Session Flow

Privacy Policy — Session Flow

Version 4 · September 29, 2026

English translation. The Portuguese version is the official one and prevails in case of any discrepancy.

Update of September 30, 2026: the app verification attestation (section 4.2, item 6) is now valid for up to 12 hours instead of about one hour. What we process and your rights do not change.

Update of October 3, 2026: section 4.2 (item 3) now says that access records also keep the app platform (Android, iPhone or iPad, or browser), as they have since September 27, 2026. The new section 3.4 describes reading the device calendar, which only happens if you choose to import sessions and stays on the device. Retention periods, legal bases and your rights do not change.

Update of October 5, 2026: section 4.7 now says that, when the way the cloud stores data changes for technical reasons, the previous form is kept for up to 7 days and then deleted, and that parts of an interrupted upload are deleted within 6 weeks. What we process, the legal bases and your rights do not change.

Update of October 6, 2026: section 3.1 now says that a record keeps, if you choose, its grammatical gender, used only so the app's texts agree (in Portuguese and Spanish, "o aluno" or "a aluna"), and gains the item "Activity log": what was done in the app, when and on which kind of device, for you to consult. What we process, the legal bases and your rights do not change.

1. Who we are

Session Flow is a scheduling and payment tracking app for professionals who work in sessions. It is developed and maintained by Kaio Rafael de Oliveira Diniz, an individual ("we").

2. Summary

3. Using the app without the cloud (default)

3.1 What the app stores on your device

3.2 Who has access

This data stays only on your device, and we have no access to it. Session Flow works without an account and without internet.

3.3 When data leaves the device — always through an action of yours or of your system

3.4 Device calendar

If you choose to import sessions from the device calendar, the app asks for the system permission and reads the events in the period you choose (title, date, time, recurrence, location and meeting link). The reading happens only on the device, and nothing from it is sent to us. What you confirm becomes records and sessions in the app, like those in section 3.1 — and, with the cloud on, it syncs like them. You can remove the permission in the device settings at any time.

3.5 Subscriptions

Purchases and renewals are handled by Google Play or the App Store. We do not receive card or payment details. The app checks with the store whether your subscription is active.

4. Using the cloud (optional)

4.1 When it applies

Only after you read the key points, check "I have read and accept the terms and the policy" and sign in with your Google or Apple account, in Settings → Cloud & privacy. Without this acceptance, the cloud is not turned on.

4.2 What data we process

  1. Account: account identifier, email and sign-in method (Google or Apple), provided by Google or Apple at sign-in.
  2. Acceptance record: versions of the Terms and of this Policy, date and time, sign-in method and IP address at the time of acceptance.
  3. Access records: date, time, IP address and app platform (Android, iPhone or iPad, or browser) of each use of the cloud — opening the app with the cloud on, accepting the terms, activating the subscription, turning the cloud on or off, deleting the data or the account.
  4. Subscription: plan, store, expiry and an irreversible code (hash) of the purchase receipt. The receipt itself is not stored.
  5. Your app data: a copy of the data in section 3.1, with the date of the last change and a random identifier of the device that made it.
  6. Technical control:
    • usage counters per account, to prevent abuse;
    • app verification: each time the cloud is used, the app obtains an attestation that it is the original Session Flow, on a real device or browser. On Android, Google Play attests; on iPhone and iPad, Apple; in the browser, Google's reCAPTCHA Enterprise (section 4.8). We only receive the result, an attestation valid for up to 12 hours that does not identify you or the device;
    • server operation logs, which may include the account identifier and the IP address and are kept for Google Cloud's default period (usually 30 days).

4.3 What we use it for

4.5 Where the data is stored and who helps us (sub-processors)

International transfer (art. 33). It happens at sign-in, with the account data, and during app verification, with the technical data of the device or browser that Google and Apple analyze. The transfer relies on the Standard Contractual Clauses offered by these providers, in accordance with the requirements of the Brazilian National Data Protection Authority (ANPD).

4.6 Security

4.7 How long we keep data (retention)

4.8 Web app (browser)

The web app uses the same cloud account. While you are signed in, the data is stored in the browser itself so the app can work. When you sign out, it is deleted from the browser. The web app does not use advertising or tracking cookies. To protect the cloud against automated access, it uses Google's reCAPTCHA Enterprise, which analyzes information about the browser and the device and the interaction with the page, and sets a security cookie. reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.

5. Your clients' data

6. Your rights (art. 18 of the LGPD)

You may request:

How to exercise them:

Deletion does not cover what the law requires us to keep: the access records (6 months) and the acceptance record kept for our defense (5 years), as described in section 4.7.

You may also file a complaint with the Brazilian National Data Protection Authority (ANPD).

7. If you are in the European Union, the European Economic Area or the United Kingdom

If you are in the European Union, the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR) and the UK GDPR also apply. In that case:

8. Minimum age

Session Flow is intended for professionals aged 18 or over.

9. What we do not do

10. Security incidents

If an incident may cause relevant risk or harm, we will notify the ANPD and the affected people (art. 48), and we will let you know through the available channels.

For those in the European Union, the European Economic Area or the United Kingdom, we will notify the competent data protection authority within 72 hours when the incident may pose a risk, and the affected people when the risk is high.

11. Changes to this Policy

12. Governing law

This Policy is governed by Brazilian law, in particular Law No. 13,709/2018 (LGPD).