Flow
Data Security Policy
Effective Date: July 3, 2026
Flow-Entertainment applies technical and organisational measures designed to protect the personal data processed through Flow.
1. Message Encryption
Direct messages and related media are protected with end-to-end encryption: an elliptic-curve key exchange (X25519) establishes a shared secret between the two devices, message keys are derived using HKDF-SHA256, and message content is encrypted with XChaCha20-Poly1305 authenticated encryption. Keys are generated and stored on-device; message content cannot be read by Flow-Entertainment in transit or at rest.
2. Infrastructure
3. Access Control
Access to production systems and user data is limited to authorised personnel on a need-to-know basis and is logged.
4. Testing and Audits
We conduct periodic security reviews of the App and backend and remediate identified issues on a risk-prioritised basis.
5. Incident Response
In the event of a data breach affecting your personal data, we will notify affected users and, where legally required, the relevant supervisory authority, without undue delay and in line with GDPR breach-notification timelines.
6. Your Role
Keep your device, operating system, and the App updated, use a strong device passcode, and never share your one-time SMS codes with anyone.
7. Contact
Security concerns or suspected vulnerabilities: privacy@flow-entertainment.com.