Privacy Policy
Last updated: January 14, 2026
1. Introduction
Bookflow ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
2. Information We Collect
We collect information that you provide directly to us, including:
- Account Information: Email address, name, and password when you create an account.
- Profile Information: Information about your connections, including names, relationships, birthdays, and preferences.
- Content: Moments, memories, and messages you create within the app.
- Media: Photos you upload to accompany your moments.
- Payment Information: Billing details processed securely by Stripe.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve our services
- Generate personalized Weekly Flow summaries and expression drafts
- Send reminders about birthdays and anniversaries
- Process payments and manage subscriptions
- Send you service-related communications
- Respond to your requests and provide customer support
4. AI Processing
We use AI (OpenAI GPT-4o-mini) to generate personalized content based on your moments and profile information. Your data is sent to OpenAI's API for processing. OpenAI does not use your data to train their models. We retain only the generated outputs, not the raw API requests.
5. Data Storage & Security
Your data is stored securely on Cloudflare's infrastructure:
- Database: Cloudflare D1 (SQLite) with encryption at rest
- Media Storage: Cloudflare R2 with secure access controls
- Sessions: Cloudflare KV with automatic expiration
We implement industry-standard security measures including HTTPS encryption, secure password hashing, and access controls.
6. Data Sharing
We do not sell your personal information. We may share your information with:
- Service Providers: Cloudflare (hosting), Stripe (payments), Resend (email), OpenAI (AI processing)
- Legal Requirements: When required by law or to protect our rights
7. Your Rights (GDPR & CCPA)
You have the right to:
- Access: Request a copy of your personal data
- Export: Download all your data in JSON format
- Delete: Request permanent deletion of your account and all associated data
- Correct: Update or correct your personal information
- Restrict: Limit how we process your data
To exercise these rights, visit your Settings page or contact us at [email protected].
8. Data Retention
We retain your data for as long as your account is active. When you delete your account, all your personal data is permanently deleted within 30 days, including all moments, connections, and uploaded media.
9. Cookies
We use essential cookies only for maintaining your session. We do not use tracking cookies or third-party analytics that collect personal information.
10. Children's Privacy
Bookflow is not intended for users under 16 years of age. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the app.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us at: