Privacy Policy
Last updated: May 2026
1. Controller
The data controller is:
LeanBytes UG (haftungsbeschränkt)
Goldmühlestraße 65
71065 Sindelfingen
Germany
Represented by: Stephan Arenswald
Contact: privacy@leanbytes.io
For technical detail and architecture (network activity, models, code-signing, GDPR posture): see /security.
2. Overview
We build software, not surveillance.
FlowMoose does not collect personal data about your identity and does not track across apps or services. Only the minimum necessary data is collected to operate and improve the product.
3. What Data We Process
a) Usage Data
Limited usage data we may collect:
- Feature usage (actions performed)
- Timestamps
- App version
- Operating system version
- Device type
- Coarse geographic region (country level)
- Session identifier (per-session, not linked across sessions)
- Locale
- Successful-transcription event (when text is transcribed and pasted)
- Delayed-paste event (when previously-transcribed text is pasted later)
- History-entry-copied event (when a saved transcription is re-copied to the pasteboard)
This data is not used for personal identification.
b) Installation and Session Identifiers
A random installation identifier is generated and stored locally. It is unique per installation and reused across sessions, but not linked to your identity.
A temporary session identifier may be used only during active sessions to understand feature usage within that period.
These identifiers are not combined with personal data, not used for cross-app tracking, and cannot identify individuals.
c) What We Do Not Collect
We do not collect:
- Name, email, or personal identity (except when you contact us)
- Precise location data
- Cross-app or cross-service tracking data
- Behavioral profiles
Voice data stays on your Mac. Always. FlowMoose does not send any voice-related data anywhere — ever. Neither what is recorded, nor what is transcribed, nor your dictation history. All audio, transcripts, and history remain locally on your system. There is no cloud sync, no server-side processing, no telemetry on what you say or what gets transcribed.
d) Analytics Infrastructure
Inside the FlowMoose Mac app: we use our own analytics system to process the limited usage data described above. We do not use third-party analytics services inside the app. Data is processed exclusively for internal purposes and not shared externally.
On the FlowMoose website (flowmoose.app): we use Vercel Web Analytics and Vercel Speed Insights to measure page views, traffic sources, Core Web Vitals (loading performance), and a small set of conversion events such as “Buy now clicked,” “trial download,” and “purchase complete.” Vercel Web Analytics is cookieless and does not use cross-site tracking. Event payloads contain non-credential identifiers only (e.g. an `order_id` after purchase); we never send your license key, email, or other personal identifiers to Vercel Analytics.
4. Payments and Subscription Processing
Subscriptions and one-off payments are processed by Lemon Squeezy, which acts as our merchant of record. Lemon Squeezy receives and stores your payment details; LeanBytes does not. Lemon Squeezy’s privacy policy governs that processing.
LeanBytes receives limited transaction-related metadata from Lemon Squeezy (your name, email address, billing country, subscription state — active / past-due / cancelled — and order identifiers) for license management, support, legal compliance, and renewal handling.
After a successful subscription purchase, Lemon Squeezy redirects your browser to a confirmation page on flowmoose.app (/thanks) with an order_id in the URL. order_id is a non-credential identifier used only to fire a conversion event in our analytics; it does not by itself grant access to anything. Your license key is delivered to you by email and is not transmitted via this URL.
Renewal payment failures may trigger automated transactional emails from Lemon Squeezy (dunning communications) during the grace period before subscription deactivation.
4a. Subscription Validation
While your subscription is active, the FlowMoose desktop app periodically queries Lemon Squeezy’s License API (typically every 14 days) to verify your subscription state. LeanBytes does not operate a separate webhook endpoint that receives subscription data.
5. Legal Basis (EU/EEA)
Usage data is processed on the basis of our Legitimate Interest under Article 6(1)(f) GDPR. The legitimate interest is in understanding app usage and improving performance and usability, with data minimization, no personal identification, and no profiling.
6. Data Retention
Analytics data is retained only as long as necessary for analyzing usage trends and improving the product. Data may be aggregated or deleted over time.
7. Data Security
We implement appropriate technical and organizational measures to protect data against unauthorized access or misuse.
For the FlowMoose macOS app’s technical architecture, network activity, and update integrity, see the Privacy & Security Whitepaper at /security.
8. Your Rights
Depending on your location, you may have rights to access your data, request deletion, or object to processing. Contact privacy@leanbytes.io to exercise these rights.
You also have the right to lodge a complaint with the supervisory authority:
Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)
Lautenschlagerstraße 20
70173 Stuttgart
Germany
poststelle@lfdi.bwl.de
www.baden-wuerttemberg.datenschutz.de
9. Changes
We may update this privacy policy from time to time. The current version is always available at /privacy. The “last updated” date at the top reflects when the policy was last revised.
10. Contact
For questions about this policy: privacy@leanbytes.io