FlowBox · Privacy Policy
FlowBox Privacy Policy
FlowBox is an iOS content organization tool provided by Beijing XingheBit Science & Technology Development Co., Ltd. This policy explains how FlowBox handles data when you import text, web pages, images, or PDFs, and how you can access, export, or delete that data.
Effective date: 2026-08-24 · Version 1.4
01
Data we process
Content you choose to import, including text, readable web content, images, PDFs, OCR text, processing instructions, and generated results. Sign-in may process an Apple user identifier, name, and email supplied by Apple, or an email address you submit. Subscription and credit-pack transaction state is validated by Apple and the FlowBox service. FlowBox does not store full payment-card details. The server stores verified transaction IDs, products, and credit posting state only after Apple server verification is configured.
02
On-device processing
Image OCR, table recognition, sensitive-content detection, and translations supported by Apple Translation run on device. Using these features does not by itself upload the content to FlowBox servers.
03
Optional cloud AI
Relevant text, instructions, and required context are sent over HTTPS only when cloud services are configured, you select an operation that requires them, and you confirm processing. Production cloud text processing currently uses DeepSeek V4 Flash through api.deepseek.com. Cloud-history search sends only the search terms you enter and returns titles and limited snippets; it does not write complete cloud source text to this device. If the server enables embeddings, uploaded content may produce a derived vector index subject to the selected retention period. If FlowBox detects possible identity documents, bank cards, medical records, passwords, or keys, it offers Private Mode, field redaction, or explicit upload confirmation.
04
Storage, sync, offline queue, and Spotlight
History and attachments are stored in the app's Application Support directory and removed according to your chosen retention period. Selected image, PDF, and audio attachments are uploaded over HTTPS only when you actively start cloud sync; the server deduplicates by SHA-256 and removes copies when content, the account, or retention expires. When a non-private cloud task is offline, it may enter an AES-GCM encrypted queue using a device-only Keychain key; the queued copy is removed after completion. Private Mode does not write source content to history or the offline queue. Spotlight indexing is off by default; when enabled, it indexes only titles, content types, and project names—not source text, OCR, results, or attachments.
05
Diagnostics and analytics
Product analytics records feature events and limited category fields, not source content, OCR, images, result bodies, passwords, or keys. Up to ten MetricKit crash payloads may be retained locally for reliability diagnostics. FlowBox does not track you across apps or websites.
06
Third-party services
Subscriptions and credit-pack purchases are handled through Apple StoreKit. Sign in with Apple credentials are supplied by Apple and, when cloud services are configured, exchanged for a FlowBox session. On-device language resources are managed by Apple Translation. The current cloud AI provider is DeepSeek V4 Flash (api.deepseek.com) and it processes necessary content only when you invoke the related feature; its service region, retention, and security terms are governed by DeepSeek's official terms.
07
Your controls and deletion
You can delete an individual result, content item, project, or all history, and you can export your data. Account deletion first requests removal of the cloud account, files, derived results, and associated data, then clears local credentials, caches, offline queue, projects, tasks, and preferences. If server deletion fails, local data is retained so you can retry.
08
Children, retention, and security
FlowBox is not directed to children and does not knowingly collect children's data. Cloud data is retained only as needed to provide the service, meet legal obligations, and resolve disputes. Safeguards include encrypted transport, device file protection, Keychain storage, idempotent requests, and minimized logs, though no system can guarantee absolute security.
09
Updates and contact
We update the effective date when this policy changes and provide a prominent in-app or website notice for material changes. For privacy, access, or deletion requests, contact admin@xinghebit.com. Operator: Beijing XingheBit Science & Technology Development Co., Ltd.