01 — Scope
Who is responsible for your data
This Privacy Policy is effective July 21, 2026. It applies to the FlowMaster macOS application, FlowMaster accounts and cloud services, our websites, collaboration and team features, AI and search tools, support, account appeals, and Teams & School Plan inquiries and purchases (collectively, the “Service”).
FlowMaster Team operates from the Hong Kong Special Administrative Region (“HKSAR”). For personal data that we decide how and why to collect, hold, process, or use, FlowMaster Team is the data user under the Personal Data (Privacy) Ordinance (Cap. 486) of HKSAR (the “PDPO”).
This Policy does not govern an independent third-party website, service, or integration. Those providers apply their own privacy terms when you choose to use them. If a school, debate program, or other organization gives you a FlowMaster account or directs how it uses information in its own workspace, that organization may also have separate privacy responsibilities and policies.
02 — Collection
Personal data we collect
We collect personal data directly from you, from activity in the Service, from people who collaborate with you, from an organization that provisions your access, and from providers involved in a feature or purchase. The data depends on which features you use.
Account and profile data
- Your email address, display name, profile photograph, account identifier, and any profile information you choose to provide.
- Your password in cryptographically hashed form. We do not store your readable password.
- Authentication and recovery data, such as session identifiers, password-reset records, verification codes, device-session information, and the time of account activity.
Content and collaboration data
- Docs, Flows, cases, cards, evidence, citations, speech documents, files, notes, messages, and other material that you choose to upload or sync after enabling Shareflow, together with team posts, assignments, submissions, and other material you deliberately place in a cloud Team workspace.
- Flow ownership, sharing roles, share and join codes, collaborators, revision and synchronization records, and presence information needed for real-time collaboration.
- Team membership, role, roster status, channels, groups, prep documents, assignment activity, and administrative actions in a Team workspace.
AI, search, and audio data
- Prompts, AI chat messages, search queries, selected flow or document context, files submitted to an AI feature, generated answers, cited sources, fact-check results, tool actions, and feedback.
- If you opt in to automatic opponent scouting: the published Tabroom pairing details, opponent name and tournament record, available tournament standing, assigned judge name and paradigm, and the resulting AI round brief. Your Tabroom password, bearer token, and session cookie stay in macOS Keychain and are not sent to FlowMaster's cloud or an AI provider for this feature.
- Audio that you deliberately record or upload for transcription, together with the resulting transcript and round analysis.
- Automated security, abuse, and content classifications produced when necessary to protect the Service and enforce our policies.
Purchase, inquiry, and support data
- Your plan, entitlement, product identifier, transaction identifier, renewal or expiration status, team key or gift-code redemption, organization, licensed seat count, order status, invoice details, and related accounting records.
- If you contact us about a Teams & School Plan: your name, work or school email, organization, role, telephone number, expected seats, plan interest, message, and any other information you submit.
- Support messages, security reports, account suspension information, appeal messages and history, decisions, and communications with our team.
Technical and security data
- IP address, user-agent or app version, device identifier, request time, route and response information, login history, rate-limit events, security alerts, session revocation, and diagnostic information.
- Standard network and security logs created by Cloudflare and other infrastructure providers when the app or website communicates with the Service.
Data that stays on your Mac
FlowMaster keeps local app data so features can work offline. Some information—such as local caches, certain preferences, personal calendar entries, temporary files, and credentials for optional integrations stored in macOS Keychain—may remain only on your Mac unless you submit, sync, share, or otherwise send it through a cloud feature. FlowMaster Team does not receive data that remains solely on your device.
Required and optional data
An email address, account name, and password are required to create a standard account. Data requested for a particular feature is required only if it is necessary to provide that feature—for example, a team key to join a Team or transaction information to activate a paid entitlement. Other profile fields, AI prompts, uploads, recordings, team inquiries, and integrations are voluntary. If you do not provide required data, we may be unable to create the account, complete the purchase, or provide the requested feature.
03 — Purposes
How and why we use personal data
We use personal data only for purposes connected with the Service, purposes identified when it is collected, and other purposes permitted by law. These purposes include:
- Operating the Service. Creating and securing accounts; authenticating requests; storing, syncing, displaying, and exporting content that you choose to place in the cloud Service; maintaining offline and cloud continuity; and providing requested app and website features.
- Collaboration and teams. Applying ownership and role permissions, delivering real-time edits, showing appropriate presence information, maintaining team rosters, and providing channels, documents, assignments, and coach controls.
- Providing AI features. Sending the content necessary to answer a prompt, perform a search, transcribe audio, analyze a round, prepare an opted-in opponent brief from published tournament information, fact-check a claim, or carry out an agent action that you request.
- Plans and transactions. Activating and restoring entitlements, administering seats and codes, confirming transaction status, processing direct Teams & School Plan orders, issuing invoices, responding to refunds or charge reversals, and keeping required accounting records.
- Security and integrity. Preventing unauthorized access, spam, fraud, scraping, credential attacks, unsafe use, and policy violations; enforcing rate limits and account restrictions; investigating incidents; and handling reports and appeals.
- Support and communications. Responding to questions, sending password-reset, security, purchase, team-administration, suspension, appeal, and other service-related messages, and maintaining necessary correspondence.
- Improvement and compliance. Debugging, measuring reliability and capacity, developing features, creating aggregated or de-identified operational information, complying with legal obligations, and establishing or defending legal claims.
We do not sell personal data, provide it to data brokers, use it for cross-app advertising, or use advertising identifiers. We do not use personal data for a new purpose unrelated to the original purpose without the consent required by the PDPO, unless the use is otherwise permitted or required by law.
04 — AI
AI features and automated systems
AI and search features run when you invoke them or when limited automated processing is reasonably necessary for security, abuse prevention, or policy enforcement. Depending on the feature, FlowMaster currently uses GPT-5.6 services provided by OpenAI for product chat, synthesis, agent, and transcription functions; Perplexity for search-grounded answers and fact-checking; and DeepSeek for limited classification, support, and triage functions. We send only the input and context reasonably needed for the requested or protective function.
- Inputs and outputs. Relevant flow text, documents, prompts, chat history, search requests, recordings, transcripts, user reports, or appeal text may be sent to the applicable provider. Generated text, sources, transcripts, analyses, and chat history may be stored with your account so you can reopen them.
- Automatic opponent scouting. This optional feature is off until you enable it for your FlowMaster account. While the macOS app is active and your Tabroom account is connected, the app may periodically check your own current entries. After a pairing is published, it sends a bounded set of round-relevant, published facts and available judge-paradigm text through FlowMaster's cloud to GPT-5.6 services provided by OpenAI to prepare a brief. It does not upload your Tabroom credentials or raw Tabroom pages, does not infer an unpublished ranking, and does not persist the submitted Tabroom snapshot. To prevent duplicate model calls after a retry or disconnect, an account-scoped copy of a successful brief may be reused from FlowMaster's Cloudflare D1 cache and that Mac for 24 hours. After that reuse window, an hourly scheduled cleanup removes the expired cloud entry. A usage event containing the account identifier, outcome, and request/token counts—but no snapshot or brief text—is kept for a 30-day accounting window and then removed by the same cleanup. Turning the feature off clears the Mac copy immediately; account deletion removes that account's cloud cache, usage events, and device copies.
- Audio. Raw audio is accepted for the transcription request and handled temporarily during processing. FlowMaster Team does not intentionally persist the raw recording in Cloudflare D1 or R2. The AI provider may process or temporarily retain it under its API data terms. The transcript and resulting analysis may remain in your account until deleted.
- Training. FlowMaster Team does not use your flows, documents, prompts, chats, recordings, transcripts, or AI results to train its own general-purpose AI models. AI providers process submitted data under their applicable API terms, including their own security, abuse-monitoring, and retention rules.
- Automated protection. Security systems may rate-limit, lock, restrict, or suspend access when they detect credential attacks, abuse, or serious policy violations. User reports and appeals may be automatically categorized or summarized, but account appeals are reviewed and decided by an authorized person.
- Human judgment. AI output may be inaccurate or fabricated. It should not be treated as verified evidence or used as the sole basis for a consequential decision about a person. See our Usage Policy for rules on AI, evidence, recordings, and fair use.
05 — Collaboration
What other users and organizations can see
FlowMaster content is not public by default. It becomes available to other users when you share it, accept a collaboration invitation, submit it to an organization, or place it in a Team workspace.
- Collaborators. A person you authorize may see your display name, profile photograph, presence, the shared content, and its revision history. Their ability to view, comment, edit, copy, or export depends on the assigned role.
- Share codes. A valid share or join code acts as a permission. Protect it and give it only to intended recipients. Revoking access cannot recover a copy that a previously authorized recipient already exported or lawfully retained.
- Team members and administrators. Members may see content posted to their channels, groups, prep libraries, or assignments. Coaches and authorized administrators may manage the roster, view seat status, administer team-owned areas, review assignment submissions, and remove access.
- Organizations. Your school, program, or other organization may separately determine how it uses roster, assignment, or workspace data. Direct questions about its own practices to that organization.
06 — Payments
Plans, purchases, and payment data
Plans purchased on our website
FlowMaster Team sells Individual Pro passes and subscriptions, and Teams & School Plans, through the official FlowMaster website. Stripe handles the payment interface. We may receive the FlowMaster account identifier and email, Stripe customer and transaction identifiers, selected product and price, subscription status and dates, limited billing information, refund or dispute status, and—where applicable—organization, contact, seat, invoice, and order details. FlowMaster Team does not receive the full card number or card security code entered in Stripe’s hosted checkout.
Stripe, banks, and payment networks handle information under their own legal and privacy terms. We retain the transaction and accounting records reasonably needed to manage entitlements, refunds, disputes, audits, tax, and other legal obligations.
07 — Disclosure
Classes of people and providers who may receive data
We disclose personal data only as reasonably necessary for the purposes described in this Policy. Recipients may include:
- Cloud infrastructure providers, principally Cloudflare, for hosting, database, object storage, networking, real-time collaboration, caching, security, and request processing.
- AI and search providers, currently including OpenAI (including its GPT-5.6 services), Perplexity, and DeepSeek, when a relevant feature, safety check, report, or appeal requires their processing.
- Payment, invoicing, and email providers, including Stripe, that process a purchase, deliver a required message, or support our direct billing and communications.
- People you authorize, including collaborators, team members, coaches, administrators, and organizations, as described in Section 5.
- Optional integration providers such as tournament, research, document, or account services when you deliberately connect or use the integration.
- Professional advisers and authorities, where reasonably necessary for security, insurance, accounting, legal advice, an audit, compliance with a lawful request, protection of a person, or the establishment, exercise, or defence of legal claims.
- A successor organization in a genuine merger, financing, reorganization, acquisition, or transfer of all or part of the Service, subject to applicable confidentiality and data-protection obligations.
We do not transfer personal data to advertisers or data brokers. We do not permit a provider to use FlowMaster data for its own advertising merely because it processes data for the Service.
08 — Location
Where data is stored and processed
FlowMaster Team operates in HKSAR, while our principal cloud provider, Cloudflare, Inc., is a United States company. We treat personal data submitted to the cloud Service as transferred outside HKSAR, with the United States as the principal overseas service-provider location.
Account records and cloud content—including Docs and Flows only after you enable Shareflow for them—are hosted using Cloudflare D1; files such as profile photographs and team uploads use Cloudflare R2; and Cloudflare Workers, Durable Objects, and KV support the API, sessions, caching, security, and real-time collaboration. Cloudflare operates a global network. Its request routing, security processing, service-specific default data placement, replicas, and resilience systems may process or store data in the United States and in other countries. We therefore do not promise that every physical copy or transient processing operation remains exclusively in the United States.
AI, search, payment, email, and optional integration providers may also process data in the United States and other jurisdictions where they or their subprocessors operate. Privacy and access laws in those places may differ from HKSAR law.
We select providers for operational and security needs, limit the data sent to the purpose of the service, use contractual or other reasonable safeguards where appropriate, and retain responsibility under the PDPO for personal data that we control. Your offline copy and device-only data remain on your Mac unless you use a feature that sends them to the Service or another provider.
09 — Retention
How long we keep data and what deletion means
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to operate the Service, or to satisfy security, accounting, dispute, and legal requirements. Different records have different lifecycles:
- Account and cloud content. Account details, Docs and Flows uploaded after Shareflow is enabled, team content, AI chats, transcripts, and saved results are generally kept while the account or relevant workspace remains active, unless you delete an item earlier. Docs and Flows that never leave your Mac are not part of our server-side retention.
- Raw audio. FlowMaster Team does not intentionally persist raw transcription audio in D1 or R2. Transcripts and resulting analyses may be retained as account content.
- Security data. Short-lived sessions, codes, request records, and alerts expire or are removed according to their function. For example, security-alert records are normally scheduled to expire after 30 days, while a private account-appeal link normally expires after 90 days. Information may be retained longer if an active incident or legal requirement makes that necessary.
- Purchases and administration. Transaction, invoice, redemption, fraud-prevention, and audit records may be retained or pseudonymized for accounting, legal compliance, enforcement, and dispute resolution after an account is deleted.
- Support, inquiries, and appeals. We keep correspondence while the matter is active and for a reasonable period afterwards. We may delete a pending appeal with an account and pseudonymize a decided appeal when continued retention is necessary to document the decision.
- Other people’s workspaces. Account deletion removes your account and content from active systems under your control, but shared or submitted material may remain where another user or organization has an independent right to retain it. We remove or pseudonymize your identity from retained records where reasonably possible.
- Local data and provider copies. Data on your Mac remains until you remove it through the app or operating system. Residual provider backups, logs, and cached copies roll off under the provider’s normal security and retention schedules.
You can delete your FlowMaster account through Settings → Account → Delete Account. The deletion process removes the account, authentication record, active sessions, owned cloud content, AI history, and stored profile photograph from active systems, subject to the limited exceptions above. Account deletion does not cancel a paid subscription or erase records held independently by Stripe or another payment provider, an organization, collaborator, or integration.
10 — Security
How we protect personal data
We use administrative and technical safeguards appropriate to the nature of the Service, including HTTPS/TLS in transit, cryptographically hashed passwords, signed session tokens, macOS Keychain for supported device credentials, server-side authorization checks, account and IP rate limits, login lockouts, session revocation, restricted administrative access, provider security controls, and monitoring for abuse.
We also require service providers that process personal data for us to protect it through contractual or other reasonable means appropriate to their role. No internet transmission, device, or storage system can be guaranteed to be completely secure. Keep your credentials and share codes confidential, maintain independent exports of essential tournament work, and contact us promptly if you suspect unauthorized access.
11 — Control
Your rights and choices
Subject to the PDPO and permitted exceptions, you may ask whether FlowMaster Team holds personal data about you, request a copy of that data, and request correction of inaccurate data. We will respond within the period required by the PDPO—normally within 40 calendar days after receiving a valid request—and may charge only a fee permitted by law. We may ask for information reasonably necessary to verify your identity and locate the requested records.
You may also use in-app controls to edit your profile, delete content, leave shared work, revoke sharing where you have permission, or delete your account. You may ask us to delete data or stop an optional use, although we may retain data where needed for another lawful purpose, an unresolved transaction, security, another user’s rights, or a legal obligation.
Direct marketing
Operational messages about accounts, security, purchases, teams, support, suspensions, and policy changes are service communications rather than direct marketing. If we propose to use your name, email address, or other personal data for direct marketing, we will first provide the notice and obtain the consent or indication of no objection required by the PDPO. You may opt out of direct marketing at any time and without charge.
How to make a request
Email support@flowmasterdebate.com from your account address with the subject “Privacy request.” If you cannot use that address, explain why and provide enough information for us to verify the account safely. If you are dissatisfied with our response, you may contact the Office of the Privacy Commissioner for Personal Data, Hong Kong.
12 — Children
Children’s privacy
FlowMaster may be used by students, including through a school or debate program. Parents, legal guardians, schools, and team administrators are responsible for providing any notices, permissions, or consents required by applicable law for their students.
If you believe a child’s personal data has been provided to FlowMaster without a permission required by applicable law, contact us. We will investigate and delete or otherwise handle the data as required by law.
13 — Changes
Changes to this Policy
We may update this Policy when the Service, our providers, our practices, or the law changes. We will post the revised Policy and change its effective date. If a change materially affects how we handle personal data, we will provide reasonable notice through the Service, by email, or by another appropriate method before the change takes effect where practicable or legally required.
14 — Contact
Contact FlowMaster Team
For questions, complaints, access or correction requests, deletion requests, or security concerns about personal data, contact:
Privacy Contact
FlowMaster Team
Hong Kong Special Administrative Region
Electronic address: support@flowmasterdebate.com
Please do not send passwords, full payment-card details, private share codes, or unnecessary sensitive information by email.