standing offer is built on that honesty: run Flow for a week and ask why your best day was your best day. If it notices nothing, uninstalling is a reasonable response — and telling us so is the feedback we need most.

How far Flow interprets

You will set how far Flow interprets — Show me, Tell me, Advise me — and the bolder setting is a choice you make, with the fragility of the claim printed on the label. That is a design commitment we build against, not a control in the app today; until it ships, Flow stays at the quiet end of that dial.

On the Mac

  • Guest by default. Flow works completely with no account. A random guest session identifies the installation, not you.
  • The Guide runs on your Mac and sends nothing. The Coach is the persona that runs in Ascenda's cloud; it sends only the payload you approve in the grant sheet, each time, before anything leaves.
  • Your licence key is treated as a credential. It's sent once over TLS when you press Redeem, then stored in the macOS Keychain — never logged, never in analytics, not even hashed. A licence key is not a sign-in: the token it returns can only read your entitlement (your plan and its expiry), and the server rejects it everywhere else. It can't reach your journal, chat, or sync.
  • If you link an account (optional — e.g. to back up your model), desktop analytics become identified from that point, which we disclose in the App Store listing. Your licence key and email are never analytics properties.

Your controls

  • Every share is opt-in, never opt-out.
  • You can revoke any consent at any time in Data & Privacy → Consent History; revoking stops that data from being included going forward.
  • You can ask us to delete data already sent.

What Flow refuses to do

A refusal only ships when its mechanism is real and checkable. These are the eight, with the mechanism behind each one:

No fabricated data

Provenance on every value. If you didn't say it, it isn't stored as said. When there isn't enough signal, Flow says so instead of guessing.

No scores

No number to satisfy. Not a productivity grade, not a personality profile, not a rank. None, not hidden ones either. Patterns, not verdicts.

No streaks, no guilt

A missed day is recorded as nothing, not as failure. There is nothing to keep alive, and nothing to lose on a Friday.

No nagging

One prompt a day at most, never mid-block. Declining is honoured with a long cooldown. Protecting a block means not being the thing that breaks it.

No emotion inference

The check-in is you telling Flow how the work felt. It never concludes your state from telemetry, and it never stores what you didn't say.

No manager view

There is no employer access to any individual. Structurally absent, not restricted. Ascenda Flow is your instrument alone.

No training on your data

Your patterns never train shared models. Flow builds a model of you, for you, and what it learns stays yours.

No countdown anything

The free product is complete, not a teaser. No trial clock, no history cliff, nothing that expires because you didn't pay.

Don't trust us — verify

The point of this page is that you don't have to take our word for it:

Watch the import run.

Then read what it wrote — one JSON file per tool store, on your disk, before anything else happens. The first thing Flow does with your history is put it where you can read it.

Read the code path.

The routine that builds the weekly summary computes only the declared metrics — review it and confirm.

Watch the wire.

Proxy the app's HTTPS traffic and diff the payloads against the published schema.

Independent attestation.

We publish a third-party confirmation that the app sends only what this document describes.

Read the guard, not the promise.

What a paired tool refuses to send is enforced by a test that fails the build the moment a content field is added to the interruption event — in the Claude Code collector and the Codex one both. Ask us for the file and diff it against what lands.

If you're a security researcher and want to verify any of this, get in touch at privacy@ascenda.one.

The collectors are not open source yet. When that changes, this section gets a repository link and “read what leaves” becomes a one-click check. Until then the traffic is checkable the hard way — and we would rather say that plainly than point at a repo that isn't public.

This page is versioned. If any of the above changes, it changes here first, as a dated entry in the changelog — not quietly.