Privacy Policy
Last updated: August 24, 2026
The Exec Flow ("the App") is operated by Victoria Exec Agency ("we", "us"). This policy explains what information the App collects, how it is used, and the choices you have.
Information we collect
- Account information. Your name and email address when you create an account, plus your selected plan and subscription status.
- Work data you enter. Clients, tasks, scheduled blocks, time entries, reminders, and notes you create inside the App.
- Calendar data (optional). If you connect Google Calendar or Outlook, we read event titles, times, and calendar names so your meetings appear alongside your tasks. We request read-only access and never create, edit, or delete your events.
- Technical data. Basic log and device information needed to keep the service running and secure.
How we use information
- To provide the daily dashboard, tasks, calendar, time log, and reminders.
- To authenticate you and enforce the limits of your plan.
- To process subscription purchases, renewals, and cancellations.
- To respond to support requests you send us.
We do not sell your personal information, and we do not use your data to train machine learning models.
Google user data
The App's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only to display your schedule inside the App. It is not shared with third parties, not used for advertising, and not read by humans except when you ask us to troubleshoot or when required by law. You can disconnect a calendar at any time from the Integrations page, which removes the stored connection and clears the cached events from your device.
Data protection for sensitive data
The App requests two sensitive Google scopes: Gmail (gmail.send) to send documents and messages you explicitly compose inside the App — we never read, search, or store your existing mailbox contents, and this scope cannot access or delete emails — and Google Calendar (calendar.readonly) to display your events inside the App's dashboard; we cannot create, edit, or delete events with this access.
To protect this data we encrypt it in transit (TLS) and encrypt OAuth tokens at rest; limit access to the minimum systems and staff needed to run the App, with no one reviewing your email or calendar content except when you request troubleshooting help or as required by law; retain tokens and cached data only while your integration stays connected, deleting them immediately when you disconnect from the Integrations page; never use this data to train models or share it for advertising; and follow Google's API Services User Data Policy, including Limited Use. You can also revoke access anytime at myaccount.google.com/permissions.
Storage, sharing, and security
Your data is stored with our hosting and database providers, and access tokens for connected calendars are encrypted at rest. We share information only with service providers that help us operate the App (hosting, database, authentication, and payment processing), or when required by law.
Retention and your choices
You can edit or delete your clients, tasks, and time entries at any time. You may request deletion of your account and associated data by emailing us; we will action the request within a reasonable period, except where we must retain records for legal or accounting reasons.
Children
The App is intended for business use and is not directed at children under 13.
Changes
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.
Contact
Victoria Exec Agency — victoriasvahub@gmail.com