Personal style, without the noise
Last updated: 18 July 2026
FlowSet is a personal space for your wardrobe. The photos, notes and reflections you keep here are private by default — written for you, not for an audience. This policy explains what we process, why, where it lives, and the rights you have under the EU General Data Protection Regulation (GDPR).
FlowSet is currently offered as a free service. Some accounts carry a historical "Legacy Supporter" recognition from earlier paid or complimentary access — this is a quiet acknowledgement only and does not unlock separate features today. Historical billing and invoice records from that period may still be retained where required by law (see Retention).
Data controller
Flavia Marfella
Country
Sweden
Contact
Supervisory authority
Integritetsskyddsmyndigheten (IMY), imy.se
We process only the data needed to run FlowSet:
FlowSet is not intended specifically for children. Where applicable under local law, users who cannot independently provide valid consent should use FlowSet with the involvement or permission of a parent or legal guardian, who may also exercise data-protection rights on their behalf.
We use a small number of carefully chosen providers to operate FlowSet. Each one only receives the data they need for their function, under a data processing agreement.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication and storage of wardrobe photos | EU |
| Cloudflare | Application hosting, CDN, DDoS protection | Global edge |
| Stripe | Historical payment processing and invoice records from earlier paid access. Not used for new charges today. | EU / US |
| Resend | Transactional and account emails | EU / US |
| Lovable AI Gateway | Routes styling, vision and language requests to underlying AI models on our behalf | EU / US |
| AI model providers | Underlying styling, vision and language models reached via the Lovable AI Gateway (currently include OpenAI, Anthropic and Google). They process only the prompt needed to answer your request and do not train their models on your content. | EU / US |
Some of our sub-processors are based outside the European Economic Area, primarily in the United States. Where data leaves the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses (SCCs) and, where available, by adequacy decisions such as the EU–US Data Privacy Framework.
Photos you upload are stored in your private space on our managed storage. They are scoped to your account by row-level security, so no other user can access them. When you view a photo inside FlowSet, it is served through a time-limited signed URL — there is no public link to your wardrobe.
When you ask FlowSet to style you, generate Insights or complete a look, we send the minimum input needed — typically a short text description of your wardrobe and your prompt — to an AI model via the Lovable AI Gateway. For features that need to look at a photo, the image (or a temporary reference to it) is shared with the vision model only for that single request.
We do not allow your photos, reflections or wardrobe content to be used to train any AI model.
FlowSet does not ask you to configure personalisation up front. Instead it learns gradually from the information you choose to share, the pieces you add to your wardrobe, and the way you use the app — so that suggestions become more relevant over time.
As you continue using FlowSet, you may occasionally be invited to answer additional short questionnaires — for example after your wardrobe has grown or you've used a particular feature for a while. These are part of FlowSet's progressive learning approach and are always optional; skipping them never removes access to any core feature.
FlowSet uses a minimal set of cookies and browser local storage to keep you signed in, remember your preferences, and store short-lived drafts (for example unsaved journal text). We do not use third-party advertising or cross-site tracking cookies.
We record product analytics events — such as which screens are opened or how often looks are generated — to understand how the product is used and improve it. These signals are stored against your account so we can show you your own activity, and may be reviewed in aggregated and anonymized form. They never include the content of your photos, notes or reflections.
If you grant location permission in your browser or on your device, FlowSet may use your device's approximate location to display the local place name and current temperature on the Today page. Coordinates are sent to a weather provider and to a reverse-geocoding provider only to produce that single reading, and are not stored against your account.
Location is entirely optional. If permission is denied or unavailable, the weather line is simply hidden and the rest of FlowSet continues to work normally. Your approximate location is never used for advertising.
FlowSet does not sell your personal data. We do not share it with third parties for their own marketing. Data is only shared with the sub-processors listed above, under contract, to operate FlowSet.
Anything you choose to share — for example a look posted to a Circle or exported as an image — becomes visible only to the people you explicitly share it with.
You have the right to:
To exercise any of these rights, email us at hello@everydayflow.life. We respond within 30 days.
You can delete your account yourself at any time from Account Settings. The process is immediate, irreversible, and removes your data as described in section 11. If you prefer, you can also request deletion by emailing hello@everydayflow.life from the address tied to your account.
All connections to FlowSet are encrypted in transit (TLS). Wardrobe content is stored on managed infrastructure with row-level security so each row can only be read by its owner. FlowSet uses passwordless email sign-in (one-time code or magic link), so no password is stored on our side. Any historical payment card data was handled exclusively by Stripe and never stored on our servers.
We may update this policy as FlowSet evolves. When we do, we will change the "Last updated" date at the top of the page. Material changes will be communicated by email or in-app notice before they take effect.
Only shared when you choose