Cloud Terms of Use — Session Flow
Version 4 · September 29, 2026
English translation. The Portuguese version is the official one and prevails in case of any discrepancy.
Update of October 3, 2026: in section 3, the copy of the data from before the cloud is now kept in Backup & Restore for 2 days, and the text says it is also made when merging the data. The copy stays only on the device.
Update of October 5, 2026: section 6 now says that, when the way the cloud stores data changes for technical reasons, the previous form is kept for up to 7 days and then deleted, and that parts of an interrupted upload are deleted within 6 weeks.
1. Who these Terms apply to
- Without the cloud, there is nothing to accept. Session Flow works without an account and without internet, with the data only on your device. In that case, only the rules of the store that distributed the app (Google Play or App Store) and our Privacy Policy apply.
- These Terms apply only to the cloud: the optional sync between your devices and access through the browser.
- How you accept them. You accept these Terms when you check "I have read and accept the terms and the policy" and sign in with Google or Apple, in Settings → Cloud & privacy. Without this acceptance, the cloud is not turned on, and the app keeps working only on your device.
- Provider: Kaio Rafael de Oliveira Diniz, an individual. Contact: mundi.labs.flow@gmail.com.
2. Who can use it
- Professionals aged 18 or over, with an active Premium Monthly, Yearly or Lifetime plan purchased on Google Play or the App Store. The Essential and free plans do not include the cloud.
- One subscription serves one cloud account: the first account that activates the subscription keeps it. After that, Premium applies on any device that signs in with the same account.
- Sign-in only with Google or Apple. You can link both sign-in methods to the same account.
3. How the cloud works
- A copy of your app data is stored on Google Cloud servers in São Paulo, Brazil. The devices and the browser linked to the same account stay in sync.
-
First sync with data on the device and in the cloud. You choose one of these options:
- Merge both: nothing is lost. What exists only on the device goes up, and what exists only in the cloud comes down.
- Use only the cloud data: the device's data is replaced by the cloud's.
- Use only this device's data: the cloud becomes the same as the device. What existed only in the cloud is deleted from it and from the other connected devices.
When the cloud changes the device's data (when merging or when using only the cloud data), a copy of the previous data is kept in Backup & Restore for 2 days. After that, it is deleted.
- The cloud syncs; it is not a backup. A change or deletion made on one device reaches the others. We recommend exporting backups regularly in Backup & Restore.
- Session reminders stay scheduled on each device.
- Usage limits. To protect the service, there are usage limits, such as the number of calls to the server and the size of the data.
- App verification. The cloud only serves the original Session Flow, verified by Google Play, Apple or reCAPTCHA (Privacy Policy, section 4.2). Old versions of the app, devices without Google Play, modified apps and browsers that block reCAPTCHA may lose access to the cloud. The app keeps working on the device.
- Availability. We strive to keep the cloud running, but we do not guarantee that it will be available at all times. There may be maintenance, failures and unavailability of our providers. Without a connection, the app keeps working on the device and syncs when the connection returns.
- Changes to the service. We may change or discontinue the cloud. If it is discontinued, we will give reasonable notice in the app. The data on your devices stays with you.
4. Your responsibilities
- Record only what is necessary for your schedule, billing and documents. Session Flow is not a clinical record: do not use it for clinical documentation.
- Legal basis for your clients' data. Have a legal basis to process this data and inform your clients that you use Session Flow and the cloud (arts. 7, 9 and 11 of the Brazilian General Data Protection Law — LGPD — and, if you or your clients are in the European Union, art. 9 of the GDPR). Health data requires you to process it as a professional bound by secrecy.
- Minors. Obtain the authorizations of the legal guardian when you record minors (art. 14).
- Security of your account. Protect your Google or Apple account and access to your devices. Let us know if you suspect unauthorized access.
- Misuse. Do not try to access other accounts' data, bypass the usage limits or app verification, use modified versions of the app, overload the service or use it for unlawful purposes.
5. Your clients' data: you as controller, we as processor
When you store your clients' data in the cloud, you are the controller and we are the processor (art. 5, VI and VII, and art. 39 of the LGPD; art. 28 of the GDPR). In this role, we commit to:
- Process this data only to provide the cloud, following your instructions, which are what you record, sync and delete in the app.
- Keep it confidential. We do not access the content of your data, except to handle a request from you or a legal obligation.
- Use only the sub-processors described in the Privacy Policy: Google (Firebase and Google Cloud), Apple and the stores.
- Report incidents. We will notify you without undue delay of security incidents affecting your data, so that you can assess notifying the data subjects and the ANPD.
- Help with data subjects' requests where the cloud is involved.
- Delete the data at the end of the service, within the periods in section 6.
- Confidentiality of those with access. Only those who need it to keep the service running will have access to the data, under a duty of confidentiality.
- Security. We maintain the measures described in section 4.6 of the Privacy Policy.
- Sub-processors. You authorize the sub-processors listed in the Privacy Policy. We will notify you in the app, in advance, of any addition or replacement. If you do not agree, you may delete the cloud data before the change. Each sub-processor is bound by data protection obligations equivalent to those in these Terms.
- Help with your obligations. Where the cloud is involved, we help with security, incidents, impact assessments and consultation with the authority.
- Information and audits. We will provide the information you need to demonstrate compliance with the law, and we will respond to reasonable audits notified in advance.
- Unlawful instructions. We will let you know if we believe an instruction infringes data protection law.
At the end of the service, you may export the data in Backup & Restore before deleting it (item 6).
Annex — details of the processing
- Subject matter and purpose: storing and syncing the app's data between your devices and the browser.
- Duration: while the cloud is turned on, plus the periods in section 6.
- Nature: storage, syncing and deletion.
- Types of data: those in section 3.1 of the Privacy Policy — your clients' name, WhatsApp number, CPF, RG, date of birth, address and legal guardian; sessions, absences and payments; documents and templates.
- Data subjects: your clients and their legal guardians.
6. Ending the use of the cloud
- Turning off the cloud: syncing stops on all devices. The cloud data is kept for 30 days, in case you want to turn it back on, and then deleted. You can also delete it right away.
- Plan ended: the cloud data is kept for 90 days and then deleted.
- Delete account: immediately deletes the cloud data and the sign-in account. The acceptance record, with the account email, is kept separately for 5 years, solely for our defense in case of a dispute about the acceptance.
- Access records (date, time and IP of each use of the cloud): kept for 6 months, even if the account is deleted earlier, as stated in the Privacy Policy.
- "Delete all data" in Settings, with the cloud on: immediately deletes the cloud data and the device data.
- Once deleted, cloud data cannot be recovered. We do not make our own backup copies. When the way the cloud stores data changes for technical reasons, the previous form is kept for up to 7 days after the change and then deleted — right away if you delete your account or all your data. Parts of an interrupted upload are deleted within 6 weeks.
- Your devices. What is on your devices is not affected when the cloud is turned off, when the plan ends or when you delete the account.
- Suspension. We may suspend access to the cloud in case of a serious breach of these Terms, such as an attack on the service or an attempt to access third parties' data. Whenever possible, we will warn you first.
7. Subscription and payments
The cloud is part of the Premium Monthly, Yearly and Lifetime plans and has no separate charge. Billing, renewal, cancellation and refunds follow the rules of Google Play or the App Store.
8. Liability
- We are not liable for losses caused by actions taken on your devices and synced, such as deletions. We are also not liable for failures of internet providers, Google or Apple, or for use contrary to these Terms.
- Nothing in these Terms excludes the rights guaranteed by the Brazilian Consumer Protection Code.
9. Changes to these Terms
- Each version has a number and a date.
- A relevant change requires a new acceptance in the app. Without the acceptance, syncing is paused, and the data on the device remains available.
10. Governing law and jurisdiction
These Terms are governed by Brazilian law. The courts of the user's domicile are chosen as the forum.
If you are in the European Union, the European Economic Area or the United Kingdom, this choice does not take away your rights under the GDPR, nor your right to complain to the data protection authority of your country or to go to court in the country where you live.