Privacy Policy — Session Flow
Version 4 · September 29, 2026
English translation. The Portuguese version is the official one and prevails in case of any discrepancy.
Update of September 30, 2026: the app verification attestation (section 4.2, item 6) is now valid for up to 12 hours instead of about one hour. What we process and your rights do not change.
Update of October 3, 2026: section 4.2 (item 3) now says that access records also keep the app platform (Android, iPhone or iPad, or browser), as they have since September 27, 2026. The new section 3.4 describes reading the device calendar, which only happens if you choose to import sessions and stays on the device. Retention periods, legal bases and your rights do not change.
Update of October 5, 2026: section 4.7 now says that, when the way the cloud stores data changes for technical reasons, the previous form is kept for up to 7 days and then deleted, and that parts of an interrupted upload are deleted within 6 weeks. What we process, the legal bases and your rights do not change.
Update of October 6, 2026: section 3.1 now says that a record keeps, if you choose, its grammatical gender, used only so the app's texts agree (in Portuguese and Spanish, "o aluno" or "a aluna"), and gains the item "Activity log": what was done in the app, when and on which kind of device, for you to consult. What we process, the legal bases and your rights do not change.
1. Who we are
Session Flow is a scheduling and payment tracking app for professionals who work in sessions. It is developed and maintained by Kaio Rafael de Oliveira Diniz, an individual ("we").
- Privacy contact: mundi.labs.flow@gmail.com
- Data Protection Officer (encarregado, art. 41 of the Brazilian General Data Protection Law — LGPD): Kaio Rafael de Oliveira Diniz — mundi.labs.flow@gmail.com
2. Summary
- Without the cloud, everything stays on your device. We do not receive, see or store the data you record in Session Flow.
- The cloud is optional. It is only available on the Premium Monthly, Yearly and Lifetime plans, and it only works if you turn it on. When you do, you accept the Cloud Terms of Use and this Policy. From then on, a copy of your data is stored on Google Cloud servers in São Paulo, Brazil, to sync your devices and the browser.
- Session Flow is not a clinical record. The app has no fields for diagnoses or clinical notes.
- We do not sell data. We also do not use advertising, usage analytics or tracking tools.
- You control your cloud. You can turn it off, delete its data or delete your account from within the app at any time.
3. Using the app without the cloud (default)
3.1 What the app stores on your device
- Records: name, WhatsApp number, video session link, fees, billing method and timing, reminder and billing message texts and, if you choose, the grammatical gender of each one (so the app's texts in Portuguese and Spanish say "o aluno" or "a aluna").
- Schedule and payments: sessions (dates, times, status, no-shows, cancellations and reschedules), payments and prepayments, days off and events.
- Activity log: what was done in the app (payments, reschedules, no-shows, changes), when and on which kind of device, for you to consult.
- Documents (receipts, statements), with:
- the professional's details: name, contact, tax ID, professional registration, specializations, address and signature text;
- additional client details: full name, CPF, RG, date of birth, address and legal guardian;
- document templates.
- App settings.
3.2 Who has access
This data stays only on your device, and we have no access to it. Session Flow works without an account and without internet.
3.3 When data leaves the device — always through an action of yours or of your system
- System backup. Android (Google backup) and iPhone (iCloud) may include the app in the device backup, according to your Google or Apple account settings.
- Manual backup. You can export a
.jsonfile with your data. You decide where to keep it. - WhatsApp. When you tap to send a reminder or a payment request, the app opens WhatsApp with the message ready. You send it, through WhatsApp.
- Documents. The PDFs you generate stay on the device until you share them.
- Reminders. They are scheduled on the device itself, as local notifications. Nothing about them is sent to servers.
3.4 Device calendar
If you choose to import sessions from the device calendar, the app asks for the system permission and reads the events in the period you choose (title, date, time, recurrence, location and meeting link). The reading happens only on the device, and nothing from it is sent to us. What you confirm becomes records and sessions in the app, like those in section 3.1 — and, with the cloud on, it syncs like them. You can remove the permission in the device settings at any time.
3.5 Subscriptions
Purchases and renewals are handled by Google Play or the App Store. We do not receive card or payment details. The app checks with the store whether your subscription is active.
4. Using the cloud (optional)
4.1 When it applies
Only after you read the key points, check "I have read and accept the terms and the policy" and sign in with your Google or Apple account, in Settings → Cloud & privacy. Without this acceptance, the cloud is not turned on.
4.2 What data we process
- Account: account identifier, email and sign-in method (Google or Apple), provided by Google or Apple at sign-in.
- Acceptance record: versions of the Terms and of this Policy, date and time, sign-in method and IP address at the time of acceptance.
- Access records: date, time, IP address and app platform (Android, iPhone or iPad, or browser) of each use of the cloud — opening the app with the cloud on, accepting the terms, activating the subscription, turning the cloud on or off, deleting the data or the account.
- Subscription: plan, store, expiry and an irreversible code (hash) of the purchase receipt. The receipt itself is not stored.
- Your app data: a copy of the data in section 3.1, with the date of the last change and a random identifier of the device that made it.
- Technical control:
- usage counters per account, to prevent abuse;
- app verification: each time the cloud is used, the app obtains an attestation that it is the original Session Flow, on a real device or browser. On Android, Google Play attests; on iPhone and iPad, Apple; in the browser, Google's reCAPTCHA Enterprise (section 4.8). We only receive the result, an attestation valid for up to 12 hours that does not identify you or the device;
- server operation logs, which may include the account identifier and the IP address and are kept for Google Cloud's default period (usually 30 days).
4.3 What we use it for
- Syncing your devices and the browser.
- Confirming that your plan includes the cloud.
- Protecting the service against abuse and unauthorized access, including confirming that access comes from the original app.
- Handling your requests and complying with legal obligations.
4.4 Legal bases (art. 7 of the LGPD)
- Performance of a contract: the cloud is a service you choose to use. The acceptance record proves the conditions you accepted.
- Compliance with a legal obligation: the access records (date, time and IP address), as required by art. 15 of the Brazilian Internet Civil Framework (Marco Civil da Internet, Law No. 12,965/2014). The acceptance record also relies on this basis.
- Legitimate interest: security and abuse prevention, such as usage limits and app verification.
- Regular exercise of rights: after the account is deleted, the acceptance record is kept separately, solely for our defense in case of a dispute about the acceptance (section 4.7).
4.5 Where the data is stored and who helps us (sub-processors)
- Google (Firebase and Google Cloud):
- database (Firestore) and server functions in the São Paulo region
(
southamerica-east1); - sign-in (Firebase Authentication). This service does not allow choosing the region, and account data (identifier and email) may be stored outside Brazil, including in the United States;
- hosting of the web app (Firebase Hosting). The web app does not store your data on the hosting server;
- app verification: Play Integrity (Google Play), on Android, and reCAPTCHA Enterprise, in the browser.
- database (Firestore) and server functions in the São Paulo region
(
- Apple: Sign in with Apple and app verification on iPhone and iPad (DeviceCheck). Apple may offer a relay email instead of your real email.
- Google Play and App Store: subscription verification.
International transfer (art. 33). It happens at sign-in, with the account data, and during app verification, with the technical data of the device or browser that Google and Apple analyze. The transfer relies on the Standard Contractual Clauses offered by these providers, in accordance with the requirements of the Brazilian National Data Protection Authority (ANPD).
4.6 Security
- Encryption in transit (TLS) and at rest, the latter provided by Google.
- Access rules that only release each account's own data, and sign-in only with Google or Apple.
- Usage limits and server-side subscription verification.
- Verification that access comes from the original app, on a real device or browser.
- There is no end-to-end encryption. Technically, whoever administers the project on Google Cloud can read the data. We commit not to access it, except to handle a request from you or to comply with a legal obligation.
4.7 How long we keep data (retention)
- While the cloud is on and your plan is active.
- If you turn off the cloud: the data is kept for 30 days, in case you want to turn it back on, and then deleted. You can also delete it right away.
- If your plan ends: the data is kept for 90 days and then deleted. What is on your devices is not touched.
- "Delete account" or "Delete all data" (with the cloud on) delete the cloud data immediately. "Delete account" also deletes the sign-in account.
- Acceptance record: kept while the account exists. After the account is deleted, it — together with the account email — is kept separately for 5 years, the period set by art. 27 of the Brazilian Consumer Protection Code, solely for our defense in case of a dispute about the validity of the acceptance. After that, it is deleted.
- Deleted records: a deletion marker is kept for up to 30 days, so that other devices know the record was removed.
- We do not make our own backup copies. Once deleted, it is deleted. Temporary technical copies in Google's infrastructure follow Google Cloud's own deletion policy. When the way the cloud stores data changes for technical reasons, the previous form is kept for up to 7 days after the change and then deleted — right away if you delete your account or all your data. Parts of an interrupted upload are deleted within 6 weeks.
- Technical records (logs): records of access to the cloud (such as date, time and IP address) are kept for 6 months, for security, auditing and compliance with the legal standards of the Brazilian Internet Civil Framework. After this period, they are deleted. This also applies if the account is deleted earlier.
4.8 Web app (browser)
The web app uses the same cloud account. While you are signed in, the data is stored in the browser itself so the app can work. When you sign out, it is deleted from the browser. The web app does not use advertising or tracking cookies. To protect the cloud against automated access, it uses Google's reCAPTCHA Enterprise, which analyzes information about the browser and the device and the interaction with the page, and sets a security cookie. reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.
5. Your clients' data
- You decide what to record about your clients. Therefore, you are the controller of this data (art. 5, VI). When we store this data in the cloud at your request, we are the processor (art. 5, VII). In this role, we process the data only to provide the cloud, under the Cloud Terms of Use.
- Session Flow is not a clinical record and was not designed for clinical documentation: there are no fields for diagnoses, progress notes or free-text notes. Even so, recording sessions with health professionals may reveal information about a person's health. That is why we handle this data with the care the LGPD requires for sensitive data (art. 11).
- Children and adolescents (art. 14). If you see and record minors, it is up to you to obtain the necessary authorizations from their legal guardian.
- Requests from your clients. You answer them as the controller. Where the cloud is involved, we help.
6. Your rights (art. 18 of the LGPD)
You may request:
- confirmation that we process your data, and access to it;
- correction of data;
- anonymization, blocking or deletion of data;
- portability, which the app already offers through the
.jsonexport; - information about whom we share data with;
- withdrawal of consent and objection to processing.
How to exercise them:
- In the app: in Settings → Cloud & privacy you can turn off the cloud, delete the cloud data or delete the account. In Backup & Restore, you can export your data.
- By email: mundi.labs.flow@gmail.com. We reply within 15 days (art. 19, II).
Deletion does not cover what the law requires us to keep: the access records (6 months) and the acceptance record kept for our defense (5 years), as described in section 4.7.
You may also file a complaint with the Brazilian National Data Protection Authority (ANPD).
7. If you are in the European Union, the European Economic Area or the United Kingdom
If you are in the European Union, the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR) and the UK GDPR also apply. In that case:
- Legal bases. The cloud relies on the performance of the contract (art. 6(1)(b)). The access records, app verification and the acceptance record rely on our legitimate interest in protecting the service against abuse and in defending ourselves in case of a dispute (art. 6(1)(f)).
- Your rights. In addition to those in section 6, you may ask us to restrict processing (art. 18) and object to processing based on legitimate interest (art. 21). We may keep what is necessary for our defense in legal proceedings.
- Complaints. You may file a complaint with the data protection authority of the country where you live or work, or where the infringement occurred.
- Transfers. The European Commission recognizes that Brazil protects personal data adequately (Implementing Decision (EU) 2026/179). Account data that may be stored in the United States, and the technical data of app verification processed by Google and Apple, are covered by the EU-U.S. Data Privacy Framework and by the European Commission's standard contractual clauses offered by these providers.
- No automated decisions. We do not make decisions based solely on automated means, and we do not do profiling.
- Required data. To use the cloud, you need to sign in with Google or Apple. Without that, the app keeps working on your device only.
8. Minimum age
Session Flow is intended for professionals aged 18 or over.
9. What we do not do
- We do not sell or rent data.
- We do not share data for marketing.
- We do not use advertising or usage analytics, tracking or crash reporting tools.
- App verification (section 4.2) is used only for the security of the cloud.
10. Security incidents
If an incident may cause relevant risk or harm, we will notify the ANPD and the affected people (art. 48), and we will let you know through the available channels.
For those in the European Union, the European Economic Area or the United Kingdom, we will notify the competent data protection authority within 72 hours when the incident may pose a risk, and the affected people when the risk is high.
11. Changes to this Policy
- Each version has a number and a date.
- For cloud users, a relevant change requires a new acceptance in the app. Without it, syncing is paused, and the data on the device remains available.
- For those who do not use the cloud, nothing changes in how the app works.
12. Governing law
This Policy is governed by Brazilian law, in particular Law No. 13,709/2018 (LGPD).