OraFlow Privacy Policy
OraFlow helps turn your WhatsApp messages and voice notes into Google Calendar drafts.
What we collect
- Your WhatsApp number
- Messages you send to OraFlow
- Voice note transcriptions
- Calendar drafts OraFlow creates
- Basic usage and error data to keep the service working
What we do not store
OraFlow does not store raw voice note audio files. Audio is processed temporarily for transcription and then deleted.
Google Calendar data
If you connect Google Calendar, OraFlow may access your calendar availability, upcoming events, timezone, and calendar metadata so it can draft realistic schedules, warn about conflicts, show pending OraFlow-created events, and create events only after you approve a draft.
OraFlow does not add events until you reply YES. OraFlow does not sell Google user data, use it for advertising, or use it to train non-OraFlow models.
How Google user data is shared
OraFlow shares or transfers Google user data only when necessary to provide and secure the calendar features you request. We do not sell Google user data or share it with advertising platforms, data brokers, or information resellers.
- Google: OraFlow exchanges OAuth credentials and Calendar API requests with Google to connect your account, read calendar information, create events you approve, and remove OraFlow-created events when you request an undo.
- Supabase: OraFlow stores encrypted Google OAuth tokens, your OraFlow account record, calendar drafts, and records needed to make approved calendar writes reliable and prevent duplicates.
- Railway: OraFlow’s application and background worker run on Railway, where Google Calendar requests and responses are processed to provide the service.
- Twilio and WhatsApp: Calendar previews, conflict warnings, pending-event summaries, confirmations, and errors may be delivered to you through Twilio’s WhatsApp messaging service.
- Service administrators: OraFlow’s developer/admin may access limited Google Calendar status information and error logs when necessary to support users, investigate abuse, comply with law, or fix reliability and security problems.
OraFlow does not transfer Google user data to OpenAI, advertising platforms, data brokers, or information resellers. OraFlow does not allow other third parties to use Google user data for their own purposes. If OraFlow is involved in a merger, acquisition, or sale of assets, Google user data will be transferred only after obtaining any consent required by Google’s policies and applicable law.
How we protect sensitive data
- Google OAuth access and refresh tokens are encrypted using AES-256-GCM before they are stored.
- Data is transmitted between your browser, OraFlow, Google, and service providers using HTTPS/TLS encryption.
- Production credentials and encryption keys are kept in restricted environment variables and are not included in user-facing messages or application source code.
- Access to production systems and Google user data is limited to authorized service components and administrators who need it for operation, support, security, or legal compliance.
- Calendar writes use unique idempotency keys to reduce accidental duplicate events, and OraFlow requires your explicit confirmation before creating events.
- Raw voice-note audio is processed temporarily, deleted after transcription, and not retained by OraFlow.
- Operational logs and user-facing errors are designed to avoid exposing OAuth tokens, API keys, and other credentials.
Data retention and deletion
OraFlow retains account details, encrypted Google OAuth tokens, messages, transcriptions, drafts, planning preferences, calendar-write records, and operational logs only for as long as reasonably necessary to provide, secure, troubleshoot, and improve the service or meet legal obligations. You can disconnect Google Calendar or request deletion of your OraFlow account and associated stored data by emailing useoraflow@gmail.com. We will delete or de-identify eligible data, subject to limited security, fraud-prevention, backup, and legal-retention requirements.
How we use your data
- To transcribe your voice notes
- To create calendar drafts
- To check calendar availability and avoid scheduling conflicts
- To add approved events to your Google Calendar
- To improve scheduling quality
- To debug errors and prevent abuse
Google API Services Limited Use
OraFlow’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Policy changes
If OraFlow changes how it uses Google user data or other personal data, this policy will be updated on this page. Material changes will be communicated in-product where appropriate.
Support and deletion
You can ask questions or request deletion of your data by emailing useoraflow@gmail.com.
Last updated: August 15, 2026. By using OraFlow, you agree to this privacy policy.