MeFlow

Privacy Policy

App
MeFlow
Last updated
27 April 2026

This Privacy Policy explains how Cybiqon ("we", "us", "our") collects, uses, and protects your information when you use the MeFlow mobile application ("MeFlow", the "App"). MeFlow is owned and operated by Cybiqon.

Quick summary

  • MeFlow is a personal productivity app (expenses, tasks, habits, goals, journal, notes) developed by Cybiqon.
  • Your data is stored in your private account on Google Firebase and is not sold to anyone, ever.
  • We collect the minimum needed to run the app: account info, the content you create, and basic technical/diagnostic data.
  • You can export, edit, and permanently delete your data at any time from inside the app, or by emailing us.

1. Information we collect

Account information
Email address and display name (or, for Google Sign-In, the email and name returned by Google). An encrypted password hash — only if you sign up with email and password, managed by Google Firebase Authentication; we never see your raw password. An optional profile photo URL.
Content you create in the app
Expenses, income records, accounts, categories and budgets. Tasks, to-dos, goals, milestones, routines, habits and side quests. Notes, sticky notes, folders and tags. Journal entries and mood logs. Reminders, achievements, wishlist items and app preferences. This content is private to your account and is not visible to other users.
Device and diagnostic information
Device type, OS version, app version and language, used to diagnose issues and target updates. Crash reports and non-fatal error logs via Firebase Crashlytics, when enabled. Anonymous usage events used in aggregate to improve the app. Approximate timestamps for sync.

What we do not collect. We do not collect your precise location. We do not access your contacts, photos, microphone, camera, SMS or call logs. We do not collect financial-account credentials — expenses you enter are typed by you, and we never connect to your bank. We do not use your content to train AI models. We do not sell or rent your personal data to third parties.

2. How we use your information

PurposeWhat we useLegal basis
Provide the App's core features (sync, log in, store your entries)Account info, content you createPerformance of contract
Send local and push notifications you have configuredReminder schedules you setPerformance of contract
Detect crashes and fix bugsDiagnostic data, crash logsLegitimate interest
Understand which features are used so we can improve themAggregated, anonymous usage eventsLegitimate interest
Prevent abuse, fraud and security incidentsAuthentication metadataLegitimate interest / legal obligation
Respond to your support requestsEmail, account ID, message you send usLegitimate interest

3. How your data is stored and protected

  • Your content is stored in Google Cloud Firestore in the asia-south2 region (Delhi, India).
  • Authentication is handled by Google Firebase Authentication.
  • All data is transmitted over HTTPS/TLS.
  • Firestore security rules ensure that only you, the authenticated owner, can read or write your data.
  • You can enable biometric app lock (fingerprint or face) inside the app for an additional on-device layer of protection.

No system is perfectly secure. If we ever become aware of a data breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law.

4. Third-party services we use

MeFlow uses a small number of trusted third-party services, all provided by Google. These providers process limited data on our behalf and are bound by their own privacy policies.

ProviderWhat it doesPrivacy policy
Google Firebase AuthenticationSign-up, sign-in, password resetfirebase.google.com/support/privacy
Google Cloud FirestoreStores your account content and sync statecloud.google.com/terms/cloud-privacy-notice
Firebase Crashlytics (optional)Reports crashes so we can fix themfirebase.google.com/support/privacy
Google Sign-In (optional)Lets you sign in with your Google accountpolicies.google.com/privacy
Google Play ServicesPush notifications and app deliverypolicies.google.com/privacy

5. Data sharing and disclosure

We do not sell your personal data. We share data only in these limited situations:

Service providers
Listed in section 4, strictly to operate the App.
Legal requests
When we are legally required to comply with a valid court order, subpoena, or government request under applicable law.
Business transfers
In the event Cybiqon is acquired or merged. You will be notified before your data is transferred and becomes subject to a different privacy policy.
To protect rights and safety
Where necessary to investigate fraud, abuse, or threats to users.

6. International data transfers

Your data is primarily stored in India (Google Cloud asia-south2). Some of our service providers, such as Google, may process limited diagnostic data in other countries. Where such transfers happen, they rely on safeguards required by applicable law, such as Standard Contractual Clauses.

7. Data retention

  • Account and content data is kept as long as your account exists.
  • If you delete your account, all personal content is removed from our active databases immediately.
  • Backups are rotated on a 30-day cycle; deleted data is fully removed from backups within that window.
  • Firebase Authentication may retain hashed identifiers for up to 30 days after deletion to prevent abuse.
  • Anonymous, aggregated analytics, which cannot identify you, may be retained indefinitely.
  • Records we are legally required to retain (fraud investigation, tax, and similar) are kept only for the legally mandated period.

8. Your rights and choices

You have the following rights with respect to your personal data:

Access and export
View and export your data from inside the App.
Correction
Edit any entry directly in the App.
Deletion
Delete individual entries, or delete your entire account from inside the App.
Withdraw consent
Sign out, disable notifications, or uninstall the App at any time.
Object or restrict processing
Email support@cybiqon.in to exercise rights granted by laws such as GDPR, UK GDPR, India's DPDP Act, or applicable U.S. state privacy laws including CCPA and CPRA.
Lodge a complaint
You may complain to your local data protection authority.

We respond to verified requests within 30 days.

9. Children's privacy

MeFlow is not directed at children under 13, or the equivalent minimum age in your jurisdiction, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us at support@cybiqon.in and we will delete it.

10. Permissions used by the App

MeFlow may request the following Android permissions:

Internet
To sync your data with Firebase.
Notifications (POST_NOTIFICATIONS)
To deliver reminders you have configured.
Schedule exact alarms
To fire reminders on time.
Biometric / use fingerprint
To support the optional app lock.
Receive boot completed
To restore reminder schedules after the device restarts.

Each permission is used only for the feature described above. You can revoke any permission from your device's system settings.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, notify you in the App or via email before the change takes effect.

12. Contact us

App
MeFlow (com.cybiqon.meflow)
Chat with us!