← Back

Flow

Data Security Policy

Effective Date: July 3, 2026

Flow-Entertainment applies technical and organisational measures designed to protect the personal data processed through Flow.

1. Message Encryption

Direct messages and related media are protected with end-to-end encryption: an elliptic-curve key exchange (X25519) establishes a shared secret between the two devices, message keys are derived using HKDF-SHA256, and message content is encrypted with XChaCha20-Poly1305 authenticated encryption. Keys are generated and stored on-device; message content cannot be read by Flow-Entertainment in transit or at rest.

2. Infrastructure

3. Access Control

Access to production systems and user data is limited to authorised personnel on a need-to-know basis and is logged.

4. Testing and Audits

We conduct periodic security reviews of the App and backend and remediate identified issues on a risk-prioritised basis.

5. Incident Response

In the event of a data breach affecting your personal data, we will notify affected users and, where legally required, the relevant supervisory authority, without undue delay and in line with GDPR breach-notification timelines.

6. Your Role

Keep your device, operating system, and the App updated, use a strong device passcode, and never share your one-time SMS codes with anyone.

7. Contact

Security concerns or suspected vulnerabilities: privacy@flow-entertainment.com.