Privacy Policy

Last updated: May 2026

1. Controller

The data controller is:

LeanBytes UG (haftungsbeschränkt)
Goldmühlestraße 65
71065 Sindelfingen
Germany

Represented by: Stephan Arenswald
Contact: privacy@leanbytes.io

For technical detail and architecture (network activity, models, code-signing, GDPR posture): see /security.

2. Overview

We build software, not surveillance.

FlowMoose does not collect personal data about your identity and does not track across apps or services. Only the minimum necessary data is collected to operate and improve the product.

3. What Data We Process

a) Usage Data

Limited usage data we may collect:

This data is not used for personal identification.

b) Installation and Session Identifiers

A random installation identifier is generated and stored locally. It is unique per installation and reused across sessions, but not linked to your identity.

A temporary session identifier may be used only during active sessions to understand feature usage within that period.

These identifiers are not combined with personal data, not used for cross-app tracking, and cannot identify individuals.

c) What We Do Not Collect

We do not collect:

Voice data stays on your Mac. Always. FlowMoose does not send any voice-related data anywhere — ever. Neither what is recorded, nor what is transcribed, nor your dictation history. All audio, transcripts, and history remain locally on your system. There is no cloud sync, no server-side processing, no telemetry on what you say or what gets transcribed.

d) Analytics Infrastructure

Inside the FlowMoose Mac app: we use our own analytics system to process the limited usage data described above. We do not use third-party analytics services inside the app. Data is processed exclusively for internal purposes and not shared externally.

On the FlowMoose website (flowmoose.app): we use Vercel Web Analytics and Vercel Speed Insights to measure page views, traffic sources, Core Web Vitals (loading performance), and a small set of conversion events such as “Buy now clicked,” “trial download,” and “purchase complete.” Vercel Web Analytics is cookieless and does not use cross-site tracking. Event payloads contain non-credential identifiers only (e.g. an `order_id` after purchase); we never send your license key, email, or other personal identifiers to Vercel Analytics.

4. Payments and Subscription Processing

Subscriptions and one-off payments are processed by Lemon Squeezy, which acts as our merchant of record. Lemon Squeezy receives and stores your payment details; LeanBytes does not. Lemon Squeezy’s privacy policy governs that processing.

LeanBytes receives limited transaction-related metadata from Lemon Squeezy (your name, email address, billing country, subscription state — active / past-due / cancelled — and order identifiers) for license management, support, legal compliance, and renewal handling.

After a successful subscription purchase, Lemon Squeezy redirects your browser to a confirmation page on flowmoose.app (/thanks) with an order_id in the URL. order_id is a non-credential identifier used only to fire a conversion event in our analytics; it does not by itself grant access to anything. Your license key is delivered to you by email and is not transmitted via this URL.

Renewal payment failures may trigger automated transactional emails from Lemon Squeezy (dunning communications) during the grace period before subscription deactivation.

4a. Subscription Validation

While your subscription is active, the FlowMoose desktop app periodically queries Lemon Squeezy’s License API (typically every 14 days) to verify your subscription state. LeanBytes does not operate a separate webhook endpoint that receives subscription data.

5. Legal Basis (EU/EEA)

Usage data is processed on the basis of our Legitimate Interest under Article 6(1)(f) GDPR. The legitimate interest is in understanding app usage and improving performance and usability, with data minimization, no personal identification, and no profiling.

6. Data Retention

Analytics data is retained only as long as necessary for analyzing usage trends and improving the product. Data may be aggregated or deleted over time.

7. Data Security

We implement appropriate technical and organizational measures to protect data against unauthorized access or misuse.

For the FlowMoose macOS app’s technical architecture, network activity, and update integrity, see the Privacy & Security Whitepaper at /security.

8. Your Rights

Depending on your location, you may have rights to access your data, request deletion, or object to processing. Contact privacy@leanbytes.io to exercise these rights.

You also have the right to lodge a complaint with the supervisory authority:

Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)
Lautenschlagerstraße 20
70173 Stuttgart
Germany
poststelle@lfdi.bwl.de
www.baden-wuerttemberg.datenschutz.de

9. Changes

We may update this privacy policy from time to time. The current version is always available at /privacy. The “last updated” date at the top reflects when the policy was last revised.

10. Contact

For questions about this policy: privacy@leanbytes.io