Transparency
Versioned · Last updated: October 2026
Flow is local-first. Your journal, your reflections, your check-ins, and the conversations you have with the on-device Guide live on your machine, in an encrypted database, and stay there unless you turn on sync. What syncs is counts and timings, never your words. What leaves your device beyond that is a short list of derived numbers, and only if you turn that on. This page says exactly what that means, and how to check it yourself.
These stay on your machine, full stop:
On the Mac, all of this sits in a local, SQLCipher-encrypted database. It leaves only through the specific, listed flows below — nothing else reaches for it.
Two kinds of thing, both narrow:
To make the app work at all.
If you use the cloud Coach, your message goes to our server to be answered. Signing in (optional) runs through Kinde. A check-in you record syncs as a mood entry. Push tokens register so reminders can arrive. That's the baseline, and it's covered by the privacy policy.
A weekly derived summary — off by default, on if you choose.
Once a week, if you've opted in, Flow sends a small set of derived, categorical values computed from what you told it during your check-ins: counts, averages, and ratios. Not the text. Not the raw signals. You report; Flow summarises what you reported. Flow does not watch how you work or infer your state on its own.
The summary is grouped into: things you told Flow about how the week went, how much you used the practices, a few optional health-derived averages (only if you've granted Apple Health access), and light context values. The full metric-by-metric registry, with exact field names and units, is published in our data-transparency document so an auditor can check it line by line.
Flow can take telemetry from your editor or CLI agent — Claude Code, Codex, VS Code, Cursor. That is a separate thing from everything above: it comes from the tool, not from this app, and only for a tool you have paired. Pairing is the grant. Revoking the pairing ends it.
What a paired tool reports.
Shape of the work, not the work. Per session: when it started and ended, which tool and model, how many prompts and replies, tokens, errors, a duration bucket. Project and branch names are hashed before they leave.
Per turn, two more. That your agent asked you a question — this one has been in the count for months, and we should have named it here sooner. And that it stopped and waited for you — a permission prompt, or an idle prompt, or something else. Both are counts. Neither carries what was said.
We count interruptions, and we say so.
Two of those signals are about being interrupted: when your agent pauses to ask you something, and when it pauses and waits. We decided to record both deliberately, and this is us saying so rather than letting it ride in under a heading that said “IDE telemetry” and left you to guess.
The question count is already running — it has been for months, under this same pairing. The waiting count is not: it exists in the collectors but no released version sends it yet, and a machine only starts once you update the tool there. Collectors never update themselves, so what yours sends is always a fact about the version you installed.
When it does arrive, an interruption is a single word — permission_request, idle_prompt, or other — attached to a timestamp. Not the question. Not the options. Not your answer. Not the wording of the notification, and not the command it was waiting for approval to run.
Nothing is built on this yet. It is measured and stored; there is no budget, no streak, no indicator, and nothing that goes off when your day gets chopped up. If that changes, it changes on this page first.
To be explicit, the weekly summary never includes:
Some records are thin, and Flow says so instead of filling the silence. A phone with no health history shows an empty body record, not a borrowed one. A day you can't remember is recorded as a gap, never a rating nobody gave. And if you're new to these tools, months of history simply aren't there — the Reveal will be honestly thin, and Flow won't pretend otherwise.
The standing offer is built on that honesty: run Flow for a week and ask why your best day was your best day. If it notices nothing, uninstalling is a reasonable response — and telling us so is the feedback we need most.
You will set how far Flow interprets — Show me, Tell me, Advise me — and the bolder setting is a choice you make, with the fragility of the claim printed on the label. That is a design commitment we build against, not a control in the app today; until it ships, Flow stays at the quiet end of that dial.
A refusal only ships when its mechanism is real and checkable. These are the eight, with the mechanism behind each one:
No fabricated data
Provenance on every value. If you didn't say it, it isn't stored as said. When there isn't enough signal, Flow says so instead of guessing.
No scores
No number to satisfy. Not a productivity grade, not a personality profile, not a rank. None, not hidden ones either. Patterns, not verdicts.
No streaks, no guilt
A missed day is recorded as nothing, not as failure. There is nothing to keep alive, and nothing to lose on a Friday.
No nagging
One prompt a day at most, never mid-block. Declining is honoured with a long cooldown. Protecting a block means not being the thing that breaks it.
No emotion inference
The check-in is you telling Flow how the work felt. It never concludes your state from telemetry, and it never stores what you didn't say.
No manager view
There is no employer access to any individual. Structurally absent, not restricted. Ascenda Flow is your instrument alone.
No training on your data
Your patterns never train shared models. Flow builds a model of you, for you, and what it learns stays yours.
No countdown anything
The free product is complete, not a teaser. No trial clock, no history cliff, nothing that expires because you didn't pay.
The point of this page is that you don't have to take our word for it:
Watch the import run.
Then read what it wrote — one JSON file per tool store, on your disk, before anything else happens. The first thing Flow does with your history is put it where you can read it.
Read the code path.
The routine that builds the weekly summary computes only the declared metrics — review it and confirm.
Watch the wire.
Proxy the app's HTTPS traffic and diff the payloads against the published schema.
Independent attestation.
We publish a third-party confirmation that the app sends only what this document describes.
Read the guard, not the promise.
What a paired tool refuses to send is enforced by a test that fails the build the moment a content field is added to the interruption event — in the Claude Code collector and the Codex one both. Ask us for the file and diff it against what lands.
If you're a security researcher and want to verify any of this, get in touch at privacy@ascenda.one.
The collectors are not open source yet. When that changes, this section gets a repository link and “read what leaves” becomes a one-click check. Until then the traffic is checkable the hard way — and we would rather say that plainly than point at a repo that isn't public.
This page is versioned. If any of the above changes, it changes here first, as a dated entry in the changelog — not quietly.
by Ascenda (ascenda.one)How Flow handles your data
© 2026 Ascenda One Pty Ltd. All rights reserved.