Skip to content

Trust & Security

How we look after your data

What you write in Dareflow is personal. Here's exactly how it's handled — no certifications we don't have, no vague promises.

Your writing is private

  • Situations, plans, reflections and quiz answers are stored under your account. Database access rules (Row Level Security) mean other users can't read them.
  • They are never sent to product analytics. Analytics only record events like “plan created”, with non-identifying details such as a pattern name.
  • Error reports have request bodies removed, so your text doesn't end up in logs.

Payments are handled by Stripe

  • Card details go directly to Stripe. Dareflow never sees or stores your card number.
  • Your plan and credits only change after Stripe sends a signed confirmation to our server — never because of something the browser says.
  • You can cancel, change plans, update your card and download invoices yourself from Settings → Billing.

Secrets stay on the server

  • API keys for AI, payments and email live only on our servers and are never sent to your browser.
  • AI requests are made from our servers, with rate limits and usage caps to prevent abuse.
  • If you connect Google Calendar, the access token is encrypted before it's stored.

Your account, your choice

  • You can delete your account at any time from Settings → Privacy. That permanently deletes your plans, actions, reflections, quiz results and credits, turns off share links and cancels any subscription.
  • Sharing a quiz result is opt-in and shows pattern names and scores only.

What Dareflow isn't

Dareflow is a confidence and action-planning tool. It isn't therapy or medical care and doesn't diagnose or treat anything. If you're struggling, please contact a qualified professional — in Canada or the US you can call or text 9-8-8.

Reporting a problem

If you think you've found a security issue, email scottwang320@gmail.com. Read our Privacy Policy for the full details.