Legal
Privacy Policy
Beta notice: Flowvio is currently in a closed beta. Our practices, features, and this policy may evolve as we develop the product, and we will notify you of material changes. Our commitment to student data privacy — including FERPA, COPPA, and applicable state laws — applies fully during the beta. Schools and districts must execute a Data Privacy Agreement (DPA) with Flowvio before counselors use the platform with student education records.
Introduction
Flowvio ("we," "us," or "our") is a web application that helps K-12 school counselors manage their daily work — student caseloads, tasks, notes, calendar events, communication logs, and student interactions.
This policy explains what information we collect, how we use it, how we protect it, and what rights you have. We wrote it in plain language because you deserve to clearly understand how your information is handled.
Who this policy applies to
- Counselors who create accounts and use Flowvio to manage their work
- Waitlist subscribers who sign up on our landing page to receive updates
- Visitors to our website
What information we collect
Information you provide directly
Counselor account information. When you create a Flowvio account, we collect your name, email address, school name, and password (stored only in hashed form — we never store or see your plain-text password).
Student data entered by counselors. Counselors enter information about their students into Flowvio, which may include student names, grade levels, GPA information, parent/guardian contact information, interaction notes and communication logs, task and calendar information, and any other information a counselor chooses to record. We do not collect information directly from students. All student data in Flowvio is entered by counselors in the course of their professional duties.
Waitlist and beta signup information. If you join our waitlist or beta onboarding, we collect your name, email address, school name, state, role, and (optionally) caseload size and related details you provide.
Information collected automatically
When you use the Flowvio application, we may automatically collect browser type and version, device information, IP address, pages visited and features used, and dates and times of access. On our website and within the application we use PostHog for usage analytics, and within the application Sentry for error monitoring, to understand how Flowvio is used and to find and fix bugs. We do not run advertising trackers.
How we use your information
- To provide the service: managing your account, storing and displaying your caseload data, and enabling Flowvio's features
- To communicate with you: account notices, support responses, and beta program updates
- To improve the product: understanding how Flowvio is used so we can fix bugs and improve features
- To manage our waitlist: contacting you when seats open or when we have relevant updates
- To maintain security: detecting and preventing unauthorized access or misuse
We do not sell your personal information or student data to anyone, use student data for advertising or marketing, use AI or machine learning to process student data, or share student data with other counselors, schools, or third parties except as described below.
Who we share information with
We do not sell, rent, or trade your information. We share data only with service providers we use to operate Flowvio, and only as necessary:
- Supabase — our database and authentication provider. Your account data and application data (including student records entered by counselors) are stored in Supabase's PostgreSQL database, hosted on Amazon Web Services infrastructure in the United States (US East, Ohio).
- Vercel — our hosting provider. Vercel serves the Flowvio web application and may process server logs that include IP addresses and request metadata.
- Resend — our transactional email provider, used to send waitlist confirmations and account-related email.
- PostHog — product analytics for the application.
- Sentry — error monitoring for the application.
We may also disclose information when required by law, regulation, or legal process; to protect the rights, safety, or property of Flowvio, our users, or the public; or in connection with a merger, acquisition, or sale of assets (in which case we would notify users before their data becomes subject to a different privacy policy).
Student data and FERPA
The Family Educational Rights and Privacy Act (FERPA) is a federal law protecting the privacy of student education records. Counselors may use Flowvio to manage information that constitutes student education records under FERPA.
When a school or district adopts Flowvio, it designates us as a school official with a legitimate educational interest under FERPA §99.31(a)(1)(i)(B) through a signed Data Privacy Agreement. That means Flowvio performs a service the school would otherwise use its own employees for, remains under the school's direct control with respect to education records, and uses those records only for the purposes specified in the DPA.
Schools and districts execute a Student Data Privacy Consortium (SDPC) National Data Privacy Agreement with Flowvio before counselors use the platform with student data. The DPA covers data ownership (the school owns its student data), permitted uses, security obligations, breach notification, deletion and return of data at termination, sub-processor obligations, and applicable state student privacy laws.
What this means for counselors: your school or district should have an executed DPA with Flowvio before you enter student education records. If you are unsure whether your school has one, contact your administrator or write to us.
Technical safeguards supporting FERPA compliance
- Audit trail: access to and modification of student education records is logged (user identity, action, record state, IP address, timestamp) and retained for at least 7 years, consistent with FERPA §99.32.
- Access controls: Row Level Security ensures each counselor can only access their own students' records.
- Session management: sessions expire after 30 minutes of inactivity.
- Data export: counselors can export their data from the application's Settings page; schools and parents may request access to student records.
- Soft deletes: student records are flagged rather than immediately destroyed, preserving audit integrity; permanent deletion occurs through a controlled process on DPA termination or authorized request.
Children's privacy (COPPA)
Flowvio is designed for use by adult school counselors, not by students or children. Students do not create accounts, log in, or interact with Flowvio directly; all student information is entered by adult counselors as part of their professional responsibilities. Because Flowvio is not directed at children and does not collect information directly from children, we believe COPPA does not apply to our service. We recognize that data entered by counselors may concern children under 13, and we protect all student data with the same level of care regardless of age.
Data security
- Row Level Security: access control is enforced at the database level — the database itself prevents one user from querying another user's records.
- Encryption: data is encrypted in transit (HTTPS/TLS 1.2+) and at rest (AES-256).
- Authentication: passwords are hashed with bcrypt and checked against the HaveIBeenPwned breach database to block known-compromised passwords.
- Audit logging: data access and modifications are recorded in a tamper-resistant audit log retained for at least 7 years.
- Infrastructure: our database is hosted on Supabase, which maintains SOC 2 Type II certification; the application is hosted on Vercel.
Access to production systems is restricted to authorized personnel, changes go through code review, and schema changes are version-controlled. No method of electronic storage or transmission is 100% secure; we cannot guarantee absolute security, but we are committed to promptly addressing any incident.
Data retention
We retain your account data and associated records for as long as your account is active. If you request deletion, we remove your account and associated data from our active database within 30 days, and from backups as they rotate (no longer than 90 days), except where a school's DPA or applicable law requires otherwise. Waitlist information is retained until you ask to be removed, we contact you and receive no response within a reasonable period, or the waitlist program ends. Server logs and usage data are retained for no longer than 12 months.
Your rights
You have the right to access the personal information we hold about you, correct inaccurate information, delete your account and associated data, withdraw from the waitlist at any time, and object to certain uses of your data. To exercise any of these rights, contact us at the address below. Depending on where you live, you may have additional rights under state privacy laws. Schools and districts have additional rights regarding student data under FERPA, state student privacy laws, and their DPA, and we will work with them to meet their data governance needs.
Artificial intelligence
Flowvio does not currently use artificial intelligence, machine learning, or automated decision-making to process student data or counselor information. If we introduce AI-powered features, we will update this policy before deployment, clearly disclose what data is processed and why, provide opt-outs where feasible, and ensure compliance with applicable student data laws.
Security incidents
If a breach or security incident affects your personal information or student data, we will investigate and contain it promptly, notify affected users and relevant authorities within the timeframes required by applicable law and any governing DPA, and explain what data was affected and what we are doing about it.
Changes to this policy
We may update this policy to reflect changes in our practices, features, or legal requirements. We will update the "Last updated" date above, and for material changes we will notify users by email or an in-app notice.
Contact us
Questions about this policy, your data rights, or how your data is handled: info@useflowvio.com.
Summary
| Topic | Key point |
|---|---|
| Who is this for? | K-12 school counselors (adults, not students) |
| What do we collect? | Counselor account info, student data entered by counselors, waitlist info |
| Do we sell data? | No, never |
| Do we use AI on student data? | No |
| Who can see my data? | Only you (enforced by Row Level Security) |
| Student data and FERPA | Schools execute a DPA before student data is involved; safeguards are built to FERPA requirements |
| How is data secured? | Encrypted connections, database-level access controls, hashed passwords, audit logs |
| Can I delete my data? | Yes — contact us to request account and data deletion |