Trust & Security
How we look after your data
What you write in Dareflow is personal. Here's exactly how it's handled — no certifications we don't have, no vague promises.
Your writing is private
- Situations, plans, reflections and quiz answers are stored under your account. Database access rules (Row Level Security) mean other users can't read them.
- They are never sent to product analytics. Analytics only record events like “plan created”, with non-identifying details such as a pattern name.
- Error reports have request bodies removed, so your text doesn't end up in logs.
Payments are handled by Stripe
- Card details go directly to Stripe. Dareflow never sees or stores your card number.
- Your plan and credits only change after Stripe sends a signed confirmation to our server — never because of something the browser says.
- You can cancel, change plans, update your card and download invoices yourself from Settings → Billing.
Secrets stay on the server
- API keys for AI, payments and email live only on our servers and are never sent to your browser.
- AI requests are made from our servers, with rate limits and usage caps to prevent abuse.
- If you connect Google Calendar, the access token is encrypted before it's stored.
Your account, your choice
- You can delete your account at any time from Settings → Privacy. That permanently deletes your plans, actions, reflections, quiz results and credits, turns off share links and cancels any subscription.
- Sharing a quiz result is opt-in and shows pattern names and scores only.
What Dareflow isn't
Dareflow is a confidence and action-planning tool. It isn't therapy or medical care and doesn't diagnose or treat anything. If you're struggling, please contact a qualified professional — in Canada or the US you can call or text 9-8-8.
Reporting a problem
If you think you've found a security issue, email scottwang320@gmail.com. Read our Privacy Policy for the full details.